Would it be possible to use the same open source proto and crypto that Signal chose, but in a way that does not rely on third parties to run servers, such as OWS, WhatsApp, Facebook, Google, Microsoft, etc.?
Would it be possible to use the same open source proto and crypto that Signal chose, but in a way that does not rely on third parties to run servers, such as OWS, WhatsApp, Facebook, Google, Microsoft, etc.?
1. https://en.wikipedia.org/wiki/OMEMO 2. https://prosody.im
https://signal.org/blog/private-contact-discovery/
Moxie has said repeatedly that they're working to do better on this front, but it's not without its technological challenges. He's written repeatedly about this and has also called for anyone willing to try to make it happen and offered to help them. Just one example springs to mind:
https://news.ycombinator.com/item?id=12883410
And federation is possible over XMPP with Signal:
That article does not say this. In fact, it more or less has the opposite meaning.
NAT, Firewall, etc all make it very difficult to do true P2P as well.
Or Outlook(Office365), Ymail, Zoho, GMX, iCloud, Yandex, Proton.
http://lettergram.github.io/AnyCrypt/
The problem is we need to stop worrying about end-to-end encrypted <insert name here>. We need something that blocks javascript, and encrypts our messages before they even enter the pipeline (there will still be meta data though).
The extension I built was a POC just showing how it could be done easily with Keybase.
It's not like "today, you feel white-ish enough to not be silently dropped at gw, black-ish enough to go in the spam folder without warning" is the only valid policy to fight spam.
Even simply rejecting with an error (spam suspected) would be better than the silent treatment.
And I don't see anything wrong with telling people how you set up a firewall. We even write books about that.
The only systems that have had even tiny problems with were Gmail and Microsoft. With Gmail it took a while to build reputation as a non-offender. With Microsoft the first time I sent mail to their way, I got an automated bounce with instructions to forward to a certain address for human verification. That check round took maybe 12 hours and I haven't had any problems since.
I find that pretty reasonable.
But how do you know that when you send mail to a new Gmail contact it won't be silently flagged as spam? And how many times will the recipient have to "un-flag" before the behaviour changeges?
> The only systems that have had even tiny problems with were Gmail and Microsoft
The "only" big provider missing from that list is apple (in the West anyway).
I've never meant to claim that smaller providers that know what they're doing aren't capable of sending proper bounces, setting proper smtp error codes on reception or of handling email to postmaster@.
It's just that with Gmail and outlook not being God net citizens - it becomes unreasonably hard to send legitimate email to a large percentage of Internet users. One possible "fix" is to send mail to Gmail users via a Gmail account and Gmail authenticated smtp servers - and so on for outlook.com - but as the number of "silos" one needs to send data to grows, that solution becomes cumbersome. Not to mention if you publish an mx record for your domain, you should be accepting email... That's the whole point...