Live data from Hacker News

Drawbacks of P2P and a defense of Signal

changelog.complete.org

131–140 of 215 posts

Re: Drawbacks of P2P and a defense of Signal

#131
post #83

Earlier quoted context omitted.

Isn't XMPP a horribly designed protocol and not very good for mobile devices, though? I'm not someone implementing XMPP but I remember reading articles about it back in the day and I recall hearing that the consensus that it's not a good protocol for mobile. Mobile being probably 95% of messaging traffic.

Without the optimizations added since 2016, it is not a great protocol for mobile devices, but only because mobile devices are stupid and equate a background TCP connection with something bad and battery-heavy. That means they make it much more difficult (or impossible re: iOS) to do so. That means apple & google are effectively dictating how you can use TCP (i.e. not outside of HTTP and friends), and everything is n…

> That means apple & google are effectively dictating how you can use TCP (i.e. not outside of HTTP and friends), and everything is now terrible.

Ok, but this is our reality. Windows has been the dominant desktop OS since 1995 or so (and MS-DOS was the one from 1985 until 1995 or so, from the same company).

Linux has been dominating the server space since about 2005 or so.

iOS and Android have dominated the mobile since about 2010.

I'm not holding my breath for any of these OSes disappearing from their niches before I die...

Re: Drawbacks of P2P and a defense of Signal

#132

I think a half-way point is needed for something to be truely durable. I agree with the criticisms of P2P in that you need to make some privacy tradeoffs. But durability is another concern (as we've seen recently with the takedown of Element from the Play Store). Is it possible for somebody else to spin-up a new centralised Signal server? Why isn't the server code-base open source? Signal would grow immensely in my e…

Server is open source too. https://github.com/signalapp/Signal-Server

look in their forums , few get it running an those who do discover that certain features like reactions etc don't work. So why exactly is happening on the server ??

Re: Drawbacks of P2P and a defense of Signal

#133

This is all a bit depressing, speaking as the project lead for Matrix. 1. It's true that Synapse can use a lot of RAM. - The biggest cause of this is due to spikes in RAM during state resolution (the merge resolution algorithm used to converge your server's view of a room with the other servers in a room), which Python doesn't always recover nicely. We fixed the main cause of this in Synapse 1.26, which was released…

An interesting aside as a casual observer (thank you for all your work, I see you post here a lot) I found it very interesting that the new Rocky Linux project stood up Mattermost (chat.rockylinux.org) instead of Matrix. When I Google "Mattermost vs Matrix" (because I'll be honest, they seem the same to me as a casual) the insta-Google popup result/excerpt inline is this article:

https://www.troopmessenger.com/blogs/mattermost-vs-matrix

That's a year old, so Google isn't doing y'all a service by highlighting that as it's insta-hit, we need something updated out there for 2021 for Google to latch onto.

I've created a Mattermost account for Rocky stuff and honestly, as a casual I can't tell why I'd want one vs. the other, they seem pretty much the same to me (even the UI is kinda the same). Matrix touts a lot of extra privacy stuff I think, that's about it...

$0.02 from the peanut gallery! :) I'm just using web clients and not the mobile clients (per my preference for this stuff) and use app.element.io as a comparison.

Re: Drawbacks of P2P and a defense of Signal

#134
post #106

Earlier quoted context omitted.

On the other hand Signal is encouraged by people like Edward Snowden (who I assume is paranoid enough about American big corps). The clients are open source and feature a strong E2EE, which is called the Signal protocol and is used by many other clients nowadays because it has such a good reputation. There are lot of efforts to reduce metadata further. Just dismissing it as "smells funny" is not a valid criticism.

> The clients are open source But you can't verify that the open-source matches what's on the Play Store, you can't link to the official server with your own build, and you can't run your own because the server is no longer open source. (Last released a year ago)

> But you can't verify that the open-source matches what's on the Play Store

According to their blog, builds are reproducible[0]. Am I missing anything?

> you can't link to the official server with your own build

Why not? (I know Moxie discouraged publishing custom builds while linking them against the official Signal server but this is not the same thing.)

[0]: https://signal.org/blog/reproducible-android/

Re: Drawbacks of P2P and a defense of Signal

#135
post #59

Earlier quoted context omitted.

XMPP is nice, but I have never see regular folks use it. Only tech peoples. The fact that you can't "install and go" is killing decentralized solution because when you ask regular folks the "server url" (or even to choose on a server list), they give up because it's too complicated already. It's already HARD enough to get them on Signal because they can't just click on the "Connect with Facebook" button. I got my mom…

I use XMPP with "regular folks". At least on Android it works well to point someone to https://play.google.com/store/apps/details?id=im.quicksy.cli... and that's it.

Quicksy is the onboarding app we need for XMPP but until we have a perfect like for like Quicksy also available on iOS (like Element has) I can't in good conscience recommend my social circles join.

Re: Drawbacks of P2P and a defense of Signal

#136

All apps that require a phone number are a scam, privacy-wise. Use Matrix.

> All apps that require a phone number are a scam, privacy-wise. Use Matrix.

…and leak my message content, IP address and social network to everyone who cares to look? You're making a very broad claim here and implicitly assume a very specific threat model. I can come up with dozens of other threat models that are more relevant to me and everyone I know and that completely invalidate your statement.

Re: Drawbacks of P2P and a defense of Signal

#137
post #77

Earlier quoted context omitted.

To easily get regular folks onboard you should recommand Quicksy (a Conversations spin off made by the same developper) : https://play.google.com/store/apps/details?id=im.quicksy.cli... It's as easy to use and to automatically recognize contacts as Whatsapp and Signal but it's federated to XMPP. And people who don't use Quicksy host service can register to be easily recognize as a contact : https://quicksy.im/#get-li…

You've commented at least 3 times pushing this service. From their home page: > We charge a small fee to enter your Jabber ID and phone number into our directory. This cross financing allows us to make Quicksy completely free for its users. If you are a paying customer of the conversations.im hosting service, you can enter your number for free. As stated on their home page, it's a fork of the Conversations (conversat…

This is a misunderstanding. Quicksy is free for anyone who signs up. And I'm not that commenter.

Re: Drawbacks of P2P and a defense of Signal

#138

All apps that require a phone number are a scam, privacy-wise. Use Matrix.

What does "scam" even mean here? I know what I'm signing up for, privacy-wise, when I provide Signal my phone number and access to some of my contacts, and I clearly get something in exchange.

I would not call passing phone numbers (or reversivle hashes thereof) of my friends to a third part a scam. I would call it treason.

Re: Drawbacks of P2P and a defense of Signal

#139

OK. How can you guarantee that your favorite three-letter agency does not have an agreement with Signal, so they can MITM you transparently, or deliver a custom-built app to you? Trustless is the only way to fly. I don’t need to trust any central authority to pay someone with Bitcoin or other cryptocurrencies. Why should I trust someone to route my messages?

It is actually possible because Signal is 1. Open source. 2. Has verifiable builds (just being open source isn't enough). 3. Uses end to end encryption. You need all three of those to get what you want. Also you need to spend a ton of time building Signal from source and auditing it, which I doubt you're going to bother with but at least in theory it is possible.

[deleted]

Re: Drawbacks of P2P and a defense of Signal

#140

OK. How can you guarantee that your favorite three-letter agency does not have an agreement with Signal, so they can MITM you transparently, or deliver a custom-built app to you? Trustless is the only way to fly. I don’t need to trust any central authority to pay someone with Bitcoin or other cryptocurrencies. Why should I trust someone to route my messages?

> so they can MITM you

They can't, provided you verify the (reproducible) builds you download from the app store and check your verification codes.

Besides, it would be rather difficult for Signal to target just you and hand-deliver a custom build to you – Apple/Google would have to in on this, too. And if you use a Play Store alternative like the Aurora Store with a random Google account, this wouldn't work, either.

> Why should I trust someone to route my messages?

Unless you want to put the cables in the ground yourself and run the entire internet's infrastructure on your own, you'll always have to trust someone.

Post reply on HN