Sure, but « better than nothing » doesn’t make it the best. In the end, it’s a much worse look when wording it this way: « they sell your visit's information to google for profit »
It’s a bit odd for a « for privacy » distro to have this on their website
I’ve tried Signal, Session, Matrix and SimpleX and the most convenient one is Signal. Some will refuse to switch, some, the closest people to you, will agree but probably just for you, unless they see an interest in signal themselves
For WhatsApp users: I’m saying that they leak all the contacts to Meta/Facebook and use it for advertising and tracking, + sending to the US gov because we all know they share data
For discord users: they’re a bit known for not deleting things, and backed by Tencent (if I recall correctly) they could have a reason to start using messages for advertising or similar. They’re already using game activity data to push ads (or quests as they’re called). Based in the US so also probably leaks to the gov.
But most importantantly: I just ask if they’re really to have all their messages, and especially their private messages leaked to the public in case they get hacked. Including all images sent in PMs, and having those analyzed by some other companies as well (often for CP, but still, I’m not really ok with that). Some will say that they’re not, in this case alright, go switch to Signal! Some will say they are okay with it, and tbh they’re probably lying or underestimating the risks and the impact.
Discord is alright, but please, or all sensitive messages, please switch to an encrypted messenger.
I imagine you keep your password manager unlocked, or as not requiring 2FA on trusted devices then? Re entering 2FA each session is annoying
You still have the treat of viruses or similar. If someone gets access on your device while the password manager is unlocked (ex: some trojan on your computer), you’re completely cooked. If anything it makes it worse than not having 2FA at all.
If you can access your password manager without using 2FA on your phone and have the built in phone biometrics to open it like phone pin, finger or face, someone stealing your phone can do some damage. (Well, the same stands for a regular 2FA app, but meh, I just don’t see an improvement)
I have never understood the goal of passkeys. Skipping 2FA seems like a security issue and storing passkeys in my password manager is like storing 2FA keys on it: the whole point is that I should check on 2 devices, and my phone is probably the most secure of them all.
You publish source and respect the rules, you get paid. Easy, right?
Yet you didn’t publish the source and didn’t respect the rules, so don’t complain you didn’t get paid.