Live data from Hacker News

On Privacy versus Freedom

matrix.org

151–160 of 209 posts

Re: On Privacy versus Freedom

#151

My biggest problem with messaging applications as a whole is that I need so many of them. I have a few contacts who are reachable with Signal, a few more who are reachable on Hangouts or whatever Google is calling its latest thing, and a few more who are reachable with Skype. That's three programs, to communicate with three different subsets of people. I'm sure if I used Facebook Messenger and Whatsapp, I'd have two…

> I want messaging to be like email

I'm not sure if I want that. Most of my communication over email can be read by Google, regardless of myself using Google. Moreover, there's the risk of things like AMP for email unilaterally changing the protocol in ways that as a user I might not like, but that I can't really influence through my choice of client.

I don't believe matrix.org will become such a thing, but if Matrix becomes as successful as email, I fear it's practically inevitable for a Google, Facebook or whatever to arise and become the dominant player, whereas that is practically impossible with, say, Signal.

I do see the value of the world that's made possible by technologies like Matrix, but I'm not so sure if they're possible with social processes evolving the way they do. I feel like Signal may be the best we can get.

(Though I'm certainly happy that Matrix is trying to prove that wrong.)

Re: On Privacy versus Freedom

#152

Earlier quoted context omitted.

Google Play Services obviously aren't required to run Signal on iOS.

Of course not, but what's the point? Who complains that Signal doesn't run without Google Play Services are the kind of users that wants to run a mostly free distribution of Android (like LineageOS) without any Google software on it. Saying well you should buy a more closed and proprietary system that can run Signal without Google software is nonsense.

Luckily for those users, Signal does run on mostly free distributions of Android without Google software on it - specifically without Google Play Services. I do so.

Re: On Privacy versus Freedom

#153
post #22

Moxie / signal chooses pragmatism over purity, and is striving towards improve the status quo bit by bit vs a pure perfect solution that never ships, even though that improvement has it's own vital problems. You can see it in his choices, and you can see how they want to eventually deliver improvements like no phone numbers, with them working on things like secure value recovery. I kind of wish he spelled it out full…

I'd argue that Matrix also chooses pragmatism over purity - the balance is more that we prioritise freedom as well as privacy. Signal's whole mantra of "only implement features which are privacy preserving" is a great mentality. It's just a shame it comes at the expense of locking down the platform.

I'd argue you can't prioritise two things: prioritisation means deciding what comes first when you have to choose between two things. And it appears to me that Signal tries to ensure privacy first, and then sees if it can make that work with freedom later (see e.g. the delay in adding support for de-googled Android, or the ground work they're only doing now that might (or might not) lead to accounts without phone numbers), whereas Matrix does it the other way around (by first working on support for many different clients, and then trying to make that work with encryption). I hope that both succeed, and I'm happy that both paths are taken.

As an aside, I'd like to voice my appreciation for how you respectfully acknowledged moxie's point of view, take effort to understand it, and then pinpoint why you reach different conclusions from the same observations. A pleasure to read.

Re: On Privacy versus Freedom

#154

My biggest problem with messaging applications as a whole is that I need so many of them. I have a few contacts who are reachable with Signal, a few more who are reachable on Hangouts or whatever Google is calling its latest thing, and a few more who are reachable with Skype. That's three programs, to communicate with three different subsets of people. I'm sure if I used Facebook Messenger and Whatsapp, I'd have two…

A 'chat' client in the style of eg WhatsApp, but based on S/MIME over SMTP/IMAP, seems perfectly doable, and appropriate for most people's needs, with the obvious advantage of being supported by traditional email clients as a fallback.

Additionally, message threading is the feature I most appreciate in a messaging system, but which is painfully lacking in most products (and no, Slack doesn't cut it). SMTP has built-in support for it.

Re: On Privacy versus Freedom

#155
post #91
post #50

Earlier quoted context omitted.

Generally, the way app stores work is that the developer uploads a copy of the app to the app store, and then the app store makes and distributes copies of that for people that request the app. Note that since it is the app store making those copies for end users, the app store needs permission of the copyright owner to do so. There will be something in the agreement between the app developer and the app store that s…

IMO this is pure laziness on the part of the app store. Any store could just say “this app is licensed to you under the GPL — download source here.” Even ignoring licensing, I think app stores could add considerable value by offering reproducible builds. Let developers upload source, verify the has (git tree hash or plain sha256sum), and rebuild in a sandbox server-side. Reject the submission unless the binary’s hash…

Adding that license information doesn't help the end user to run modified code. You need an apple developer license to run changes that you have made. Thus, the code is not free.

On the other hand, apple offering to compile and run any modification that users made will never happen. Then, people could start with one program and run whatever they want. The app store would collapse.

Re: On Privacy versus Freedom

#156
post #147

Earlier quoted context omitted.

The IRC bridge between matrix.org and freenode disconnects almost every week, showing sometimes hundreds of clients disconnecting, then reconnecting a few hours later. I didn't check it personally, but I heard they (understandably) have issues enforcing bans: if one of their users is banned but another one is in the channel, the banned user can still read messages.

Matrix is general lacks support for community tools to handle stuff like that (unless you're running a channel with loose rules that doesn't get raided by 4chan on a weekly basis).

Yes and it's perfectly acceptable for a Beta service. It's just too bad they don't have a single bridge that's of release quality yet, while it was their main promise.

Re: On Privacy versus Freedom

#157
post #70
post #69

Earlier quoted context omitted.

To be fair, since there is no remote attestation possible for the Signal servers, and you realistically can't run one yourself, you only have their word that they don't store any of that information. This is similar guarantees that a lot of other chat and VPN companies offer. Personally I would consider any information given out to a company non-secret, especially to those operating outside my jurisdiction.

The difference is that Signal's competitors are designed in such a way that they have to keep this information, and Signal has delayed key features, like user profiles, until they've managed to create designs that don't have these restrictions. So the logic you're using here is essentially: "since we have to take Signal's word for some part of this, we might as well use services that promise the exact opposite". I do…

Not all Signal alternatives store user information on servers. Threema for example has fully decentralized groups and even decentralized profiles (while Signal uses encrypted-but-centralized profiles, and their new Private Groups system moved from decentralized to encrypted-but-centralized as well).

Re: On Privacy versus Freedom

#158

Earlier quoted context omitted.

> XMPP was supposed to solve all those problems when it came out That's also what Matrix said it would solve when it started. Except now it's yet another protocol with its own chatrooms that are not reachable from any other protocol by default (even rooms on matrix.org); and bridges are at best in "beta" (except the Telegram bridge, which is "late beta"): https://matrix.org/bridges/

We tend to be pretty conservative on maturity estimates on Matrix (and bad at keeping the website updated). IRC, Slack, Gitter bridges are all considered stable these days. XMPP, Discord, Telegram, WhatsApp work usably too. The UX for managing them is not always great or consistent (we’re working on that currently), but “yet another protocol with its own chatrooms” is untrue. You can certainly access the entirety of…

I only have experience with the IRC one, which is ok, but I think it deserves to still be considered Beta (see https://news.ycombinator.com/item?id=21944035 )

Regarding Bifrost, it's the first time I hear about it. I'm glad it exists.

Is there an hosted instance that allows me to access Matrix rooms without installing anything other than an XMPP client? I can't find any info about it other than the code repo.

Re: On Privacy versus Freedom

#159
post #154

My biggest problem with messaging applications as a whole is that I need so many of them. I have a few contacts who are reachable with Signal, a few more who are reachable on Hangouts or whatever Google is calling its latest thing, and a few more who are reachable with Skype. That's three programs, to communicate with three different subsets of people. I'm sure if I used Facebook Messenger and Whatsapp, I'd have two…

A 'chat' client in the style of eg WhatsApp, but based on S/MIME over SMTP/IMAP, seems perfectly doable, and appropriate for most people's needs, with the obvious advantage of being supported by traditional email clients as a fallback. Additionally, message threading is the feature I most appreciate in a messaging system, but which is painfully lacking in most products (and no, Slack doesn't cut it). SMTP has built-i…

There's an open source (GPL) client app (last updated last week) on F-Droid called Dib2Qm for exactly this, and it's apparently e2e as well.

I haven't used it, I just happened across it yesterday out of sheer coincidence.

Link: https://f-droid.org/en/packages/net.sourceforge.dibdib.andro...

Re: On Privacy versus Freedom

#160
post #154

My biggest problem with messaging applications as a whole is that I need so many of them. I have a few contacts who are reachable with Signal, a few more who are reachable on Hangouts or whatever Google is calling its latest thing, and a few more who are reachable with Skype. That's three programs, to communicate with three different subsets of people. I'm sure if I used Facebook Messenger and Whatsapp, I'd have two…

A 'chat' client in the style of eg WhatsApp, but based on S/MIME over SMTP/IMAP, seems perfectly doable, and appropriate for most people's needs, with the obvious advantage of being supported by traditional email clients as a fallback. Additionally, message threading is the feature I most appreciate in a messaging system, but which is painfully lacking in most products (and no, Slack doesn't cut it). SMTP has built-i…

I'm old enough to remember when this was exactly how email was used. (but using a normal email client).

It was acceptable to send one-word email replies, and there were email chains of hundreds of emails (I was the guy who tended to "snip" them after 20 or replies).

Now email seems to have taken over from where snail mail was: bills, newsletters, and formal communication. Chat is now the norm.

Though I do notice a generational divide: one of my co-founders is in his 60's, and will phone randomly (which is now considered rude), another is a bit younger and prefers email to messaging, but will message to ask if it's OK to call. My younger colleagues send formal email replies, and use Whatsapp/Keybase for all other communication. I vetoed using Slack in the organisation completely ;)

I wonder if in another 30 years, chat apps will be the formal channel, and something else will have taken over for just chatting.

Post reply on HN