Live data from Hacker News

Easy XMPP: What are we doing here?

mail.jabber.org

71–80 of 169 posts

Re: Easy XMPP: What are we doing here?

#71

> A single decision by Moxie or a single court order in some country can make Signal unavailable to a large part of its user base. This is a great point made later on the thread. And already happened in some countries, for example, with whatsapp. Social pressure was big enough to revert it in a reasonable time, but time is very relative on how much you or your business relies on it.

> A single decision by Moxie

I'm sure that if Moxie turned evil it would be difficult for the project to survive, but that's also one of the reasons they've been successful. They have control over what they're building, and they can move fast and make breaking changes. It's very difficult to build something beautiful when you can't make breaking changes.

Re: Easy XMPP: What are we doing here?

#72
post #62
post #36

I recently tried riot.im and I'm realy blown away by the good UI they have and how easy it is to get started to develop your own stuff. It is a shame that nothing by the likes exists in the XMPP-sphere. EDIT: As a side note: Daniel Gultsch from the conversations-fame is doing a great job by providing/developing a realy awesome XMPP client for android and pushing the standard forward.

There's also Zom (zom.im), which like Conversations is derived from the Guardian Project's ChatSecure.

Conversations isn't derived from ChatSecure. Newer versions of ChatSecure were (are?) going to be derived from Conversations.

Re: Easy XMPP: What are we doing here?

#73
post #14

Earlier quoted context omitted.

There are attempts at creating an XMPP compliance suite[0], but the biggest problem is actually a lack of volunteers / money to improve the clients and servers. Conversations is driven by one full time developer, most other applications are hobby projects. [0] http://xmpp.org/extensions/xep-0375.html

What kinds of skills would a volunteer need to be able to contribute?

What skills you have are laregely irrelavant; just find something that annoys you personally about [your favorite client here], dig in, fix it, and send in a patch. Or, if you're not a developer, use whatever skills you have, mock up a way that a UI component could work better and send it in, or write documentation, or simply file bug reports. Everything helps :)

Re: Easy XMPP: What are we doing here?

#74
post #49
post #44

Earlier quoted context omitted.

What is this constant rumor about that Google killed XMPP federation? I think they killed the XMPP support in their own clients, but in general they still provide the service. I've at least three active @gmail.com XMPP accounts in my roster on a private server. I've read some rumor that they do not do TLS for server2server traffic, but in the end if you use XMPP on your desktop you most likely use OTR.

In 2013, the xmpp community decided to enforce TLS on all server-to-server links [0]. Google still doesn't support this, essentially preventing non-gmail users to communicate with them. While OTR is a possible solution, it has its own can of worms (multi-device, offline use). Besides of this, Gmail xmpp silently fails if the other party upgraded to hangouts. [0] https://github.com/stpeter/manifesto/blob/master/manife…

Apologies in advance for pedantry, but OTR and TLS aren't comparable security solutions. Unlike TLS, OTR is end-to-end. You can't trust the security of an XMPP conversation that occurs over TLS connections without also trusting all the servers in between.

Re: Easy XMPP: What are we doing here?

#75

These would be my concerns about potential differences between Signal and an 'Easy XMPP' client; would someone who knows Signal say whether these are accurate?: * Signal users are not anonymous; Signal requires users' phone numbers. * Signal is centralized. Is there a way to run your own Signal server? * Signal uses Google Chrome on the desktop (and Android?) and Google Play Services (or some part of them) on Android…

> Is Signal's system (not user data) fully open and transparent, end-to-end?

I believe that it is not transparent in the usual sense, because the server-side component is has no source available, but also that it does not need to be transparent in a cryptographic sense: the amount of information known by the Signal servers is minimal, and doesn't include messages, contact graphs, or even which users are communicating with each other. It does include what users they have and what phone numbers, and when they log in / where from: I assume they could also learn whether someone is using Signal at a given time and how much (from bytes transferred) but nothing more interesting about the conversation. I believe the use of Google Cloud Messaging is the same way.

I haven't looked into the protocol myself and I'm not sure if all of this is true. In particular, while OWS says they don't have any "records" of who a user is communicating with (https://whispersystems.org/bigbrother/eastern-virginia-grand...), I'm not actually sure if this means they're just not logging it, and a system could be built to record this.

Re: Easy XMPP: What are we doing here?

#76
post #44
post #38

Earlier quoted context omitted.

Signal requires users' phone numbers. True for Signal. XMPP is using JIDs which are functionally comparable to email addresses, and similarly anonymous (or not). Is there a way to run your own Signal server? The Signal client is open source, the server mostly so. You could create your own semi-Signal community, but it would not be able to talk to official-Signal users. XMPP is designed for federation by default, and…

What is this constant rumor about that Google killed XMPP federation? I think they killed the XMPP support in their own clients, but in general they still provide the service. I've at least three active @gmail.com XMPP accounts in my roster on a private server. I've read some rumor that they do not do TLS for server2server traffic, but in the end if you use XMPP on your desktop you most likely use OTR.

It's not a rumor. Yes, TLS doesn't work, but that's not a big deal, because you can still allow unsecure connections.

The issue is that you see 3 people are online, you can also receive their messages, but they can't see anything you write[1]. This behavior is worse than outright blocking, because it creates confusion at first seems like everything works and why people are complaining, then makes you suspicious that perhaps Jabber is broken, and in order to talk to your friends you might start using gmail.com.

[1] Initially this happened to anyone who converted to hangouts. I don't think there's option anymore to opt out from hangouts and get back to GTalk.

Re: Easy XMPP: What are we doing here?

#77
What federated / decentralized protocols have been actual successes? For what protocols can I set up my own server in my house or in some cloud service, and have a comparable experience to using a major provider's service (modulo scalability and personal sysadmin effort)?

I'm worried that the only ones seem to be email and the web, both of which came into existence when the internet was small and academic and it was natural for universities to decentralize. And running email on your own is getting increasingly hard because of spam and IP reputation. (We seem to have more-or-less won the war on spam, but at the cost of making email much less decentralized than it used to be.)

There's a mention of BitTorrent elsewhere in these comments, and there might be an argument for Bitcoin. But even for IRC, people tend not to run their own servers (although they could); there are a very small number of IRC networks, run by random people.

I would love to see a decentralized and federated team chat app along the lines of Slack or Discord, but I'm having trouble believing that such a thing would have a chance of success in a post-1995 internet.

Re: Easy XMPP: What are we doing here?

#78
post #66

Earlier quoted context omitted.

I registered when it was called called Vector and recently started using it more seriously. It is freaking fantastic. Voice/video calls actually works and the Android app is very good. It was long since I had such as strong feeling of "this is it". When it comes to protocols (as opposed to "services"), they're seldom replaced. I mean, we're still using IRC for open source projects. Matrix/Riot gives me a glimpse of t…

> I mean, we're still using IRC for open source projects. Matrix/Riot gives me a glimpse of the future. Matrix/Riot does tend to break down in channels with 30k users all chatting, sending hundredthousands of messages per minute. (Which is a real use case of IRC).

I'm ignorant on the subject, how can hundred/thousands messages per minute be a real use case? I would expect such massive amount to be parsed by robots, not humans, and in that case why use IRC at all instead of a queue system like RabbitMQ? Maybe because it's easier to share an IRC channel than an open queue?

Re: Easy XMPP: What are we doing here?

#79

Earlier quoted context omitted.

It was a real sad day when Facebook and Google decided that proprietary was the way to go...

The writing was on the wall before that, though. WhatsApp was eating everyone's lunch and Facebook / Google wanted to move faster and own the messaging space.

WhatsApp didn't exist yet

Re: Easy XMPP: What are we doing here?

#80
post #77

What federated / decentralized protocols have been actual successes? For what protocols can I set up my own server in my house or in some cloud service, and have a comparable experience to using a major provider's service (modulo scalability and personal sysadmin effort)? I'm worried that the only ones seem to be email and the web, both of which came into existence when the internet was small and academic and it was…

Correct me if I am wrong, but https://riot.im/ seems to fit the description of a decentralised and federated team chat app.
Post reply on HN