Live data from Hacker News

XMPP: The secure communication protocol that respects privacy

notes.nicfab.it

141–150 of 160 posts

Re: XMPP: The secure communication protocol that respects privacy

#141
post #134

Earlier quoted context omitted.

> XMPP is an open standard -> Doesn't this apply to Signal, too? The Signal protocol is neither an open (you cannot propose changes or extensions in an open process) nor has it been submitted to an standards body. > Some developers claim not to track users. With Signal you have to trust a single entity not to track you. With XMPP you have the freedom to choose that entity (including choosing yourself). > if we assume…

> The Signal protocol is neither an open (you cannot propose changes or extensions in an open process) nor has it been submitted to an standards body. Who defines "open standard" in the first place? There is no global definition for this. > With Signal ... With XMPP ... Another person just claimed comparing both is silly. There are already other comments addressing the rest of your statement. > non-identifiable phone…

> Who defines "open standard" in the first place?

Most people on here would say: https://en.wikipedia.org/wiki/Internet_Engineering_Task_Forc...

Re: XMPP: The secure communication protocol that respects privacy

#142

Earlier quoted context omitted.

I'm arguing with your comments, not the article. Comparing Signal with XMPP is silly. It's like saying 'Firefox is more secure than XML'. Signal is a product, XMPP is a protocol. That said, XMPP can be potentially used to build communication products that are far more secure than Signal because of a simple virtue of being able to control all components of a service instead of relying on someone else to run a server f…

> Comparing Signal with XMPP is silly. Could you please add your statement to any other comments by XMPP proponents that state "XMPP is better than Signal because ..."? Plus, could you also consider this for all of your own comparisons of XMPP and Signal? > XMPP can be potentially used Again, a lot of guessing and assumptions what could be in a perfect XMPP world, but nobody finds nowadays. > with your custom XMPP de…

> Again, a lot of guessing and assumptions what could be in a perfect XMPP world, but nobody finds nowadays.

The German police and British health service would say that their XMPP implementations are pretty secure implementations:

- https://twitter.com/inputmice/status/1203611711967813633

- https://hellopando.com/ / https://www.erlang-solutions.com/case-studies/pando-health-c...

Re: XMPP: The secure communication protocol that respects privacy

#143

Earlier quoted context omitted.

> XMPP is as secure as Signal nowadays, it implements the same encryption scheme Signal enforces E2EE, you can't disable it. If XMPP supports E2EE depends on the XMPP clients and servers, so it isn't enforced and can be disabled. Server admins can even inject XMPP messages that look like coming from the legitimate sender. This is far from "secure as Signal."

> Signal enforces E2EE, you can't disable it. Exactly! It seems like there is a combination of tenuous assertions being made about XMPP security here, followed by naive questions from people who apparently don't understand the basic feature set of something like Signal. Any clue why this is happening?

XMPP is about choice.

I use OMEMO everywhere. However, I do know of people out there who simply do not see the point of OMEMO as, when they are the server admin, OMEMO adds no value over TLS. OMEMO also doesn't make sense in large public groups, cause you're not going to go and verify 100+ people's encryption keys one by one.

OMEMO and end-to-end encryption are also incompatible with keeping a reliable server-side archive of your messages - which will be accessible to all future XMPP clients that you add to your account - which apparently some people want. You can see this at the table at https://conversations.im/omemo/

Meanwhile, you occasionally find people on the Signal subreddit bemoaning that they lost their entire message history with a loved one because some backup file got corrupted and failed to restore or; they lost some device. Here's an example: https://www.reddit.com/r/signal/comments/rbtdtb/

As I said: XMPP is about choice.

Re: XMPP: The secure communication protocol that respects privacy

#144
post #95

Earlier quoted context omitted.

> EDIT: Signal can totally be used through Tor, so the IP can be hidden from Signal. For a centralized service like Signal, your IP doesn't matter, they own your account, literally. You can randomize it as much as you like, and your peers may too, in the end it will not hide from them who sent a message to whom and when.

Nope. As we already discussed, Signal has no idea who sent messages with Sealed Sender. The recipient finds out who sent them a message, but Signal does not.

> Signal has no idea who sent messages with Sealed Sender.

Sorry to deceive you, but "Sealed Sender" is just an empty promise.

Even if you could assess that this is indeed what is being done server-side (and you won't, because Moxie will neither let you, nor will ever federate his server with yours in case you wanted to run your own Signal instance), this does nothing against the fact that every message still enters and exits Signal's walled garden. No amount of indirection in the middle will change that. You are back to trusting all intermediaries' good faith (which extend beyond Signal, btw, Amazon also controlling every packet that enters/exits its cloud on which Signal runs).

Re: XMPP: The secure communication protocol that respects privacy

#145
post #132
post #100

Earlier quoted context omitted.

> I'm very unlikely to recommend it to anyone over alternatives that default to end to end encryption, or even require it. Which are they? Alternatives that require you to reveal your identity (via a phone number), or to reveal your whole social graph/usage patterns (by being organized around a single actor in the middle knowing about everything and everyone in the network)? Federated and P2P networks are the only tr…

>Alternatives that require you to reveal your identity (via a phone number), or to reveal your whole social graph/usage patterns (by being organized around a single actor in the middle knowing about everything and everyone in the network)? No. Matrix and Tox come to mind.

Agreed about Matrix and Tox qualifying (not being centralized).

I can't vouch for Tox from a security standpoint (haven't looked at the details), but I can guarantee that it's not ready for widespread use (esp. on mobile where P2P messaging still needs a breakthrough).

Matrix is fine. In my biased opinion, it's just XMPP with more steps, more overhead and a less diverse ecosystem. Also, its security story is no better than XMPP so it's funny that we came to that from "XMPP, encryption is optional and not even the default", where that's practically truer for Matrix than it is for XMPP.

Re: XMPP: The secure communication protocol that respects privacy

#146

Earlier quoted context omitted.

> If you start with an argument ..., it's strange that you don't apply same logic to Signal admins Where is this 1-to-1 comparison you demand in the OP's original article? Security: They mainly highlight TLS and experimental OMEMO as the main security features of XMPP. TLS is also present in Signal, and OMEMO is based on the Signal Protocol, which is enforced for Signal. So comparing this 1-to-1 in OP's article, Sign…

> XMPP is an open standard -> Doesn't this apply to Signal, too? Signal is the opposite of an open-standard, there's a single server implementation and basically three clients (Android, iOS, desktop) and they discourage people from using other clients. Best way to think about Signal is that it's just WhatsApp with some marketing on top. Meanwhile, I can link a raspberry pi anywhere in the world to my XMPP server with…

> Do not know of a single XMPP client that requires a phone number

Here is the only one I know: https://quicksy.im/

Re: XMPP: The secure communication protocol that respects privacy

#147

Earlier quoted context omitted.

> If you start with an argument ..., it's strange that you don't apply same logic to Signal admins Where is this 1-to-1 comparison you demand in the OP's original article? Security: They mainly highlight TLS and experimental OMEMO as the main security features of XMPP. TLS is also present in Signal, and OMEMO is based on the Signal Protocol, which is enforced for Signal. So comparing this 1-to-1 in OP's article, Sign…

> XMPP is an open standard -> Doesn't this apply to Signal, too? Signal is the opposite of an open-standard, there's a single server implementation and basically three clients (Android, iOS, desktop) and they discourage people from using other clients. Best way to think about Signal is that it's just WhatsApp with some marketing on top. Meanwhile, I can link a raspberry pi anywhere in the world to my XMPP server with…

> I can link a raspberry pi anywhere in the world to my XMPP server with a few lines of Python and some libraries.

Once again, "I, as a tech-savvy person, can operate my highly-customized XMPP setup everywhere", while ignoring that most people do not run their own servers.

> they discourage people from using other clients

This was discussed numerous times various platforms and proven wrong.

> I can verify that my server isn't tracking users

As discussed before on this page, most XMPP users don't run their own XMPP server but use a public XMPP server on the internet. Nobody can check whether this public XMPP server tracks its users without accessing the server itself.

> all of your eggs in a centralized basket, both in terms of privacy and reliability.

So, do you assume the Signal network infrastructure consists of a single server?

> Do not know of a single XMPP client that requires a phone number

At least Quicksy (from the Conversations developer who bragged in a public video about copying WhatsApp/Signal) and Kontalk require a phone number. They even market the phone number requirement as a benefit in comparison with other XMPP clients.

> most people will tell you

I could just claim the opposite. Without any sources, it remains an assumption.

> Signal doesn't

Signal does. You wrote, you use Signal. Did you ever join a Signal group? There is a dialog when entering a group the first time.

Re: XMPP: The secure communication protocol that respects privacy

#148
post #146

Earlier quoted context omitted.

> XMPP is an open standard -> Doesn't this apply to Signal, too? Signal is the opposite of an open-standard, there's a single server implementation and basically three clients (Android, iOS, desktop) and they discourage people from using other clients. Best way to think about Signal is that it's just WhatsApp with some marketing on top. Meanwhile, I can link a raspberry pi anywhere in the world to my XMPP server with…

> Do not know of a single XMPP client that requires a phone number Here is the only one I know: https://quicksy.im/

Yes, Quicksy from the Conversations developer who bragged about copying main features of WhatsApp and Signal.

Another one is Kontalk, https://www.kontalk.org/.

Both XMPP clients require a phone number, and both present the phone number as a benefit in comparison with other XMPP clients without this requirement.

Re: XMPP: The secure communication protocol that respects privacy

#149

Earlier quoted context omitted.

> XMPP is as secure as Signal nowadays, it implements the same encryption scheme Signal enforces E2EE, you can't disable it. If XMPP supports E2EE depends on the XMPP clients and servers, so it isn't enforced and can be disabled. Server admins can even inject XMPP messages that look like coming from the legitimate sender. This is far from "secure as Signal."

Signal admins too can ship you an app version that would show injected messages like coming from legitimate sender. [1] However, while you can be your own xmpp server admin, you can't be Signal admin. [1]: And for god's sake pls don't even start on reproducible builds, nobody really verifies every app updates.

You just wrote it is "silly" to compare XMPP with Signal while constantly doing it yourself.

> Signal admins too can ship you an app

Or I could just use my own Signal client since it is open-source and there are several working forks such as https://molly.im/. How do "Signal admins" (whoever this is) manipulate these open-source forks?

Instead of providing any proof or details, you just post one assumption after another to distract from obvious problems with current XMPP servers and clients. As soon as we debunk a myth, the next assumption comes up.

Re: XMPP: The secure communication protocol that respects privacy

#150
post #146

Earlier quoted context omitted.

> Do not know of a single XMPP client that requires a phone number Here is the only one I know: https://quicksy.im/

Yes, Quicksy from the Conversations developer who bragged about copying main features of WhatsApp and Signal. Another one is Kontalk, https://www.kontalk.org/ . Both XMPP clients require a phone number, and both present the phone number as a benefit in comparison with other XMPP clients without this requirement.

It's a trade-off. If you are unwilling to provide a phone number you can choose any other XMPP provider and still can communicate with friends who use Quicksy/Kontalk. You simply don't have this freedom if you use WhatsApp or Signal.
Post reply on HN