Live data from Hacker News

We can do better than Signal

icyphox.sh

211–220 of 290 posts

Re: We can do better than Signal

#211
post #203

Earlier quoted context omitted.

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

Here's a screen recording of me trying to log in to app.element.io [0]. 0:10 - Stuck on "Verify this login" despite cancelling 1:00 - Same as above. The security phrase I have saved seems to be invalid. 1:38 - Can't drag or expand the left panel. Went away when I made the window wider after I stopped recording. 1:52 - After clicking "Verify" again, the session immediately verifies? I didn't enter any passphrase or do…

Firefox 68? I'm running Firefox 84.0.2 on Pop_OS 20.04. I can empathize with the project maintainer for not prioritizing a browser ~20 versions behind latest.

Re: We can do better than Signal

#212

Earlier quoted context omitted.

The solution is simple. Make the decentralized systems social, with reputation.

And that then is extremely easy to abuse as soon as you have enough people with high rank enough deciding to start to misbehave.

It even happens in the real world too. I remember one guy who had been on eBay or something for years working up a huge positive karma, and then one day a switch flipped and he disappeared with everyone's money and was never seen again.

Re: We can do better than Signal

#213
post #183

Earlier quoted context omitted.

I can't see how this is a problem on its own. If they were eschewing some better option than "don't trust the server", that would be a problem, but is there a better option?

Yes, the solution is … allow the protocol to let people run their own servers?

It's the Signal app that depends on their server, there isn't anything in the protocol that stops someone from building an app that talks to other servers.

It's kind of fascinating, they have done a pretty good job of laying out their goals, easy contact discovery, forced protocol upgrades, etc, and people come up with all these improvements they could make by just setting aside those goals.

Re: We can do better than Signal

#214

Earlier quoted context omitted.

Yep, there should be a crash or bug report form within the app itself, and an email for bugs at something like support@element.io

There is one in Element Android. When the phone is shaken, a dialogue pops up "It seems you're shaking your phone in frustration, file a bug report". It has in-app bug reporting.

Also 'Menu > Report Bug' on Element Android.

Re: We can do better than Signal

#215

Earlier quoted context omitted.

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

I don't actually think anything is awful, but my main complaint about Element as a GUI app, is that aside from opening the chromium developer console and watching what it does, it has very few options to diagnose client-server connectivity or TLS crypto key handshake issues. I wish it wasn't an Electron app built on Chromium which makes it a huge resource hog. There's lots of underlying dependency and reliance on wha…

Isn't the beauty of Matrix that you or anyone else can build a client on top of the platform easily? I know on my Linux machine there are some non-electron options, like Qt [0].

[0] https://matrix.org/clients/

Re: We can do better than Signal

#216
post #203

Earlier quoted context omitted.

Here's a screen recording of me trying to log in to app.element.io [0]. 0:10 - Stuck on "Verify this login" despite cancelling 1:00 - Same as above. The security phrase I have saved seems to be invalid. 1:38 - Can't drag or expand the left panel. Went away when I made the window wider after I stopped recording. 1:52 - After clicking "Verify" again, the session immediately verifies? I didn't enter any passphrase or do…

Firefox 68? I'm running Firefox 84.0.2 on Pop_OS 20.04. I can empathize with the project maintainer for not prioritizing a browser ~20 versions behind latest.

I forgot to turn on automatic updates. Still, it's only 1.5 years old.

Re: We can do better than Signal

#217
post #160

Earlier quoted context omitted.

By punishing their connections when they misbehave. Or at least, that's how you make it not matter. If spam-bot hands out reputation to spim-bot and then you get a bunch of garbage from spim-bot, derate everything coming from anyone that has given either of them reputation (and perhaps ignore their attestations also).

Now what happens when spam is done through a compromised user, or when the user acts human and has real interactions before spamming?

I suppose it depends on the details quite a lot.

But fundamentally, it isn't particularly harmful to just burn a user that starts spamming. If a compromised account is recovered, it's fine if they have to restore communication out of band, if it isn't recovered it's fine that it is burned.

Re: We can do better than Signal

#218
post #57

Earlier quoted context omitted.

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

I should be clear, I wouldn't say Matrix/Element "sucked", and I apologize if that's the tone that my comment implied. It's pretty cool, and I greatly preferred it over trying to finagle XMPP + OMEMO, and I will probably try it again soon enough.

In my case, my issues came down to mostly your last point:

> Verifying yourself when you log in on a new device has confusing UX, and there's a known bug that can stop keys being synced to the new login even once verified.

If I installed a desktop client on two different mac computers, I would have issues with messages not decrypting properly until I do a re-verification, and figuring that out took some Googling and trial-and-error.

Re: We can do better than Signal

#219
post #203

Earlier quoted context omitted.

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

Here's a screen recording of me trying to log in to app.element.io [0]. 0:10 - Stuck on "Verify this login" despite cancelling 1:00 - Same as above. The security phrase I have saved seems to be invalid. 1:38 - Can't drag or expand the left panel. Went away when I made the window wider after I stopped recording. 1:52 - After clicking "Verify" again, the session immediately verifies? I didn't enter any passphrase or do…

I'm not able to load your video, Firefox says unable to connect.

Re: We can do better than Signal

#220

Earlier quoted context omitted.

Simple Groups and painless multimedia was what gave WhatsApp the edge in the early days

Liked "Simple Groups and painless multimedia was what gave WhatsApp the edge in the early days" ------- ^ That's and ultra low res photo sharing what you get when you group SMS/MMS with folks in the Apple ecosystem. You don't get it in WhatsApp, etc.

I'm not sure what this comment is saying.
Post reply on HN