Messaging is analogous to money in a lot of ways. Perhaps we'll see a good distributed peer to peer messaging protocol at some point in the future.
Messaging is analogous to money in a lot of ways. Perhaps we'll see a good distributed peer to peer messaging protocol at some point in the future.
The Matrix protocol is actually fairly promising, as long as you only use it for Matrix<->Matrix communication. Things fall to pieces when you try to bridge it with IRC.
It's certainly more user-friendly for non-tech. folks than, say, the awkward key exchange/setups of XMPP clients, but it's still a far cry from something like Signal in terms of 'ease of use'
What do you mean by that? Conversations.im establishes e2e secure session without any fingerprint approving interaction whatsoever. Of course you can manually scan barcodes for paranoid mode but that's not necessary.
For me it's a perfect balance between convenience and security. Read more at https://gultsch.de/trust.html
I was mainly speaking to previous experiences trying to set up Conversations on one device, Pidgin on another, there not being any good way to use a consistent key for my user on both, and trying to walk non-technical family members through that fiasco. This was about 2 years ago, maybe the situation has improved!
As much as Jobs revolutionized the smartphone industry, this is the long-lasting legacy we will have to live with for decades (or forever?).
I could be wrong though.
Any time you have a central authority providing that validation, you have to trust that your "friend" hasn't fooled them.
This is much easier to explain to a non-techie than comparing security numbers or hashes.
- Red = No trust
- Yellow = You trust that the server has verified the identity
- Green = You have verified the identity yourself
(Edit: Formatting)
Edit: Found the problem with that. Certificate authorities are supposed to actually go out and confirm that the person who requested the certificate, is the person that they say they are. This is far too much work, if you want to verify each individual person who wants to use a messenger.
And then if you want to talk to them, you encrypt your message with their Public Key. Then only they can decrypt it with their Private Key (assuming no one else their Private Key).
But if a hacker / NSA agent / script kiddo pretends to be your friend and tells you their Public Key, then they'll be able to decrypt your messages with their Private Key. You might never know that they aren't your friend.
You'll have to ensure that you actually have the Public Key of your friend by some other method. For example meet them in person to exchange Public Keys, or read it out over the phone, if you know what their voice sounds like on the phone.
It could be decentralized through pluggable identity authorities which provide the public key transfer via a secure channel. Essentially you'd use the same protocol and select what servers (WhatsApp, Signal, maybe some sort of immutable ledger elsewhere) to use.