XMPP works – 1 July 2020
xmpp.org
xmpp.org
1. Don't run your own server? A co-worker once operated a fairly popular "public" XMPP server with a decent number of typically active users, a couple hundred. Some eastern European "darkweb" drug sellers had an account on the server, so their competitors thought it worthwhile to threaten the XMPP operator with very directed violence. If you don't host your own, who is running your XMPP server? What will they do when the government/yourThreatActor threatens them?
2. If you do (or don't!) run your own server, how do the end users find a halfway decent application on their fancy iPhone 18 Pro++ that supports push notifications? Their Windows 10 desktop? Ubuntu Linux?
3. If you run your own server, what do you do in the unlikely event of spam?
4. Crypto? OTR sucks for multi-device, OMEMO isn't extensively supported.
XMPP obviously doesn't work, but I can't suggest anything that's better.
At the time, it felt like every feature was stuck in beta/RFC mode with very poor cross server compatibility. How is a federated protocol supposed to work like that?
I think XMPP just failed to cater to any audience. The Googles and Facebooks could roll their own and for everyone else it was too cumbersome. It's not as "easy" as running an email server and no one wants to do that either. It wasn't even agile enough to woo small communities with whiz-bang features.
On a related note, AOL should've open sourced and federated AIM. Everyone in the late 90's, early 2000's was on it.
afaik AIM was a derivative of ICQ, but yea those were the good times. today i know more ppl that won't touch whatsapp then there were w/o icq numbers back than, probably the closest we've got to a ubiquitous instant messanging. i still remember my icq# althou i havent used it in like 15y and have burned throu like five phone numbers since.
However, this breaking down of the protocol to small components is the strength of the protocol, not a weakness.
Outside the United States, very few people were on it. When I signed up to play some video games with some US friends from a forum, I remember having to Google a valid US address and it's matching ZIP code as it wouldn't even let me sign up without one.
MSN was more popular in western Europe and as I understand it ICQ (eventually federated and shared some tech, but not the same network) was the top early IM in eastern Europe. Can't comment on the rest of the world at that time but I doubt the sign-up form was any more accepting of Korean addresses for example.
Imagine if the global phone network was balkanized like messaging networks...
TBF, we asked them to let us use the protocol, or make it part of IMPP, or get actively involved in IMPP.
I know, I've run both for a number of years.
Very few people need clustering support.
alas MIX adoption is very low. ejabberd got MIX support in 2016 but it's stayed at 0.1.0. and, more pressingly, i don't think any clients support it. this has to change for XMPP to pass MVP muster. https://www.reddit.com/r/xmpp/comments/arpruf/what_clients_s...
Obviously for an internal company chat app this is not the best option as it will require some maintenance, and the app support is not great, though there are some good options now.
But for heavy chat load it is a great choice that will save you a ton of money, time and resources.
Matrix seems to solve items 2 and 4, lets see how much traction it gets.
2. IMO the biggest hindrance with XMPP. So which XEPs do I need to support on the server? Okay, got what I wanted. How do I find out exactly which are supported on which client?
3. Manual account creation, thanks to federation I don’t need external users to be on my server.
4. OMEMO works with every halfway decent client. Of course, closed ecosystems like iOS might be different, but that’s what you get for locking yourself in.
It's early days and there's still some way to go, but the current release (server + Android client) is receiving excellent feedback from those using it.
The next primary focus is iOS. There are several XMPP clients available on iOS, but none yet fit the bill. That's where most of the work ahead lies for the coming months.
[1]: https://snikket.org/
It took us 'only' 2.5 years to build a good XMPP client for iOS (which we plan to release this month, finally), and while building it we had to break down XMPP down almost to a core and replace most of its components with better thought through solutions that account for real life scenarios.
We had to throw away MUC garbage, do push notifications differently, make different video calling, etc. - and that requires modifications on the server-side. Now it works acceptably, just some rather little quirks/bugs remain. It is no coincidence that not one released XMPP client today can be called 'working'.
However, to make it work _really_ great we'll have to do 'break' XMPP even further and rethink how presences work. Currently, they are a major pain.
Snikket is building on and improving (pushing upstream whenever possible) existing projects in the ecosystem, not starting from scratch. The smooth invite-based onboarding flow for example originated from Snikket work, and is now upstream in Conversations and other clients are adopting it too.
I've been working with and on XMPP for 15 years, and have no illusions about the challenges we (or any fully open decentralized messaging system) face in today's world. However we can never give up on free, open and interoperable technologies.
Snikket is aimed at people who primarily just want an out-of-the-box self-hosted secure messaging service. "XMPP" is not a feature for this crowd, but the benefits of XMPP are (federation, free choice of client software, etc.). For the same reason Mozilla doesn't advertise Firefox as a "HTTP client", the Snikket marketing is focused on features and not how the underlying tech is implemented - what we do, not how we do it.
The fact that Snikket is built on XMPP is not something we aim to hide however, it's discussed in [1] for example. It's just not what we lead with when introducing the project to general users.
Many good open-source projects fall into a trap of their developers marketing their project in a way that they would want to see it marketed to themselves. The truth is that nobody outside certain internet communities cares about open standards. They should, of course, but they don't realise it. We're trying to reach these people with Snikket.
That's a problem with the iphone, not xmpp. Apple restricts what you can do with your hardware and offers no other options than their push notification approach. You cannot blame existing protocols for apple's distributed-software-hostile whims of the day. Blame apple for only offering an anemic subset of the internet.
I do manual account creation and know people there (or they are vetted by my friends). The server federates with any other server that supports s2s encryption so they can talk to whoever they want.
On windows probably the most mature client is Gajim. You can use it on Linux too, but there are more alternatives (such as the more modern Dino.im) On Android there is the excellent Conversations, with a few more to choose from. Or you can go with a platform-independent web-based client and use Movim. All support OMEMO. I am not invested in the Apple ecosystem so I don't know about that (Beagle IM? Monal?).
Typically the XMPP naysaying is a mix of bad experiences in the past and NIH syndrome. Things like server-side message archiving, message carbons, message delivery receipts or MUCs are long solved. You want to make a stand for open, federated internet you need to put your money where your mouth is.
About the only sore points are cross-platform VoIP (Windows lacking here) and direct file transfers (SOCKS5 bytestreams are wonky which leaves http uploads) although arguably neither have to be a part of a chat application.
* MIX. there's a new standard for group-chats/rooms that is far less ad-hoc/special-case, that uses other XMPP extensions (XEPs) very well & enables features people expect in chat these days. it's a good standard. MIX (XEP-0369) support is still alpha level or non-existent. this is needed for a quality experience, with reactions, chat history, & as a technical advancement out of a bad shifty early legacy solution.
* Video. There are not a lot of video supporting clients. I think the spec is mostly ok for 1:1 video. But "Muji" multi-user video got demoed a decade ago & works but is more or less unimplemented. This is not cool. I think Muji also should probably be rebuilt anyways atop MIX.
* web integration. i'd like to be able to use my XMPP account online in a well-defined way. xmpp should start to define ways to make user accounts also OpenID Connect (OIDC) providers, & begin to define interoperation for webrtc & XMPP & the web to work together harmoniously.
Works very well and Riot is on: iOS, MacOS, Windows, Google Play, F-Droid, Linux, and has a very nice web application.
This is what got me started: https://matrix.org/blog/2020/04/06/running-your-own-secure-c...
In 2011, at my job everyone used their own favorite account to chat with each other. I'd logged on Empathy with my yahoo mail. My coworkers were on gmail, aol, yahoo, hotmail, facebook, and some I can't even remember. Chatting wasn't a problem. How did it go from being a convenient thing for everyone to everyone should use slack?
I will never forget how a few years back, a friend (and a techie at that, albeit more scientific) explained to me their amazing idea of a messenger that you could use between different chat providers, and messages would just go from one to the other. "Imagine you could send a message on facebook and I would read it on google!" I could see something die in their eyes when I explained that not only was there a solution to this, but also, facebook and google had both already decided to kill that solution.
Oh well... don't buy into walled gardens kids.
At least we have some solace [1] in that, unlike chat and Git, it's fucking impossible to self-host e-mail.
[1] This part is the joke.
And you don't have any control over what they blackhole or reject without even delivering to your inbox/spam folder, if you're their user. You don't get to see logs either.
And big benefit of self-hosting is that you can actually make your server receive everything with no rejection or blackholing. So in that sense, self-hosting can actually be made extremely reliable for reception, and that is much more important to me than reliable sending. So I'd say self-hosting is superior when it comes to reliability, because at least you can make one direction "100%" reliable. With big freemail you can't make any direction comparably reliable.
As soon as you get some IP address reputation, sending gets fairly reliable too. And it will also work fine without any modern cruft on top. You really don't need spf, dkim, dmarc or any of that, for your personal e-mails to be delivered.
Kinda unfortunate that others sometimes block you when you're starting out just based on your IP address [range], so it's discouraging, but it mostly works after a while.
It's symmetric in the sense that if Alice can't communicate with Bob, then Bob can't communicate with Alice. But network effects break the symmetry. If you have a big provider you can reliably communicate with 99.99% of people. If you have a small provider you can reliably communicate with 95% of people.
*Numbers made up to illustrate the point.
So if big provider drops 95% of incomming emails from non-big providers into black void, their service is less than useless to me, and their quality would be at par with small providers that can deliver 95% emails successfully.
Think of the value of this! Anyone, anywhere, using whatever client they choose, can send a basic message to anyone and expect it to arrive and be taken seriously.
Imagine if IM had worked the same way! I know XMPP is a shitstorm, but one can dream.
Not until I left academia and started working for MegaCorp that mandates outlook web as the only email client did I truly internalize the value of this.
(Bonus: encryption is done automatically for you, by default)
Now of course that doesn't mean you should never be synchronous, and it is true email might not be the best vector here. But from my little experience it's good enough for simple messaging.
Correction. Everyone went to Facebook. Because Facebook was convenient. Now we are all heading to slack (& discord) because XMPP was no longer convenient & the right-wingnuts are the top 10 shares every single day every day on Faceboook so we no longer wanna hang out on it.
I'm not sure which Facebook you're using, but I certainly don't see anything shared by 'right-wingnuts' going very far. In fact, it's usually silenced and removed almost immediately.
I actually had to stop using Facebook over the past couple of months because of all the left-wing nut job ideas that seem to have become mainstream like the hundreds of thousands of protesters around the US that spread Covid by not wearing masks and are now trying to blame business owners and Republicans. Science and facts seem to now be a thing of the past.
It's also very difficult to have any actual opinions about any current events, especially of you are not African American and disagree with any of the current narratives the mainstream media is attempting to shove down our throats.
Sure you can have an opinion, but if the wrong person sees it, they will attempt to get you fired from your job and shame people into de-friending you. It's the 2020 Salem witch trials.
This is the response I get 99% of times when I report blatant racism, xenophobia and conspiracy theories.
As I said, we're not using it anymore.
Ben Shapiro & BlueLives Matter were 6 of the 10 most reshared pieces of content yesterday & none of the other top 10 are anything but polarizing trashy antagonistic regressives either.
https://mobile.twitter.com/kevinroose/status/128100072722610...
I would be willing to admit, this kind of content does not feature a lot in my personal experience when I did use Facebook. But in general, I'm not inclined to log in & stay logged in, as it doesn't add continuous value. And I don't want to give advertising-dollars to a platform that does, day after day after day, reliably, serve to brainwash America with these reactionary attention-hungry wolves.
I'd point out that the Salem witch trials you raise judged people based on fiction (there are no witches), & killed them. Losing some friends & your job for being a demonstratively terrible awful person does not seem like a fair comparison: there is real guilt, & the consequences seem survivable. I'm not sure that the ability of any one incident to become a lightning rod of attention is ideal, but it felt like being an absolutely terrible person for too long had no consequences: I would like to see more safety nets, more forgiveness, more healing, but there being consequences for actions is an enormous improvement over where we were, and frankly the consequences seem reasonably inline & reasonable in a vast majority of the situations at hand.
I'm sorry that this seems so overwhelming for you. I hope you can find some peace.
Around that time the iPad was showing up everywhere and I found was that there were zero good iOS XMPP clients. Every single one we tried, I'd notice it was proxying the credentials through a 3rd party server to deal with the lack of background connection support and to handle the push notifications. This was a major security issue, and also meant it would have been unusable during an internet outage.
This sort of thing, combined with the lack of server side history was probably what killed it.
But iOS doesn't let you do background sockets, so you need push messages, and that's hard to coordinate between unrelated XMPP servers and clients. Of course, modern Android doesn't let you have background sockets either.
If you don't use scheduled jobs to reopen your connections, WLAN/mobile switching is a pain and there are some smaller similar pains. If you solve that big pain and make sure to use very little battery power, the smaller pains go away.
I’m pretty sure the larger orgs that were targeted could tell that the only way this information leaked easily, or was justified, was because of XMPP metadata, or some other large scale flaw.
The XMPP group also had a pretty visible security/encryption lockdown that I didn’t feel like was explained well, or maybe I just didn’t understand it :) https://github.com/stpeter/manifesto/blob/master/manifesto.t...
I did run the older version to try Gajim out and to see how one connects to servers and which servers to use and whatever. That worked actually pretty well. I only had to find an OMEMO supporting server in at least superficially trustworthy hands. I really likes the instant feeling of sending messages and being able to log into 2 accounts on different servers and sending myself messages.
I'll have to try it again at some point. I would really like to know a reliable long term server, run by people with a privacy mindset though.