Live data from Hacker News

XMPP vs. Matrix

news.ycombinator.com

41–50 of 92 posts

Re: XMPP vs. Matrix

#41
I'm running an XMPP server for my family and have convinced most of my friends to get an XMPP address. I think XMPP is the more standard way to do messaging. I feel like all the projects that reinvent a basic thing such as instant messaging, instead of sticking to the internet standard are doing more harm than good.

Re: XMPP vs. Matrix

#42
post #7

In order to answer this question it is important to understand the fundamental difference between XMPP and Matrix. XMPP was invented at a time, where communicating online meant sending a message from one device to another. However, the modern expectations for messaging apps are much more than that. Sending media, using multiple devices, deleting messages, editing messages, read receipts, notifications when typing, gr…

Modern XMPP clients have all of those: Sending media, using multiple devices, deleting messages, editing messages, read receipts, notifications when typing, group chats.

Your comment makes it seem like they don't.

Re: XMPP vs. Matrix

#43
Imo matrix is the better protocol, however the clients are still not great. Element X is a big step up but element call is still in a kind of limbo where it's beta on desktop yet default on X.

The desktop client is capable but very very janky.

Re: XMPP vs. Matrix

#45
I use XMPP and then Cheogram for people who don't want to figure it out.

That way for people who don't care everything just works and for people who do they get a rich experience with E2EE. Unlike eg iOS/imessage I don't force them to use a different OS for this and I can talk to everyone from my laptop. Everything is 100% self hostable.

I don't know why you would use Matrix. Self hosting is awful, the clients are a huge mess, and it was bootstraped by the Israel based company that runs US telephone surveillance (it's kind of insane that's done in another country.)

Re: XMPP vs. Matrix

#46
Also: what do we know about the people and institutions developing and promoting these standards and implementations?

We've seen the appointment of people with biographies suggesting affinity with US interests, for example Katherine Maher to the Signal Foundation (and the departure of the Moxie Marlinspike.)

I see a members list for the board overseeing the spec for Matrix, but does anyone know who they are[1]? And the spec is one thing, but who controls the development of the actually used clients and implementations?

Please note I am not imputing anything w.r.t. Matrix/Element etc, but if we're bothered to put effort into E2EE then it is probably worth thinking about this aspect in addition to whether the technical basis is sound. The historical record is clear on government attempts to influence things from that end.

I have the same sort of worries about GnuPG (and the SPoF that is the hard-working maintainer.)

Maybe E2EE is not of concern to the OP, in which case disregard the above.

1. https://matrix.org/foundation/governing-board-elections/

Re: XMPP vs. Matrix

#47
post #40

Earlier quoted context omitted.

> That works in your situation, but not for most people who don't want to have to maintain a moving part. Also hosting in general on a residential connection can depend on the provider and even availability of good internet. Frankly, that works for the majority of XMPP users -- let's not forget about that. But yes, this is a problem today for many consumers. However, I see this as a much better direction for the Inte…

> conceding defeat and accepting a centralized Internet I think you can still have decentralization without having to be a sysop. That may be server operators that run small servers etc. Decentralization doesn't inherently mean privacy though and it's important to remember that. > You still do not get the point here at all. This is not about storage Pretty sure signal servers can't intercept messages or decrypt them.…

> Pretty sure signal servers can't intercept messages or decrypt them. In regard to the client you cannot send unencrypted messages. We do know that lawful interception warrants sent to Signal are not particularly effective only registration time and last connection time is available. https://signal.org/bigbrother/

Please, I'm really trying to put the emphasis on metadata, and definitely Signal servers can intercept that at will. Even here on HN there was recently an article of how "lawful interception warrants" were targeting Apple's and Google's _push notification servers_ (those _by design_ really only have access to metadata -- that should speak about how important metadata is for law enforcement). The Signal server has access to significantly more metadata about you and your communications than your typical push server. Again, there's just no contest here: simply avoiding the issue of using their server in the first place is much better than anything they claim* to do (or even better than anything they could _physically_ do).

* I absolutely detest these type of "our privacy is great, believe us!" pages. Time and time again it shown that they are absolutely useless. Where did Apple report that their push notification servers were tapped? The fact that a server collects enough data about you that it is a tempting target for authorities should be cause for concern, not relief.

Re: XMPP vs. Matrix

#48
post #40

Earlier quoted context omitted.

> conceding defeat and accepting a centralized Internet I think you can still have decentralization without having to be a sysop. That may be server operators that run small servers etc. Decentralization doesn't inherently mean privacy though and it's important to remember that. > You still do not get the point here at all. This is not about storage Pretty sure signal servers can't intercept messages or decrypt them.…

> Pretty sure signal servers can't intercept messages or decrypt them. In regard to the client you cannot send unencrypted messages. We do know that lawful interception warrants sent to Signal are not particularly effective only registration time and last connection time is available. https://signal.org/bigbrother/ Please, I'm really trying to put the emphasis on metadata, and definitely Signal servers can intercept…

> Apple's and Google's _push notification servers_

This never effected signal as no data that is sensitive was ever sent via that. Again though warrants against Signal are not new, and for years law enforcement has been getting the same answers to their subpoenas. If it was "possible" as you say and that "they do", pretty sure the ACLU would not be making submissions to a court that "this is all that is available & " especially as the source code is open, it would be easy to verify if that was in fact true.

> I absolutely detest these type of "our privacy is great, believe us!" pages

The page literally has the legal request and reply, these would be able to be checked against court records. Remember being in contempt of a court order is actually punishable, so if there was more I'm sure Signal would have been fined by now lol.

Re: XMPP vs. Matrix

#49

Matrix if any of your friends and family are on iOS. As much as I'd like for XMPP to be more popular, only Android has a decent client. Element is far from perfect, but its shortcomings are platform-agnostic.

Have you tried Monal on iOS? It has made the iOS experience a lot better recently.

Re: XMPP vs. Matrix

#50
post #48

Earlier quoted context omitted.

> Pretty sure signal servers can't intercept messages or decrypt them. In regard to the client you cannot send unencrypted messages. We do know that lawful interception warrants sent to Signal are not particularly effective only registration time and last connection time is available. https://signal.org/bigbrother/ Please, I'm really trying to put the emphasis on metadata, and definitely Signal servers can intercept…

> Apple's and Google's _push notification servers_ This never effected signal as no data that is sensitive was ever sent via that. Again though warrants against Signal are not new, and for years law enforcement has been getting the same answers to their subpoenas. If it was "possible" as you say and that "they do", pretty sure the ACLU would not be making submissions to a court that "this is all that is available & "…

> This never effected signal as no data that is sensitive was ever sent via that.

How are you still missing the point that this is _about metadata_? No one is sending "sensitive data" through a push notification in the first place. You have to go out of your way to do that. My point was to show you that the authorities _are_ after metadata.

Post reply on HN