Live data from Hacker News

XMPP: The secure communication protocol that respects privacy

notes.nicfab.it

101–110 of 160 posts

Re: XMPP: The secure communication protocol that respects privacy

#102
post #69

Earlier quoted context omitted.

That sounds significantly more complex and worse than how Matrix just works out of the box.

Omemo just works out of the box as well. You don't have to check the key fingerprints, noone forces you to. For people who aren't interested the chat opens and they can start writing and sending, the encryption is completely transparent.

I wouldn't say that it's completely transparent, at least not when you use multiple clients (eg. a PC and a phone). I frequently get messages that some device cannot decrypt.

Re: XMPP: The secure communication protocol that respects privacy

#103

XMPP is dead and I'm very happy about that. The only people who still use XMPP in a significant capacity are the likes of Nintendo (for the Switch push notifications system) and it is pretty out of reach for any average citizen. XMPP as a protocol for engineering and science is fantastic. As a set of standards it's well designed. Performant, flexible, and powerful. As a general, average Joe software however it fuckin…

[deleted]

Re: XMPP: The secure communication protocol that respects privacy

#104
I am not seeing the value in discussing privacy at the protocol level. Sure I share what I want to share with the other party but that is not where the privacy violations occur. The host of the service (like FB) will suck up all data and use it to mine info on me. That is where the leak is.

Re: XMPP: The secure communication protocol that respects privacy

#106
post #80

Earlier quoted context omitted.

Pidgin is not listed as supporting OMEMO [0] and is not recommended for newcomers on joinjabber.org [1]. There may be reasons you want to use Pidgin and i don't want to block you: also pidgin is not exactly abandoned so there's hope it will continue to improve. When a web browser fails to display a certain page, would you recommend the site operator to block it? Maybe we could allowlist specific clients and send a wa…

the omemo support in pidgin is just through a plugin, as with many recent XEPs. i think people tend to forget that pidgin's focus is being a multi-protocol messenger. it ships with XMPP support, but that mostly includes the base. i wrote that omemo plugin and tbh I am pretty burned out. so many moving parts, it's hell to debug and i'm not even sure where to go next with it. (plus people keep talking badly about pidgi…

Having built upon your work and used it as a reference myself, I appreciate the effort dude :)

Re: XMPP: The secure communication protocol that respects privacy

#107

XMPP is dead and I'm very happy about that. The only people who still use XMPP in a significant capacity are the likes of Nintendo (for the Switch push notifications system) and it is pretty out of reach for any average citizen. XMPP as a protocol for engineering and science is fantastic. As a set of standards it's well designed. Performant, flexible, and powerful. As a general, average Joe software however it fuckin…

> XMPP is dead and I'm very happy about that.

Quoted this on XMPP for the irony.

Re: XMPP: The secure communication protocol that respects privacy

#108
post #98
post #5

Earlier quoted context omitted.

Matrix supports encryption out-of-the-box without any strange key exchange problems. Most of the time the way key exchange is done in XMPP is very insecure.

> Matrix supports encryption out-of-the-box that's not true for most clients, though (AFAICT, only riot works with itself). I might even say that the situation is better/more sustainable in XMPP where more diverse implementations of the encryption protocol are available, with all mainstream clients supporting it: https://omemo.top/

FluffyChat and Syphon are doing pretty well. I don't think any of the clients are mainstream

Riot doesn't exist anymore. It's been Element for a while now

Re: XMPP: The secure communication protocol that respects privacy

#109
post #4

Encryption is "activily bein worked on", sound about right - I never got encryption to work across two of my own devices with a third party. Yet I do not understand why a rewrite of messaging as [matrix] was necessary, when XMPP was already there and matrix did not even have an edit-message feature on release, perhaps not even now.

Perhaps the real distinguishing factor of Matrix isn't its technology, but its governance. Instead of an extensible, plugin-based approach like XMPP, Matrix has just a single "official" spec that can only be extended by amending the spec itself. IIRC this was one of the motivations behind Matrix's inception.

As to whether one approach is better than the other is left as an exercise to the reader :) But having each approach belong to separate projects allows them to carry on as they see fit, and means they don't have to participate in a zero-sum game.

Re: XMPP: The secure communication protocol that respects privacy

#110

Earlier quoted context omitted.

> What would be your alternative? A good starting point would be more balanced articles also talking about downsides or not-so-secure/-private defaults; not only in case of XMPP but in case of any instant messaging protocol or ecosystem. Instead of claiming, "XYZ is secure because it supports TLS," articles should also mention what this means in terms of limitations (e.g., TLS protects data in transit, so server-side…

Quoted post unavailable.

[deleted]
Post reply on HN