Earlier quoted context omitted.
Matrix is merely federated, right? Why is it unlikely that a situation like email or the Internet will emerge, where the network still ends up massively centralized because that's just more convenient ?
We're proactively working on P2P matrix, as per https://matrix.org/blog/2020/06/02/introducing-p-2-p-matrix/ , to prevent this risk.
We can do better than Signal
251–260 of 290 posts
Re: We can do better than Signal
#252Re: We can do better than Signal
#253Hey icy, the issue you raise about Signal not being decentralized, I think, is a valid one. You should check out a decentralized messaging and social media app I have been working on - Omnii. Omnii allows each user to manage their encryption keys, and all data exists in a decentralized manner - only on endpoints (users' phones), and not on a backend. https://omnii.co is our website if you are interested.
Re: We can do better than Signal
#254I feel like Signal is held to a ridiculously high bar when it comes to anything. Is it perfect? No. But come on now; I see other threads on HN where people are debating/bashing their use of Intel SGX, really? Assuming you trust the client builds (or use a verified build) and verify the public key, all of these arguments go out the window with the exception of exposing your phone number. This situation seems like a pr…
Messages arriving out of order when you switch devices and missed notifications isn't supposed to be a high bar for a messenger. Telegram and WhatsApp get these things right, Signal is just lacking at the moment.
Signal requires and only supports a single mobile device, you can link multiple desktop clients to a mobile device. But one cannot have signal on multiple devices.
Re: We can do better than Signal
#255As I wrote in https://news.ycombinator.com/item?id=25795575 - WhatsApp: Oh wait, SMS etc. is completely insecure - Signal: Oh wait, WhatsApp is structurally unable to be a force for privacy - Matrix: Oh wait, even benevolent centralization is an unnecessary risk It's not that worse is better, but the general public's imagination can only grow so fast. We need to coax people along. As such, I do think all 3 serve a pu…
In fairness, I think WhatsApp's value proposition is and was as little more than 'just' oh wait, sms etc. is completely insecure. I don't think the majority really cared about that (especially since end-to-end encryption was a later addition). I think most people primarily started using WhatsApp because a) it was (is) free b) cross-platform c) worked very reliably
Re: We can do better than Signal
#256Earlier quoted context omitted.
your causality is wrong here; on day 1, matrix.org was 100% of the network, because there weren't any other servers. since then it's been decreasing steadily - at around 30% atm.
But when Matrix gains massive adoption from the mainstream, wouldn't you expect those people to primarily rush to matrix.org?
Re: We can do better than Signal
#257So you know maybe we just can't do better for now.
Re: We can do better than Signal
#258Earlier quoted context omitted.
If they're transparent, why don't they expose their commits to server code to the public?
This is a great example of what I'm talking about. Are you also commenting how you can't see the source of your phone's baseband, Google's services, your ISP's router firmware, WhatsApp's servers, Facebook's service's, etc? Because Signal's client is open source it's considered a unique-to-Signal downside that we don't have access to the server's source. I feel like some people would bring up the server source issue…
FB, Google etc never claimed to be open source with their infrastructure.
So if WhatsApp cant be trusted as to what happens on the server, right now neither can Signal.
Can Signal show that what they are running on the server is the same as whats on Github? Are we just trusting them because we have been trusting them all along?
Re: We can do better than Signal
#259Earlier quoted context omitted.
What's untrue about that? There haven't been any commits to Signal-Server for almost a year. https://github.com/signalapp/Signal-Server
I'm not saying it's untrue. but that op is saying that something bad is happening at signal without saying what exactly they mean (hence my !!1!-ing) is what I find annoying and I would qualify that as FUD.
Re: We can do better than Signal
#260I feel like Signal is held to a ridiculously high bar when it comes to anything. Is it perfect? No. But come on now; I see other threads on HN where people are debating/bashing their use of Intel SGX, really? Assuming you trust the client builds (or use a verified build) and verify the public key, all of these arguments go out the window with the exception of exposing your phone number. This situation seems like a pr…
If they're transparent, why don't they expose their commits to server code to the public?