# Recommend Molly alongside Signal

**URL:** https://discuss.privacyguides.net/t/recommend-molly-alongside-signal/17597
**Category:** Site Development
**Tags:** completed
**Created:** 2024-03-30T18:32:52Z
**Posts:** 24

## Post 1 by @jerm — 2024-03-30T18:32:52Z

Instead of just adding a link at the bottom “Signal Configuration and Hardening”

Molly has a really great track record with almost immediate updates with Signal upstream.

it is also recommended by GOS [https://twitter.com/GrapheneOS/status/1769277147569443309](https://twitter.com/GrapheneOS/status/1769277147569443309)

\< volunteer note: changed the title from “Recommend Molly instead of Signal” to “Recommend Molly alongside Signal” to represent the actual change made to the site for any readers passing by \>

---

## Post 2 by @Equinox — 2024-03-30T20:37:48Z

While I generally think Molly is safe, it’s yet another party you have to put your trust in. Also, if you like the original software, you should probably use that or sponsor it, instead of a fork, so the project keeps getting maintained.

---

## Post 3 by @jerm — 2024-03-31T00:28:55Z

> [@Equinox](#):
>
> you should probably use that or sponsor it, instead of a fork

Molly forked Signal because Moxie (signal dev) didn’t want to implement local database encryption because “it will be stored in memory forever at first unlock” which Molly dev proved him wrong [Signal vs Molly vs Molly-FOSS - GrapheneOS Discussion Forum](https://discuss.grapheneos.org/d/8976-signal-vs-molly-vs-molly-foss/7) and with a lot of other features.

---

## Post 4 by @Regime6045 — 2024-04-02T16:24:15Z

The real killer feature of Molly is that it uses much less battery to get notifications without Play Services.

---

## Post 5 by @Privasix — 2024-04-02T16:45:39Z

The devs of Signal posted [this](https://github.com/signalapp/Signal-Android/issues/9966#issuecomment-681943985) shady comment about such forks, so I don’t think recommending Molly is good idea, even if it is somehow better.

> **In case comment will be removed:**
>
> #Quote
> 
> Hey there! Just some background on the website release: it was never intended to be completely free of any Google Play dependencies – instead, all our builds have a fallback such that during registration, if we detect there’s no Play Services, we will fallback to using a websocket for notifications. Using FCM for notification delivery still provides the most reliable user experience and is something we’d prefer to use if the user has Play Services available on their device.
> 
> Concerning F-Droid, we already providing an auto-updating APK directly from our site, and we really don’t want forked versions of the app maintained by other parties connecting to our servers. Not only could the users using the forked version have a subpar experience, but the people they’re talking to (using official clients) could also have a subpar experience (for example, an official client could try to send a new kind of message that the fork, having fallen out of date, doesn’t support). I know you say you’d advocate for a build expiry, but you know how things go. Of course you have our full support if you’d like to fork Signal, name it something else, and use your own servers.
> 
> I think the rest of the discussion can happen on [#9644](https://github.com/signalapp/Signal-Android/pull/9644). Thanks!
> 
> #Archive link:
> 
> [Link](https://web.archive.org/web/20240108105548/https://github.com/signalapp/Signal-Android/issues/9966#issuecomment-681943985)

---

## Post 6 by @dngray — 2024-04-02T17:52:17Z

One of the reasons I’m kind of against this is because people should know that Molly uses the Signal network and isn’t just based off it. Signal has strong branding and I don’t think we should confuse people by pretending Molly is something else entirely.

Without Signal, Molly would not exist not just development wise but in the physicals sense too.

It did however get moved off into the blog article about [hardening Signal though](https://www.privacyguides.org/en/real-time-communication/#signal).

---

## Post 7 by @jerm — 2024-04-02T17:59:47Z

well you could just base of the Signal description to recommend using Molly client.

And documented the reasons.

---

## Post 8 by @jonah — 2024-04-03T01:14:14Z

We’re definitely not going to recommend Molly instead of Signal, but I think we could probably add it in to Signal’s listing the same way we list [Vaultwarden](https://www.privacyguides.org/en/passwords/#bitwarden).

---

## Post 9 by @dngray — 2024-04-03T01:39:01Z

> [@jonah](#):
>
> Signal’s listing the same way we list [Vaultwarden](https://www.privacyguides.org/en/passwords/#bitwarden)

That’s what I had in mind.

---

## Post 10 by @jerm — 2024-04-11T18:02:29Z

@jonah @dngray Mentioning that you don’t have to use your real phone number and that VoIP works fine with Signal at [The Best Private Instant Messengers - Privacy Guides](https://www.privacyguides.org/en/real-time-communication/#signal) is important imo.

---

## Post 11 by @jerm — 2024-08-22T11:55:52Z

Features that Molly has but Signal lacks:

1. Uses OpenStreetMap for maps and not Google maps unlike Signal.

2. Supports UnifiedPush for Push notifications. If you got no Play services on your phone, Molly falls back to WebSocket which is [more efficient than Signal and drains less battery power](https://xcancel.com/GrapheneOS/status/1814821600794927290#m).

3. ( **Fully FOSS** ) Contains no proprietary blobs, unlike Signal ( **Molly-FOSS** version).

4. ( **Local encryption** ) Protects database with [passphrase encryption](https://github.com/mollyim/mollyim-android/wiki/Data-Encryption-At-Rest).

5. ( **Automatic locking** ) Locks down the app automatically when you are gone for a set period of time.

6. ( **RAM Shredding** ) Securely shreds sensitive data from RAM.

7. ( **Backup scheduling** ) Automatic backups on a daily or weekly basis.

8. Supports SOCKS proxy and Tor via Orbot. Before you say Signal supports “proxy” it is [just for their TLS signal server proxies](https://github.com/signalapp/Signal-Android/issues/13045#issuecomment-1625342774).

And [a lot more](https://github.com/mollyim/mollyim-android?tab=readme-ov-file#features)…

What Molly is working on or planning to work on:

1. Use a private crypto wallet (Monero) for payments integrated in app, unlike MobileCoin that is currently in Signal app [that is](https://xcancel.com/resistancemoney/status/1480885572004503553?s=21) a well known [scam](https://xcancel.com/sethisimmons/status/1379791201558278144?s=21).

2. Remote attestation (based on auditor)

3. Sandboxing WebRTC

4. Text only mode

It is actually funny how you think these features should be present in the official Android client as Signal “prioritizes privacy and security”, but Signal have clearly refused to implement any of those.

Molly devs are planning on getting an audit soon.

---

## Post 12 by @Pragmatic — 2024-08-22T12:09:40Z

The question I’m asking myself is why is Signal refusing to implement Molly’s features in their applications, even though they are widely requested by the community?

---

## Post 13 by @sha123 — 2024-08-22T12:15:29Z

> [@jerm](#):
>
> ( **Backup scheduling** ) Automatic backups on a daily or weekly basis.

For people who use Signal as their main messenger including sending videos and pictures, this can definitely be a plus. Unnecessarily having to backup 10+ GB each day sucks. There are no incremental backups in place in signal and only the option to do it every day or not at all.

---

## Post 14 by @anon48875053 — 2024-08-22T15:14:48Z

Because things like implementing stories and MobileCoin are more important. /s

---

## Post 15 by @anon63378630 — 2024-08-22T17:45:56Z

> [@jerm](#):
>
> Supports UnifiedPush for Push notifications.

This requires running the server counterpart as well: [GitHub - mollyim/mollysocket: MollySocket allows getting Signal notifications via UnifiedPush.](https://github.com/mollyim/mollysocket)

> [@jerm](#):
>
> Securely shreds sensitive data from RAM.

Anyone on GrapheneOS or 64-bit DivestOS will be using the GrapheneOS hardened memory allocator which zeros ram on free anyway.

> [@jerm](#):
>
> Remote attestation

Would love to see this, but I haven’t seen anyone actually start working on it yet.

* * *

(to be clear I think valldrac has done a great job with Molly over the years)

---

## Post 16 by @Tech-Trooper — 2024-08-22T19:38:52Z

I think molly is only available for android, right? No iOS or desktop app.

---

## Post 17 by @jerm — 2024-08-22T20:08:55Z

> [@anon63378630](#):
>
> This requires running the server counterpart as well: [GitHub - mollyim/mollysocket: MollySocket allows getting Signal notifications via UnifiedPush.](https://github.com/mollyim/mollysocket)

Yeah, I’m pretty sure a lot of people are using [MollySocket - adminForge](https://adminforge.de/services/mollysocket/)

> [@Tech-Trooper](#):
>
> I think molly is only available for android, right? No iOS or desktop app.

Yes.

---

## Post 18 by @anon80779245 — 2024-08-23T20:32:34Z

> [@Tech-Trooper](#):
>
> I think molly is only available for android, right? No iOS or desktop app.

Yes, but you can still use Signal desktop app even though you use Molly

---

## Post 19 by @jerm — 2024-08-24T06:20:04Z

But the Desktop app is insecure mess.

---

## Post 20 by @Ganther — 2024-08-24T06:29:33Z

Hopefully with the attention that Signal got over that quite recently, they will do something about it.

But as has been stated earlier, Mobilecoin is probably more important to them.

Personally, I would like Molly to make a browser plugin that works with Signal. That way you get the security updates of a browser rather than having to rely on updating Electron.

---

## Post 21 by @jerm — 2024-08-24T07:11:43Z

1. Never.

2. Yes.

3. What? how you can fit a whole chatting application into an extension? Also they are not that secure. Can be susceptible to targeted attacks as extensions auto-update without user interaction.

---

## Post 22 by @Ganther — 2024-08-24T11:25:55Z

> [@jerm](#):
>
> What? how you can fit a whole chatting application into an extension? Also they are not that secure. Can be susceptible to targeted attacks as extensions auto-update without user interaction.

Signal for desktop was originally a browser extension. It had the huge advantage that it was available literally everywhere a Chromium browser could be run.

Is take a potential auto update attack any day over Signal having the sandbox intentionally disabled for a decade.

---

## Post 23 by @jonah — 2024-08-24T14:58:46Z

This change is being made here:

> <https://github.com/privacyguides/privacyguides.org/pull/2729>
>
> Changes proposed in this PR:
> 
> - Move the Molly listing and other relevant part…s from the Signal Configuration and Hardening blog post to a listing under the Signal recommendation
> - Relevant discussion: https://discuss.privacyguides.net/t/recommend-molly-instead-of-signal/17597/8
> - Signal Config and Hardening post
> - Remove parts about Molly in the Signal blog post that were ported to the RTC recommendation page
> - Remove the Endpoint Security section
> - Reason: IMO, the advice given here is somewhat redundant with the advice given elsewhere on the website regarding mobile OSes.
> - Remove the Caveats section in the Molly section and move the relevant parts of it to the listing on the main site
> - Reword Molly description to emphasize that it still uses the Signal network (credit goes to dngray's [comment](https://discuss.privacyguides.net/t/recommend-molly-instead-of-signal/17597/6) in the above forum thread)
> - Sharpen some parts of both pages by including threat model labels and relevant links to the Common Threats page
> - Lowercase "Forward Secrecy" on the RTC page where appropriate
> 
> ## To Do
> - [x] Restructure and add introduction to Molly section in blog post
> 
> ---
> 
> 
> <summary>
> 
> 
> - [x] I agree to the terms listed below:
> <details><summary>Contribution terms (click to expand)</summary>
> 1) I am the sole author of this work.
> 2) I agree to grant Privacy Guides a perpetual, worldwide, non-exclusive, transferable, royalty-free, irrevocable license with the right to sublicense such rights through multiple tiers of sublicensees, to reproduce, modify, display, perform, relicense, and distribute my contribution as part of this project.
> 3) I have disclosed any relevant conflicts of interest in my post.
> 4) I agree to the Community Code of Conduct.
> </details>

---

## Post 24 by @Cyber-Typhoon — 2024-08-24T23:53:36Z

It seems a bit like Librewolf for Firefox.

---

## Post 25 by @redoomed1 — 2024-08-25T04:51:17Z

Closing this thread as the PR marked as solution has been merged
