Live data from Hacker News

We can do better than Signal

icyphox.sh

121–130 of 290 posts

Re: We can do better than Signal

#121
post #68

Earlier quoted context omitted.

Matrix is merely federated, right? Why is it unlikely that a situation like email or the Internet will emerge, where the network still ends up massively centralized because that's just more convenient ?

We're proactively working on P2P matrix, as per https://matrix.org/blog/2020/06/02/introducing-p-2-p-matrix/ , to prevent this risk.

Thanks for the official response; I look forward to P2P Matrix.

Re: We can do better than Signal

#122
post #10

I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't. Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.hos…

We need to think of ways to run the various Matrix, Mastodon, peertube etc in tiny boxes in our homes! There is no real reason for not promoting self hosting. The same way i buy a small Nas or an amazon firetv stick, with apps, I would buy a small box with pihole, mastodon and matrix.

Re: We can do better than Signal

#123
post #57
post #10

I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't. Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.hos…

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…

It doesn't seem like these problems are fundamental to Matrix, though.

I agree that Element is not that good, but if you were to replace Signal's backend with Matrix, your experience would (could?) be nearly identical as Signal is now and we wouldn't have the issues of a closed ecosystem anymore.

Re: We can do better than Signal

#124
post #72
post #6

Lots of FUD in the opening paragraphs ("no changes to server code since April!!1!"). I stopped reading after that

What's untrue about that? There haven't been any commits to Signal-Server for almost a year. https://github.com/signalapp/Signal-Server

I'm not saying it's untrue. but that op is saying that something bad is happening at signal without saying what exactly they mean (hence my !!1!-ing) is what I find annoying and I would qualify that as FUD.

Re: We can do better than Signal

#125
Nothing is ever good enough, is it?

No matter what is built you'll have people complaining about any aspect of it they can find. Most of them won't so anything more than that. They won't contribute a single thing, pat themselves on the back and call it a day.

There's not even a hint of constructive feedback in that post. Not even an attempt at resolving any of the identified problems or thinking further about implications of possible changes.

I need a downvote button on HN...

Re: We can do better than Signal

#126
post #10

I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't. Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.hos…

We need to think of ways to run the various Matrix, Mastodon, peertube etc in tiny boxes in our homes! There is no real reason for not promoting self hosting. The same way i buy a small Nas or an amazon firetv stick, with apps, I would buy a small box with pihole, mastodon and matrix.

Have you tried running Mastodon and Matrix on a Pi? I'm not so confident it'd work, these aren't lean servers.

I would love a tiny server I can run on my home server (for my tiny message volume), but Mastodon and Synapse are optimized for large servers.

Re: We can do better than Signal

#127
post #57

Earlier quoted context omitted.

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…

I'm not worried about people that I moved to signal "grumbling" about being moved again to Matrix. If the Signal move was successful it should build confidence in future moves. The killer app for Matrix for most people won't be ability to run your own home server, but the easy generalization of Matrix to things like Reddit/HN with good integration with 1-1 chat someday will be. Also organizational usage. That of cour…

HN won't even get dark mode, so the only way we'd ever get Matrix on HN is through a random macroscopic quantum event.

Re: We can do better than Signal

#128
post #10

I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't. Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.hos…

We need to think of ways to run the various Matrix, Mastodon, peertube etc in tiny boxes in our homes! There is no real reason for not promoting self hosting. The same way i buy a small Nas or an amazon firetv stick, with apps, I would buy a small box with pihole, mastodon and matrix.

one of the challenges with that from the perspective of an ISP, is that residential broadband connections are very often highly asymmetric in bandwidth.

for example on two of north america's largest DOCSIS3/DOCSIS3.1 based cable modem operators, you can get 200-600 Mbps downstream speeds, but uploads may max out at 16-18 Mbps. Depending on your exact location. This is because of how RF channels are bonded together by the CMTS operator.

lots of other access technologies will face significant challenges and capacity constraints if a sizeable percentage of residential broadband end users start trying to actually use their upstream bandwidth at a greater rate than they do now, when averaged over the traffic for hundreds or thousands of individual end point users.

Re: We can do better than Signal

#129
post #6

Lots of FUD in the opening paragraphs ("no changes to server code since April!!1!"). I stopped reading after that

Care to educate those of us who are confused by this?

See my other reply here: https://news.ycombinator.com/item?id=25812853

Re: We can do better than Signal

#130
post #53

Earlier quoted context omitted.

>If an active attack is carried out, I'm reasonably sure people would not notice. If the attack happened after you have started communicating wouldn't you get a notification that the key of those you're communicating with has changed? An attack would only be invisible if it happened from the first communication. But unless it's very targeted someone somewhere would compare the keys and notice.

> An attack would only be invisible if it happened from the first communication. This is the scenario I'm talking about.

I'd argue that if you're currently the target of a government you should take the time to verify the cryptographic signatures at least every so often. Any platform you use they could have gotten to the servers or the owners of the servers. Hell, they could patch the servers in memory so there's never any trace in source code.
Post reply on HN