Hi all, I am new to tails os. I am trying to set up xmpp over tor in tails os. I have read about services like jabber calyxinstitute and others, but don't know if any of them support .onion in 2025. Are there any recommended xmpp onion servers still active in 2025 that works well in tails? If anyone here is using pidgin inside tails, i would really appriciate any beginner friendly tips.
Thank y'all
If you want solid XMPP over Tor, avoid Pidgin it’s outdated and not great for privacy. Instead, use Gajim, which has better support for Tor and privacy features. Even better, consider running your own XMPP server with a .onion address That way, all your communication stays inside the Tor network, for anonymity and security. For beginners, start with Gajim on Tails and look up guides on setting up a personal onion XMPP server it’s worth the effort.
Use Gajim, not Pidgin better encryption and privacy support.
Always connect through Tor’s SOCKS5 proxy (127.0.0.1:9050) to prevent IP leaks.
Use an XMPP server with a .onion address or set up your own onion server for anonymity.
Enable OMEMO encryption for end-to-end security.
Avoid logging in with any personally identifying accounts or info.
It is not a standard for safety for a very long time. It is a medieval tech loved by the LEs for easiness of all metadata capture and potentially the MITM against the users. Move to more modern solutions.
SimpleX with Tor is probably the best option out there, I would say. Cwtch hasn't had any external audits, so we don't know if it's for sure the real deal.
Yep, SimpleX is the best coms tool out there. CWTCH didn't have any audits, true. But the background of the project is ideological - the queer people building the tool to communicate with their likes. The probability of intentional cracks is quite limited here. The unintentional ones are stil possible of course.
It always comes down to one's operation requirements. We advised few of our client orgs on Briar usage for their specific use case. And they are more than happy now , clearing up many red fields from their OpSec ;)
/u/jake0126 gave guide in his profile on how to setup