Live data from Hacker News

We can do better than Signal

icyphox.sh

241–250 of 290 posts

Re: We can do better than Signal

#241
post #181

Earlier quoted context omitted.

Matrix has the same problem. It requires out-of-band communication to trust the E2E encryption. Indeed, EVERY decentralized communications system will have this problem. There's no way to establish trust over a compromised channel without either a centralized pre-trusted agent (like the CA system in TLS) or an out-of-band secure channel (like Signal, Matrix, PGP, etc).

Sure it does, but I'm more inclined to trust my own server than trust Signal's server (thus reducing the need for that verification to happen in the first place)

But if I'm on a different server how do you know if it's really me or that other server is lying to you?

Re: We can do better than Signal

#242
post #10

I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't. Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.hos…

Skype was good when it used to be p2p... but when Microsoft bought it, they changed how it works.

Re: We can do better than Signal

#243
post #69

Earlier quoted context omitted.

One thing that I think will always give Signal and WhatsApp an edge over something like Matrix is that it's simply tied to a phone number. You don't "make an account" and have to memorize a password or anything, it just falls into place like any other texting app. The barrier to entry is about as close to frictionless as possible.

There's nothing inherent about this to Matrix, I don't believe.

Maybe so, but that is completely irrelevant for now.

I have been able to convince quite a few non-tech friends to use Signal, but that would have been impossible with Matrix.

Re: We can do better than Signal

#244

Earlier quoted context omitted.

For me, this was a month or two ago. I don't remember exactly now, but my friend and I tried to verify each other, but one of us quit the device verification (with the five emojis) half-way through and uninstalled the app, so now there is a half-verified device that we can never remove. My icon with him always shows up red because of this device, and there's nothing we can do. UPDATE: I just checked now, there's a "m…

In case you don't know, like Gitter, Freenode has a public Matrix bridge!

I remember trying the bridge but it wasn't working entirely well, has this changed recently? That's going to be another great integration if it works well.

Re: We can do better than Signal

#245
post #57

Earlier quoted context omitted.

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

I've been self-hosting synapse for 6 years (? before vector) with small active group of about 30 non technical users. You've helped me to set up synapse all those years ago. I am super grateful for that and for your work.

But we've had issues over the years

Some issues i thought are happening because we are not always on the most up to date synapse (my problem) and clients expect version of the master instance but it seems happening even on the root instance: - Verification issues that are impossible to understand even for me. Often it fails even you go through the process. - In past year huge increase in amount of notifications. Everytime i log in i am greeted with "Review where you’re logged in Verify all your sessions to ensure your account & messages are safe". - Some my users enabled e2e and randomly locked self out of rooms because they log out somewhere or updated client and couldn't back in.

All my users have similar problems and actually started avoid e2e on matrix now. It's shame because most of them are now also on Signal because they want e2e.

Other issues:

- I had to make special video tutorial for users to be able to register and log in at our own instance. They keep trying to log into matrix.org instance. Custom instance seems like something second tier in clients. It would be really nice if instead "login to matrix" vs "use custom server". It would be login to your server with multiple public servers as options by default and + button to add custom servers. More like you add services/logins in ios or something. It wouldn't feel like discrimination.

Overall i feel like there is some duality in Matrix goals. On one hand it markets federation and decentralization but on other hand it promotes matrix.org so it looks like is the only instance. It would be cool to support different servers to get some diversity (like this https://www.hello-matrix.net/public_servers.php is not on matrix.org page).

Re: We can do better than Signal

#246
post #239

Earlier quoted context omitted.

> I feel like Signal is held to a ridiculously high bar when it comes to anything. Maybe I can help: I feel Signal is doing a lot right and if I need to send a message right now and be 99.999% sure nobody except the recipient can read it, Signal is my choice. My criticism is mainly directed not at Signal, but at the people trying to promote Signal by trying to trash every other messaging technology. The reason is tha…

> - and allow armed forces and other groups that need it to run their own servers if you can afford to run your own servers, then you can afford to run a build server too and push your own releases with the server patched.

> then you can afford to run a build server too and push your own releases with the server patched.

I think you are looking in the right direction.

The cost for servers were never the reason why others aren't running their own Signal networks AFAIK.

Re: We can do better than Signal

#247

Earlier quoted context omitted.

Funnily enough it seems like opposite and people are trying to put down Singal. Seriously we are all on the same side. It's not competition. I've been running matrix instance for probably 6 years from times even before Vector. The constant popups happening and mysterious verification fails gotten pretty annoying. So much that my non-technical friends started to complain. It has gotten objectively worse in past year.…

Signal is a single point of failure, cell-phone number dependent chat app. It should be put down along with WhatsApp. If you don't own the server, you are not in control of your information.

Nobody cares if you own the server if there are no users on it.

Also it's not like Matrix.org is not single master instance that can fail just as easily. Even better most of data there is not e2e encrypted so yes if somebody hacks it you will loose all the information.

Re: We can do better than Signal

#248

Earlier quoted context omitted.

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

I can share the bugs that happened to me. All of these happened in the last 6 months: - A message would get "pinned" to the bottom in Element. Basically, you could send new messages but a specific message would always look like it was the most recent message (even though it was not). This was a purely visual bug and the other party wouldn't have the issue. - Messages send/receive slowly compared to other services. It…

> - A message would get "pinned" to the bottom in Element. Basically, you could send new messages but a specific message would always look like it was the most recent message (even though it was not). This was a purely visual bug and the other party wouldn't have the issue.

Is this in Element Android? I've had that issue happen there too, but only there.

Re: We can do better than Signal

#249

Earlier quoted context omitted.

Liked "Simple Groups and painless multimedia was what gave WhatsApp the edge in the early days" ------- ^ That's and ultra low res photo sharing what you get when you group SMS/MMS with folks in the Apple ecosystem. You don't get it in WhatsApp, etc.

I'm not sure what this comment is saying.

It's mocking iMessage trying to convey some extra features (like liking) over SMS which doesn't work very well.

Re: We can do better than Signal

#250
post #153

Earlier quoted context omitted.

Why is not wanting vendor lock-in a high bar? After dealing with Messenger, WhatsApp, Face time, etc all my life I'm tired of it. It doesn't matter if the code is open source, I'm still going to be locked in when all my friends move to Signal.

I understand what you're saying but I don't know if calling it vendor lock in is quite correct. You can export your list of messages out of Signal and presumably import them to whenever you motivated to do so. Your friends could then join you on the new service and life would continue on. I am personally unaware of any communication service with a universally portable user identifier and that allows you to freely swi…

Well... yes, email and sms and telephone. They're protocols that anyone can decide to support and participate in. Honestly SMS was a good solution for my needs for 1:1 messages, it just didn't properly evolve to support the f a featureset we expect from modern messaging.
Post reply on HN