Live data from Hacker News

Reflections: The ecosystem is moving

whispersystems.org

61–70 of 103 posts

Re: Reflections: The ecosystem is moving

#61

Earlier quoted context omitted.

I was using Signal, too. One day it phoned home, got some new instructions from its creators, refused to work any longer, and demanded that I download an upgrade. I was not excited about this, since upgrades generally break things, but after a few days of grumbling I knuckled under. Sure enough, the upgrade is broken: it insists that I have to upgrade Google Play Services, which I can't do, because I deleted it along…

Wisper's arguement here is basicly: you don't matter, and we arn't going to do anything to help you. And due to their walled garden, you can't do anything to help yourself either. so much for "open source infrastructure for a centralized network now provides almost the same level of control as federated protocols" Unless you mean control for Google.

Signal is open source, so you can just fork it to remove the dependency on GCM.

In fact, someone already has, so you can just use it: https://fdroid.eutopia.cz/

Re: Reflections: The ecosystem is moving

#62
This is very confusing and the argument don't hold very much. It looks sadly more like a justification against making the effort, which he has a right to not want to attempt, but doesn't make sense.

The real issue is how can we have an open governance model that moves protocol forward a lot faster and it seems that with a little imagination we could tackle most of the pain points. So maybe we should fix the infrastructure instead of celebrating silos that don't talk to each other even when using the same protocols?

Re: Reflections: The ecosystem is moving

#63
I'm largely sympathetic to Moxie's core arguments, and to the extent that I disagree, it's his prerogative to do what he thinks is best with his project.

I will point out that some people are using "federated" and "decentralized" as synonyms, when they are distinct concepts. The Tor network, for example, is decentralized, but not federated. You can run your own Tor node, but that node has to be accepted by the directory authorities in order to become a part of the network. You could conceivably set up your own Tor network, with your own directory authorities, but of course you can also create your own alternative network with Signal, since both the client and server code are free software.

Ricochet, the messenger that uses client-side Tor hidden services to create server-less chat, is also decentralized, but not federated. Ricochet clients talk to other Ricochet clients. There is not IETF RFC out there for Tor or Ricochet, that you can use to build your own implementation and federate into the network.

Moxie's claim that federation inevitably leads to moribund cruft may be over-stated; after all, http is not exactly in trouble. Nevertheless, I think that it's probably true that maintaining a federated protocol that is also an easy, seamless, user-facing piece of software is most likely a tall order.

Re: Reflections: The ecosystem is moving

#64

In general I agree with @moxie's arguments, however I've come to to be wary at his condescending attitude and discontent towards people disagreeing with his choices. Like there's a review on the Android Signal app complaining that it asks for too many permissions, and it does ask for an arm, a leg and your soul, with the reply being unprofessional imho. I understand that this is open-source, but if you publish it and…

I think you're really missing the point here.

> Moxie says that email is frozen, being why it is unencrypted, blaming the lack of progress on it being federated. But you know, I'm willing to bet that in 10 years from now WhatsApp and Slack will be both dead, just like Yahoo Messenger and ICQ before them, while email and IRC will still be around.

Yes, and email will still be unencrypted, while the WhatsApps and Slacks of the future will probably be encrypted end-to-end.

> And I think that email is unbeatable, because it is federated, because it's governed by standards and because in spite of all constraints, it's quite adaptable, being the kind of platform supporting short term proprietary solutions because (and not in spite of) its client/server decoupling.

It's not adaptable enough to introduce meaningful encryption to it.

Re: Reflections: The ecosystem is moving

#65
post #24
post #8

Some relevant background information on this issue: https://github.com/LibreSignal/LibreSignal/issues/37

Interesting discussion.

I don't understand how Guardian were unable to obtain a license to use Signal/Axolotl in Chatsecure. The libraries on Github are GPL3, is there some missing IP I'm not aware of?

Also it saddens me that LibreSignal is effectively dead now, along with any future third-party clients. I think forking the Signal server and (later) adding federation could spark a community of free and secure messenger apps for the 21st century.

Even if that means starting with an empty user base. After all, most of my contacts with Signal only ever use it to contact me, it wouldn't be difficult to convince them to change app.

Re: Reflections: The ecosystem is moving

#66
post #61

Earlier quoted context omitted.

Wisper's arguement here is basicly: you don't matter, and we arn't going to do anything to help you. And due to their walled garden, you can't do anything to help yourself either. so much for "open source infrastructure for a centralized network now provides almost the same level of control as federated protocols" Unless you mean control for Google.

Signal is open source, so you can just fork it to remove the dependency on GCM. In fact, someone already has, so you can just use it: https://fdroid.eutopia.cz/

Open Whisper Systems have asked LibreSignal to stop using their servers and may decide to shut it out.

See https://github.com/LibreSignal/LibreSignal/issues/37 and discussion upthread.

Re: Reflections: The ecosystem is moving

#67

In general I agree with @moxie's arguments, however I've come to to be wary at his condescending attitude and discontent towards people disagreeing with his choices. Like there's a review on the Android Signal app complaining that it asks for too many permissions, and it does ask for an arm, a leg and your soul, with the reply being unprofessional imho. I understand that this is open-source, but if you publish it and…

> And I think that email is unbeatable, because it is federated, because it's governed by standards and because in spite of all constraints, it's quite adaptable, being the kind of platform supporting short term proprietary solutions because (and not in spite of) its client/server decoupling.

E-mail's biggest problem is that many, many, many people get it wrong either through configuration snafus or a holier-than-thou approach to how it talks to other servers. It's a miracle that it has managed to function as well as it has; and has done so only only out of sheer necessity.

The problems that e-mail face are the problems that Moxie doesn't want to deal with. If other people want to go for a protocol that has interoperability that's fine, but he wants no part in it. He has no obligation to provide a service to clients he doesn't want connecting and he's right to demand that those who use "Signal" in their name cease its use so to not confuse their attempts with his own.

We already saw a revolt when Signal (when it was known as "TextSecure") went away from its SMS model to a client-server one, leading to a version that still relies on SMS. The point of switching away was to further remove metadata that otherwise would have become exposed. This demonstrates that the type of people who want to go against Moxie's wishes are the type that are to get this implemented incorrectly.

> Is it unencrypted? Sure, but it doesn't matter though. Because we are willingly trading that for a capable search engine and a good web interface. Trade secrets aren't communicated over email anyway.

Your username should be enough to tell you that trade secrets are traded over e-mail routinely.

A multitude of inappropriate material that should not be shared via e-mail is done so on a regular basis. If you work at any company that has credit card numbers being used for either expenses or customer details, you'll quickly find that with a search for 16-digit strings within e-mails will give results.

The problem you're neglecting to acknowledge here is that data at rest can be left unencrypted but overall has no business being unencrypted when in transit. If data from party A is meant for party B (and C, D, E, F, and so on) then any party that is not involved has no business knowing about its contents other than where it is destined to--and even that is questionable.

Those who favour convenience over security are part of a huge problem that faces the Internet.

> I think Moxie is missing the point. He's emulating WhatsApp, but you can't beat WhatsApp at their own game. Did WhatsApp really deliver encryption to 1 billion users? Well, those are 1 billion users that probably won't use Signal or chat with Signal users. Oops.

Moxie isn't trying to beat WhatsApp at its game; he in fact went and improved it by incorporating aspects of Signal into it [1]. Signal is meant to be something else and not something to directly compete with WhatsApp on. Signal and WhatsApp cater to different groups and markets.

[1] https://whispersystems.org/blog/whatsapp-complete/

Re: Reflections: The ecosystem is moving

#68
post #6

I'll add my thoughts here, since I think a number of people will be disappointed in this post. There are a number of competing goals when developing software that "the whole world can/will use". And it seems obvious to me that getting the whole world to use a secure, encrypted messenger like Signal (now, Whatsapp) is a noble goal. The obvious competing goal is federation, and the fact that we've failed at improving f…

It's precisely the fact that Moxie is so credible on this topic that makes his post so frustrating. I believe that he's telling the truth as he sees it, and I believe that he's as well-situated as anyone could be to pull off a white-hat secure messaging system, so if he says it can't be done with federation, it's awfully hard for me to assert that he's wrong. The problem is that I don't see the point of doing any of…

"It's precisely the fact that Moxie is so credible on this topic that makes his post so frustrating."

Exactly. He's right. And it sucks.

It's especially annoying for messaging. There are now all these messaging apps that don't interoperate. If you're on WhatsApp and the other party is on Telegram, the message doesn't get through. It's like the early days when MCIMail and CompuServ didn't talk. But if you don't have a walled garden with broken glass on top of the walls, you can't monetize messaging.

Re: Reflections: The ecosystem is moving

#69
There's a sort of resignation about the tone here, both in the article and the comments, which is very depressing.

Let's take that punch, roll with it, and redirect its energy. If centralized efforts, much like BDFLs, are looking like a good option for development cycles, okay. How can we wield that knowledge, but also build lifecycles around it that can help us buy back the powers and critical freedoms of federated systems?

Re: Reflections: The ecosystem is moving

#70
Moxie: there's a third alternative to centralization and federation which nobody is talking about on this thread: P2P. I'd be interested to hear your thoughts on what pitfalls someone (me) might encounter trying to implement a peer-based messaging system. I've got a lot of learning to do before I feel qualified to actually write code for such a project, but it's something I'm actively working toward.
Post reply on HN