Signal is having technical difficulties
status.signal.org
status.signal.org
I realised I was more than happy to pay WhatsApp's yearly charge back in the pre-Facebook days (think it was 70p or so?).
Figured I could give Signal a few quid every now and then, maybe keep a server up for a few seconds :)
Donation link should anyone be interested: https://signal.org/donate/
I’d prefer to pay yearly than to feel the spectre of guilt for using a “free” app.
So they’re 4mil in the hole? How is it possible that they’re still running?
I have no idea why anyone would donate $20 when they're sipping on $100m ...
Signal is using AWS & GCP ( for cloud fronting ), they could be approaching that spend level.
That is 100% their problem, though. I trust that they will develop a sustainable business model when it becomes necessary. Otherwise, look at their tax info shared above. Sporadic donations won't even make a small dent.
I mean, shoot, they won't even give us a hint at how much to donate to cover our own costs. That would be a start.
TBF they havent had to think about this too much before the last 5 days, so give them some time to come up with a plan.
In the mean throw them whatever you are comfortable with.
Donate to them so they can buy more servers https://signal.org/donate/
* If you work in the US, many corporations will match your donation. Easy double of your donation
* Set https://smile.amazon.com to Signal, so your purchases on Amazon go to Signal
* Use services like Paypal to donate, that sends 100% of the money to the foundation
Why am I saying this? Users don't give a damn, they expect free things, and they expect things which work. They have been taught to use appstores on their phones where tapping on a button installs an app and everything just works with zero effort on their end, while completely ignoring the work that someone put into creating the very app they depend on. Majority will never, ever, even think about it, let alone click on the developers website to find out who created the miracle they use.
This practice needs to end. I believe that it is time to stop making free products. Developers should unite in this and finally start to value their hard work.
The world would be better if the world were better, but until it is, would you mind helping out a bit?
The problem is, this is not a sustainable model (Wikipedia is a whole other universe and can not be compared) and it bugs me so much to see developers pour their souls into projects which end up dying.
Is there any indication that applying capital to the problems we're seeing will fix them?
I want to help, but only in a way that will be effective in improving the situation. If they already have enough money, giving them more will not. If they don't have enough money following a $100mm USD donation, it's possible that giving them more will not.
You can't stop someone trying to make a free to use product
Where they'd be told to get lost if they misbehaved.
With GitHub, the branding of products is lost and most credit goes to GitHub. If a user isn't satisfied, he does the proverbial left-swipe and goes to the next project in a second.
If you tell a user to get lost, you violate the tenets of the new corporate sponsored cultural revolution: Newcomers are always right.
The last 10 years have been a coordinated attack on OSS to make developers obedient and silent cogs. It works, because at present they are showered with money in return.
Will it continue to work in 5 or 10 years?
There was a time in the 90s/00s where you bought software in a big box, and it came with all sorts of manuals and such. The tangible assets (manual, floppy, box, whatever) along with the licensing agreement made that software much more valuable than the software we use today.
A better comparison would be how people gladly pay ten bucks a month for spotify/netflix but would probably never pay that for messaging and IMHO that's where the industry should be going.
People in the past also thought music and movies should be free and pirated the shit out of them, but by making it simple and accessible, for ten bucks a month, most people with a job just won't bother with piracy anymore, even though they gladly pay for something they'll never actually own.
So, the billion dollar question is, how do we transfer that model to messaging?
I keep dreaming about a Pied Piper like decentralized internet.
With messaging it’s different. Transferring messages is relatively simple topic to do as a software. But the cost of running and maintaining it is hard and that’s what users don’t care.
Free iPhones not so much.
here is another one (with an insane amount of likes/retweets for something so wrong):
"Signal is owned by Twitter and monitored. While open source it is not as secure as they say. Use telegram." -- https://twitter.com/RebelOutlaw1990/status/13471653380777000...
> Telegram is owned by Google if not mistaken!?
sigh.
> Telegram uses custom cryptography.
> Signal uses encryption protocols sponsored by Broadcasting Board of Governors, a sister federal agency to the State Department. In plain words, data easily accessible by CIA, NASA and FBI.
I wonder what NASA will do with my Signal messages, maybe use them for a giggle in between transmissions from Mars.
Also, recent blog post about Telegram and its crypto: https://buttondown.email/cryptography-dispatches/archive/cry...
They batch them up and send them to deep space through SETI. The aliens are the real ones behind surveillance operations which they use to create a reality TV show. And with this NASA prevents the world from being destroyed from said aliens.
At the same time, I agree that there is practically criminal negligence of the education of people about what makes those techno-social institutions which "just work", work:
* Commercial interests and the role and nature of large corporations in tech and elsewhere;
* The massive amount of hard work, expertise, and good will invested by people in public-benefit work (which could be writing FOSS or volunteering in retiree caregiving etc.)
* What the machinery of government - and its myriad branches and institutions - does, beyond the political horse race shown on the evening news;
and through that, the realization that free lunches get made by someone, and its very important who and how they get made.
> Majority will never, ever, even think about it
It is a challenge for us to educate people around us about this fact.
> I believe that it is time to stop making free products.
Software is free by its very nature. It is only state coercion via threats of incarceration and violence that we are deterred from copying software.
For that reason alone I think it's important for the service to be free. Though I would perhaps support some reasonable free usage limits if needed to prevent abuse.
This all makes me assume that Signal’s security is meant to shield phone owners against advertisers and ordinary criminals, not the state.
I can also acknowledge that it's a universally good thing that they are moving in a positive direction here, and I do not hold it against them for being unable to solve all problems for all people at the same time.
NSLs are a problem generally, but I have a lot less concern in Signal's case because they have no data, and they'd have to be forced to make significant software modifications to enable targeted interception of messages. This is something I expect they would be motivated to fight, more so than any for-profit company might.
Let's acknowledge and appreciate progress where it is being made.
They haven't seriously considered that for long. I don't think it's even been a year when they announced this switch for the first time.
Please don't spread this kind of false information. Signal gets enough of that already.
You realise that this is something completely different than what you wanted to imply are you? Up until they introduced the PIN, they've been defending the phone number. Just because someone had a issue on github, doesn't mean they've been working on it...
You think I’m knocking the app. I’m not, I think it is the best option available. I just feel that as long as the phone number was required, they could have been clearer to ordinary users about the threats that Signal aimed to protect users from: advertisers and ordinary criminals, sure, but not necessarily the state authorities, and so it might not be suitable for dissidents for the time being.
One is some guy posting someone in the issue tracker where 1000s of other ideas are. The other is "them working on it".
Moxie is one of the best security researchers in the business, he was definitely aware of this before anyone ever brought it up on GitHub. Was it really so hard for the Signal devs to acknowledge this downside on the blog?
There’s a known problem where the majority of Chinese Android users use a third-party IME to enter text. This is vulnerable to eavesdropping and easy for Signal to detect and warn the user about. Chinese people have been asking them to do this for over a year, telling them that they know of people who have been detained by the government after using Signal, thinking it was secure. Signal have constantly ignored and dodged this. Just lately, their attitude seems to be that somebody needs to prove it is being actively exploited before they will look into it.
Until I saw their behaviour on this, I was recommending Signal to people. Now I can’t help but feel it’s security cosplay. They pride themselves on strong encryption, but won’t lift a finger when people unwittingly use Signal in an insecure context and are being extraordinarily evasive about it.
More info: https://community.signalusers.org/t/signal-should-warn-users...
It's always someone else's job to change the world, eh?
Oh and, you're not getting enough recognition and praise from your customers? Maybe you should make something which would really justify it? I'd recommend a FREE APP which helps poor people! Jesus, you run a page which rips off content other people provided you for FREE...unbelievable...
A better world for whom?
I'd have ticked "recurring annually" if the option had existed.
Edit: unless they have some special lower cost stripe rate of course, in which case you can ignore my comment altogether ;)
"...The initial $50M in funding was a loan, not a donation, from Brian Acton to the new nonprofit Signal Technology Foundation. By the end of 2018, the loan had increased to $105,000,400, which is due to be repaid on February 28, 2068. The loan is unsecured and at 0% interest..." [1]
What happens when they add 50M or 100M more users?
[0] https://en.wikipedia.org/wiki/Signal_%28software%29 [1] https://en.wikipedia.org/wiki/Signal_Foundation
I dont understand it much, but its to make Signals life easier during tax time since its such a large gift.
https://www.irs.gov/businesses/small-businesses-self-employe...
And a donation would bring him deductions which he probably doesn’t want..
And there is a gift tax but since it’s a non profit, it gets different treatment. But having said that IRS scrutiny increases with such large donations.
Chances high for an IRS audit. Etc.
So many reasons why the loan aspect is a better idea.
> There could be conflict of interest if it’s a gift considering Acton was involved with WhatsApp before Signal was formed.
Why is this conflict of interest less significant by structuring as a loan?
> And a donation would bring him deductions which he probably doesn’t want..
Why wouldn't he want them?
Is he time-shifting them or forgoing them?
> And there is a gift tax but since it’s a non profit, it gets different treatment.
A charitable donation isn't subject to gift tax.
> But having said that IRS scrutiny increases with such large donations.
> Chances high for an IRS audit. Etc.
Acton is a billionaire, his returns will receive scrutiny every year.
What's the etc? How is it better with a loan and why?
Generally speaking, noncompete agreements prevent you from taking equity / ownership or active role in competitors
They say nothing about loans. Thats from the many agreements i have come across between businesses and partners/employees
I think there is a limit to the amount of gift in cash or other assets you can make without triggering a federal gift tax of around 40%. For an individual there is a limit of life time gift tax exemption around 11.5 million and 23 million if the gift is made as a couple.
1. A loan is a business transaction here. There is an expectation that it will be repaid. It can also be forgiven. A donation to a non profit can be ‘rewarded’ by way of tax deductions.
So Acton will profit from a similar tech he has already sold to Facebook as WhatsApp. His wealth likely came from WhatsApp sale to Facebook. It can be argued as conflict of interest.
Loan deals are very clean. Cut and dried. Any implied contract between the parties ends when the loan is repaid and the relationship is terminated.
2. I can’t speak for Acton. Or in any legal capacity, but if it were me, tax deductions to a non profit can be rife with complications because if he ever gets involved with signal as a board member or employee, it might rise questions.
3. Signal foundation is not a charity.
4. Even a billionaire ..and especially one..would prefer to keep books less complicated for IRS. Donations are often scrutinized for money laundering or tax evasion.
5. A gift invites taxes, iirc. Like..if I gifted you above 15k(and you are not my family or part of a trust/insurance beneficiary etc), you will have to pay taxes on the realized value of the gift.
6. This might have been an ideological instinct for Acton as there seems to have been some disagreement between Acton and FB on how they intended to take WhatsApp. Maybe this isn’t about money at all. Who knows. Hence the ‘Etc’.
Also I don’t know exactly what kind of non profit Signal is...
AFAIK, this does not apply when giving to a charity.
> I can’t speak for Acton. Or in any legal capacity, but if it were me, tax deductions to a non profit can be rife with complications because if he ever gets involved with signal as a board member or employee, it might rise questions.
And the loan won't raise similar questions? Why?
> Signal foundation is not a charity.
> A gift invites taxes, iirc. Like..if I gifted you above 15k(and you are not my family or part of a trust/insurance beneficiary etc), you will have to pay taxes on the realized value of the gift.
> Also I don’t know exactly what kind of non profit Signal is...
It's a 501(c)(3) https://signalfoundation.org/
Brian Acton is listed as Principal Officer/President
You can’t donate to your own company and then claim it for a tax deduction.
That being said, this basic point seems like it might explain the whole thing. I can believe that he cannot be the sole (or nearly sole) donor and have the company be a 501(c)(3) rather than a private foundation or similar.
Startup funding that looks more like debt than stockholding isn’t all that weird, and has various implications for exit scenarios.
If you wanted to create something similar to a nonprofit, this is a way you could do it while protecting it from vultures.
I've been using Signal for a couple years now. Finally deleted WhatsApp this week. This is the first outage of Signal that I noticed. It's a shame, but growing pains do happen.
Everyone around me starts switching suddenly and I want to keep them on Signal.
Oh well...
They do https://hexus.net/tech/news/software/125747-14-open-source-p...
It looks more like they are giving funds to projects who apply for them. IMO, they should state 3 clear goals and sponsor specific projects which reach those goals. To give some example how those could look like:
- create a decentralized, federated instant messaging platform, that is build on public standards
- create an e-learning platform that is usable with already established devices
- establish a market for the created software with partners
Naturally, all result would have to be open-source products and the goals would need some details/numbers to measure them. They could even invest into already established projects, but please, with easy to understand goals.
Just give them money and trust them that they'll do whatever it is they've done so far that many people recognised and started relying on their solution to the problem.
Without looking them up, there's exactly three pieces of software in the list above your comment that I don't recognize: FLUX TL, WSO2, midPoint. I'm happy to see all the other names on it, and I'm pretty sure I'll feel the same way about these three after I look them up.
I find it heartbreaking, that we still depend on WhatsApp and Zoom. Neither service owner is particular trustworthy. Communication is definitely critical infrastructure and yet, the open-source alternatives are very limited (in quality, not in quantity). So investing in this kind of functionality is key.
Cynical, profit driven and well funded operations have enough capital to weather these downpours, indeed they’re actually planning for them.
I hope Signal sorts their capacity quickly, I’m terrified that my circles switch back to WhatsApp. And then I’m fucked, I either surrender myself to Facebook or cut off from society
Signal, on the other hand, probably comes close to the WhatsApp features (I use neither one) and while I encourage everyone to to switch, I am missing the federation aspect. IMO, communication should be federated by law (which would also solve the network effect problem). Imagine a world where you could not call someone who has a phone number from a different provider? The current state of instant messaging is exactly this.
XMPP solved these problems decades ago and just because the standard didn't catch up with the speed of the mobile revolution, we don't have to reinvent everything from scratch. Properly implemented modern clients work very well (including reliability and battery consumption), the big issue though is that many traditional clients don't support all features and all companies in the business try, to build walled gardens as those tend to driver stock prices.
Governments don’t fund things, taxpayers do.
It's also quite ineffective at giving money to the projects that are meaningful.
Large companies and large university projects rake in plenty.
NLnet does 'funding as a service'. If you want to fund a particular area of FOSS, we (I work there) can administer that. We provide low overhead funding to FOSS projects and pay particular attention to how the ecosystem benefits from projects.
So 'boring' projects that improve adherence to standards, increase deployments of standards compliant software, test standards compliance are very welcome. Redecentralizing the web requires this work, but few people think that this work is fundable. It is and in our opinion is has a high ROI for society.
It hurts me to watch systems full of broken incentives emerge and have money thrown into them repeatedly - there's "tech startups" (which would be laughed out of the valley due to their head-count and lack of any product market fit) receiving large ongoing subsidies to their payrolls while they slowly pretend to iterate on a product, all because they have "created" an agreed number of jobs, and need to keep those chairs full.
Europe on the whole doesn't have a culture of taking the same level of risks with capital, and there's a real push to fund things that are "safe" and help cover up weaknesses in the market - funding a company to hire people into basic tech roles at below-market pay helps to reduce graduate unemployment, which covers up the fact their education isn't giving them the right skills. That's pleasing to government.
On the other hand, giving 1m EUR to a small company with low head-count but a great idea could be a game-changer, and lead to far greater longer-term gains, but any government funding like this would be accompanied by so much red tape that you'd spend half of the 1m EUR on satisfying the monitoring requirements of the grant, attending monthly external progress review meetings, defending your progress to agreed (and inflexible) milestones etc.
That last point is perhaps the killer for innovation - most of the innovation funding schemes I've seen require detailed project plans before receive a cent of funding, and then hold you rigorously to that plan. Need to pivot? Welcome to the multi-page "change request form", which must be approved by a panel of non-technical bureaucrats before you can dare to change direction. They'll get back to you within 3 months, until which time you should continue with your original plan, as you will still be judged by your previous milestone payment plan. Your idea not working? That's not an acceptable outcome - you simply must deliver what you said! Failure is not welcome, you must deliver exactly what you said, else they will complain you are causing them to under-spend by the end of the financial year (as they now won't pay you!)...
In each and every framework so far, the EU is touting 'reduced administrative overhead', 'simplification of participation' and 'focus on SME's', but has in practice done exactly the opposite.
Especially since Horizon 2020, there has been a 'coup' by the large enterprise and large academic research groups. You can see the same trends in national programs as well.
That's why, in my view, the bigger companies and universities do well - they have a scale that helps them to deliver these kinds of outputs. As a small company, the "spend-and-claim-back" approach to most research funding can be a real issue, especially if the claims are delayed due to bureaucratic "checks and balances". These are necessary to prevent blatant outright fraud (i.e. people not doing the work they say they did, and pocketing the cash), but they tend to be applied across the board, rather than in a targeted way proprortional to the level of risk, and size of the organisation. The end result is smaller players spend more time (proportionately) handling bureaucracy if they do win funding.
RE selecting meaningful projects, this is arguably because EU research funding looks further ahead, at lower technology readiness levels. An open source project used by everyone is "high TRL" and therefore hard to fund. If they have an entity (as you point out, many don't, which makes them harder to fund),
If you don't have a company to pay yourself through an official payroll system, I believe there are rules in place which effectively define that you work a maximum of 8 hours per day, 5 days per week, and that you can't possibly earn more than 25 EUR per hour, which is of course completely out of line with the sector, and makes it really hard to work without creating a company. At which point you then become subject to state aid rules, and need to keep a handle on that.
And beyond the research programmes, any kind of "innovation funding" then drags you into the state aid system of partial funding, which is very difficult for a small company - getting 60% of full payroll costs funded sounds nice, but it requires you have the cashflow/capital in place to run payments through payroll, in order to claim back a percentage. Not ideal for the kinds of non-commercial "critical internet infrastructure" that need this kind of funding the most.
Alas, this is what happens when tech policy is written by people without tech experience, I suspect.
In short, federation makes a lot of things more difficult, and Signal opted not to do that to get a polished product quickly. Still, it's not either-or. As I remember it, Moxie welcomes the Matrix developers to try their approach and would be glad if they can get it right, he was just worried that it'd basically never lift off.
I think it's not bad to donate to either project, it's a good thing that we have both.
Why would the newly-funded software be the useful kind instead of the useless kind?
They should employ teams of investors to decide where EU money is best invested.
They should use their governmentness to investigate companies after a few years and where they find someone got rich, yet the company failed, put some people in prison. Being the EU they can say "using legal loopholes to suck the company dry is in itself illegal".
Still, it does seem something infrastructure/utility-ish like Signal would be a good candidate for at least some support.
You go donate an hours wage a week instead; that’s virtuous.
That's why, in a democracy, you vote to elect your representative who will, hopefully, make sure your taxes contribute to causes you deem worthy. Be it open source, health services, education, ...
Certainly far from “love thy neighbour”.
Donate yourself, you can be a hundred times more efficient than EU bureaucracy, no exaggeration
This is how public schools are funded in my country and I like that we fund them like this instead of private schools with fees that would exclude some families. This model of funding works for a lot of public infrastructure and I doubt individual donations would make up for that. I think it is critical for this public funding to be under democratic control. Otherwise it is definitely unjust. In the end I think public funding / taxes is a way to bypass the tragedy of the commons (not sure if that is the right term here).
My fellow man sometimes wishes me to fund expensive wars too.
Wishing for how your taxes are spent is an aspect of democracy.
No one hinders you from donating to Signal if you wish, but if I am a Matrix user, do you want to use the violent force of the state to force me to fund Signal? It’s a moral absurdity.
When CEOs and owners make the same as cashiers, donating by yourself makes sense.
I feel public money should only be donated to them once people are able to setup their own signal instances, like Matrix.
France for example uses Matrix for their internal communications. They don't use the public homeserver, rather, they use their own.
One of my friends who just jumped ship to Signal this week said in his first Signal message to me that he wished he’d “bought some shares” in Signal when I first told him about it...
The first challenge is getting people to join the platform.
The second challenge is educating them on how it’s actually funded... (ie NOT by pimping out your personal data for shareholder benefit).
All you need to store server-side is "this user has the badge until date X".
Sure, but espionage and surveillance are rarely about proving anything, they're about making good educated guesses. Besides, the receiver will very likely be among your friends and acquaintances, so the NSA would only have to look at your social circle to find them.
display_badge_until
Store no payment info.
I've tried to donate, but none of my 3 cards worked, I got "card rejected error" without any info why and none of banking apps notified me about new transactions.
They aren't on liberapay as far as I can see.
I use the Privacy app and generated a merchant specific credit card for Signal. This is the best way I have found to do online transactions. You don't even need to use your actual name or address when making a payment to a merchant since Privacy acts as a proxy for you. https://privacy.com
Donated.
Remember: regular donations are better because they help with long term planning.
But your link now leads to a “The charity you're looking for isn't available right now” page?
Try searching for Signal Tech Foundation here https://www.paypal.com/fundraiser/hub
Non-American users can access the Signal PayPal page at Paypal’s US site: https://www.paypal.com/us/fundraiser/charity/3675786
Not sure what the logistics of sending money to the USA PayPal Giving Fund are for non-Americans.
Let's do some math: In signal's case, since they use Donorbox, there is a 2.9% + 30¢ fee for credit card transactions going via Stripe (in addition to another percentage that goes to donor box). If you were to donate $24 once per year, Signal would end up with just over $23 after processing fees had been deducted. If you donated $2 per month, they would end up with $19.7 per year, an additional $3 being spent on fees!
Edit: unless they have some special lower cost stripe rate of course, in which case you can ignore my comment altogether ;)
[0] https://www.forbes.com/sites/ashleaebeling/2020/12/22/new-bi...
This is one of the most frictionless donation buttons ever. I love it.
Patreon, Paypal, SEPA transfer, all those are a hassle, comparatively.
This donation thing used by Signal works exactly as it should be. Enter numbers, hit enter, done. No "please cookie us", no 20 times transfer to other domains, no account creation, and they also don't require stuff like MasterCard 3D secure (which IMNSHO really is useless for donations).
Zero hassle, 100% great, and with a nice UX.
All my friends are in Signal. One of my favorite group chats is in Signal. My mom is using Signal, I just sent her a message I might need to leave WhatsApp, so she immediately installed Signal all by herself. Now we have video chats that have been working really well.
I mean, this is the first time the mobile app gives trouble. I'd wish the desktop app would be better, like it's been the biggest problem between me and Signal. Otherwise it's an amazing tool and I'm happy to donate for it to be even better.
I also installed a browser extension to automatically bring me to smile.amazon when buying anything on Amazon - so far it has had no weird glitchiness when not buying something and works exactly as advertised. Highly recommend looking into this option if you're forgetful like me - so far it has helped me donate 4 times that I would have otherwise forgotten.
I don’t use the add on and just type “smi” to autocomplete the domain.
edit : which presumably drives licensing income from Microsoft to The Signal Foundation, which I am presuming is better than nothing and if like me you can start using Signal protocol for calling your family elders via Skype without friction, and I simultaneously create widespread adoption of the Signal protocol, I can't see any downside myself anyhow.
https://az705183.vo.msecnd.net/onlinesupportmedia/onlinesupp...
Right now is the time for us to invest in Signal to help see it through this groundswell of adoption.
If you talk about Brian Acton, he sold WhatsApp to Facebook and btw made a big gift to the FreeBSD foundation and is the founder of the Signal Foundation.
Learn to inform yourself, this is not a place for fake information.
Awesome
It’s not a far leap for Amazon to “take a strong stance against serious threats to our democracy” by kicking off signal.
De-platforming a private messenger like Signal would be a strong signal against an open, unmonitored Internet and raise too many eyebrows. Amazon would be seen as complicit with government for not allowing citizens to communicate freely and privately with each-other.
If Signal adds features to let users post extremist views publicly, that’s a whole different ballgame and the cards are off the table.
No autoscaling?
It is, but most consumers don't care, they just what their stuff to work 100% of the time as frictionless as possible, and, on top of all things, for free. Otherwise they just run back to the usual free surveilanceware.
I've tried and failed to convince some young, highly educated zoomer friends with good incomes to move away from WhatsApp and Facebook and even when I told them "Look, they're basically spying on you" they just brush it off and say "I don't care, it's fun, easy to use and all my friends are already there".
Ironically, it was easier to convince my boomer parents to move to Signal and they also understand and agree with the tradeoffs and extra friction for the sake of free privacy but younger people just want to be where their friends are and not feel left out (remember the blue vs green bubble stigma on iMessage).
The more someone cares about security and is willing to trade away other good things for security, the better a platform Signal is — but remember, this also flows the other way.
WhatsApp and Facebook Messenger offer the same level of security as Telegram. In fact, I think WhastApp is more secure since it does E2E encryption by default.
It's true that Telegram is about "fun" and not security. I just wasn't sure if you tried to imply Telegram is like Signal with a focus on fun as well, or you just meant most people don't care about security and would rather have fun chats?
WhatsApp, for all its faults is E2E-encrypted by default and all the time.
Not that it helps much unless you avoid activating backups and convince all your contacts to avoid backups.
I don't like WhatsApp (anymore), but we should stick to the facts.
If you look only at encryption, WhatsApp is even better.
Once you factor in the fact that all your metadata is vacuumed into Facebooks data lake and that it might very well end up in Google Cloud if either you or someone you chat with activate cloud backups.
(I am not here to defend Telegram's portrayal of itself as a secure messaging service — Telegram is grotesquely bad on that axis)
tg is light on resources like phone storage and bandwidth (and hence money) and has excellent multidevice support.
apart from that i don't belive one can have a seriously private conversation involving a device running popular versions of android/ios.
You carrot them with a unique way to ping you, over tech no one else has, and they see it like an intimate connection with you
I had my elder parents and SO use it for years before friends i consider privacy aware and tech savvy... For years
Added benefit: its a lot harder to share memes over a young network with no traffic.
I guess that may change now....
I too wish Signal engineers good luck!
(Even if I personally mostly use Telegram and hope for Matrix to "win", Signal is a fantastic piece of software as far as I can see, both as an extremely secure (I think) messaging client in its own right and also as an inspiration for other messaging platforms.)
Or obviously Signal.
When it comes to Matrix, it's a little trickier. Riot, the most common Matrix client does E2E encryption on DMs and invite only rooms. What I'm not sure is what happens if you send a private message to someone who is using Matrix client that doesn't do E2E. Will it fail to send? Or will it like fallback to not encrypted?
Fun fact: I didn't even write that.
The rest is not so much for you personally as for a number Signal fans:
I get it, I get it: Signal is best. But seriously: do you Signal fans have to derail every conversation?
Do you have to take a jab at every other messenger at every given opportunity?
Or can we agree that there's room for more than one solution? Because physical mail, email, irc, Telegram etc are probably going to stay around for a long time, at least until Signal solves:
- large groups
- backups
- grows a stable messaging API
- creates a Bot api
- and starts teleporting physical goods
- etc
Until Signal solves all this we are going to have to deal with other mesaging solutions.
Deal with it. Seriously.
Yes: Signal is probably the most secure now IMO.
No: talking down other messengers doesn't make it better.
@dang: apologies in advance. I've tried hard to keep it polite.
We are going to have to live with various systems for a long time, IMO hopefully "forever" since competition typically often does wonderful things.
I don't really have a horse in this race, just a guy who was scrolling through these comments and was struck how rude and ridiculous this remark is.
You're in a discussion thread for an article about Signal. You're the one who brought up Telegram and now you're having a little fit and accusing Signal fans of "derail[ing] every conversation"? This conversation is about Signal. If you didn't want people comparing it to Telegram, why did you bring it up?
This would be a good point, if it wasn't for the point that the only reason I brought up Telegram was to say I was a Telegram user cheering for the Signal team!
I know this happens a lot in other threads about other messengers, so it's probably a fair comment. But I find there is something ironic about someone commenting on a story about Signal that they use Telegram and then complaining that other users talking about Signal are derailing the conversation.
> The result was a mass migration that, if it lasts, could weaken the power of Facebook and other big tech companies. On Tuesday, Telegram said it added more than 25 million users over the previous three days, pushing it to over 500 million users. Signal added nearly 1.3 million users on Monday alone, after averaging just 50,000 downloads a day last year, according to estimates from Apptopia, an app-data firm.
> “We’ve had surges of downloads before,” said Pavel Durov, Telegram’s chief executive, in a message on the app on Tuesday. “But this time is different.”
As someone who semi-fondly remembers the Twitter failwhale, I really don't think a more conspiratorial theory than "a few million people suddenly tried to jump on" is required here.
Java/DropWizard app
And this is also not open source for my understanding: * Last commit was on 2020-04-22 * only a single committer (moxie-signal) * only „bump version to xyz“ commits * not a single PR is getting merged but all are just closed (one references „pr was created on wrong repository“) * not a single code comment in what I saw so far * there are also references to AWS and GCP but I could not find any reference to Microsoft/Azure (where their current IP is pointed to)
Is there some other place where the „real“ open source process is happening? Maybe some sources how their production architecture looks like?
Edit: here is a lot explanation for this https://www.reddit.com/r/signal/comments/kxusy8/signal_needs...
EDIT: We know it was a joke. Maybe you are downvoted because of your username.
Based on my friends, mostly foreigners and English-speaking locals here in Hong Kong, Signal has grown about 20% in the past week.
I will continue to use iMessages for my iOS contacts. For SMS people I will gently nudge (hey, have you tried Signal? and then let the convo go where it does) and then use Signal as the primary for those people.
99.9% of messaging (for me) occurs via iMessages or SMS. FB Messenger is occasionally used for people who are more acquaintances (don't have their phone number).
I don't really have a good reason to not use iMessages (blue bubbles). Reasonably secure and Just Works. SMS on the other hand.... my least favorite part of SMS (besides the complete lack of security) is that media messages are crippled in quality. Photos and videos are compressed and distorted beyond belief.
not just android, they work with every mobile handset even with the poorest reception or (even lack of) data-plan.
i use ~200 sms per year, pretty constant since i got my first mobilephone.
kinda sad we didnt come up with something better thou.
https://twitter.com/signalapp/status/1349577579091566592
https://twitter.com/elonmusk/status/1347165127036977153
edit: as daniel_sk points out this is not a x5 increase but crossing the threshold from 10+ to the next 50+ mm downloads.
They operate on their own schedules and priorities, and it's tricky to get your PR into any of the clients.
https://projects.propublica.org/nonprofits/organizations/824...
Good luck Signal team!
> We have been adding new servers and extra capacity at a record pace every single day this week nonstop, but today exceeded even our most optimistic projections. Millions upon millions of new users are sending a message that privacy matters. We appreciate your patience.
https://twitter.com/signalapp/status/1350165610936766464
They've seen it coming, just never expected this much new traffic.
Last night a friend from India popped up on signal. I told him "Welcome!" and he said "You finally wore me down, I've left WhatsApp and I'm trying to move my family off of it..."
So is Signal. 'right wingers' are everywhere.
This has now become a usability and reliability issue for Signal.
anyways. It will be really difficult to convince my friends to remain on signal. At least they are technically sound. Thinking an excuse to come up with though. i donated money today too.
I don't know if it is true, but for your peers it certainly is a different story to tell them about all the people who are switching than just about a service who had an outage. Hopefully, the next days will bring some light to the cause of the outage.
Please stop moving people to centralized services.
That shit works on a small scale. Serving the entire planet needs hierarchy and co-ordination.
Doesn’t necessarily mean everything has to be completely centralised, but some of the woolly wishful thinking you come across is not based in the real world.
These are all people who have completely abandoned Facebook for WhatsApp and Instagram.
Element is less polished than Signal app but they've been catching up quite fast. If you and your friends aren't locked into the Signal ecosystem yet, might be worth considering, especially if you're techies.
Or just use the standard matrix.org home server if you're just trying it out / don't mind a not-super-fast home server. Or one of a dozen public Matrix servers: https://www.hello-matrix.net/public_servers.php
Alternatives would be Threema and Wire, but Wire has the same main issues as Signal and Threema doesn't have video calls nor a desktop client and an unusable web client (deal breaker for me: you need to navigate two menus on your phone to reconnect every time your phone connects to another wifi or you suspend your laptop or anything).
Do you mean that they have servers in the US? US based company? They don't leak metadata, that's the difference between Signal and Telegram/WhatsApp. If the encryption is good it shouldn't matter what country the company or servers is in. That's kinda the point of encryption...
They can do sealed sender stuff all they like, but when 10.0.1.1 sends a 17-byte message and the server then sends a 17-byte message to 10.0.2.1, and a minute later 10.0.2.1 submits something to the server of 48 bytes and then 48 bytes are forwarded to 10.0.1.1... traffic analysis based on a tap of a Signal server isn't rocket science.
Still, it's the best we've got for non-techies. Better than handing over more metadata to Facebook. Even if the jurisdiction is the same, the company (Signal Foundation) is better and is known to collect almost nothing historical by themselves. Other than, say, your real-life-identity-tied user ID of course. (In many countries, phone numbers are given out only after passport/ID verification.)
I'm not an networking guy but can you explain this more? I'm actually curious and what better place to get actual info than HN? If you have a sealed sender then shouldn't this be impossible? Shouldn't the size of the message be sealed as well and when the message is received you'd see that 1) it is signed by a different key and 2) the message size doesn't match? Shouldn't this be rejected? 3) Shouldn't this also apply to any app because traffic is going to bounce through some US based (or US company owned) server? My understanding is that sending data from San Francisco to Berkeley can route through Seattle or Tokyo depending on optimal routing, server configurations, and loads.
> Other than, say, your real-life-identity-tied user ID of course.
This is why I'm excited for the usernames. They are promising them this year.
> Shouldn't the size of the message be sealed as well
To hide the volume of data being sent, you need to limit how much data you can send. How would you hide from the relaying server how much data you're sending without adding dummy data? And if you add 0-500 bytes of dummy data every 5 minutes, then whenever you send >500 bytes or send a message more often than once per 5 minutes, the server still knows that it was an actual message and its size, and you can start to do traffic analysis.
> Shouldn't this also apply to any app because traffic is going to bounce through some US based (or US company owned) server?
Um, when I message my friend whose Matrix homeserver I'm using, the traffic involved is:
1. DNS lookup of a .de domain (does not reveal message size or anything else, even if I were to use Google DNS and reveal my home server to a USA company)
2. TCP connection to a German server
3. More traffic to his German server
And same on the receiving side. Unless one of us travels to the Americas, it's not likely to ever pass through the USA. That isn't to say that American agencies might not collaborate with European agencies or even tap European land-based connections, but it's harder and would not be an option available to criminal (or civil, for that matter) investigations due to the disproportionality of the method.
> can you explain this more?
I'm not quite sure what's unclear about it, but I'll give it another general shot. Imagine you see this traffic log, where A/B/C/D are different IP addresses. You see various people sending data of various sizes (you don't know who's who, but everyone connects from their own IP address, or in networking terms, a TCP tuple). Since the server is just pushing messages from one contact to another, like if Alice messages Bob, it will always forward a message as soon as possible.
00:00 A -> server: [17 encrypted bytes]
00:00 C -> server: [29 encrypted bytes]
00:00 server -> D: [17 encrypted bytes]
00:00 server -> B: [29 encrypted bytes]
00:01 D -> server: [48 encrypted bytes]
00:01 server -> A: [48 encrypted bytes]
From this, I would assume (without knowing any contents or anything else) that the subscriber behind IP address "A" is talking to the subscriber behind IP address "D", and that "C" is talking to "B". Now you can start building a social graph, which according to a paper I recently read (I could maybe dig it up again) needs only a few nodes before they can tell who you are, or they just ask the ISP (or in the case of the Netherlands, query the CIOT database[1]).If you think that a "sealed sender" might hide your IP address, the answer is no because the packets somehow need to make it across the network to the right devices (or to the server for that matter) and then the receiver decrypts it.
[1] https://nl.wikipedia.org/wiki/CIOT only available in Dutch. TL;DR central mapping system of IP addr -> subscriber info, available at the police's discretion, updated daily.
> They can do sealed sender stuff all they like, but when 10.0.1.1 sends a 17-byte message and the server then sends a 17-byte message to 10.0.2.1, and a minute later 10.0.2.1 submits something to the server of 48 bytes and then 48 bytes are forwarded to 10.0.1.1... traffic analysis based on a tap of a Signal server isn't rocket science.
True, though with a bazillion connections going in and out of Signal's AWS instances every minute and additional domain fronting by AWS, the NSA would probably have to be inside the AWS datacenter to carry out their traffic analysis and even then it doesn't seem like a triviality to me.
Compare this to someone hosting their own Matrix node (which you're mentioning further down): In this case, it is clear that every message sent to that node has something to do with the node's owner. More generally, reconstructing a social network in a p2p network (without onion routing or anything like that) is much easier than doing this in a centralized network where all messages get routed through a central location. There's a reason why the guys from GNUnet have so far spent two decades on getting p2p right. (Though, of course, anonymity is just one of their concerns and not their only one.)
Is still Amazon operating those locations, so I assume it's still the USA who's calling the shots. Please do prove me wrong if I am, this is somewhat of an assumption (even if I am fairly confident it works this way in practice).
Though perhaps I'm putting too much weight on this aspect, it's just that everything we do in Europe can be monitored through one USA organisation or another. It feels really weird when you think about the number of actually European services you use (very few) and how much money the ad machines are making with your data in the USA, how much that data is apparently worth. We're wholly dependent.
Domain fronting: didn't Amazon and Google say they were not going to do that anymore, because they didn't want to stand up for the organisations using it at the time? Some countries wanted to block certain services (was it sci-hub? TPB? Tor? I don't remember) and instead of standing up for them, they just banned domain fronting.
Therefore I'm assuming that one can see when a packet is actually intended for Signal and filter those out. From there, it should only be a very manageable number of packets, since we're only interested in the routing header and packet size.
One does need proper equipment to capture and filter multiple gigabits per second, but the attack scenario was more about legal interception (which you put in front of the server rather than in front of the datacenter) than about dragnet surveillance. The latter is indeed less applicable on non-USA soil, hence my saying Wire and Signal have the same issue but e.g. Threema does not, though centralization still makes it way easier (thus Matrix is king in this regard).
> reconstructing a social network in a p2p network (without onion routing or anything like that) is much easier than doing this in a centralized network
Hmm, you mention gnunet and I'm not up to date there, perhaps you know something I don't, but this doesn't seem quite right to me.
Sure, once you know who is running a server, you can install a tap and learn whom they are talking to. Way less traffic than doing surveillance on a Signal server, I'm with you there. But you do need to figure out who you're interested in first. The way that I understood these metadata targets work, is that you take a popular network (say, WhatsApp) and check who talks to whom. Anyone within 3 degrees of a suspect is now also a suspect if I remember and understood USA law correctly. But if there is no single central service, you need to install a lot of taps or capture the right internet backbones to get close to the same information.
And if you're serious about anonymity, if you're hiding from the police or an intelligence agency, then surely you'd host that server somewhere paid for without traces to your real name. Or use some public home server -- they still need to tap that specific home server rather than a centralized server.
The whole point of Amazon operating datacenters in multiple regions is that, apart from improving availability of the stuff they host, datacenters outside the US get to be legally independent from US law. (At least at the consulting firm I work for we strongly advise clients to follow GDPR and use the European region only.) My guess would therefore be that European datacenters, for instance, are operated by Amazon EU S.à r.l.
> Domain fronting: didn't Amazon and Google say they were not going to do that anymore, because they didn't want to stand up for the organisations using it at the time? Some countries wanted to block certain services (was it sci-hub? TPB? Tor? I don't remember) and instead of standing up for them, they just banned domain fronting.
You might be right, I'm not sure what the state of domain fronting is, either. In any case, the fact alone that inside an AWS datacenter Signal can operate an almost arbitrary number of servers (as opposed to a single one) without anyone outside the datacenter being able to tell which machine a packet gets routed to or originates from, means that the Signal servers inside the datacenter can potentially handle millions of messages per second which would make correlating them with one another anything but easy. Remember that messages get padded anyway and that there might be additional random delays, depending on which server in a datacenter your message gets routed to. On top of that, judging from the Distributed Systems Developer position Signal advertizes on their website[0] I would assume that Signal's servers need to communicate with one another, too, i.e. your message might go to a European datacenter first and then, from there, go to one on the other side of the world – which would further complicate tracing it. Finally, message notifications on phones usually use Firebase Cloud Messaging (or the Apple equivalent) which adds yet another layer of indirection, delays and mixing[1] and, thus, obfuscation.
All in all, I am not sure, therefore, if I agree with your assessment that
> it should only be a very manageable number of packets, since we're only interested in the routing header and packet size.
as the number and overall scenario don't seem that trivial to me.
> the attack scenario was more about legal interception (which you put in front of the server rather than in front of the datacenter)
Fair enough, if you tap every single server's network cable, it certainly seems more doable. But how do you, as the NSA, carry that out in practice? Knock at the door of that European datacenter and hope employees won't say anything to the press? I'm not saying it's impossible (it's certainly not) but Amazon EU S.à r.l. being a separate legal entity and employees not being bound to US law would certainly be big operational challenges. I'd say it's much more likely that the NSA's European intelligence agencies carry out such a task for them (or provide support) and even then it's not as easy as in the U.S. (no Patriot Act or anything similar).
Finally, don't forget that AWS instances can be deployed within a minute, meaning that "putting something in front of a specific server" becomes a lot less trivial if you don't really know which server it is or new servers get deployed every other day. (For once, an advantage of The Cloud™ haha.) You basically have no other choice than to put your wiretapping device in front of the entire datacenter.
> thus Matrix is king in this regard [legal interception]
I'm not sure it is. There are pros and cons to both centralized and federated networks here: A central big provider might have the legal power and sufficiently deep pockets to successfully fend off a "request" by an intelligence agency. Small ones like in the federated case do not. Sure, it takes longer to subvert a federated network. But once done, the traffic analysis is a lot easier compared to the centralized scenario (as we already agreed).
> Sure, once you know who is running a server
I don't think it's that hard to find out who's running a server (in Europe) when you have its IP address. Almost everyone who operates a server for private purposes ties the server to a domain or at least a bank account. (Remember that the EU forwards financial data to US agencies.)
> But if there is no single central service, you need to install a lot of taps or capture the right internet backbones to get close to the same information.
The NSA already does that! (Compare what's been reported e.g. about NSA's Tailored Access Operations (TAO) team.) My general assumption, therefore, is always that the NSA and its partner agencies are sitting at every major internet backbone.
> And if you're serious about anonymity, if you're hiding from the police or an intelligence agency, then surely you'd host that server somewhere paid for without traces to your real name. Or use some public home server -- they still need to tap that specific home server rather than a centralized server.
I agree with the first sentence but I don't understand the second. Practically all traffic to and from a public server you're running at home gets routed through an internet backbone anyway. (Unless, maybe, your Matrix contacts are all in your neighborhood and are all with the same ISP.)
Perhaps it would go this way and perhaps they would rather incur sanctions or take to the media when ordered to hand over data stored in Europe. But so we're trusting Amazon with our data.
I guess, if I'm being fair, I just don't really know enough about this. Perhaps a legal entity in the USA cannot be held liable for not complying with a judge's orders to tell its wholly owned subsidiary to do something, or either of them for the subsidiary not complying. It might work that way. I just expect that in practice, they might very well simply comply. Or, like you say, that a "European intelligence agencies carr[ies] out such a task for them".
> message notifications on phones usually use Firebase Cloud Messaging (or the Apple equivalent)
When questioned about the privacy of using Google/Apple messaging stuff, what I've always heard as reply is that it only nudges the phone to fetch new messages. It still connects directly as well, as I have heard it (though it seems silly to me, why not just put the encrypted message right in there? Or is that a metadata thing then, revealing the message length to Google/Apple? Idk).
> Knock at the door of that European datacenter and hope employees won't say anything to the press?
That is very much how legal intercept works. And the NSA doesn't do those, it's a judge that gives the tap warrant and something like police (or a person of similar status) that executes it. I have never heard of it being leaked that some company is being tapped or in relation to which case (for all we'd know, it would be on European orders). That taps are happening is a well-known fact, just not on whom and especially not for what purpose. In a tour of an ISP data center, they pointed out now-decommissioned tap boxes to us that the police had put there. Distinctively blue in color if I remember correctly, and a hacker space later made a, um, tap out of one of them (beer tap).
> For once, an advantage of The Cloud™ haha
:D
> I don't think it's that hard to find out who's running a server (in Europe) when you have its IP address.
Indeed; that's not what I meant, but I that sentence can indeed be read both ways (sorry). I meant to say that you don't know who's running servers, like, do you run one? Do I? Or the other way around: do I connect to a Matrix server? You have to actively check the server since the traffic is just TLS on tcp/443 (so much for passive tapping). More concretely, if a government (judge, secret service, ...) wants to find whom I talk to, instead of knocking on the door of a (few) central service(s) like Amazon or even Signal itself and telling them to send copies of TCP flow logs, you have to first tap my home IP, mobile data, see where I connect, then check those servers if any of them might be chat servers, then request a tap on those IPs in their respective countries, use that to check who else connects to those, if it's more than a handful of people you need to do traffic correlation there as well...
I see what you mean, though, with the centralized system requiring one to overcome scaling issues before any intercept can start, and potentially requiring cooperation of a party like Signal who will certainly make a ruckus. Which one will turn out to be easier might depend a lot on the situation.
> the NSA and its partner agencies are sitting at every major internet backbone.
They definitely have taps in many places, but all of them, in each country? And what about private peerings, can I not talk to anyone within one country without it being caught? Surely when ISPs A and B have a private peering in Germany, the BND doesn't automatically have a permanent tap installed there. It seems to me like there would be too many interconnects to really monitor all of them. But this is rather speculative, I don't really know. Also about the tier 1 backbones: sure it's a fair assumption that a random one of them is being tapped and so we need proper encryption, and also multiple strategic ones, but all of them all the time all across the world? I don't know.
> (Unless, maybe, your Matrix contacts are all in your neighborhood and are all with the same ISP.)
We here are Internet people, we talk to faraway people all the time. A good friend of mine lives on the second-furthest continent, latency-wise (Australia/NZ would be further), our traffic typically runs through the USA when we do a traceroute. Some of my friends moved to work in other countries. But an average mom, who does she talk to on WhatsApp? I think the furthest person my mom regularly talks to is me (~50km), and for faraway old friends maybe 150km across the country. The Matrix home server I use traceroutes through the nearest internet junction point (Frankfurt, 200km), I guess depending on how the physical interconnects go this might be on an easily tappable line, but it's not a given that it passes through a big backbone to make it onto another ISP's network within the country. In case you have some way to tell (I'm curious now), these seem like the most likely points in the trace:
6 bundle-ether2.0003.dbrx.02.fra.de.net.telefonica.de (62.53.28.149) 25.9 ms bundle-ether1.0003.dbrx.02.fra.de.net.telefonica.de (62.53.14.163) 21.5 ms
7 bundle-ether1.0005.prrx.02.fra.de.net.telefonica.de (62.53.10.51) 20.1 ms
8 ae3-1337.bbr02.anx25.fra.de.anexia-it.net (80.81.195.166) 24.3 ms
Anyway, what I was saying is that if you're hiding from the police or an intelligence agency, you'd probably avoid centralized servers, and that a random public home server is not as centralized as Signal. Not so much that this would definitely prevent a backbone capture, but that it would not make the traffic be caught in the same filter where they capture traffic going to/from a central chat service.By the way, in general, I like your reasoning. I think the places we differ in opinion are mainly about how we weigh different risks or how prevalent we assume things are that neither of us can truly know. It's interesting to exchange thoughts and speculate about, though. There is no contact info in your profile but it might be fun to talk more about various topics - I see that you were asking in another thread about getting into cyber security. There are already good answers on that particular question, but as someone already in that field, perhaps I can be of help :). Since I keep this username loosely decoupled from chat accounts, you could shoot me an email at https://lucb1e.com/email-address/ with your matrix/signal/wire/... if you like!
We crucified Jesus some time ago for delivering a message. Downvotes for no reason are to be expected.
However, if you want a server, installing it using Synapse's docker image is very easy. You literally have to run two commands.
(Not a Matrix user, BTW - looked into it some months ago and ran away)
To be fair: I've been pleasantly impressed with Element actually from what I've seen of Mozilla's set-up. I can format my text, I can run it in my browser and it starts up very quickly.
I've been using Matrix for maybe a year now with a group of techie friends and I would definitely not recommend it for my family members (who I just onboarded from Whatsapp to Signal the other day).
Just look at this: https://wiki.mozilla.org/Matrix
And compare it to installing the Signal app and verifying your phone number with an SMS code. Frictionless.
Sure, I'm not saying that either, and Matrix has been improving a lot since I first tried it maybe 2 years ago. But there's still a long way to go. I wasn't as focused on onboarding as I was on criticizing Element's UI/UX in general.
> And we definitely don't need phone numbers and SMS verification for usability: a username will do just fine
Phone number is just the easiest thing to do. No one is confused by the process and you immediately have access to all of your contacts, while with a username you somehow need to get all the usernames of all of your friends. Inviting new users to various channels kind of works, but it's not as personal as your own contact list.
Mind you I'm not saying it's the best option. Personally I'd rather register with a username, not only because I currently have three different phone numbers in use.
> we don't have to spend 1.5 million USD from donations just on SMS codes in 2018 alone (source: tax filing)
Signal was paying that much? That's crazy.
> Signal was paying that much? That's crazy.
Yeah unfortunately they were. Income for that year (only year they filed so far) is 600k versus about 5M expenses, the largest single expense being sms verifications. Zero income from donations, perhaps they still ran that through the freedom of press foundation or what was it again that accepted donations on their behalf until they had the Foundation status? Either way, I wouldn't want to see the january 2021 bill.
Haha definitely not.
I would assume/hope that if Signal now starts going mainstream the donations will increase. I had donated sporadically in the past (have been using Signal since 2015) and now (since a couple of days ago) I'm doing monthly recurring donations. I'll recommend my friends to do the same, as I have been with Wikipedia and Archive.org.
Once nice thing about the Matrix protocol is that you can build your own client following the specs (unlike Signal).
If you want something closing to the average instant messaging client, you can look here https://matrix.org/clients/
I personally find FluffyChat a great casual client. https://fluffychat.im
Exactly, which means that it lost.
There are opportunities that are rare or unique, and it doesn't matter that you're "catching up" - either you're good enough when the opportunity arises, or you've missed that window.
You might get a second chance later, but this opportunity is lost, and the options aren't "Signal or Matrix", the options are "Signal or frustrate people, get them to go back to Whatsapp, and be even more reluctant to switch later".
And even if through some magic Element was polished right now: Signal has been polished for years now, and as a result, has built up a brand and user base.
I'm not going to be able to switch all my already switch-reluctant friends to something they haven't heard about and that nobody uses; I am going to be able to switch them to Signal, because they've already been pestered about it by several people, have heard about it in the news, and (except for today, which is a huge problem for adoption/switching people over), it works.
At least on Android, Element is simply not suitable for end users. I'm not talking about some poorly formatted UI, I'm talking about confusing/broken UX and features that don't properly work.
So I put my tech elitism away and do what works, because otherwise we'll be stuck with Facebook.
Edit: Forgot the biggest problem: Matrix has no chance because it doesn't use phone numbers as a forced default. With Signal, if your friends have already installed it, you can just start using it with them. With Matrix, you can't. This is one of the hard choices that Moxie made that is a bit of a dick move but was absolutely necessary.
Is now the time to be dogmatic about decentralization?
Edit: worth noting that I've been a Signal user since ~2015, and I've stood by them through multiple amateur-hour mistakes (including one where the iOS app would simply crash on boot for about a week, rendering it unusable to me and every other iOS user). The app was just starting to get into a non-insanely-buggy state that I was quite happy with, so it's upsetting to know that these sorts of mistakes are still being made.
Additionally, the status page, IMO, lacks of some information e.g. what services are up, historical view etc. Anyway, thrilled to see how it will change after this incident.
In the meantime, best of luck to the signal sre team.
Judging from their jobs page they are just hiring in US time zones, so it’s understandable that they might run out of steam after an incident going on into the middle of the night.
HugOps!
Hope they get it fully running soon. Maybe they’ll provide a good, public root cause analysis and I hope that they rethink hiring in order to get more TZ coverage.
The client entry point (api.directory.signal.org) seems to be pointing exclusively to Azure and IBM Cloud depending on geography. It looks like just DNS, the website, and maybe some backend stuff are on AWS.
> should be able to throw more hardware at it in a matter of minutes, hours tops
Who exactly is going to pay for the hundreds of thousands of dollars in cloud spend you propose they turn up?
Their 100M+ loan they got from Acton
It's there on https://status.signal.org/ though.
Edit: A few minutes after the message failed to send I got a yellow banner stating that the service was experience interruptions.
However the banner disappeared shortly afterward, so it would have been easy to miss.
I am not vouching for WhatsApp. I just don't think we should pretend that Signal is more reliable than it is.
My internet's fine.
I can understand not having 100% uptime, but going on 10 hours now and this is really not leaving me with a good impression.
I can count on SMS; I can't count on this.
[EDIT]Now I'm not even getting that specific error; my messages are simply failing to send (ios, desktop/windows)
https://support.signal.org/hc/en-us/articles/360007321171-Ca...
You'll keep all your message history in Signal that way. Good to know when your contact don't have an Internet connection, too.
The NSA will have a copy too, just in case you lose yours!
They should offer a paid subscription service for data retrieval, in case we do lose our copy!
Compared to installing the Signal app and verifying your phone number over SMS, the difference is quite remarkable. Signal has had smooth and frictionless onboarding as part of the design.
But also, comparing Matrix to Signal is a bit like comparing apples to oranges IMO.
The real apples to oranges comparison is you thinking that this wiki page is somehow comparable to registering a signal account.
This is the level of technical ability that you need to be targeting.
Re "you said it was called Matrix": fair, but I wouldn't send people to "matrix" / the protocol for any system with multiple implementations. I'd send them a link to one of the user-friendly apps (i.e. Element). Similarly, you wouldn't tell someone to join XMPP, you'd send them to the Google Hangouts or MSN Messenger or Playstation apps.
This is a friction-filled experience for someone coming from WhatsApp
Also, search still doesn't work in encrypted rooms.
> Cannot reach homeserver > Ensure you have a stable internet connection, or get in touch with the server admin
wise prediction of yours ;)
next you're going to tell me grandma should just use IRC instead.
I host my web, my email, my XMPP, my TURN/STUN, etc, so I gave Matrix a try. In short: it's horrible. It's insanely resource hungry, both synapse and dendrite, plus dendrite is so not finished it hurts.
Stick to XMPP until Matrix is in an actually usable shape when one doesn't need a small power reactor to run it.
About an hour ago.
1. Click reset password 2. You enter your email and new password (already here!) 3. A password reset request has been received for your Matrix account. If this was you, please click the link below to confirm resetting your password: [link] If this was not you, do not click the link above and instead contact your server administrator. Thank you. 4. Text page with the sentence "You have requested to reset your Matrix account password" but a button saying "Confirm changing my password" 5. Button clicked, password is set to the one entered in step 2.
This just absolutely is waiting for abuse. Every other site asks you to enter the new password after you have clicked the link. Here it's before you have clicked and there is no option to see or confirm the password entered initially. There is no indication that that is what's happening. In addition the word 'reset' is confused with 'change'.
Super easy for anyone - even the most techie user - to be fooled by this workflow. Someone else initiates the request and enters a new password, grandma gets the reset link and clicks it, password is changed and the other party can login and change also the email.
I would have to spend hours getting my family signed up for this thing.
I paid for Matrix and got my team on it, working great.
The nice thing about paying for something is you know what it costs.
I know in their own terms they basically say “we can delete your account, but we won’t”. I chuckled and never bothered.
I’m pretty sure keybase is end-to-end encrypted, at least that’s what they are claiming. What makes you think it isn’t?
> after [installing the Keybase app] and starting a chat with your friend, you still need to verify that the server sent you the right encryption key. Since you can't host your own server, it has to be the Keybase, Inc's server that sends you the encryption key of your friend.
> there is no way to display [the 'signature chain' of the person I'm chatting with], I have to trust the server to send me the right key. [Yet the client] displays a banner above the chat saying "end-to-end encrypted".
> It was mentioned on hacker news that the app should check third party proofs by itself. This is not exactly what end to end encryption means since it still relies on third parties, but nevertheless, having to [compromise] 2 or more companies' servers before being able to MitM someone's keys (which are additionally TOFU'd) should give quite some confidence.
> However, when checking in Wireshark whether it actually does this (ask the Twitter API for the proof string and verify the signature with the the public key it received from Keybase), Keybase on my phone did not contact Twitter at all. (It did, however, proudly proclaim that the new chat was end to end encrypted.)
> The packet capture started before the username was typed into the search field on the test device and ended only after Keybase completely established the chat and claimed it was end to end encrypted.
> It is deemed implausible for the mobile Keybase client to simply have downloaded all signature chains from all users that exist on Keybase and to have checked all their proofs prior to starting the packet capture. This is the only way I can think of how the third party hosted proof could have been verified prior to the packet capture.
- Wire
- Signal
- Jami
- Matrix/Element with central servers
- Threema
- Briar
- WhatsApp if you turn on key change notifications
- even Telegram secret 1:1 chats on a client that supports these kinds of chats
- anything you add OTR or PGP to... and the list goes on
You just need to do key verification, since key distribution is an unsolved problem in cryptography.
> after [installing the Keybase app] and starting a chat with your friend, you still need to verify that the server sent you the right encryption key. Since you can't host your own server, it has to be the Keybase, Inc's server that sends you the encryption key of your friend. [...] How does this work with Keybase?
> there is no way to display [the 'signature chain' of the person I'm chatting with], I have to trust the server to send me the right key. [Yet the client] displays a banner above the chat saying "end-to-end encrypted".
It's all marketing department with a sprinkling of blockchain magic.
If I had an IT department and a secure server center I would for sure self-host. In the mean time I will get used to the tech and support the cause
Ambiguity goes away by understanding the total finance model not by knowing you paid 5 bucks.
That being said I'd like to at least cover my cost to them to see it better grow. A payment isnt the same thing as that though it only tells you you at least paid a portion e.g. buying a smart tv doesnt mean you now know the tv cost less than that to make.
for a platform that bills itself after installation as a suitable drop in replacement for your SMS service (and encourages you to shill it to friends as such) this is completely unacceptable and could have easily been avoided with better leadership and architecture.
Cheerleading your users endorsement of privacy on twitter during an outage is insulting.
Most sites and apps monitor things like news sites, twitter and the like for instances where their namesake may be trending. This is done in order to quickly head off DDoS type outages due to things like the slashdot effect. Signal doesnt do this for the same reason Signal is centralized: Moxy writes code like he still lives in 2006.
- Nobody scrambled to bolster capacity after the electric car porn star (Elon Musk) gave a full throated endorsement?
- Nobody raced to improve capacity after Apple looked to be in a position to piss in Facebooks cheerios?
- Nobody even thought to reconsider capacity after Whatsapp showed up in the news JANUARY 6 with a bombshell announcement of privacy changes for users? we waited over a week?
It also needs to be said --yes im aware of my audience-- that centralized services DO NOT scale. Moxys response to this has been cantfix/wontfix, so in traditional dev fashion he throws more hardware at the problem to make it go away instead of looking into a better architecture.
Microservices do not scale. Yes, they scale across the cloud, but they do not scale across support channels. Microservices trade gaming cloud providers for precious pay-by-the-second service for an endless byzantine dumpster fire of almost impossible to diagnose failure conditions. A highly secure end to end encrypted service that expects to replace your SMS needs to be quick to diagnose and fix. Again: NINE HOURS.
A more callous review would suggest that Signal remains centralized because Moxies waiting for an IPO, or an offer from FAANG to buy him out. Im certainly not of that opinion, but FWIW this was a disaster for Signal and most of HN is about to break an arm patting the company on the back.
Whatsapp certainly took notice, and certainly used it as an opportunity to win back some of its detractors.
They’re not losing profits or anything. They’re hosting a free service. When they get the service back online users will have a secure messaging option that is even more battle-tested.
They are losing face. In oriental cultures, that's bad.
EDIT apologies for bad wording. In certain situations, losing face is worth, than losing money - in this very moment, in my opinion, this is rather bad for Signal.
Of course you got all the metadata going to FB, but it's still a good messenger feature-wise for now, so I'll keep it as a backup in case my favorite privacy-conscious messenger is down again for 10 hours.
There is no evidence that messages ever leak outside of WhatsApp via means other than potential unencrypted backups that you may or may not be using at a cloud provider not connected to Facebook or your IME.
If you're targeted by NSO or whatever nation state that would be interested enough in you to compromise you, you got other things to worry about.
WhatsApp does filter messages on the client side but it’s stuff like submitting image hashes to the CP database. If Signal reaches the scale of WhatsApp they will be forced into doing this as well. And nothing in Signal’s architecture prevents this kind of data exfiltration the same as WhatsApp.
BTW, is there an authoritative source whether these cloud backups to Google Drive are unencrypted/encrypted with Google keys, or encrypted with keys held by Facebook?
I see no reason not to encrypt them the same as local backups (with a key that is held by Facebook, and provided to your phone once they verify your phone number).
The difference between these against the US government filing warrants is just one piece of paper, but against an attacker that compromises your Google account, it does make a significant difference.
What do you mean by centralized and what makes you think they can’t scale?
Reliability is more important than privacy for messaging most of the time. Some major balls are being dropped here.
Obviously, The Signal team should have done a better job of coordinating the mass user migration with the WhatsApp team at Facebook. Such a failure. /s
I don't get why some people see the need to bitch about Signal at every opportunity. The criticisms are usually unfair (like this one), missing the point, or a self-centered whine that Signal didn't decide to focus on catering to the whiner.
Despite your deliberate conflation of them, shill and recommend are not synonyms
> Cheerleading your users endorsement of privacy on twitter during an outage is insulting.
How is a non-profit charity saying "we are having trouble right now but thanks for all the support" insulting? How did these folks insult you?
> Tesla, Apple, Facebook, WhatsApp
These are all corporations that ultimately only care about money. They have customers. Signal has supporters.
> because Moxies waiting for an IPO, or an offer from FAANG to buy him out
Just like all the other 501c3 IPOs and buyouts, right?
> this was a disaster for Signal and most of HN is about to break an arm patting the company on the back
A charity is having a temporary problem most HN readers would kill to have: They literally can't scale up fast enough to meet demand. Truly a disaster.
> I fully expect to be downvoted to oblivion
I wonder why.
> Microservices trade gaming cloud providers for precious pay-by-the-second service for an endless byzantine dumpster fire of almost impossible to diagnose failure conditions.
Distributed systems design is hard, Signal team might not be equipped to deal with the sudden surge of users and this definitely is not a good look. But federated/decentralized servers doesn't make this problem any easier, you still have to diagnose and fix your issue across a fleet of multiple servers. You can offload the problem to users, but then you will not have the adaption to begin with to create this problem.
If so, they couldn't have picked a worse corporate structure, because their current one forbids this.
> Even if we don't know what services they use
and it merely helping to find
> what language the [server] stuff is written in
Indeed I'd be interested in the post mortem here and I also don't expect anything from them (depending on how large this turns out to be, though, and so far it's actually a rather huge outage so maybe we'll get some info after all).
Sadly, whenever there was such an opportunities to shine, they ran into technical difficulties.
As a result, many friends tell me on a different messaging app like telegram that they finally tried out signal but moved on because it wasn't working.
This makes me very sad and I hope that the Signal team is able to learn from that and plan ahead.
@Signal please take your opportunities and make a reminder like a big banner in your office reminding you to ask yourself "is there an opportunity?" Or more concrete "did WhatsApp messed up with privacy?"
For me, I will still try to convince more people to switch to signal :-)
Since often its really difficult to spot it yourself.
For some Signal related education, listen to the Security Now! podcast from 2016 - Steve Gibson dives into the protocol underlying Signal, "Open Whisper Systems".
Also easy to self-host a server, if you need full control:
$ mkdir -p ~/synapse
$ pip3.6 install --user jinja2 matrix-synapse
$ cd ~/synapse
$ python3.6 -m synapse.app.homeserver \ --server-name my.domain.name \ --config-path homeserver.yaml \ --generate-config \ --report-stats=no
If you do want to set up your own server I wrote a guide when I learned how to do it with Google cloud instances: https://munfred.com/matrix
There is no such thing as decentralized messaging on iOS for this reason.
The matrix developers run a push service, which all servers have to talk to to push notifications to their iOS app, even if you run your own instance.
[ EDIT: The following statement is false! Changes in APNS have rendered my previous understanding out of date. ] This means that both the push server operator, as well as Apple, can see the content of all of the push notification messages, thereby bypassing the e2e encryption as well.
This isn't really true: there are lots of Matrix iOS clients out there, and each run their own separate push server. Only Element iOS's push server is run by the 'matrix developers', and if you are worried about that then (if you are an iOS developer) you can build your own copy of Element iOS pointed at your own push server.
> This means that both the push server operator, as well as Apple, can see the content of all of the push notification messages, thereby bypassing the e2e encryption as well.
This is completely incorrect. By definition, the server can't see the contents of end-to-end encrypted messages, and we don't send push contents (encrypted or otherwise) to the push gateway anyway. Instead, the push notification is a single flag sent to the client to tell it to wake up, which then runs a Push Extension (on iOS) to talk to the Matrix server and do E2EE in order to display the notification body (if desired). It's become particularly painful since iOS 13 thanks to https://appleinsider.com/articles/19/09/05/secure-messaging-....
Recommended specs will include 16GB RAM only for synapse, SSD storage, etc.
If someone wants to self-host, start with Prosody and XMPP, not with Matrix.
What? If you want a server for 200+ users, yes maybe. But 2GB of RAM is plenty for hosting a few active users federating in large chats.
As a longish time Matrix user I've never experienced scalability issues due to federation. The federation actually works pretty well. Scalability from Matrix comes/came due to the fact that some servers were too popular. Though that is actively being worked on: https://matrix.org/blog/2020/11/03/how-we-fixed-synapses-sca...
Obviously I'm not going to complain that a free service isn't working for me 100% of the time, and I'm not "angry" or anything, but I hope this is resolved soon; pretty much the only way I talk to my friends and family is via Signal.
For a free service, intended to survive with very small amounts of donated money, you need a fundamentally different architecture. Whatsapp was not built for this, and since Signal copied them, neither is Signal.
Even if Signal is able to survive on meagre donations, I would think it is a better use of that money to be spent on resilient, distributed architecture than AWS bills. A good architecture ensures sustainability, a large AWS bill just makes Bezos richer.
On desktop at least, I'm generally of the position that messaging apps should need no capability outside of what's available in my browser (i.e. sending notifications), so when the option is available that's the one I tend to go for (usually have my commonly used ones sitting around in a pinned tab).
Pretty much every chat app out there today (including WhatsApp) has a web app. Anyone know why Signal doesn't? Is it just a prioritization/lack of resources thing?
But with a web app you redownload the application everytime which means you'd have to recheck that checksum every time you use the app. I guess that WhatsApp, Discord, et al have decided that this is a reasonable risk. But the privacy oriented Signal team disagrees.
I don't think it's a prioritization issue, the desktop app is currently running via electron which means it's effectively a web app already.
Or do you have a different use case?
The background here is that WhatsApp previously stated that they would never share user data for profit, i.e., not selling ads [1]. Reading that blog post leaves a sour taste in HN's collective mouth, because not 2 years later they would get acquired by the ad giant Facebook and now mandate that users agree to share their data with FB. The wording made it seem like accounts that didn't agree with the new policies would get terminated on February 8th.
A few days later, WhatsApp posted [2] that their update was misinterpreted by users and media, and that the clarifications to their policies were to increase transparency. They also pushed the ultimatum for a few months.
[1] https://blog.whatsapp.com/why-we-don-t-sell-ads
[2] https://blog.whatsapp.com/giving-more-time-for-our-recent-up...
Does she have any Q/Right wing/Parler friends?
Shame they couldn't anticipate this, or scale better. Curious what their postmortem will have in it.
That one pissed me off a lot more than today's outage, which is understandable, hopefully short, and unlikely to be repeated once they get scaling under control. It's also the reason why I'm not donating today.
I assume that the hostname(s) of the central Signal servers are hardcoded in the app somewhere, since they're not meant to be replaced.
Since Signal doesn't federate, if you switched your client to an alternate server you would be unable to communicate with the 99.9% of people out there using the official Signal server. Signal isn't going to give a UI option that is certain to cause frustration and bafflement for the vast majority of users. Those wanting to use an alternate server are probably a small nerd niche who already know how to fork the client.
It's actually decentralized so like email only one server goes out at a time.
Good point.
For AMEX Platinum cardholders there’s a promotion for a $30 credit per month for things paid via PayPal, make AMEX donate
I just wish it was as easy to switch from Amazon and Google.
But the Signal folks did indeed help WhatsApp implement the Signal protocol, which is kind of ironic.
How do we structure this? Donations(private individuals, users, governments?), usage fees(annual subscriptions for a household?) or some other payment model we haven't discovered yet (like USPS stamps/postage fee - PAYG)
Signal is going to be better than ever by going through these moments and improving the platform. I don't mind the inconvenience and don't expect premium quality with five nines of availability. I'm not in a position to complain.
In principle it shouldn't matter. But I'm worried userbase demographics will determine from which quarter the next legislative threat to end-to-end encryption emerges.
Also, why can’t I send a message any time, instead of just sometimes?
The same principles should and could apply for decentralized one; pick conversations.im for XMPP, pick matrix.org for Matrix, pick Mastodon.social for fediverse - or something smaller. Or ask someone to do it for you. Or run your own.
Then money people came, and destroyed it, then the idea of Matrix came, because of Slack, but thanks to people like Daniel Gultsch of https://conversations.im/ , XMPP is actually growing again. Slowly, but steadily: https://blog.prosody.im/2020-retrospective/
We know already it works. Federation and choice is a win for everybody. For this to start though you need either a good client/server combo for people to individually adopt, or a GREAT/POPULAR client with a default server.
I'm sorry to say that Element/Riot fails flat on this. I've used Riot and then Element for a while, and it got worse in usability and features (I genuinely can't stand it). As the reference client, it doesn't support multiple server accounts, which kill the ability to have an independent server. Federation is nice, but what's nicer currently is to be able to use matrix a teams/slack replacement where tech users can drive adoption. The central matrix.org server is slow already, and even with federation you cannot tell your users to switch servers because of this, defeating the point.
The positive side is that on the client side there's already choice. On the user front I've found FluffyChat to be vastly superior. Using Jitsi for audio/video was weird at first, but it works much more reliably than signal (I gave up on signal for audio calls due to the time it takes to establish a connection and the horrible lag it randomly has - to the point I just hang up and call via GSM to finish the conversation, defeating the point).
If I was element I'd get FluffyChat and it's author onboard as _the_ default client. On desktop I can choose multiple clients, and I have none of the "Signal" phone number/pin/central server/electron BS. It works as intended, and it will only get better with time. It's great.
IIRC, Signal calls are P2P.
> Always relay calls:
> Relay all calls through the Signal server to avoid revealing your IP address to your contact. Enabling will reduce call quality.
I'm not sure why nobody uses it.
EDIT Ring. It was called Ring.
https://www.youtube.com/watch?v=OZ0NkT6gbP0
https://open.spotify.com/episode/2uVHiMqqJxy8iR2YB63aeP
===
(Clearly downvoted by idiots who didnt even watch the short edit about signal...
HN has an arrogance problem... Moxy Marlinspike is the founder of signal - and he talks about why he did so...
Listen to him...)
For example, I have never once received a "you should watch this as well" decent recommendation from Youtube, the sidebar is absolute garbage and cant even keep the concept of a topic-thread... Youtube is total trash.
I've skimmed through the code and found references to Protobuf, GCM and Redis
It's open source so you can check the code here: https://github.com/signalapp/Signal-Server
Just because you own a platform doesn't mean you have an economic moat. The crowd's sentiment can change overnight and I think Zuck is honestly out of touch with public sentiments.
He probably thinks that he can run for US presidency using Facebook as a launchpad but all the money in the world won't fix myopia.
Did the United States attack Signal to further clamp down on speech and private communication?
Where do people think all these parlor users are going?
As much as I love Signal, we've got to move to things that are decentralized. I setup a prosody[1] server a while back, but have nobody to talk with. If anyone wants to try their system out, I'm bjt@2n3904.net on XMPP.
I'm using Conversations for Android. If you have a server that will allow self service registration, you can make an account right from the app.
Edit: Aaand I'm up! Got my first message. Thank you for your help, and for your work on Prosody!
That's not to say decentralized doesn't have a ton of benefits just uptime for the user isnt one.
How easily can Signal replace those dependencies if this comes for them?
"Extremists move to secret online channels": https://www.nbcnews.com/politics/congress/extremists-move-se...
AWS S3 is/was used to share files with other users. It became a standardized API, with many alternatives supporting the protocol, so switching to a different provider or on-premises should not be difficult.
Signal intends to remove the dependency on phone numbers, and therefore Twilio, but this has not be done yet.
And if the OS decides to kill your app's process, your polling dies with it and you don't get notifications.
Maybe that's a good reason to open for federation and now I wonder if it would be possible to have an user migration between servers without cooperation from the origin server. This would allow users to move to a new one without losing track of existing conversations.
Seems crazy, but the reason we can't do this with email is the lack of a generally agreed identity for an user account that does not depend on the server itself. Signal accounts have a "master" key that can provide this and it's only stored in the device and backups (it's the most trusted of all keys, after all).
A sketch:
- User creates an initial account on server X (account: user@serverX.org), the procedure includes signing a message saying "I use server X since $TIMESTAMP and this is the 1st server that I use";
- Everything works as now.
- User wants to change server, so they signs a new message "I use server Y since $TIMESTAMP and this is the 2nd server that I use" (account: user@serverY.org); this message is sent to all chats/groups/contacts and to the old server (as an information only, it may be already down or be non-cooperative). Contacts update the server part of the account and start sending messages through the new one. Maybe the user can still try to contact the old server for a while, for the event it delivers a message from a account that didn't get the first, but at some moment all users will get the new address.
Notice: I have no idea of how this can work with sealed senders of other metadata-prevention measures that Signal uses and we all love.
Bonus: no more dependency on phone numbers.
Or if it goes to an more email-like architecture were users only speaks with their servers, it can adopt concepts from djb's Internet Mail 2000 [https://cr.yp.to/im2000.html]. This will *not* work for current email due to the need of keeping compatibility with the enormous existing user base, but this problem does not exist for a new protocol.
Maybe you're mixing it up with Matrix, Briar, or some other decentralized chat system.
I know they don't like third party implementations because then if you need to make a protocol change you'd have to wait 30 years for everyone else to update their clients. But if you're already requiring a single client that it makes it easier to do decentralized messaging for exactly the same reason.
Another option that works pretty well is to do both. So try decentralized (DHT / direct connection) first and fallback to a central server if that doesn't work. Then you're up as long as either one of them is working. And there is a lot less load on your central servers.
Do you need a static IP? (Xfinity appears alergic to allowing static IPs any more, and I am too lazy to setup my own router after 26 years setting up other peoples net infra..)
Id love to chat with you...
I've used XMPP servers for intra-organization chatservers before though, and it worked great!
Sure.
>Do you need a static IP?
Well you need a domain name to identify your server. It's the same thing as with email. So however you can do that...
It might be less work to just use a preexisting public server:
Easily.
> Do you need a static IP?
No, but you need access to a domain record to add the required entries for XMPP, and update them if your IP changes. One can do this for free (once you have a domain that points at their DNS records) with a provider like Digitalocean and their API to update the domains.
Set up guides: https://prosody.im/doc
Community to ask: https://homebrewserver.club/
But there are also solutions that don’t require everyone to host their own server. Rather, people just host impersonal nodes on the network and everyone uses the whole network together.
Examples would be Status[1] (Ethereum) and Session[2] (Oxen neé Loki).
I’m sure there are others that use this architecture too. I just like it because I don’t have to be personally concerned with who is running my “home server”. Because there is no one single home server in this model.
[1]: https://status.im/
It sounds like these must be centralized systems presented as decentralization, similar to how Keybase marketed themselves as end to end encrypted and nobody noticed that you can't actually verify peer's keys thus making it TOFU (similar to blindly accepting ssh keys). (And when you asked people about their claims about Keybase, they'd tell you to RTFM regardless of whether you already said you did that... A marketing department can be very powerful even on HN.)
Personally I think that’s the best way to do it. Public keys aren’t very different from phone numbers at this point. Nobody memorizes phone numbers anymore either. Each person just has their own Rolodex mapping of keys to names.
Is there any decentralized protocol that's in widespread use? Email is the only one, and if hackers take out Gmail and 2-3 other major email providers 99% of the world's personal email is gone.
They are going to be the next Facebook. I don't understand why people underestimate them so much. When they rolled their own crypto in some areas, people made fun of them, yet no one could break it. When they published their source code openly, people say they aren't open source like signal. When FB bought WhatsApp, people seriously continued to choose it over Telegram, despite Telegram able to host much bigger chats, and so on. And being used all over the world, by the same government officials who were officially trying to get it offline LMAO.
I just don't get what's so bad about Telegram.
> I just don't get what's so bad about Telegram.
Pick one.
You say Telegram is a for-profit company, but I am not sure how Telegram makes money, at all. It was approached by various government agencies looking for backdoors and claims to have rebuffed them all. Unless the whole thing with the founder of vkontakte having to give up his shares to mail.ru and run, was staged, I'm pretty sure he's an anarcho-capitalist who isn't very happy with states having data. So if that's the case, Telegram (unlike Moxie Marlinspike and Jan Koum) is much less likely to sell out their platform down the line.
1. e2e chats are not default, and they are clear on this fact. It is very easy to start one, though.
2. All voice and video calls are e2e encrypted. [1]
3. They do not harvest your data, and they are not for-profit. All of the money invested so far has been put up by the founder, Pavel Durov, [2], but they have outlined possible methods for financing. [3]
[1] https://core.telegram.org/api/end-to-end/video-calls
Signal has just encountered the worst usability issue today (Which is by going down) which is costing them users to look elsewhere.
- Messages can't be edited so any corrections made by users need to be entirely new transmission over the wire (probs negligible)
- Encrypted data can't be effectively compressed, and compression before encryption can lead to side-channel attacks. You can generally mitigate this by building your compression and encryption together (e.g. SSL does this), but not entirely sure this works for Signal with an E2EE arch. Either way I would assume that E2EE payload sizes transmitted over the wire are larger than stuff sent over the wire with GZIP/SSL (as Telegram is probably doing).
- MAIN REASON (my guess): group chats in the Signal protocol require sending a different encrypted message to each participant, rather than a single identical message to all participants. Honestly my algorithmic complexity chops aren't the best, but I think that would make Signal group chats O[2n] while Telegram group chats are more like O[log n], if they utilize clients sending the group chat to each other, which is a crazy level of difference in efficiency for what is effectively the same thing and a pretty common use case (group chats).
Long story short, secure things that are hard to mess with are less efficient than things that are easier to mess with. This is why blockchains like Bitcoin are much more lethargic than a normal database – there are some necessary performance trade-offs required when you want high levels of security in your system. There are a bunch of small little things that probably aren't a big deal, but every little bit adds up when you're trying to scale a service to millions of active users / billions of messages.
If the system is built for it, that is.
Though on 2018 there was some noise from Amazon about stopping their hosting due to practice called "Domain Fronting", no idea what came out of it. At least signal.org is hosted on Google.
Jumping from Facebook or WhatsApp to Telegram doesn't make any sense from a privacy perspective. Well Telegram supports secret chats, It unfortunately defaults to non-secret chats, which are just to secure as any old Facebook post. In fact, if we're comparing WhatsApp to Telegram, from a privacy perspective, you would be giving up more data by switching to Telegram because WhatsApp is completely end to end encrypted by default.