Live data from Hacker News

Colibri – chat platform built on the AT Protocol for communities big and small

colibri.social

71–80 of 108 posts

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#72
We need more aggressive laws to prevent privacy destroying platforms. Every person who creates a website or platform that advertises any kind of private communication but does not fully encrypt user data must go to jail. This cancer needs to be stopped.

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#73
Not sure who the target audience for this is?

ActivityPub (Mastodon etc) has already very granular permissions wrt. who to federate with, which posts to make public, edit or withdraw posts after initial creation, etc. catering to EU privacy and moral/personality rights demands.

For closed group chat, there are many alternatives.

Discord is after all a video chat app designed to be used during a gaming session first and foremost.

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#74
post #29

Users in a Discord server/local community on tools like Discord naturally expect that their actions within that community are private in so far as they trust everyone in the community (including the operator) to keep it so. By using ATProto, Colibri fundamentally makes all of your communication within any community completely public to everyone on the internet. That’s fine for something like Twitter, where the produc…

[flagged]

MLS would be the primary standard for group messaging these days with the usual guarantees right? (PFS, backwards secrecy, etc) As I understand it from the RFC, large groups was an explicit design requirement and costs are supposed to be asymptotically logarithmic with group size, so I don't see why it couldn't be used. I feel like Colibri (based on their page) just doesn't believe it's there problem, which seems... irresponsible.

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#75
post #29

Users in a Discord server/local community on tools like Discord naturally expect that their actions within that community are private in so far as they trust everyone in the community (including the operator) to keep it so. By using ATProto, Colibri fundamentally makes all of your communication within any community completely public to everyone on the internet. That’s fine for something like Twitter, where the produc…

[flagged]

Bluesky DMs aren't end to end encrypted. Where are you getting that impression from?

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#76

It's impossible to consider ATproto apps usable until the horrific oauth situation is fixed. It's still not possible to adjust oauth permissions to something restrictive dynamically so every app needs a new account which kind of defeats many of the interop promises, if apps even allow it (colibri requires invite code)

Permission sets have existed for some time now https://atproto.com/guides/permission-sets#permission-set-de...

Those are set by the site requesting the login though.

I believe what they are referring to is custom permissions set by the person logging in, regardless of what the app itself requested.

e.g. login, disable all writes, all attempted repo writes using that oauth token fail.

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#77
post #29

Users in a Discord server/local community on tools like Discord naturally expect that their actions within that community are private in so far as they trust everyone in the community (including the operator) to keep it so. By using ATProto, Colibri fundamentally makes all of your communication within any community completely public to everyone on the internet. That’s fine for something like Twitter, where the produc…

[flagged]

Even with all that, you're leaking an unacceptable amount of metadata.

And what about reliability? If I cause the key to change, and then alter my PDS so it only shows that event to one half of users, did I completely mess up your protocol so you have to delete the chat room and start over?

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#78
post #9

Please consider adding screenshots of the UI that provide an idea of what the experience will be like without having to log in using Bluesky or other credentials.

I assume it looks the same as literally every other chat app

Nash.

There are always quirks and edges. Like using Bluesky itself, there's a number of viable apps for them (some better, some worse), they're all slightly different. There was a large number of Reddit apps, every single one very different.

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#79

Not sure who the target audience for this is? ActivityPub (Mastodon etc) has already very granular permissions wrt. who to federate with, which posts to make public, edit or withdraw posts after initial creation, etc. catering to EU privacy and moral/personality rights demands. For closed group chat, there are many alternatives. Discord is after all a video chat app designed to be used during a gaming session first a…

See, for you it's that, for me it's strictly text app with good notifications and messages delivery, convenient group management, etc.

If i wanted video chat app I'd to for twitch.

Re: Colibri – chat platform built on the AT Protocol for communities big and small

#80
post #29

Users in a Discord server/local community on tools like Discord naturally expect that their actions within that community are private in so far as they trust everyone in the community (including the operator) to keep it so. By using ATProto, Colibri fundamentally makes all of your communication within any community completely public to everyone on the internet. That’s fine for something like Twitter, where the produc…

The first assumption has been long disproved since multiple full scale Discord data leaks. If it's a public server, it can be scraped.

https://www.malwarebytes.com/blog/news/2024/04/billions-of-s...

Post reply on HN