Live data from Hacker News

Reflections: The ecosystem is moving

whispersystems.org

71–80 of 103 posts

Re: Reflections: The ecosystem is moving

#71
post #6

I'll add my thoughts here, since I think a number of people will be disappointed in this post. There are a number of competing goals when developing software that "the whole world can/will use". And it seems obvious to me that getting the whole world to use a secure, encrypted messenger like Signal (now, Whatsapp) is a noble goal. The obvious competing goal is federation, and the fact that we've failed at improving f…

It's precisely the fact that Moxie is so credible on this topic that makes his post so frustrating. I believe that he's telling the truth as he sees it, and I believe that he's as well-situated as anyone could be to pull off a white-hat secure messaging system, so if he says it can't be done with federation, it's awfully hard for me to assert that he's wrong. The problem is that I don't see the point of doing any of…

There's an old quote from Arthur C. Clarke that I think is relevant here:

"When a distinguished but elderly scientist states that something is possible, he is almost certainly right. When he states that something is impossible, he is very probably wrong."

(Apologies to moxie for the whole "elderly" bit!)

Re: Reflections: The ecosystem is moving

#72
post #10

I totally get this; federation is hard , and its so much easier and nicer ─ as a developer ─ to have a centralised service. Often centralisation is the right choice for a particular project, and I respect that. That doesn't mean we should give up trying to federate things, though. The major upside (for me) to federated systems is simple: choice . Choice over the client you use. Choice over the servers you use. Choice…

> The major upside (for me) to federated systems is simple: choice. Choice over the client you use. Choice over the servers you use. Choice. For something so fundamental as how we communicate over the internet that's incredibly important. I want to be able to use the app I want without having to figure out if the other person is using the same app, and i don't want to have to have 10 different apps on my phone just t…

And yet the Matrix team is doing it remarkably well.

I've been a user of Matrix for going on a year now, and they continue to roll out updates and improvements, over ALL of their platforms -- I use the android, iPad, and desktop/web apps every single day. They're also a federated service. Several of my friends run their own servers.

Some days there's a little bar across the top of my page on the desktop client that says "refresh to update your experience!" and I do. My experience updates. Everything continues to work.

Matrix has done such a good job making it easy to roll out updates that people... do.

And I can't tell you how thrilled I am to be living in a federated world. You just can't compare this to e.g. Slack. I can get friends from all backgrounds on the same system because it's so open.

The Matrix team is proof by example that federation and rapid forward motion is possible.

Re: Reflections: The ecosystem is moving

#73
post #57

Earlier quoted context omitted.

It's precisely the fact that Moxie is so credible on this topic that makes his post so frustrating. I believe that he's telling the truth as he sees it, and I believe that he's as well-situated as anyone could be to pull off a white-hat secure messaging system, so if he says it can't be done with federation, it's awfully hard for me to assert that he's wrong. The problem is that I don't see the point of doing any of…

I think this post misses one of the points in the original essay, which is that federation is less important for user-level protocols because the network layer beneath it is open. That tilts the slow-moving-federated-service vs. fast-moving-centralized-service tradeoff towards fast-moving-centralized-service, which is why we see the landscape we see today. His argument applies for any centralized top-layer services b…

"what happens in the case where you have centralized services emerging on top of another centralized service"

It is too shaky ground. Both Facebook and Twitter had a chance to be a platform for 3rd party apps, and they both chose to leave the developers in the cold.

Re: Reflections: The ecosystem is moving

#74
post #65
post #24

Earlier quoted context omitted.

Interesting discussion.

I don't understand how Guardian were unable to obtain a license to use Signal/Axolotl in Chatsecure. The libraries on Github are GPL3, is there some missing IP I'm not aware of? Also it saddens me that LibreSignal is effectively dead now, along with any future third-party clients. I think forking the Signal server and (later) adding federation could spark a community of free and secure messenger apps for the 21st cen…

Apple imposes usage rules on software downloaded from the App Store. The GPL doesn't allow this, so Open Whisper Systems would have to offer different terms.

Re: Reflections: The ecosystem is moving

#75
Are we super sure about this premise: a vendor builds a centralized solution on top of (or evolved from) a federated protocol in order to be able to adapt with speed to a moving environment?

For instance, I am not so sure that is the reason Whatsapp built a custom XMPP.

I am more inclined to think that decentralized-anything is basically impossible to monetize so companies thinking for-profit will always chose the centralized walled garden.

Re: Reflections: The ecosystem is moving

#76
post #44

Nonsense, the www is not stuck in the 90's. Browsers adapt, compete and innovate. And err http is at 2.0. The fact that gopher didn't kick off does not rubbish the idea of common protocols in the first place.

HTTP is used for far more than just browsers. how broad is the current adoption of HTTP 2.0? Will there ever be a time when all HTTP clients, servers, proxies, etc will have upgraded to 2.0 - clearly that's never going to happen in the foreseeable future so we're stuck in a mishmash of supporting HTTP 1.x and HTTP 2.x clients and server software indefinitely - similar to XMPP extensions the article refers to. It's ob…

What's more, HTTP's recent movement is arguably only because the web experience has centralized so much around Google.

Google already had the top two most popular websites in the world, so once Google Chrome also became the most popular web client, it was easy for them to develop a new communication protocol of their own, which everyone else has more or less begrudgingly agreed to call HTTP/2 and start deploying as well.

Re: Reflections: The ecosystem is moving

#77

Are we super sure about this premise: a vendor builds a centralized solution on top of (or evolved from) a federated protocol in order to be able to adapt with speed to a moving environment? For instance, I am not so sure that is the reason Whatsapp built a custom XMPP. I am more inclined to think that decentralized-anything is basically impossible to monetize so companies thinking for-profit will always chose the ce…

I'm writing from the perspective of Signal, which is not a business, so it's definitely not about monetizing users for us.

Re: Reflections: The ecosystem is moving

#78

Earlier quoted context omitted.

You cannot use it with EVERYONE though, can you? Signal requires Google Play Services and is refusing to remove that dependency - leaving out all those users who cannot install Google Play Services, either for privacy reasons (as moxie calls them: "cryptonerds") or because they live in countries where Google is banned (all of China for example). LibreSignal folks are willing to do the work for removing that dependenc…

I'm an outsider, so I'd like to make sure I understand this... So moxie here is claiming to offer the superlative encrypted communication service. On the other hand, he's insisting on a hard dependency that not only compromises privacy, but locks out one of the biggest emerging markets?

His reply here may be relevant: https://news.ycombinator.com/item?id=10665520

Re: Reflections: The ecosystem is moving

#79

In general I agree with @moxie's arguments, however I've come to to be wary at his condescending attitude and discontent towards people disagreeing with his choices. Like there's a review on the Android Signal app complaining that it asks for too many permissions, and it does ask for an arm, a leg and your soul, with the reply being unprofessional imho. I understand that this is open-source, but if you publish it and…

I think you're really missing the point here. > Moxie says that email is frozen, being why it is unencrypted, blaming the lack of progress on it being federated. But you know, I'm willing to bet that in 10 years from now WhatsApp and Slack will be both dead, just like Yahoo Messenger and ICQ before them, while email and IRC will still be around. Yes, and email will still be unencrypted, while the WhatsApps and Slacks…

Slack isn't encrypted and it doesn't make sense to pretend that it is. Introducing encryption is actually difficult for them, since they rely on a web interface connecting to a central server.

But anyway, email can support encryption if you want it, not by one, but two protocols. Email is actually the main channel that journalists and businesses are using for communicating actual secrets over the wire. It's actually the only generally available "meaningful" channel, because even with WhatsApp's encryption, you still can't fully trust a binary blob communicating with a proprietary server, not without the ability to do third-party reviews.

You can do S/MIME, which is encryption with certificates released by an authority (just like HTTPS), or you can do PGP/GPG which is more decentralized, putting the onus of establishing a chain of trust on you. S/MIME is supported out of the box in most email clients and setting up GPG in something like Thunderbird is actually not that hard: https://support.mozilla.org/en-US/kb/digitally-signing-and-e... ; And even for web interfaces there's this browser extension called Mailvelope that's pretty cool: https://www.mailvelope.com/

You see, email does support encryption, just not by default. And the reason for why encryption isn't popular with email is because people don't freaking care.

And the often dreaded protocol that Moxie usually speaks against is XMPP. XMPP apparently isn't good for delivering push notifications on mobile phones, but it does supports easy to use encryption. It's called OTR: http://wiki.xmpp.org/web/OTR ; Oh, and there are is of course an open-source Jabber / XMPP client for Android and it does support OTR, working quite well actually: https://play.google.com/store/apps/details?id=eu.siacs.conve...

You see, WhatsApp's progress is extraordinary, but only because of popularity, because they delivered encryption to people that don't care. Which is quite a feat, except that with another update they can also revert all of that, without users being able to do anything about it. And WhatsApp's progress is not extraordinary for its technical challenges.

Re: Reflections: The ecosystem is moving

#80
post #76
post #44

Earlier quoted context omitted.

HTTP is used for far more than just browsers. how broad is the current adoption of HTTP 2.0? Will there ever be a time when all HTTP clients, servers, proxies, etc will have upgraded to 2.0 - clearly that's never going to happen in the foreseeable future so we're stuck in a mishmash of supporting HTTP 1.x and HTTP 2.x clients and server software indefinitely - similar to XMPP extensions the article refers to. It's ob…

What's more, HTTP's recent movement is arguably only because the web experience has centralized so much around Google. Google already had the top two most popular websites in the world, so once Google Chrome also became the most popular web client, it was easy for them to develop a new communication protocol of their own, which everyone else has more or less begrudgingly agreed to call HTTP/2 and start deploying as w…

Google did not write the HTTP/2 spec.

While Roberto Peon is one of the authors (and a core developer of the preceding SPDY protocol) saying that HTTP/2 is some Google invention is a bit of a punch in the face to the IETF and the two other authors who do not work at Google.

Post reply on HN