How can accounts be distributed? What would prevent impersonation?
XMPP: The secure communication protocol that respects privacy
101–110 of 160 posts
Re: XMPP: The secure communication protocol that respects privacy
#102Earlier quoted context omitted.
That sounds significantly more complex and worse than how Matrix just works out of the box.
Omemo just works out of the box as well. You don't have to check the key fingerprints, noone forces you to. For people who aren't interested the chat opens and they can start writing and sending, the encryption is completely transparent.
Re: XMPP: The secure communication protocol that respects privacy
#103XMPP is dead and I'm very happy about that. The only people who still use XMPP in a significant capacity are the likes of Nintendo (for the Switch push notifications system) and it is pretty out of reach for any average citizen. XMPP as a protocol for engineering and science is fantastic. As a set of standards it's well designed. Performant, flexible, and powerful. As a general, average Joe software however it fuckin…
Re: XMPP: The secure communication protocol that respects privacy
#104Re: XMPP: The secure communication protocol that respects privacy
#105Re: XMPP: The secure communication protocol that respects privacy
#106Earlier quoted context omitted.
Pidgin is not listed as supporting OMEMO [0] and is not recommended for newcomers on joinjabber.org [1]. There may be reasons you want to use Pidgin and i don't want to block you: also pidgin is not exactly abandoned so there's hope it will continue to improve. When a web browser fails to display a certain page, would you recommend the site operator to block it? Maybe we could allowlist specific clients and send a wa…
the omemo support in pidgin is just through a plugin, as with many recent XEPs. i think people tend to forget that pidgin's focus is being a multi-protocol messenger. it ships with XMPP support, but that mostly includes the base. i wrote that omemo plugin and tbh I am pretty burned out. so many moving parts, it's hell to debug and i'm not even sure where to go next with it. (plus people keep talking badly about pidgi…
Re: XMPP: The secure communication protocol that respects privacy
#107XMPP is dead and I'm very happy about that. The only people who still use XMPP in a significant capacity are the likes of Nintendo (for the Switch push notifications system) and it is pretty out of reach for any average citizen. XMPP as a protocol for engineering and science is fantastic. As a set of standards it's well designed. Performant, flexible, and powerful. As a general, average Joe software however it fuckin…
Quoted this on XMPP for the irony.
Re: XMPP: The secure communication protocol that respects privacy
#108Earlier quoted context omitted.
Matrix supports encryption out-of-the-box without any strange key exchange problems. Most of the time the way key exchange is done in XMPP is very insecure.
> Matrix supports encryption out-of-the-box that's not true for most clients, though (AFAICT, only riot works with itself). I might even say that the situation is better/more sustainable in XMPP where more diverse implementations of the encryption protocol are available, with all mainstream clients supporting it: https://omemo.top/
Riot doesn't exist anymore. It's been Element for a while now
Re: XMPP: The secure communication protocol that respects privacy
#109Encryption is "activily bein worked on", sound about right - I never got encryption to work across two of my own devices with a third party. Yet I do not understand why a rewrite of messaging as [matrix] was necessary, when XMPP was already there and matrix did not even have an edit-message feature on release, perhaps not even now.
As to whether one approach is better than the other is left as an exercise to the reader :) But having each approach belong to separate projects allows them to carry on as they see fit, and means they don't have to participate in a zero-sum game.
Re: XMPP: The secure communication protocol that respects privacy
#110Earlier quoted context omitted.
> What would be your alternative? A good starting point would be more balanced articles also talking about downsides or not-so-secure/-private defaults; not only in case of XMPP but in case of any instant messaging protocol or ecosystem. Instead of claiming, "XYZ is secure because it supports TLS," articles should also mention what this means in terms of limitations (e.g., TLS protects data in transit, so server-side…
Quoted post unavailable.