Delta Chat adalah aplikasi obrolan baru yang mengirim pesan melalui email, diekripsi jika memungkinkan, dengan Autocrypt Anda tidak harus mendaftar di mana saja, cukup gunakan akun email Anda yang ada dengan Delta Chat.
Dengan Delta Chat, anda dapat mengetik ke semua alamat email yang ada - meskipun si penerima tidak menggunakan aplikasi Delta Chat. Tidak perlu bagi penerima untuk menginstal aplikasi yang sama seperti milik Anda, seperti halnya dengan messenger-messanger lain.
By default, Delta Chat shows all e-mails.
At “Settings -> Chats & Media -> Show Classic E-Mails”, you can change this. You have these options:
Ya, Di samping teks biasa, semua lampiran email ditampilkan sebagai pesan terpisah. Pesan keluar mendapatkan lampiran sesuai kebutuhan secara otomatis.
For performance, images are optimized and sent at a smaller size by default, but you can send it as a “file” to preserve the original.
You can easily work with additional accounts on Delta Chat mobile and desktop clients by clicking either:
You may also wish to learn how to add accounts to multiple devices.
Anda dapat menambahkan gambar profil di pengaturan Anda. Jika Anda menulis ke kontak Anda atau menambahkannya melalui kode QR, mereka secara otomatis melihatnya sebagai gambar profil Anda.
Contacts who don’t use Delta Chat do not see the profile picture (however, of course, they can install Delta Chat :)
Untuk alasan kerahasiaan, tidak ada satupun yang dapat melihat Foto Profil anda hingga anda menulis sebuah pesan kepada mereka.
Gambar profil Anda tidak dikirim dengan setiap pesan, tetapi cukup secara teratur kontak Anda akan menerima kembali gambar profil Anda, bahkan jika mereka menambahkan yang perangkat baru
Seperti program E-Mail lainnya seperti Thunderbird, K9-Mail, atau Outlook, program membutuhkan kata sandi sehingga Anda dapat menggunakannya untuk mengirim email. Tentu saja, kata sandi hanya disimpan di perangkat Anda. Kata sandi hanya dikirimkan ke penyedia E-Mail Anda (saat Anda login), yang tetap memiliki akses ke email Anda.
Jika Anda menggunakan penyedia E-Mail dengan dukungan OAuth2 seperti gmail.com atau yandex.ru, tidak perlu menyimpan kata sandi Anda di perangkat. Dalam hal ini, hanya token akses digunakan.
Karena Delta Chat adalah Open Source, Anda dapat memeriksa file Source Code jika Anda ingin memverifikasi bahwa kredensial Anda ditangani dengan aman. Kami bahagia tentang umpan balik yang membuat aplikasi lebih aman untuk semua pengguna kami.
Tergantung operasi sistem yang digunakan, Anda mungkin diminta untuk memberikan izin ke aplikasi. Inilah yang dilakukan Delta Chat dengan izin ini:
Use these tools to organize your chats and keep everything in its place:
Pinned chats always stay atop of the chat list. You can use them to access your most loved chats quickly or temporarily to not forget about things.
Mute chats if you do not want to get notifications for them. Muted chats stay in place and you can also pin a muted chat.
Archive chats if you do not want to see them in your chat list any longer. Archived chats remain accessible above the chat list or via search.
When an archived chat gets a new message, unless muted, it will pop out of the archive and back into your chat list. Muted chats stay archived until you unarchive them manually.
To archive or pin a chat, long tap (Android), use the chat’s menu (Android/Desktop) or swipe to the left (iOS); to mute a chat, use the chat’s menu (Android/Desktop) or the chat’s profile (iOS).
Either delete yourself from the member list or delete the whole chat. If you want to join the group again later on, ask another group member to add you again.
As an alternative, you can also “Mute” a group - doing so means you get all messages and can still write, but are no longer notified of any new messages.
Yes. Delta Chat implements the Autocrypt Level 1 standard and can thus E2E-encrypt messages with other Autocrypt-capable apps.
Delta Chat also supports a strong form of end-to-end encryption that is even safe against active attacks, see “verified groups” further below.
Tidak ada.
Delta Chat apps (and other Autocrypt-compatible e-mail apps) share the keys required for end-to-end-encryption automatically as the first messages are sent. After this, all subsequent messages are encrypted end-to-end automatically. If one of the chat partners uses a non-Autocrypt e-mail app, subsequent messages are not encrypted until an Autocrypt-compliant app is available again.
If you want to rather avoid end-to-end-encrypted e-mails by default, use the corresponding Autocrypt setting in “Settings” or “Advanced settings”.
If you are within immediate distance of the chat partner:
If you are not near the chat partner, you can check the status manually in the “Encryption” dialog (user profile on Android/iOS or right-click a user’s chat-list item on desktop):
For end-to-end-encryption, Delta Chat shows two fingerprints there. If the same fingerprints appear on your chat partner’s device, the connection is safe.
For transport encryption, this state is just shown there
A little padlock shown beside a message denotes whether the message is end-to-end-encrypted from from the given sender.
If there is no padlock, the message is usually transported unencrypted e.g. because you or the sender have turned off end-to-end-encryption, or the sender uses an app without support for end-to-end-encryption.
The best way to ensure every message is encrypted, and metadata deleted as quickly as possible is creating a verified group and turning on self-destructing messages.
Verified groups are always encrypted and protected against MITM attacks.
Metadata can’t be encrypted, as the server needs to know where to deliver your messages. But turning on “self-destructing messages” deletes the messages on the server after they were delivered.
If you need the messages on your device, but not on the server, you can also agree in the group to turn on “delete messages from server automatically”.
If you want to protect a 1:1 conversation like this, you should create a verified group with only 2 people. If the other person loses their device but not their account, you can still communicate in the 1:1 chat. (Read more)
Autocrypt is used for establishing e2e-encryption with other Delta Chat and other Autocrypt-capable mail apps. Autocrypt uses a limited subset of OpenPGP functionality.
Delta Chat implements countermitm setup-contact and verified-group protocols to achieve protection against active network attacks. This goes beyond the opportunistic base protection of Autocrypt Level 1, while maintaining its ease of use.
1:1 chats with a verified contact and verified groups are not the same, even if there are only 2 people in the verified group. One difference is that you could easily add more people to the group, but there are other implications as well.
Verified groups are invariably secured. Any breakage (cleartext or wrongly signed messages etc.) will be flagged and such messages will not be shown in this chat. You can trust all messages in this verified-checkmark chat to have not been read/altered by middle parties.
1:1 chats are opportunistic, it is meant to allow people to communicate no matter if they change e-mail clients, devices, setups etc. That’s why there is no verification checkmark, even if you have verified the contact.
No, OpenPGP doesn’t support Perfect Forward Secrecy. Perfect Forward Secrecy works session-oriented, but E-Mail is asynchronous by nature and often used from multiple devices independently. This means that if your Delta Chat private key is leaked, and someone has a record of all your in-transit messages, they will be able to read them.
Note that if anyone has seized or hacked your running phone, they will typically be able to read all messages, no matter if Perfect Forward Secrecy is in place or not. Having access to a single device from a member of a group, will typically expose a lot of the social graph. Using e-mail addresses that are not easily tracked back to persons helps group members to stay safer from the effects of device seizure.
We are sketching ways to protect communications better against the event of device seizure.
As Delta Chat is a decentralized messenger, the metadata of Delta Chat users are not stored on a single central server. However, they are stored on the mail servers of the sender and the recipient of a message.
Each mail server currently knows about who sent and who received a message by inspecting the unencrypted To/Cc headers and thus determine which e-mail addresses are part of a group. Delta Chat itself could avoid unencrypted To/Cc headers quite and always put them only into the encrypted section. See Avoid sending To/CC headers for verified groups. For opportunistic chats the main concern is how it affects other mail apps who might participate in chats.
Many other e-mail headers, in particular the “Subject” header, are end-to-end-encryption protected, see also this upcoming IETF RFC.
Yes. The best way is to send an Autocrypt Setup Message from the other e-mail client. Look for something like Start Autocrypt Setup Transfer in the settings of the other client and follow the instructions shown there.
Alternatively, you can import the key manually in “Settings -> Advanced settings -> Import secret keys”. Caution: Make sure the key is not protected by a password, or remove the password beforehand.
If you don’t have a key or don’t even know you would need one - don’t worry: Delta Chat generates keys as needed, you don’t have to hit a button for it.
The most likely cause is that your key is encrypted and/or uses a password. Such keys are not supported by Delta Chat. You could remove the passphrase encryption and the password and try the import again. If you want to keep your passphrase you’ll have to create an e-mail alias for use with Delta Chat such that Delta Chat’s key is tied to this e-mail alias.
Delta Chat supports common OpenPGP private key formats, however, it is unlikely that private keys from all sources will be fully supported. This is not the main goal of Delta Chat. In fact, the majority of new users will not have any key prior to using Delta Chat. We do, however, try to support private keys from as many sources as possible.
Removing the password from the private key will depend on the software you use to manage your PGP keys. With Enigmail, you can set your password to an empty value in the Key Management window. With GnuPG you can set it via the command line. For other programs, you should be able to find a solution online.
Yes. Delta Chat 1.36 comes with a new, experimental function for using the same account on different devices:
On the first device, go to Settings → Add Second Device, unlock the screen if needed and wait a moment until a QR code is shown
On the second device, install Delta Chat
On the second device, start Delta Chat, select Add as Second Device, and scan the QR code from the old device
Transfer should start after a few seconds and during transfer both devices will show the progress. Wait until it is finished on both devices.
In contrast to many other messengers, after successful transfer, both devices are completely independent. One device is not needed for the other to work.
Double-check both devices are in the same Wi-Fi or network
Your system might have a “personal firewall”, which is known to cause problems (especially on Windows). Disable the personal firewall for Delta Chat on both ends and try again
Ensure there is enough storage on the destination device
If transfer started, make sure, the devices stay active and do not fall asleep. Do not exit Delta Chat. (we try hard to make the app work in background, but systems tend to kill apps, unfortunately)
Delta Chat is already logged in on the destination device? You can use multiple accounts per device, just add another account
If you still have problems or if you cannot scan a QR code try the manual transfer described below
This method is only recommended if “Add Second Device” as described above does not work.
Sending a copy of your messages to yourself ensures that you receive your own messages on all devices. If you have multiple devices and don’t turn it on, you see only the messages from other people, and the messages you send from the current device.
The copy is sent to the Inbox, and then moved to the DeltaChat folder; it’s not put into the “Sent” folder. Delta Chat never uploads anything to the Sent folder because this would mean uploading a message twice (once through SMTP, and once through IMAP to Sent folder).
The default setting for copy-to-self is “no”.
The only reason one wants to watch the Sent folder is if you are using another mail program (like Thunderbird) next to your Delta Chat app, and want your MUA to participate in chat conversations.
However, we recommend using the Delta Chat Desktop Client; you can download it on get.delta.chat. The option to watch the “Sent” folder might go away in the future. It was introduced at a time where there was no Delta Chat Desktop client available on all platforms.
Some people use Delta Chat as a regular email client, and want to use the Inbox folder for their mail, instead of the DeltaChat folder. If you disable “Watch DeltaChat folder”, you should also disable “move chat messages to DeltaChat”. Otherwise, deleting messages or multi-device setups might not work properly.
In Delta Chat, you can share “private apps”, attachments with an .xdc
file
extension. They can do very different things, and make Delta Chat a truly
extendable messenger. The technical term is webxdc.
We are very grateful about feedback on these features - do you want to share your ideas? Join the Forum to contribute. (You like experiments? Register through “Sign up -> with Delta Chat”!)
https://meet.jit.si/$ROOM
. The $ROOM
variable will be a random value;
this way, you will have a new random jitsi room every time you call someone.A verified group is a chat that guarantees safety against an active attacker. All Messages in a verified chat view are e2e-encrypted, and members can join by scanning a “QR invite code”. All members are thus connected with each other through a chain of invites, which guarantee cryptographic consistency against active network or provider attacks. See countermitm.readthedocs.io for the R&D behind this feature.
As of Oct 2022, “verified groups” remain an experimental feature. It is continuously improved and many bugs have been fixed since the original introduction in 2018. However, there remain cases, especially with large groups where inconsistencies can occur, or messages become unreadable.
This is an experimental setting for some people who are experimenting with server-side rules. Not all providers support this, but with some you can move all mails with a “Chat-Version” header to the DeltaChat folder. Normally, this would be done by the Delta Chat app.
Enabling “Only Fetch from DeltaChat folder” makes sense if you have both:
In this case, Delta Chat doesn’t need to watch the Inbox, and it’s enough to only watch the DeltaChat folder.
To learn about the details behind this, read our blogpost on it.
The Delta Chat project underwent three independent security audits in the last years:
In 2019, Include Security analyzed Delta Chat’s PGP and RSA libraries. It found no critical issues, but two high-severity issues that we subsequently fixed. It also revealed one medium-severity and some less severe issues, but there was no way to exploit these vulnerabilities in the Delta Chat implementation. Some of them we nevertheless fixed since the audit was concluded. You can read the full report here.
In 2020, Include Security analyzed Delta Chat’s Rust core, IMAP, SMTP, and TLS libraries. It did not find any critical or high-severity issues. The report raised a few medium-severity weaknesses - they are no threat to Delta Chat users on their own because they depend on the environment in which Delta Chat is used. For usability and compatibility reasons, we can not mitigate all of them and decided to provide security recommendations to threatened users. You can read the full report here.
Beginning 2023, Cure53 analyzed both the transport encryption of Delta Chat’s network connections and a reproducible mail server setup as recommended on this site. You can read more about the audit on our blog or read the full report here.
Delta Chat does not receive any Venture Capital and is not indebted, and under no pressure to produce huge profits, or to sell users and their friends and family to advertisers (or worse). We rather use public funding sources, so far from EU and US origins, to help our efforts in instigating a decentralized and diverse chat messaging eco-system based on Free and Open-Source community developments.
Concretely, Delta Chat developments have so far been funded from these sources:
The NEXTLEAP EU project funded the research and implementation of verified groups and setup contact protocols in 2017 and 2018 and also helped to integrate End-to-End Encryption through Autocrypt.
The Open Technology Fund gave us a first 2018/2019 grant (~$200K) during which we majorly improved the Android app and released a first Desktop app beta version, and which moreover moored our feature developments in UX research in human rights contexts, see our concluding Needfinding and UX report. The second 2019/2020 grant (~$300K) helped us to release Delta/iOS versions, to convert our core library to Rust, and to provide new features for all platforms.
The NLnet foundation granted in 2019/2020 EUR 46K for completing Rust/Python bindings and instigating a Chat-bot ecosystem.
In 2021 we received further EU funding for two Next-Generation-Internet proposals, namely for EPPD - e-mail provider portability directory (~97K EUR) and AEAP - email address porting (~90K EUR) which resulted in better multi-account support, improved QR-code contact and group setups and many networking improvements on all platforms.
For 2021/2022 we are receiving Internet Freedom funding (~500K USD) from the U.S. Bureau of Democracy, Human Rights and Labor (DRL). This funding supports our long-running goals to make Delta Chat more usable and compatible with a wide range of e-mail servers world-wide, and more resilient and secure in places often affected by internet censorship and shutdowns.
Sometimes we receive one-time donations from private individuals for which we are grateful. For example, in 2021 a generous individual bank-wired us 4K EUR with the subject “keep up the good developments!”. We use such money to fund development gatherings or to care for ad-hoc expenses that can not easily be predicted for or reimbursed from public funding grants.
Last but by far not least, several pro-bono experts and enthusiasts contributed and contribute to Delta Chat developments without receiving money, or only small amounts. Without them, Delta Chat would not be where it is today, not even close.
The monetary funding mentioned above is mostly organized by merlinux GmbH in Freiburg (Germany), and is distributed to more than a dozen contributors world-wide.
Funding for second half of 2022 and especially for 2023 is an ongoing issue of concern. Apart from applying for more public funding we want to become more independent from government-related funding sources. Please see Delta Chat Contribution channels for both monetary and development related support possibilities.