Earlier quoted context omitted.
you mean that means of communication where spam problems effectively forced a centralized infrastructure provided by a few providers and that now is relegated to mostly being used as a poor man's notification service? running your own smtp server these days is painful.
Not that painful (speaking from experience of running one).
Signal Foundation
271–280 of 298 posts
Re: Signal Foundation
#272Earlier quoted context omitted.
What we've seen isn't users showing how they feel about federated systems, it's users being forced into walled gardens as closed systems added support for open systems, but open systems could not reciprocate, and the market adjusted. If your choice as a user is to buy an iPhone that can communicate with your Apple friends over imessage and Android friends over hangouts, or buy an android phone and not access anyone t…
" it's users being forced into walled gardens as closed systems added support for open systems, but open systems could not reciprocate, and the market adjusted." We haven't seen users forced to do much of anything. In general, there's multiple ways of achieving their goals. They almost always pick either a proprietary company that likes lock-in or a free, ad-driven solution that sells them out. They neither take time…
Well, it depends on how you want to interpret forced. Sure, they aren't required to use a product, but if you've been using Gtalk for years, and that's how everyone knows to get hold of you and how you get hold of people, and it's an open protocol (XMPP) which you can and do use through a third party client (e.g. Pidgin), when they switch to Hangouts you are forced to use their proprietary client and protocol if you want to keep the same contact list without making everyone switch. It's not strictly "forcing", but Google is exerting force to drive customers to a different usage.
I'm not sure any centralized IM service that expected to compete would have done different and survived with any appreciable market share, but that the ones that existed switched is notable.
> On the demand side, though, the masses haven't used open-source as a factor in their purchasing much at all.
The benefits of an open system aren't readily apparent to many people until they start experiencing the problems of a closed system. Closed systems have numerous benefits at the starting stage the open systems don't (for example, a clear way to monetize that works in line with people's expectations and human nature). We were lucky with the internet because it was federated by design (and necessity, pretty much), and grew to the point that it would be too costly to close the protocol before gaining too much popularity. Even so, we're seeing pushes to in that direction. Maybe when the problems of the closed IM systems become apparent enough, we'll actually have some more widespread adoption of open systems. WRT human nature and systems such as these, I'm not sure we've even seen full cycles of how people perceive and deal with the systems (we're only now really having a sizable group of adults that have always had the internet WRT the population as a whole), so a lot of how people deal with open/closed systems over time is still in flux.
P.S. Long time no see/read. Nice to have a conversation with you again. :)
Re: Signal Foundation
#273Earlier quoted context omitted.
Keybase is an amazing idea which seems to be trapped by the current zeitgeist. It implements smooth and intuitive PKI via a command line, a mobile app and a web/electron app and seem to be rolling it out as a slack and/or dropbox alternative which are pretty solid use cases. The downsides are that it has a very cartoony 'silicon valley' type feel which is great for early adopters, but will be a significant barrier to…
Idk if they realized what they had... They don't even need their own chat client - I implemented an example where I could encrypt and decrypt messages automatically to anyone, over any web based client: http://lettergram.github.io/AnyCrypt/ (Current version in repo doesn't automatically encrypt, but tests show it's straight forward). I think that's the real power, the centralized authority of "you are X, with public…
Using public social media accounts to help prove identity is a good idea - it's a solution to the main problem that PGP had.
I think Facebook could have done something similar by generating key pairs for all users and then allowing third part access to the public keys (basically a huge public key server). For users that wanted their own private key off of Facebook they could upload their own public key. It's probably better with the keybase model though and using multiple social media accounts.
Re: Signal Foundation
#274Earlier quoted context omitted.
Using OMEMO on XMPP is a federated implementation of the Signal protocol. I believe Matrix' e2e encryption is also based on it.
I’m really hoping OMEMO makes it into Openfire (XMPP Server) and Adium (XMPP Client) sooner rather than later, we current use OTR but OMEMO is objectively superior in every way I can see.
Re: Signal Foundation
#275Earlier quoted context omitted.
It sounds like they'll defend the Signal trademark, but not the implementation concepts. I don't see how that's bad.
Especially with crypto, one small implementation error could ruin any security value. It's completely reasonable that they don't want their trademark used with code they aren't responsible for.
Re: Signal Foundation
#276Earlier quoted context omitted.
It's small things like gif/emoji support, @-ing people with their nickname/username sends them a dedicated notification on facebook messenger. As much as I hate fb, messenger is a pretty decent application.
Signal has both gif and emoji support.
Re: Signal Foundation
#277Earlier quoted context omitted.
" it's users being forced into walled gardens as closed systems added support for open systems, but open systems could not reciprocate, and the market adjusted." We haven't seen users forced to do much of anything. In general, there's multiple ways of achieving their goals. They almost always pick either a proprietary company that likes lock-in or a free, ad-driven solution that sells them out. They neither take time…
> We haven't seen users forced to do much of anything. Well, it depends on how you want to interpret forced. Sure, they aren't required to use a product, but if you've been using Gtalk for years, and that's how everyone knows to get hold of you and how you get hold of people, and it's an open protocol (XMPP) which you can and do use through a third party client (e.g. Pidgin), when they switch to Hangouts you are forc…
There's the problem right there. They created a dependency on a single provider that could turn on them at any time. Many providers have gone out of business or done unscrupulous things. One should always have alternatives if anything is really important. In this case, they usually solely rely on one provider for convenience when not also cost (sometimes trivial cost). Still true for things like Facebook.
They walked right into a big problem because convenience or apathy about risks trumped everything. From there, they can be forced in the way you describe to go along with what vendor wants. At that point, they might also start switching and/or avoid doing that sort of thing in the future. In many cases, they avoid the switching cost and do the same kinds of things in other services. Their very nature is to willingly create opportunities for suppliers to cause them problems.
Even as they do this, there's a small subset of the market doing either the opposite or taking steps to limit the damage which make me think this is more willing than forced. If anything, history has shown we have to use things like regulations to force market participants to behave more safely on average. They usually don't do it on their own because they don't want to or don't care. Seatbelts when driving are the classic example.
"The benefits of an open system aren't readily apparent to many people until they start experiencing the problems of a closed system."
I agree. We probably need a way to quickly present that when they make these choices. Enough of the market making an informed choice might sustain more alternatives that are better. This already happens with at least some of the FOSS market where the buyers specifically liked the benefits of open source. The wider, long-term effects you describe will also be interesting to watch. We might see some of the FOSS-friendly decisions on consumer side as they see the benefits or experience the detriments.
"Long time no see/read. Nice to have a conversation with you again. :)"
Likewise, buddy. Although I comment less, I've read plenty of yours. Usually insightful and enjoyable. :)
Re: Signal Foundation
#278Earlier quoted context omitted.
The Signal app asks for a ton of permissions. Apparently this isn't decentralized either, so how is it different than Facebook? Did they prove it was mathematically hard/impossible for them to see any of the (meta)data? Have they proven that they are a 100% oblivious broker?
The courts not getting any data, as parent just mentioned, is very strong proof for that.
I don't know what that means.
Re: Signal Foundation
#279Earlier quoted context omitted.
> We haven't seen users forced to do much of anything. Well, it depends on how you want to interpret forced. Sure, they aren't required to use a product, but if you've been using Gtalk for years, and that's how everyone knows to get hold of you and how you get hold of people, and it's an open protocol (XMPP) which you can and do use through a third party client (e.g. Pidgin), when they switch to Hangouts you are forc…
" Sure, they aren't required to use a product, but if you've been using Gtalk for years, and that's how everyone knows to get hold of you and how you get hold of people" There's the problem right there. They created a dependency on a single provider that could turn on them at any time. Many providers have gone out of business or done unscrupulous things. One should always have alternatives if anything is really impor…
Well, or just lack of knowledge, and lack of knowledge about lack of knowledge. I think from our positions it's easy to overlook that. Sure, it seems like people are becoming more technically literate, and they are, but I think when it comes to knowing what you can do, and knowing what you should do, the latter comes well after the forming in almost all exploratory loarning (which internet usage mostly is). We've heard the historical stories (myths), that impart this knowledge. Usually we've lived a few cases of it as well. Even then, it doesn't always take right away, or we get caught out not heeding our own advice. I can't fault a largely novice internet populace for not having had the same conditioning we have.
That doesn't mean they are off the hook though. You're right, there's a shitload of ignoring the signs in favor of convenience and general apathy, it's just not the entire story.
> If anything, history has shown we have to use things like regulations to force market participants to behave more safely on average.
I agree with regulations. I just vastly prefer them to target the specific problems and not try to get too complex with mechanics. Sometimes that requires really looking into the problem, and it can be a hard sell if the general audience for choosing/voting the implementation doesn't have enough knowledge. In this case, I think a lot of the problem all stems from using personal information as currency. Strong regulations on the collection, notification, maintenance, and ability to force removal of personal information by remote entities would make what the real cost is of the systems obvious (you know what they collect and how it's used, or in some cases you know what actual money you pay since that will become a much more viable model again). Open source cometes well in that market, because the actual costs are all apparent instead of hidden.
> We probably need a way to quickly present that when they make these choices.
I have hope this is a problem that will be mostly solved through the normal way societal best practices are passed down, from mentors (parents, teachers, trusted authorities). We just need to get to a point where the mentors actually know this stuff, which requires time and them being bitten by it and learning the hard way, or reading about those stories, or eventually learning it from their mentors. When your Mom or Dad is usually the one that cautions you at an early age to beware any free service that might be trading on your personal info, we've reached a good equilibrium (but we'll still have issues with those that don't have as much access to mentors, which is a constant societal problem).
Re: Signal Foundation
#280Earlier quoted context omitted.
>People enjoy federated networks of regulated, good faith players; wide open federated networks tend towards anarchy. Like... email and the phone system? both of those have huge amounts of bad actors and spam, and people still use them as primary means of communication. Email and phone are generally expected to be more reliable, I think, than any of the walled garden communication protocols. (Speaking of, if you have…
I'm explicitly questioning "people still use them as primary means of communication" Really? Even internal company phone systems have largely switched over to walled garden voip or videocalling systems in most places I've seen. Nobody calls anybody any more - the only use of phones I see is for dialling in to conference bridges. Email is used internally within businesses. What do people really still use public phones…
My impression is that inter-company communications all go over email and public phone. Intra-company,of course, you use the company's walled garden, if the company is large enough to dream of forcing the world into their garden (as most of the companies I've worked for lately have been.) but even so, interviewing is conducted through public phone systems. In fact, even when I'm interviewing a candidate on behalf of my current employer, half the time the connection between the internal walled garden voice system and POTS is so bad I end up using my personal cellphone. Silicon valley companies are serious about 'dogfooding' to the point where actually doing your job sometimes feels like a secondary concern. Smaller players tend to use existing technologies, and so more often use federated systems.
I have worked at smaller places, earlier in my career; I've even setup VOIP for one of those places, but it was still terminated to a POTS T1; it just used SIP lines and asterisk rather than a wired PBX, and they mostly used public email (I mean, their own email server, but it was federated email) - those are still federated systems.
I'm currently considering going to college; today, I scheduled a bunch of academic stuff, using the phone and email. If I end up locking myself into an institution, of course, then we will probably switch to using their walled garden, because they will have the power to force me to do so, but until that happens? we're communicating via federated systems.
Whenever I'm scheduling a medical appointment outside of my primary hmo? I use the phone.
My impression is that the walled gardens are mostly used in places where the relationship has been established, and one party is big enough to have built a walled garden system, and important enough to force the other party to eat the dogfood in question. Within my primary HMO, I use the proprietary 'secure messaging' application to communicate with my doctor. Within the company, I use the company's messaging system and screen sharing system.
My own conclusion is that forcing you to login and use my communications system is a power move; everyone is still dreaming of replacing email with something more profitable.