Live data from Hacker News

Drawbacks of P2P and a defense of Signal

changelog.complete.org

101–110 of 215 posts

Re: Drawbacks of P2P and a defense of Signal

#101
post #94

Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kicking. With multiple independent implementations (both client and server) that all work together pretty decently. We're never ever going to tear ourselves away from this death by centralization if we keep inventing excuses for why we don't use the federated/distri…

>Yet another [...] post that completely ignores the fact that XMPP is still alive and kicking I didn't downvote but your comment doesn't help me because it's what I call "generic & enthusiastic evangelism" that does not actually engage any of the concrete arguments in the blog post . An example of another comment that does try to address the author's issues is the one from arathorn[1] and I hope that one gets upvoted…

> generic & enthusiastic evangelism

I'm sorry my post has come across that way. I simply wanted to point out that framing the argument as "Matrix vs $PROPRIETARY_SERVICE" is unhelpful at best.

As an actual user of XMPP who has managed to get (some) of my contacts to join me in this brave old world of federation, I get frustrated when the conversation turns to "Matrix vs $CENTRALIZED_SERVICE_OF_THE_DAY" -- it's a false dichotomy that ignores that fact that 20 years later XMPP is still here and still hasn't died. IRC and SMTP are the only other standards for messaging that can claim that kind of longevity.

Of course XMPP is not perfect. But it's what we have to work with, and throwing our hands up in defeat and crawling back to the centralized platforms that keep letting us down is not the way forward.

Re: Drawbacks of P2P and a defense of Signal

#102

Earlier quoted context omitted.

What does "scam" even mean here? I know what I'm signing up for, privacy-wise, when I provide Signal my phone number and access to some of my contacts, and I clearly get something in exchange.

Why are you providing your phone number to anyone? Software should be free.

I prefer free/libre software as well. I'm really not trying to sound inane when I say that I provide my phone number for the same reason I provide my phone number directly to my friends with whom I would like to communicate. It allows people I know to identify me among the billions of other people who have phone numbers.

To repeat my question, how are apps that require a phone number scamming users?

Re: Drawbacks of P2P and a defense of Signal

#103
post #5

A bit annoying how servers meant to be run by people themselves are written in awfully slow languages. Python for matrix server is a terrible choice. Even worse for home assistant. If it can't fit on raspberry pi it's useless.

They're working on a Go server impl, "Dendrite" which is supposed to be far faster and use less RAM. I was hoping for Rust, and I think there is a 3rd-party Rust server, but anything's better than Python. Node.js would probably be better than Python.

https://github.com/matrix-org/dendrite

/aside: this is a curious comment in their readme:

"A PostgreSQL database engine, which will perform better than SQLite with many users and/or larger rooms"

Re: Drawbacks of P2P and a defense of Signal

#104
post #94

Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kicking. With multiple independent implementations (both client and server) that all work together pretty decently. We're never ever going to tear ourselves away from this death by centralization if we keep inventing excuses for why we don't use the federated/distri…

>Yet another [...] post that completely ignores the fact that XMPP is still alive and kicking I didn't downvote but your comment doesn't help me because it's what I call "generic & enthusiastic evangelism" that does not actually engage any of the concrete arguments in the blog post . An example of another comment that does try to address the author's issues is the one from arathorn[1] and I hope that one gets upvoted…

Hmm.. I couldn't send "my car broke down" on Signal because it's one service was down for reasons entirely unrelated to my use.

One can use email and have an address at Google and one at work, and know these data points for a friend. One can use a phone and have multiple service providers (in some countries multiple sims for costs, in others legacy landlines.) One can use WhatsApp, Signal or Slack and then you need to synchronize on an entirely different backup service. None of them have the POTS guarantee and for the most part we (at least in my age demographic) don't even trust the POTS service with non-redundant numbers.

Re: Drawbacks of P2P and a defense of Signal

#105

Earlier quoted context omitted.

do you also use encryption with "regular folks" and verify each others devices?

That's the cool thing with Threema. If you verifyed the contact is so prominent, everybody want to verify each others key, even people who don't understand the concept. In Threema it is not hidden somewhere, it's just allways visible on each single contact with green or red dots.

Sounds similar to Element. However, Threema does not yet have the problem of having to deal with verification with multiple devices, (which is what I was aiming at)

Re: Drawbacks of P2P and a defense of Signal

#106
post #74

Signal needs your phone number and is run by a "former" Twitter person. It just smells funny.

On the other hand Signal is encouraged by people like Edward Snowden (who I assume is paranoid enough about American big corps). The clients are open source and feature a strong E2EE, which is called the Signal protocol and is used by many other clients nowadays because it has such a good reputation. There are lot of efforts to reduce metadata further.

Just dismissing it as "smells funny" is not a valid criticism.

Re: Drawbacks of P2P and a defense of Signal

#108
This is mostly about anonymity. Signal is not really intended to provide anonymity. Most encrypted messaging is not intended to provide anonymity. That is because anonymity is harder to do than privacy and privacy is hard. Fortunately, most people do not need anonymity in their day to day lives. They just need to live in a country with good privacy laws to prevent the commercial exploitation of their data. So if you live in a place with little or no legal privacy protection like the USA things will be fundamentally different.

There are a bunch of XMPP servers running on Tor hidden services:

* https://gist.github.com/dllud/a46d4a555e31dfeff6ad41dcf20729...

... but the article talks about Matrix instead for some reason.

Re: Drawbacks of P2P and a defense of Signal

#109
post #83

Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kicking. With multiple independent implementations (both client and server) that all work together pretty decently. We're never ever going to tear ourselves away from this death by centralization if we keep inventing excuses for why we don't use the federated/distri…

Isn't XMPP a horribly designed protocol and not very good for mobile devices, though? I'm not someone implementing XMPP but I remember reading articles about it back in the day and I recall hearing that the consensus that it's not a good protocol for mobile. Mobile being probably 95% of messaging traffic.

Without the optimizations added since 2016, it is not a great protocol for mobile devices, but only because mobile devices are stupid and equate a background TCP connection with something bad and battery-heavy. That means they make it much more difficult (or impossible re: iOS) to do so.

That means apple & google are effectively dictating how you can use TCP (i.e. not outside of HTTP and friends), and everything is now terrible.

Re: Drawbacks of P2P and a defense of Signal

#110
post #25

I think a half-way point is needed for something to be truely durable. I agree with the criticisms of P2P in that you need to make some privacy tradeoffs. But durability is another concern (as we've seen recently with the takedown of Element from the Play Store). Is it possible for somebody else to spin-up a new centralised Signal server? Why isn't the server code-base open source? Signal would grow immensely in my e…

> Signal would grow immensely in my eyes if they made the server code open source [SEE EDIT], and allowed an easy way to set the centralised server address in the Signal app. The current server would be the default, and perhaps changing the server would be hidden in Advanced Options for now. I feel like this misses the point of what Signal is. It's not just software, it is the network as well . The client is a client…

>What's preventing someone maintaining a client fork where you can do this? We have the code to run a Signal-compatible networks and software that can support this, so why does nobody?

This is actively discouraged: https://github.com/libresignal/libresignal/issues/37#issueco...

Post reply on HN