If you want to develop fast, use neither and make your own protocol that suits your custom needs.
XMPP vs. Matrix
31–40 of 92 posts
Re: XMPP vs. Matrix
#32In order to answer this question it is important to understand the fundamental difference between XMPP and Matrix. XMPP was invented at a time, where communicating online meant sending a message from one device to another. However, the modern expectations for messaging apps are much more than that. Sending media, using multiple devices, deleting messages, editing messages, read receipts, notifications when typing, gr…
Re: XMPP vs. Matrix
#33Earlier quoted context omitted.
> And does that invalidate any of my point Yes it does, because the threat model there is not the server itself. You trust that as it's your employer's server and you're using it for work related purposes. > Timing alone is enough to clearly distinguish a sender It's a lot harder to pull off than doing an MiTM attack with STARTTLS and then just observing the person's roster being sent to them when they connect lol.
> You trust that as it's your employer's server and you're using it for work related purposes. Yes, that is the point. Or it is my home server sitting at my router serving my family. I have been arguing that if I can trust the server then the discussion about E2EE becomes less relevant. > It's a lot harder to pull off than doing an MiTM attack with STARTTLS and then just observing the person's roster being sent to th…
That works in your situation, but not for most people who don't want to have to maintain a moving part. Also hosting in general on a residential connection can depend on the provider and even availability of good internet.
For a lot of people it wouldn't even be possible if they wanted to and that's not getting into the technical investment they would have to make in knowing how to do such a thing in the first place.
> And here you make the dangerous mistake that I most hate. It's not only trivially easy for the server operator to leak metadata, it's actually HARD to avoid it.
It's a lot easier than simply not having that data server side in the first place like Signal for example.
Re: XMPP vs. Matrix
#34My own experience is a two years old, but interoperability seemed not to work great. Messages frequently disappeared and all that. As long as you stayed on the same instance everything was dandy, but writing to someone one the matrix homeserver worked most of the time. Matrix as a protocol is more exciting than xmpp, but using xmpp (without omemo unless you are all on Conversations) is boring in a good way.
Unable to decrypt message
Re: XMPP vs. Matrix
#35In order to answer this question it is important to understand the fundamental difference between XMPP and Matrix. XMPP was invented at a time, where communicating online meant sending a message from one device to another. However, the modern expectations for messaging apps are much more than that. Sending media, using multiple devices, deleting messages, editing messages, read receipts, notifications when typing, gr…
Commitment in what way? I found it fairly easily to set it up with a domain of my own.
Re: XMPP vs. Matrix
#36Earlier quoted context omitted.
> You trust that as it's your employer's server and you're using it for work related purposes. Yes, that is the point. Or it is my home server sitting at my router serving my family. I have been arguing that if I can trust the server then the discussion about E2EE becomes less relevant. > It's a lot harder to pull off than doing an MiTM attack with STARTTLS and then just observing the person's roster being sent to th…
> Or it is my home server sitting at my router serving my family. That works in your situation, but not for most people who don't want to have to maintain a moving part. Also hosting in general on a residential connection can depend on the provider and even availability of good internet. For a lot of people it wouldn't even be possible if they wanted to and that's not getting into the technical investment they would…
Frankly, that works for the majority of XMPP users -- let's not forget about that. But yes, this is a problem today for many consumers. However, I see this as a much better direction for the Internet as a whole to take -- see efforts such as ownCloud and the like -- , rather than just conceding defeat and accepting a centralized Internet, or worse: the extremely dangerous idea that centralization increases security. Which should only be seen as the non-sense it is.
> It's a lot easier than simply not having that data server side in the first place like Signal for example.
You still do not get the point here at all. This is not about storage. This is not about the server implementation. As long as there is a communication at all between me and the server and then my contacts and the server, it is irrelevant if you are storing the roster or not. ANYONE (*anyone with access to that server) can easily pick it up. In fact, it is HARD not to leak it up, even by accident. Barring a P2P Freenet-like thing, this is _unavoidable_. (and even with P2P/Freenet/Onion/whatever it's not trivial) And due to the nature of IMs, metadata is practically as big an issue than protecting the payload itself.
Re: XMPP vs. Matrix
#37In order to answer this question it is important to understand the fundamental difference between XMPP and Matrix. XMPP was invented at a time, where communicating online meant sending a message from one device to another. However, the modern expectations for messaging apps are much more than that. Sending media, using multiple devices, deleting messages, editing messages, read receipts, notifications when typing, gr…
Disclaimer: I'm an XMPP server developer and work on [MongooseIM]( https://github.com/esl/MongooseIM ). > XMPP was invented at a time, where communicating online meant sending a message from one device to another. However, the modern expectations for messaging apps are much more than that. Sending media, using multiple devices, deleting messages, editing messages, read receipts, notifications when typing, group chats…
Re: XMPP vs. Matrix
#38Re: XMPP vs. Matrix
#39Re: XMPP vs. Matrix
#40Earlier quoted context omitted.
> Or it is my home server sitting at my router serving my family. That works in your situation, but not for most people who don't want to have to maintain a moving part. Also hosting in general on a residential connection can depend on the provider and even availability of good internet. For a lot of people it wouldn't even be possible if they wanted to and that's not getting into the technical investment they would…
> That works in your situation, but not for most people who don't want to have to maintain a moving part. Also hosting in general on a residential connection can depend on the provider and even availability of good internet. Frankly, that works for the majority of XMPP users -- let's not forget about that. But yes, this is a problem today for many consumers. However, I see this as a much better direction for the Inte…
I think you can still have decentralization without having to be a sysop. That may be server operators that run small servers etc.
Decentralization doesn't inherently mean privacy though and it's important to remember that.
> You still do not get the point here at all. This is not about storage
Pretty sure signal servers can't intercept messages or decrypt them. In regard to the client you cannot send unencrypted messages. We do know that lawful interception warrants sent to Signal are not particularly effective only registration time and last connection time is available. https://signal.org/bigbrother/