Live data from Hacker News

Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

element.io

291–300 of 422 posts

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#291
post #238

Earlier quoted context omitted.

I don't want "the utmost privacy". I want something better than raw SMS. I'm not an international secret agent. I encrypt things out of principal more than because I really care if some government force reads them. If a nation-state decides I'm of interest to them for malicious reasons, I'm probably screwed either way.

Then these bridges are fine. Virtually everything is better than raw SMS.

But Signal is better than Signal over these bridges, and it's easy too. Just because you don't want to run your own service doesn't mean you have to choose a poor option over a pretty good one.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#292

Earlier quoted context omitted.

The messages are encrypted end to end so compromising push notifications doesn't get you anything. That's the problem with this bridge, it adds a new server with access to the unencrypted messages.

come on. can we just drop this end to end encrypted bs on whatsapp atleast ? when you report a message, you allow admins to see the last 3-4 messages. if only you and your receipent is supposed to see the messages, "e2e", how can an admin see them? edit: https://www.huaweicentral.com/new-whatsapp-report-feature-wi...

While I can't vouch for WhatsApp's implementation of course, the capability could easily maintain e2e encryption by just forwarding those 5 messages directly to WhatsApp admins. E2E just means it gets to your recipient without being exposed on the way. It doesn't mean they can't take and then re-distribute it to others.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#293

Back in the day before the rise of Facebook, there was an open source service that combined all the popular messaging protocols - MSN, AoL, IRC, etc. It was called Pidgin[0], and it never got particularly big. I see the same thing here. While it's interesting, I'm failing to see what the use case is. What's the niche that needs this solved in a big way? [0] https://www.pidgin.im/

Pidgin is an IM client, not a service. A service would be something like XMPP servers (Google Talk used to be one and even federated until it went sideways).

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#294
post #221

Earlier quoted context omitted.

You misunderstood what he said if that is your TLDR. Furthermore, this is not the first time privacy issues with Matrix have been brought up to you and dismissed without understanding. I am going to begin recommending that people actively avoid adopting Matrix/Element.

Could you expand on the "privacy issues", please? Not sealioning or whatever, I am genuinely interested.

Not sure what exactly they were referring to, but here are some of them: https://github.com/libremonde-org/paper-research-privacy-mat...

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#295
post #110
post #97

> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…

I want this to take off. I'm tired of having to follow trends because people suddenly think there's a new shinyshinytrendy thing around: IRC to ICQ to MSN to Skype to Google Talk to Facebook Messenger to Whatsapp to Signal. Pidgin is good (I also miss the ancient Trillian, even though it was closed source), but limited to a local device. There are XMPP Transports as well for these (see https://git.eta.st/eta/whatsxmp…

I remember when I first installed Trillian around 2000, it was so cool!

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#296
post #70

Back in the day before the rise of Facebook, there was an open source service that combined all the popular messaging protocols - MSN, AoL, IRC, etc. It was called Pidgin[0], and it never got particularly big. I see the same thing here. While it's interesting, I'm failing to see what the use case is. What's the niche that needs this solved in a big way? [0] https://www.pidgin.im/

> I see the same thing here. While it's interesting, I'm failing to see what the use case is. What's the niche that needs this solved in a big way? I used Pidgin a lot. I always found it very convenient to have everything in one place and UI. Better one client than MSN + AOL + ICQ + IRC + Yahoo! + XMPP. In the last few years I haven't used it much, but that's because it just doesn't support the popular messaging apps…

Bitlbee can optionally use Libpurple too.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#297
post #140

Earlier quoted context omitted.

How can I verify you're running unmodified, unhooked source in your server if I'm a user?

You don't, you self-host your own server. My problem with the self-hosted model is that I don't trust myself to get it right and/or keep it updated. My problem with the 3rd-party model is that I don't trust them, either. So, lacking trust in either myself or the third-party, I'm just one of those people you can get only via secure e-mail, clear-text SMS, or whatever well-supported encrypted service happens to be the…

I feel the same way, I don't fully trust hosted solutions but don't completely trust myself to host my own -- which is where E2E encryption comes into play, but a malicious host would still have access to loads of metadata (timestamps, IPs, etc.).

Blockchain-based solutions like Status.im appear to do away with these sorts of issues through decentralization -- but you still have to put trust into their network.

Solutions like TLS & OMEMO over Tor for XMPP seem to be a very strong privacy-centered solution outside of blockchain-based applications.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#298

Earlier quoted context omitted.

> People flock to Signal for a reason Why would you go to a walled garden if you want more freedom/control? You should just go to Matrix and host it yourself (and keep all the metadata to yourself, too!).

People available to communicate with is a key metric of a communications platform. All of these services lack a large number of regular people. For better or for worse, Signal is the one with the most.

If you self-host Matrix, you can still bridge to Signal while avoiding the walled garden trap and having complete control of your data?

If you don't want to self-host, then you must be comfortable extending trust to someone. SaaS Matrix and Signal seem to be two sides of the same coin, in that case.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#300

Earlier quoted context omitted.

Yes, but what if this is the only way to have a profitable business such as these? Are you okay losing them entirely? More generally, my view of regulation is that it should only exist if there is some quantifiable harm to an involuntary third party (negative externality). Where is the demonstrative harm here, and who is it impacting? Having one friend on FB and another on MySpace, requiring the user to log into each…

> Yes, but what if this is the only way to have a profitable business such as these? Are you okay losing them entirely? But it isn't. We know it isn't - exchanging text, audio and video messages wasn't invented by adtech giants. Two prime examples: 1) Telephony and mobile telephony operators have strong businesses to this day, despite being made interoperable by law. 2) Non-adtech e-mail providers exist and make mone…

> Telephony and mobile telephony operators have strong businesses to this day, despite being made interoperable by law.

True, but their business model also requires payment unlike all these "free" services.

Moreover, the interop requirements here seem to me to be more preventative of physical monopoly than anything else. Physical phone lines and wireless frequencies impose physical barriers to entry or are only usable without transmission interference. Without an interop protocol, it's clear the first mover would steal the entirety of the market.

Websites are not the same. They are an interface built upon an already interop'd internet, from tcp up to http. There are no barriers to entry apart from the barrier to physcially access the internet, which is already interop among providers.

> In my opinion, there is harm - creating unnecessary burden and confusion for everyone, especially non-tech-savvy people. It is tying people down to services via network effects, and then further harming them by exfiltrating their personal data and exposing them to advertising (either directly or indirectly, making the ads more potent thanks to aforementioned personal information).

I don't think inconvenience qualifies as legislation-requiring harm. Yes, it is a pain if your network doesn't centralize, but email is still completely interop and free (not your data) or low-cost if you set up a domain on your own or pay for private email.

Tools are generally adapted because they make life easier. It is super easy to snag a Gmail account and then use it to create a WhatsApp, or Telegram, etc. account and immediately start chatting with your friends via the app' identification of them due to your phone book. No argument there. But to say that because other companies have done it and attracted your other friends first, they must now be compelled to allow you to export the data elsewhere, or at least define their systems by some standard, makes no sense to me. We have standards already and there is no physical barrier to entry for competition. There is a reason new apps keep coming out, and the low barrier to entry is one of the main factors.

> But that's not true at all. People are coerced to use these services, and coerced to stay with them. That's the literal definition of network effect. I have to use WhatsApp/Facebook/whatever because my mom is there and doesn't want yet another chat app, and my local plumber only communicates through it. I have to stay, because neither my mom nor my plumber will move. The more people are trapped in the net, the stronger its hold. (...)

Email is an interop standard. You sign up for an email account knowing you can communicate to any other email account. When you sign up for FB, you know you can only talk to people on FB. The difference is by design.

Coercion by your network that is not inhibited by physical barriers to entry is a personal problem. Your mom only wants to use FB, fine. Just speak with her elsewise or explain to her why you won't use FB. This is a personal negotiation and is not of relevance to lawmakers. Similarly, if your plumber only communicates with potential clients over WhatsApp, find a different plumber if you don't want to use WhatsApp. It's really that simple. No other plumbers around? Great! You've identified a huge opportunity that you or anyone can fulfill.

> These platforms are as successful as they are exactly because your proposed solution is impossible to implement by most people. Again: network effect.

My proposed solution is not at all impossible to implement. Difficult? Yes, extremely, but let's not confuse impossibility with difficulty. It is possible, but you'll have to be willing to make sacrifices along the way. The golden light in this is that you currently have the opportunity to make a chat system that defines an interop standard. Build it and they will come.

Anecdotal: when I joined my current employer my manager requested that I download and install WhatsApp to be able to communicate with the continent-spanning team chat for production issues. I contested. WhatsApp was not an approved company platform, and I was unwilling to install it on my personal device. I would happily install it on a work provided device, but I would not carry the work device with it on 24/7 because I didn't want to leak telemetry, etc. data to FB. So I don't use it. The team does, but I don't. They reach me through work channels if necessary or directly by phone/text.

Post reply on HN