Has anyone found a publication around what they had to do on the technical side (code)?
Edit: Their server's repo hasn't been updated since April 2020. Why?
Has anyone found a publication around what they had to do on the technical side (code)?
Edit: Their server's repo hasn't been updated since April 2020. Why?
If you compare it with Matrix, the last commits to Synapse were ~32 hours ago, Dendrite was ~31 hours ago, and Conduit was 3 hours ago - so you can keep up with where development is at, and of course see what is meant to be running in production (and run it yourself if you're able to).
My assumption is that what's happening is that Signal-Server is going through contortions to switch everything to UUIDs, in order to avoid hardcoding phone numbers everywhere as identifiers, and this work is being done on a private branch. Meanwhile, there's presumably a private branch for the current live production deployment too. (For Matrix, we maintain a separate branch for the live matrix.org homeserver instance, to allow for hotfixes etc - although it's public, at https://github.com/matrix-org/synapse/tree/matrix-org-hotfix...)
Quick question, semi-relevant: does the matrix.org homeserver have open monitoring? Is there someone I can look to see server load?
I’m curious whether Matrix saw a similar influx of users this past week.
This comment of yours is only the second time I'm hearing of Matrix (the first time was several days ago, in a bunch of comments on an ASK HN discussing the WA policy announcement). And because of your comment (and the implication that Matrix is something one can run independently in production) I am now perusing matrix.org - thanks for sharing.
Also I enjoyed your insight with respect to the Signal dev team and what they're possibly currently frantically busy with.
Mind if I ask you, what your thoughts are on the Signal project long-term?
From the article you linked:
> It’s also true that decentralised systems are harder to evolve than centralised ones - you can’t just push out a given feature with a single app update, but you have to agree and publish a public spec, support incremental migration, and build governance processes and community dynamics which encourage everyone to implement and upgrade. This is hard, but not impossible: we’ve spent loads of time and money on Matrix’s governance model and spec process to get it right.
For me it seems to largely come down to a juxtaposition between the above risk (owed to Matrix) and the below risk (owed to Signal).
> you end up thoroughly putting all your eggs in one basket, trusting past, present & future Signal to retain its values, stay up and somehow dodge compromise & censorship… despite probably being the single highest value attack target on the ‘net.
Definitely something to think deeply about.
Might I add, as a complete Matrix newcomer, the description of its decentralised model in that article reminds me a bit of IRC in the 90s - except with solid encryption.
It certainly seems to make sense if liberty is one's priority.
I have given you flack over the Synapse migration path for server operators over the last few years, but this Signal outage brought home how important it is that Matrix is a more than suitable replacement for Signal among my family and friends, and how smooth it has been to run my Synapse server over the last year.
You and your team are doing an awesome job!
Not really a privacy issue for the new user, since this is his public avatar, but a nice reminder for this issue that phone number are ill suited as identifiers
Yes and no.. I think a resource like a phone number is better than the yahoo/etc email reallocation situation. So far it seems to be rarer that someone tries to get allocated a number to impersonate a previous owner's identity.
I am not even that interested in having a fixed phone number, I would rather ever changing throwaways for many contacts.
As soon as my number gets into the wrong hands, the fight against spam is painful, and I have to drop it.
1) a bahillion new signups, so they just needed to deploy a bajillion more instances of the server.
2) The clients basically DDoS'ing their servers.
If you look at the android client source, you can see all the commits they put in are about handling errors properly when the server(s) get overloaded.
We don't even know if the main @matrix.org server would have held and if federation would have keep working.
Not worth the cost? How much did whatsapp cost to Facebook? How much did whatsapp cost before that?
Matrix is also running on free and so far we have hosted server offerings but no single individual account offer.
This is argumentum ad populum.
> main @matrix.org server
There is no "main" server. matrix.org is the biggest one, but it is circunstancial. Matrix and Element do not want be the biggest instances or keep things under their control. I can bet that people working on Matrix would be thrilled with the idea of helping people create more instances, and even it would be beneficial for their business.
> Matrix is also running on free and so far we have hosted server offerings but no single individual account offer.
https://communick.com, there you go.
I don’t doubt there’s a lot of value in federated decentralized services, but there’s also a lot of value in confusion/configuration-free usability.
Thanks to comments endorsing matrix here, I will be installing it to try, but what Signal gets right is that it pretty much Just Works, and that’s the point GP is making. Frictionless UX coupled with cryptographic excellence make it compelling for lay people, and if it’s between Signal or nothing for the majority of nontechnical folk, then they’re better off using Signal.
> it’s between Signal or nothing for the majority of nontechnical folk.
This is a false dichotomy. Nothing about federated services that make it intrinsically less usable.
> pretty much Just Works
Until it stopped working. And it failed spectacularly. For everyone.
I might have to repeat this until I go hoarse, but switching from one centralized service to another is not progress. It doesn't make us free. You are still at the mercy of an selected few to take things in the direction they want, everyone is still dependent on their success and the more people adopt it the more difficult it becomes to escape it case the leaders subvert their power to go against the will of the people.
I didn't say that. I would say that Signal is more usable than Element, though. While I was commenting, I installed Element and the UX is just not as smooth as Signal - even the quick start instructions aren't as simple: "go to matrix site, click through to Element, read instructions to return to site to configure, install app, register username/pwd, forget about configuration step because it's apparently not necessary after all (?)" vs "go to signal.org, install app, verify phone number." It's not terrible for technically capable folk, but the friction is why it's not as popular as Signal.
And while argumentum ad populum is a logical fallacy, practically speaking it is a boon to be popular in most things.
Judging by your last paragraph, it comes down to a matter of values - is decentralization important to you? Then hands down, Signal will lose. But for a large number of people who don't care about decentralization, they will do what's popular and easy. OWS, I presume, wants to make sure the easiest, most popular solution is also secure.
The outage wasn't global and didn't impact everyone ? It kept working for me and others in my contact list but some couldn't send messages.
Also, if @matrix.org fails or @something fails then it impact users who wants to interact with both those addresses. So in the end it's not that much different for users.
I think you comment about the will of the people is a bit off the rails. If anything the whatsapp exodus shows it's not true since we are seeing people moving from whatsapp to signal.
When I run my own matrix instance I am still dependent on the matrix guys and what they want to do with the protocol and the de facto only matrix server's code. I can't fix anything with my instance but basic proxy/ssl/dns errors. I can't get the ship to stir in any directions. There are no matrix board where I could voice my concerns about stickers or the default colourscheme. Just like Signal.
I am not a "Matrix guy", don't work for Element or the foundation. Yet, I can provide Matrix hosting services for you.
If you and more of my customers start asking for changes/improvements (customizations to the clients, better solutions for storage, different kinds of integrations, etc) I can go and develop the changes myself AND DEPLOY THEM on a server for you to use, without needing to ask permission from any of the Matrix devs or Element or the Foundation.
Just a very, very real example: I started looking into how I could integrate Hub20 with a Matrix homeserver to allow people to send/receive payments by messaging. It's the kind of functionality that would be super interesting for some folks, it does not require change in functionality of the core protocol in any way and it is very aligned with the Hub20's principle of facilitating access to crypto for the masses that do not want to deal with the complexities of blockchain/wallet/etc.
Such an integration will never happen on Signal. Signal being centralized, there is no separate instance that could try out this integration, or make it work only for the accounts that it can manage. Telegram is the same, WhatsApp is the same.
Instead of looking simply what is given to you "for free" in the different offerings from the market, start looking at what we can build on them. Don't let your lack of imagination become everyone else's weight to carry.
[0]: https:/docs.hub20.io
> Don't let your lack of imagination become everyone else's weight to carry.
No one here is shackling you to Signal. You're free to use and customize Matrix, but your argument that people using Signal is no progress at all based solely on being a centralized service is zealotry that is blinding you to the experiences of laypeople.
Starting with your root comment - most people use centralized services that have gone down at some point. In many cases they are still using those services, not because they're foolish muggles who can't program, but because it's worth more to use than it is to switch to something else. Centralized or not, people don't really care. This entire thread has been an effort to convince you that most people don't have the same values you do, hence the argumentum ad populum that you so despise being actually a valid metric of success for a project. Popularity is a flawed argument if you're in a formal debate, but it is useful to nearly every other venture.
So is Signal the best possible messenger it could be? No, probably not. I, too, would like to see a decentralized, federated protocol take off. But is it measurably better than plaintext SMS or Facebook Messenger? Yes, probably.
Yeah, being comfortable is not the point. The point is being free.
> No one here is shackling you to Signal.
No one forced me to use WhatsApp. I still use it and still have on my phone. I did manage to introduce some people to Matrix, setup their accounts and install their clients when they wanted to talk to me, but there is a whole lot more that I am just not close enough and that I know won't bother to switch just because I am asking them to.
If people ask me, I'd do the best case I can to get them to Matrix (or XMPP. I don't care as long as it is open and free) and I will help them whenever possible to switch away from centralized systems.
> I, too, would like to see a decentralized, federated protocol take off.
If you truly want to see a federated alternative grow, you have to help it. It's not going to happen if we just stand passively waiting for some big benefactor to show up and decide they don't want to control this space. Every big company will try to control this space and they will always have more resources and will use the advantages that centralized services (faster development, economies of scale) gives them.
Network effects matter. There is no better time to help people switch to a more free option than now with this massive WhatsApp diaspora. If people settle for Signal, it would be better than WhatsApp but it would still be a massive wasted opportunity. This is why I am arguing now so strongly.
(Lastly, do you know one software that I am somewhat forced to use? Slack. Do you know what can replace Slack with just a wee bit of training? Matrix. Two birds, one stone)
> Signal is no progress at all.
In the terms of freedom: no, it is not. The server is supposedly open source, yet the last commit in their repository is from April. If someone decided to fork Signal to run their own server, would they get a current version? Would existing clients be able to use the different server?
The answer is possibly, maybe it will require a lot of work on the people doing the fork. Which is fine from the legal perspective, but really far from the mark from Open Source ethics.
It's true that some element of grassroots activism will affect outcomes, but I think marketing, longevity, and UX make a larger difference.
Either way, getting a federated alternative up to speed in UX or forking Signal will require a lot of work.
You simply can not compare the amount of work that will be required (collectively and individually) in either outcome. Improvements to Matrix are being made, and both Element and the Matrix foundation are supportive of further developments and getting more people onboard. Signal is actively working to get forks to do extra leg-work.
What you will usually read from me is that centralized services restrict our freedom, concentrate too much power in one single entity and are not worth the convenience.
It's not circumstantial at all. You can't send off people to random server without telling them it might shut down because no one knows the owner or when he's going to stop paying for his experience. @matrix.org is the only place where I'd feel safe sending relatives if they want to onboard because it's the only place I know the matrix guys are going to keep running. Most posts I am seeing on HN these days stating registering a matrix account was easy did it on matrix.org.
I believe they should charge a fee. To avoid the GMail effect that got everyone a free email but trapped them in the end. And no, you can't jump as easily from one @something to @somethingelse because you lose your message history and attachments (that's where the often cited mail analogy fails us: with email you can take your email with you when switching). If this chat history doesn't matter BUT you have to find a way to export your contacts then I don't see why it's better than Signal for regular joes.
Two years ago I could run my own matrix instance on a small VPS. Now it requires too much resources, especially when it's federated. Also, the mail federation analogy falls short here because nothing prevents mail from circulating between @something and @somethingelse while matrix has it in its design to whitelist some federated servers.
> https://communick.com, there you go.
Not what I mean. I am not looking to forward this to people asking me "hey, how do I get on matrix ?" "here, set up or buy your own server". Where can I send them when all they want and need is a matrix address ? Where can they pay a small fee to keep their matrix address longterm without going through the hassle of maintaining/renting a server ? Matrix.org But we don't see a rush of new users on Matrix. I wish there were though but I am convinced Matrix and Signal don't address the needs of the same people. And that's certainly why every signal thread seem to attract matrix supporters and we get into that federated/centralized debate. Which has been beaten to death.
Have you seen communick? It's exactly that: a service that provides managed accounts for federated services such as Matrix/Mastodon/XMPP for a small fee. No server setup required.
I was wrong. I checked again and on Chrome you have the full site and if I am not mistaken, for $5 for three months you get a mastodon, a matrix (and a xmpp) identity which is pretty cool (or it's cumulative, I don't know. But $20/y for messaging should be okay, though it's still far away from whatsapp $1 subscription).
This page needs some love but it's exactly what I had in mind :).
Regarding pricing: It's $5 dollar/3 months for all three services and it gives you 10 accounts. So it's actually $2/user/year. Mind you, this is a "soft launch" pricing (as you could see, plenty of work to be done there) and my idea is to grandfather in the first 100 signups. Once I iron out the most critical bugs, I am working with the idea of charging $1/month ($10/year) for single users and $6/month ($60/year) for the 10-user package.
It hasn't been my first priority because there is already a good number of companies offering that for Mastodon, Matrix and XMPP - but I'd certainly want to get to this point as well.
Even in the case you have a very well federated system with users very dispersed and the federation had 100% uptime and no bugs... how does it affect uptime for users? A central server going down 1% of the time for all users is the same as 1,000,000 decentralized servers being down 1% of the time for their 1/1,000,000 users. Nobody cares others can use the service during an outage they care they can use the service.
Federation capability at the protocol (even if it's not used in a truly federated way) provides a lot of great features, uptime for users isn't really one though. The most relevant is probably when Signal shuts down intentionally (tomorrow or 1,000 years from now, doesn't matter) you can't just migrate to a different Signal server without all of your contacts moving to the same one. This is akin to taking your /24 with you to your new ISP, porting your phone number to a new phone provider, or taking your custom domain email from Gmail to a different host and the ability to do that on those federated systems is probably why they remain in use today.
If so, may I suggest you read Antifragile?
There are other valid lessons for why choose decentralized but this is not a "ha, got'em" moment for that. There are also valid pros for centralized as well, hence their real world success and the reason most "decentralized" tech ends up being run in a very centralized fashion when it matures.
This is a great case for GCP.
OTOH due to end to end encryption all the fancy features are implemented client-side so the server is very simple in scope. So maybe it's really feature-complete.