Why Jabber reigns across the Russian cybercrime underground
cyberscoop.com
cyberscoop.com
He pointed out the OTR plugin, and it blew my mind that it was guaranteed that no one could possibly snoop our conversation.
I knew that it was theoretically possible, but I can't overstate how important it is to package the crypto in a user-friendly way. Being able to get the session going in about 30 seconds was a killer feature.
But, more than that, it seemed to have an advantage over present-day Signal: I use Signal now, but I always feel a bit queasy about trusting it implicitly. I do trust it, but it's such a massive ecosystem now that it doesn't feel nearly as "transparent" as the OTR plugin did. The OTR plugin was like, if this is broken, there are many eyeballs that will know pretty quickly. Whereas Signal doesn't quite feel the same way.
I'm not entirely sure why, or if that feeling is just me. There's no reason to feel like an OTR plugin is inherently more secure. And yet, as evidenced by the article, it was rock solid for 18 years.
Conversations on Android works quite well for XMPP on Android. Quicksy by the same author even has phone-based discoverability.
Movim is another pretty great XMPP client.
I hope that post Facebook messages gets to the level of threaded messages. Sometimes pure chat is enough and sometimes chat is really annoying for accomplishing things.
Wasn't that addressed by OMEMO, the OTR "replacement" protocol?
OMEMO has pretty much replaced OTR in the clients so if you want simple/stateless you are left with one of the two PGP flavours.
Any decentralised alternatives without the cryptocurrency linkage.
The "popular" messaging service HipChat has been dead since 2018 when Slack acquired it's codebase and moved it's users to Slack.
WhatsApp no longer runs on Jabber/XMPP. They used to run on modified eJabberd a long time ago but these days they use a combination of Signal and something custom...
WhatsApp switched to Signal Protocol in 2016 however so that point still stands.
Criminal orgs require their communications be secure, ideally without the ability for whomever they're chatting with to compromise the chat without meaning to (see iMessage saving both the key and the messages to iCloud, Whatsapp backing up messages to Google Drive, etc.)
It's very true to say not every criminal organisation uses proper opsec, but my point is not every criminal is smart. I'm simply pointing out that if a communication platform isn't used by any criminals, it's likely not worth using for me.
The thing I miss with non-facebook stuff is threaded discussion. Earlier comment just get lost.
Is there an XMPP client with threaded discussion?
For example, the following XEP (XMPP Extension) talks about best practices for message threads:
https://xmpp.org/extensions/xep-0201.html
And XEP-0085 about chat state notifications has a section about threads.
https://xmpp.org/extensions/xep-0085.html#bizrules-threads
So probably your best bet is to look at the list of supported features of all XMPP clients and see which ones support XEP-0085, and then between any clients that support that see if they support threading.
That's wonderful but how do you handle the trust aspect?
I hit a wall on infosec stuff because people are pretty gatekeepy.
Is it that other cybercriminals use different tools? Or do we somehow hold Russian cybercriminals to higher esteem?