What are actual Delta Chat limitations?

I propose to list all current Delta Chat technical weaknesses/limitations that would prevent you to recommend DC instead of others (Signal, Matrix, Whatsapp, …)

The goal is to have an honest and transparent pictures of what you should not expect from Delta Chat right now. It is only technical.

Some items might be out of scope or voluntarily avoided. Others may be implemented later. The goal is not to lobby for some features but be clear about what you should expect or not.

(maybe this post could be edited to serve as a reference. )

General

Security/privacy

Groups

Channels

  • No way for channel owners to protect their identity/privacy. Channel members can always privately contact the profile which created the channel.
  • No way to share a channel you follow with someone else

General

  • Automatically reset the QR Code / invite link every time it is displayed (makes the QR Codes displayed “single-use” therefore makes leaking a permanently valid QR code impossible)
  • Also provide another QR Code / invite link which can serve as a permanent “V-card”

I suspect the contact ID (public profile) is not enough alone unless DC provides an API which turns a public profile into a (one-time) QR COde / invite link, and the DC apps are told how to use that API.

(but you can actually extract your “ID” from the invite link, see e.g. My Delta Chat profile fingerprint | Albert's pages )

I rephrased your points to explicit what is missing (not what you want) as

  • Not possible to revoke a QR/link invite. Any leak will be permanent.

From my perspective, there’s a security vulnerability in DC-Desktop.
Unlike other versions, no system password is required to create a backup or add an additional device.

DC has the advantage that profiles can use an unlimited number of devices simultaneously. However, it’s not possible to see how many devices are using a profile. Therefore, there’s a risk that an attacker (e.g., a toxic partner) who gains access to a laptop running DC-Desktop could add their own device to the profile. This means that the attacker can read everything and even send fake messages. The victim has no way of noticing this. A stalker’s dream.

Furthermore, many users are unaware of this vulnerability. The feature is called “add second device,” not “add additional device.” This lack of awareness contributes to the problem.

No: it is possible to revoke a QR Code (that’s the “reset” thing). What is not possible is to have it auto-revoke/auto-renew on each use.

How do you do that?

Indeed, this is a very important shortcoming that people must be aware of.

On the mobile app : from the main page, tap the QR code icon on the upper right next to the three-point menu. That displays your (current) QR code. Then tap the three-point menu on the upper right of that page, you’ll see three lines, the last of which is red and says “Reset the QR Code” (“réinitialiser le code QR”).

On the (Linux) desktop app, there does not seem to be a way to reset the QR code.

For mobile apps I suspect that is easy to implement through their password/pattern/fingerprint security features (that’s assuming the attacker cannot get through those, but then if they can, then the whole phone is insecure).

For the desktop app, that’s a bit more complicated, and probably requires implementing ad hoc password-based security, encrypting any on-disk file, and checking the password again on critical operations such as those you described.

Yes, that certainly involves more effort, but renaming the feature to “Add Additional Device” could actually help a bit. It would raise security awareness and also serve as good publicity. Many people believe that you can only use two devices per profile in DC.

I’d add the following to the list:

For groups, no way to use roles like admin, moderator.

One weakness to add to your list: Group invitation links require two round trips between the sender and the recipient, potentially leading to long periods of waiting to be added to a group. This is less convenient than Signal, which uses servers to handle group links so that you don’t have to wait twice for the invite sender in particular to open DeltaChat.

This issue is discussed in greater depth here:

https://support.delta.chat/t/user-stuck-at-waiting-to-be-added-to-group/5746

I still need to revisit that thread and figure out definitively whether e.g. the iOS app can complete the round trips without the user explicitly opening it.

Very similar topic:

It’s possible if you have the other person already in your contact list. Go to the group profile page (e.g., click on the header of the group) and select “Add members”.

Can be solved by the InviteBot (but I can see that this is not a solution for everyone)

Indeed, I missed that. Removing that line.

In my opinion, backing up without multiple devices is a problem. WhatsApp can back up to Google Drive transparently automatically (on Android. Maybe on iOS it does iCloud?)

(I think there should be some kind of “standard” to let apps have backing storage on configurable remote targets. It would be so cool if you could write easily apps that prompt you to choose some storage [Google Drive, but also Nextcloud or maybe even S3, etc.] to grant them access to a specific folder.)

Also note that some Delta Chat limitations might be mitigated by the ease or running multiple identities in a device. It seems easy to me to create throwaway identities for specific events (e.g. I’m selling something on the Internet, I’m going to some event, etc.) then discard them after a while- you can always send your real identity to contacts you want to keep.

While it’s true, this only works for case when you know in advance that some extra privacy is needed. The opposite is also true: I’ve created a second profile for a case when I pas a bit paranoid and now I regret it because I have to handle two “regular” profiles (and I would need to migrate all contacts from one to another, which is not possible because I manage groups in both profiles)

Question that might lead to a limitation: is there potential for messages to be deleted from your relay server if your device is offline for more days than messages are stored? (Standard for relays seems to be: “Messages are unconditionally removed latest 20 days after arriving on the server. Earlier, if storage may exceed otherwise.”)

If all your devices were offline for 30 days, for example, would you completely lose ability to access messages sent to you during that time? Or am I misunderstanding relay message storage?

Thanks!