But some people aren't LARPing, truly need privacy, and compromising their safety to make a point about federation is immoral.
People who truly need privacy in the short term, should consult a professional and not trust random comments from strangers.
Would you like an example that's especially relevant to this thread? Because I can provide you with one.
I never mentioned any particular kind of federation that I prefer. I also never mentioned word "private", which is mostly tangential to federation.
My point is that, in the long run, only federated systems are sustainable, because nobody is able to fund huge servers with millions of users without infinite money. For example, Signal and Telegram are both struggling with that currently; the latter introduced advertisement recently. On the other hand, Mastodon does not seem to have such problem (you could argue that it's too early though).
I do not want to build my own clients, I'm not even a programmer. I want a sustainable network, which could be achieved by a large number of self-hosted instances federated with (possibly) large servers. It has been working fine with email for decades. Also, the competition of various independent clients improves the user experience (like any other healthy competition elsewhere).
That doesn't make Matrix bad. It makes Matrix different. Matrix has different goals than Signal, and those goals simply prioritize security and privacy differently than Signal does.
You're completely right that we have different goals to Signal (openness + freedom rather than privacy-at-all-costs), but I'm not sure that blaming federation is the right answer here. We just prioritised building an open standard over having E2EE from day 1, instead choosing to design things so we could add it later.
Again: I'm not dunking on Matrix. There are things the Matrix approach will do better than Signal can. But protecting individuals is probably never going to be one of them; you're competing with a project that has security and privacy as its overriding goal, and nobody at Signal ever has to ask whether federation --- a protocol complexifier if ever there was one --- merits a security hit.
I don't use Signal for everything (or even most things). I'm completely open to the argument that other messengers are better "overall" than Signal. But on a thread that asks the question of whether Matrix is as secure as Signal (not "secure enough", but rather "at parity with"), there is simply a clear answer.
I'm willing to believe that this is true for Telegram, since they do pretty much everything on the server. With Signal, though, message databases and most business logic are client-side, so the servers are surprisingly dumb and lean. Signal spends way more on salaries and wages than on its servers. In 2019, Signal paid more to Twilio for SMS verification than it did to AWS for hosting: https://projects.propublica.org/nonprofits/organizations/824...
"Sustainability" is arbitrary. Everything burns eventually.
I am mostly talking about a use case, where you try to switch all your friends and relatives to a new IM system. If you have to ask them to switch again in a couple of years, you will loose their trust quickly.
The content of the message might be encrypted, but metadata can provide valuable intelligence insights.
At least Matrix can be used mostly anonymously through a user-generated identifier, without an email address or phone number, and can be used through Tor.
Signal forces you to use "a" phone number as your identifier. It does not have to be your primary phone number, or home phone number or office phone number. Just a phone number that you have control of.
In most parts of the world, you cannot get "just" a phone number not tied to your real identity.
1. the number everyone you have met since you were 12 has in their contacts.
2. the number a few people have but you also use for you facebook account.
3. the number nobody / no tech has but you have provided your legal id to the network provider.
4. the number nobody / no tech has and you gave the network provider a burner email for.
5. the number nobody / no tech has that you paid for in cash while wearing a wig and glasses half way across town. You put into a new, paid for in cash phone, activated and used briefly while carrying no other electronic devices while disguised and avoiding cctv.
6. the inbound phone number in the lobby of the ritz carlton.
Some of those are better than using 'firstname.lastname' as you identifier. 1&2 are definately public numbers 4&5&6 are not.
#3 in the real world is semi-anonymous - for those with real privacy needs, they should be taking many other precautions and shouldnt be carrying a tracking device or using a single phone number or service irrespective of it being in their name or someone elses or nobody at all. For privacy LARPERS of course it is not at all anonymous.
What metadata? Signal doesn't store anything about you aside the date you joined and the time of your last ping.
Last I checked, Signal uses AWS, Azure and GCP. All of those services are completely logged and although "Signal" may not be storing metadata, intelligence services on those networks definitely are.
Matrix OTOH would have a harder time getting adopted: businesses would need to update their websites, facebook pages and flyers to add the matrix contact info. Which they wouldn't do until Matrix is more popular. Which is a chicken and egg problem.
The most common client, Element, will by default ask you for your phone number when registering with the default matrix.org homeserver and the default vector.im identity server will associate your phone number with your matrix user.
So by default (changing servers and/or opting out is easy and encouraged BTW), Matrix already works like you would prefer.
This is BTW a main critique in the OP since it makes vector.im a PII and metadata aggregator.
of course it has, but so has the ability to NOT use a phone number. different use cases
Not, it doesn't. You would just need to copy the private key to the other devices.
https://twitter.com/durov/status/872891017418113024?lang=en
https://telegra.ph/Why-Using-WhatsApp-Is-Dangerous-01-30-4
Besides - Moxie is kind of against decentralization, he thinks that by centralizing trust in a certain entity, things can be better. I am not convinced that such an approach leads to a better model for me to have encrypted communications:
https://news.ycombinator.com/item?id=21904469
I like that Signal started using SGX though. It’s not ideal (now I have to trust Intel instead) but at least if you’re going to be running some code on a centralized service instead of byzantine consensus, let me know you aren’t backdooring it:
https://medium.com/@maniacbolts/signal-increases-their-relia...
Crypto that I trust more than Signal
Far more documented and open (even though backend is not)
Supports many clients