Live data from Hacker News

Drawbacks of P2P and a defense of Signal

changelog.complete.org

71–80 of 215 posts

Re: Drawbacks of P2P and a defense of Signal

#71

Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kicking. With multiple independent implementations (both client and server) that all work together pretty decently. We're never ever going to tear ourselves away from this death by centralization if we keep inventing excuses for why we don't use the federated/distri…

XMPP is nice, but I have never see regular folks use it. Only tech peoples. The fact that you can't "install and go" is killing decentralized solution because when you ask regular folks the "server url" (or even to choose on a server list), they give up because it's too complicated already. It's already HARD enough to get them on Signal because they can't just click on the "Connect with Facebook" button. I got my mom…

We're smoothing onboarding (e.g. choose a server) with things like easy invitations: https://blog.prosody.im/great-invitations/

Support for creating invitations from within the app was recently added to Conversations (sponsored by the Snikket project). I'm hoping to see more servers deploy this functionality in the coming year, and more clients implement support.

Snikket is built around the idea of invite-first for onboarding onto self-hosted servers. As the dev I may be biased, but I've onboarded many people seamlessly this way.

Re: Drawbacks of P2P and a defense of Signal

#72
post #17

Earlier quoted context omitted.

Sure, but what about in 1992? How much did you need to understand about TCP/IP when you got AOL? Very little. And what happened when you got online? You could communicate online, suddenly reaching millions and then billions of humans. So learning just a little bit about IP (let's be real, you didn't need to know shit about TCP) Compare that to a VPN or Tor. What do you need to understand to use it, and what is the pa…

Yep all it took was some usability products and it was easier... See what I'm saying...

I don't think it is comparable. In my opinion it would be comparable to if e-mail required you to be on the same server as your friends or you couldn't e-mail them OR to have compatible servers that could communicate across different protocols, which is a run to the bottom just as in e-mail where adding new security and removing legacy is near impossible.

Re: Drawbacks of P2P and a defense of Signal

#73
post #24
post #5

A bit annoying how servers meant to be run by people themselves are written in awfully slow languages. Python for matrix server is a terrible choice. Even worse for home assistant. If it can't fit on raspberry pi it's useless.

I see this bike-shedding comment about the language choice for the reference Matrix server implementation in every single post about Matrix on Hackernews. Every. Single One. Millions of people use Matrix. It has been adopted by the French civil service, several German states, and the German armed forces. In a previous post I saw someone saying that American Airlines was looking at adopting Matrix for their employees.…

> It has been adopted by the French civil service, several German states, and the German armed forces. In a previous post I saw someone saying that American Airlines was looking at adopting Matrix for their employees.

Do you really think "but enterprise organizations don't mind running it" is a great argument? By that measure, JIRA is also perfect software :D

I know plenty of places running their own Matrix servers, and while it's certainly not unusable (proven by the fact that they keep running it), it's a common refrain among their admins that Synapse is one of the more annoying pieces of software they run in their infrastructure. That's not "bikeshedding", but operational experience, which has an impact on if it's recommended or not. See also the ... varying ... quality of matrix's bridges to other ecosystems, even the ones that are provided officially by the Matrix project. So yes, there are actual issues with Synapse performance - "rewrite it in Rust!!111" is of course not necessarily the correct response :D

Re: Drawbacks of P2P and a defense of Signal

#75
post #59

Earlier quoted context omitted.

I use XMPP with "regular folks". At least on Android it works well to point someone to https://play.google.com/store/apps/details?id=im.quicksy.cli... and that's it.

do you also use encryption with "regular folks" and verify each others devices?

YES !

first it automatically trust the devices but if you want you can improve it with manual verification :

https://gultsch.de/trust.html

"TLDR: Automatically trust all new devices of contacts that haven’t been verified before, and prompt for manual confirmation each time a verified contact adds a new device."

Re: Drawbacks of P2P and a defense of Signal

#77

Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kicking. With multiple independent implementations (both client and server) that all work together pretty decently. We're never ever going to tear ourselves away from this death by centralization if we keep inventing excuses for why we don't use the federated/distri…

To easily get regular folks onboard you should recommand Quicksy (a Conversations spin off made by the same developper) :

https://play.google.com/store/apps/details?id=im.quicksy.cli...

It's as easy to use and to automatically recognize contacts as Whatsapp and Signal but it's federated to XMPP.

And people who don't use Quicksy host service can register to be easily recognize as a contact :

https://quicksy.im/#get-listed

Re: Drawbacks of P2P and a defense of Signal

#78
post #43

Earlier quoted context omitted.

As someone who in principle would like decentralized/federated cryptomessengers to win what usually blocks me from using them (over Signal) is that most of the people I would contact via messenger are not tech-savy. To make them switch the messenger has to be easy to setup and feature wise it has to be so promising that they don't feel like I lured them into something half baked. While being federated is a huge plus…

Exactly. When network effect is in play, the bar for adoption must be set incredibly low. There is no way any of my non-tech friends is going to spend even 5 minutes investigating “XMPP” or whatever. If it’s anything more than open app >> fill in phone number or create account >> see list of people to chat with, it’s already dead in the water.

Quicksy is made to be as easy as you say to get an XMPP account and automatically recognize contacts :

https://play.google.com/store/apps/details?id=im.quicksy.cli...

https://quicksy.im/

Re: Drawbacks of P2P and a defense of Signal

#79

OK. How can you guarantee that your favorite three-letter agency does not have an agreement with Signal, so they can MITM you transparently, or deliver a custom-built app to you? Trustless is the only way to fly. I don’t need to trust any central authority to pay someone with Bitcoin or other cryptocurrencies. Why should I trust someone to route my messages?

It is actually possible because Signal is 1. Open source. 2. Has verifiable builds (just being open source isn't enough). 3. Uses end to end encryption. You need all three of those to get what you want. Also you need to spend a ton of time building Signal from source and auditing it, which I doubt you're going to bother with but at least in theory it is possible.

4. Verification

Re: Drawbacks of P2P and a defense of Signal

#80
I'm annoyed that the comments here pile on the "ease of use" part, while largely ignoring what is more original here. (I don't know what I expected.)

The critiques of p2p identity leaking and big hungry servers are valid and I'm glad they are raised. As a Matrix user, I could respond to the first point that yes, it's a tradeoff depending on your threat model. I think that having a tractable identity is less bad than having one point of failure and moderation, on the broad social scale. If you are more concerned about very strong security now, you may decide differently. I think in the future, you could use an unfederated server of Matrix if you want something like Signal for sensitive connections. And yes, maybe pure p2p with no server nodes will never be viable for some use cases, with some threat models.

I do hope that in the future there will be an optimized Matrix server implementation in a faster language. (I'm saying Matrix, but of course my "loyalty" is ultimately more to the type of vision than some specific project.) I'm willing to cut some slack (pun unintended) to people having to iron out their big visions in an easier, more lenient language first. It's more important to have the features people want first.

As to the difficulty part, again, this is a legitimate concern, but I feel in HN comments and similar places it degenerated into a complete meme. All technology is "hard" for most/some people. I know older folks who drive to a clerk in a store to ask them to show how to do stuff on IPhone. There is always some greasing and other people having to tell you how to use it, not everything can be intuited. But you can simplify: point folks to a specific client (Element), which will point them to one server (Matrix.org). (Or, say, a random wallet like Ethereum does it?) I've done it with success with a bunch of "non-technical" people. No decisions needed on their part, but they could make them if they wanted to research (and not everyone has to want to!). It was no different in the era of email expansion and Outlook.

Post reply on HN