Signal: You were the chosen one [video]
media.ccc.de
media.ccc.de
That is no small thing. Bitch all you want but make sure when you do you compare it to the success of literally ever other attempt to bring e2e to the masses and then if I'm gonna be snarky maybe compare it to your own achievements.
It would have been fantastic if signal also achieved other things on top of what they did. Maybe. Knocking what they did? Forget it. Signal is an outstanding achievement and nothing else comes close. I will cheer you so, so hard if you beat it.
I do think Moxie is right though and the talk is wrong on the core issue which is federation doesn’t work as well unless you really boil the ocean to do it (urbit) and even that still has to prove itself. Signal is really good at doing what it does well and I’m grateful for that. Matrix is cool, but my family/friends will never use it (and element still sucked last I checked, especially to deal with encryption).
Signal is easy to use, extremely secure, and I can actually use it with less technical people I care about.
Like you said - these are major wins among an ocean of failure from technologists who have for years complained while failing to ship a solution with the right tradeoffs (normal) people would actually use.
I don’t find his other arguments very convincing either.
I'm not so sure about that. I feel like Matrix has pretty much solved the problems with federation, E2EE, and multi-device usage. I typically have Matrix clients running on three devices, talking to my self-hosted homeserver, with encrypted chats with people on different homeservers, and it's been... at least a year?... since I had any issues with encrypted messages.
It's been really good at disproving Moxie's assertion that you have to have centralization to evolve a protocol, too. The introduction of Spaces (like Discord servers) was really smooth and backward-compatible.
There are features it lacks that I miss (stickers, sending multiple images in one message), but they're not essential.
I do still also use Signal with less technical people, and I think Signal has been very successful at making adoption very easy, but with serious trade-offs for anyone not on the happy path (changing devices is a nightmare, it's too easy to lose chat history, multi-device is a trainwreck).
The best thing Signal has done is made everyone else adopt E2EE. Signal shouldn't be playing catch-up, they should be pushing others to follow suit. Companies like Meta say that they need data to protect users but Signal ,,demonstrates'' that this is not necessary. So continue in this direction. I know many want to just keep Signal as it is (Signal purists) but Moxie is right. The ecosystem is moving. Staying still will just get you killed.
[0] https://community.signalusers.org/t/signal-airdrop/37402
I honestly don't know what these features are. The only thing I hear from normal people is stickers and "but none of my friends are there." This is a genuine question because I can't figure out what others have that Signal doesn't.
The "backup" system Signal has is a joke for everyone outside the paranoid community. Every messaging platform has a single chance of losing users data before they switch away. Signal does it constantly.
The idea of any of my contacts logging every message I ever sent to them, and backing them up in clear text on whatever dumb cloud provider they're using this week, is a pretty scary one.
This arrogance is the worst cancer on "privacy" software. Essence of privacy is _control_ over data, not destruction.
It’s also awkward to try to herd a conversation partner from chat to email at some arbitrary point when you think the conversation is veering in a direction where preservation is important.
I use Signal as my main messaging app now, but even for the contacts on there I have to fall back to Whatsapp to share our live locations in order to find each other. Doesn't happen very often but it is a useful feature that it is missing.
Is it really that hard to tell someone where you are with words?
I think Apple has done a really good job with this — you can share your location for an hour, the rest of the day, or forever. I use the “share for an hour” option all the time.
Yes, people need it. Had to use Telegram for it recently, because Matrix didnt have it at that time, and I don't have WhatsApp.
Just tell them your final destination verbally, and you're done.
Sometimes its about the journey, not the destination.
"From the XYZ Street beach entrance, we're about 100 yards north, with a blue umbrella."
Using realtime GPS tracking for this sort of thing is fetishizing technology to overoptimize a problem that was trivially solved for millenia using verbal offsets from known landmarks, while at the same time introducing and normalizing grave privacy concerns in society.
Good luck at long beaches where there are endless swaths of identical copy-paste tress, tents, deck chairs and umbrellas, without any unique elements to use as bearings. I would hate to have to send people on wild goose chases in the hot sun.
>wearing a red shirt
You've obviously never experienced how difficult it is to be found by your friends if you're short in a crowd of tall people at a concert or any sort of wide festival/gathering. Telling people what color your shirt is doesn't do anything to help if they can't see you until they're within 1m of you. And that's without it being dark at night. It's like finding Waldo IRL but more difficult.
> fetishizing technology to overoptimize a problem that was trivially solved for millenia
Ok Fred Flintstone, you do you, just let me enjoy the modern comforts of current technical achievements please and you feel free to follow the stars and buffalo tracks with your friends.
Thanks for that.
This is already possible (on Android at least), and has been for a long while.
Long press on one, press "select" which allows you to select other photos, select the photos you like, and then press forward.
One issue with that is that if multiple photos are grouped together, you have to select the whole group, but you can definitely forward multiple photos in one go.
Yeah, I don't know about that. I started using Signal about 6 years ago, I think. I remember back in the day there was a stable native Telegram desktop client that just worked (keeps working without single issue for years) and web WA client that just worked if the phone is online (mildly annoying, but very rarely a problem). Over time Signal developed an Electron-based client that annoyed me every time I use it. It requires relinking to the phone, it can't decrypt messages read from mobile, it can't send messages, it can send them, but the other party can't read them. I try it again every few months hoping that they fix these problems. Instead I get stickers and reactions =/
Yeah, I get it, multi-client encryption is hard, but WA seems to solve it using the same protocol. What I experience with Signal desktop client reminds me of Jabber OTP client compatibility issues 10 years ago. I almost stopped using Signal despite shiny E2EE. 90% of my texting is from desktop. I need it to work reliably. I don't care about stickers and reactions.
While I agree the app is a resource hog for what it is, I haven't ever had to relink my phone after the first time unless I reinstalled the app or got a new phone (duh). As for unreadable messages, I use Signal daily and have never had that issue once. I have had that issue multiple times using Whatsapp however.
> Yeah, I don't know about that. […] What I experience with Signal desktop client reminds me of Jabber OTP client compatibility issues 10 years ago.
Like for the sibling commentator, the desktop client has been working for me largely flawlessly. Sure, doing backups on the desktop (and restoring them) would be nice, and no longer needing a phone number or needing to link it to a phone would be even nicer.
Meanwhile, though, WhatsApp doesn't even have a desktop client to begin with and their web UI is still mediocre and unsafe.
And let's not even speak about E2E encryption (or the general state of security) in Telegram.
So yes, I would argue most of Signal's features are more than on par with WhatsApp and Telegram.
If it's browser based just let me run it in a tab.
It's taken a few years, and there may be a few bugs left that I don't know about (out of sight, out of mind), but Matrix uses the same double-ratchet encryption, and has solved multi-client encryption with cross-signing. Some clients may be imperfect, but this is the price we pay for being able to develop other clients - something Signal steadfastly refuses.
> If they didn't care about the content of your message
I'm not saying they don't care, just that e2ee in a centralised platform whose business is data collecting does not accomplish as much as one can think.
> why would they ask signal to help them add ee2e in the first place.
"Marketing" is why.
There is no path for non-tech users to start using Element/Matrix or some Fediverse thing. These are excellent concepts, but they will remain there, as nice ideas. Because they are not a quick three-step process of Download -> Setup -> Chat with Friend
"Why am I pasting a URL given by you in this app, will you be able to track all my private conversations as well? Hell, will you be able to hack into my phone now?"
A healthy dose of skepticism is warranted, but at the end of the day this whole thread is about friend groups talking to each other. This just wouldn't be a realistic line of questioning in this scenario imo.
There is terms and service, legal systems etc for corporations. There is no such thing for individual server admins. They are right to feel weird about their friend running their private chats as opposed to a company.
People implicitly trust friends and especially family to be generally good and not misuse their information. Far more than they would trust a random stranger or corporation, regardless of legal systems, terms of service, privacy policy, etc. They are also generally grateful that you're providing a service they can use and can handle issues coming up moreso than from others.
And, of course they would, you've built up years of personal trust and relationships with them, which goes far deeper than anything professional.
Source: I do this. For multiple services. For multiple people. But also, just basic common sense.
The proof is all around us. People don’t want to use services run by their friends. Otherwise they would.
I trust my brother with my life, but I would prefer to use Instagram DMs rather than a chat service he is running on a VPS. There is so much that can go wrong with a service like that. No offense to him, but I’d rather a company handle it where people are getting paid to do it.
Generally speaking, if someone is running a service out of the goodness of their heart, they are doing it as a hobby. And you have to wonder why it is so fun to them? They enjoy handling peoples’ chats? Seems a lil weird. I love my brother, but just seems a little off.
People do think like this.
And /r/homelab (and the numerous spinoffs) would highly disagree with you; the fact that they exist is what you would call "the proof" which is "all around us".
That's actually harder than you may think in more and more countries. Even with VoIP it's hard to not associate your banking details with your phone number. It won't be long until anonymous phone numbers will disappear again.
Signal is a stunning success. If you or anyone does better I will cheer and yell about your success often.
>We now know there were zero-click iMessage exploits being used by oppressive governments to target politicians, journalists and activists.
Firstly citation needed please. Secondly, great, should they have been using email and pgp? Or google chat? Or are you saying the NSA should have just had all comms on their servers without going to any further and targeted effort.
Any software project can be criticised. And _should_ be. Just when you do it don't overlook its success which for signal was the first one that actually worked after decades of efforts. Now go do better.
Pegasus.
Is it bad to quote yourself twice in the same thread?
"... success of literally ever other attempt to bring e2e to the masses."
Attempt to bring e2e to the masses. How many actually using it is that metric.
Before open whisper & signal: how about number of people I knew with whom I could communicate securely with using pgp. 1. Total number of people in the world who could do it. A few thousand tops? You reckon it got to 10k, 100k. I can't imagine it got anywhere near a million...
Today: Number of people doing it everyday without thinking about it. Over a billion.
Sometimes metrics are so overwhelming that you have to tip your hat to it. This says nothing about any other dimensions of analysis other than "Number of people actually using e2e." It's a hell of a metric we can give credit to Moxie & co. for. That /one/ dimension is just wow. People tried before, for decades. It just didn't work out on that one metric. Something would have to be pretty bad to make that metric not dominate the discussion of overall success. But yeah, this is just the success of getting people using e2e and it's a massive achievement.
Signal being successful because it is implemented by different parties and therefor used by many people seems more a counterargument to the state of Signal because it would suggest that Signal would be better if more people could use it for more things.
pretty bad, actually.
The reported number of users does nit equate with number of securely e2e protected users
And I'm fairly sure that's not what the poster above me actually meant, anyway. When you say "it's not open", do you really think they're saying that in the context of not knowing that the source code we can see is the code that's actually running on the server? If that's what they actually meant, then why would they say that at all, since literally no third-party service is "open" by that definition?
They clearly are under a misconception that Signal is closed source or that the protocol is secret or something. They're probably thinking of Telegram, which IIRC, is not open.
That is what those criticizing it disagrees with, at least in that area. It is not a stunning success at letting you communicate with someone without disclosing a phone number.
> If you or anyone does better I will cheer and yell about your success often.
And that is what people are criticizing about the ecosystem when they say that it is hard to run your own client or infrastructure.
> Firstly citation needed please.
Search "zero-click iMessage exploit" and pick your favorite source.
> Secondly, great, should they have been using email and pgp? Or google chat?
Most already do because Signal doesn't really cater to other use cases. When people say they want federation or different clients it is often because they want to replace things like e-mail.
Which it has NEVER claimed to do.
The goalposts moved so fast my neck broke.
Basically you’re you’re shifting anytime you get pinned down and it shows.
I am happy to argue the points but don't make up some characterization. It wasn't "then", "now" or "shifting". I've made the same points all along.
You bringing them into the argument doesn’t make it valid.
Basically hijacking a discussion with irrelevant points that vaguely support your case is not valid.
OP’s point, the article is incorrect because of the value brought by E2E encryption to the masses, then various debate on how that wasn’t such a big deal, or was done wrong.
Phone numbers and iPhone zero days have nothing to do with the impact of Signal’s e2e.
The general users do not care, just like how no-one cares about the inventor of the smartphone and Apple repackaged it and brought out the iPhone to billions of users.
Therefore, WhatsApp is the chosen one because in reality and contrary to what the herd believe here on HN, research [0] shows that even when Signal was boosted by some famous people, 'the masses' gave up using Signal when migrated and instead moved back to WhatsApp or Telegram.
I think Signal has done a terrible job at selling itself and retaining its users migrated from other messengers and was only riding on the back of boosters that don't even use it, which allowed Signal to get distracted and rush and push in a private cryptocurrency project useful to criminals and scammers to execute a pump and dump scheme for the founders.
The level of delusion in the comments about that so-called 'mass migration' or great 'messenger migration' to Signal seems to be as present as a haunted house.
What a shame. And nope, anecdotes is not evidence.
[0] https://medium.com/@carlagriggio/the-great-messaging-app-mig...
> but only 0.5% uninstalled WhatsApp. Let me put these numbers into perspective: if we translated this result to the entire population of WhatsApp users (approx. 2 billion), we’d be talking about 500 million users trying to flee from WhatsApp, and only 10k uninstalling it
0.5% of 2 billion is 10 million not 10k, which incidentally corresponds quite closely (within order of magnitude) to the number of people who downloaded signal at the time. As a side note if someone argues with numbers and is 3 orders of magnitude of in their calculation are their conclusions still valid? It doesn't give a good look.
WhatsApp brought encryption to the masses. Sure, they did so using Signal's code, but they could've picked any code base for E2EE. Even XMPP has secure encryption.
Signal is "that alternate WhatsApp some people use".
Always this endless either you with us or against us shit . smh.
Approaching valid criticism from that angle, with that attitude only throws a big jug of fuel to the already volatile fire.
We are having these these kinds of arguments on another piece of software which I won't name, and it's leading to the same outcome. No productive discussion, no progress, nothing.
Signal achieved good things, yes. Kudos for them coming that far. But if there is a considerable volume of same feedback, it's at least beneficial to listen to them intently, ponder and then sleep upon them, and draw some insight out of it.
A kind reply and acknowledgement would be very fit and handsome jest, but it's not a must.
You might be thinking that Signal is a flawless piece of software, even better than the sliced bread itself, but not everyone is on the same boat with you, and this is the way it should be. If this thing is an infrastructure for some people, and use it that much, the users have at least the right to make their opinions heard.
Not really. It has the same weakness that other E2EE schemes have when it comes to general usability. In a usability study involving Signal[1], 21 out of 28 computer science students failed to establish and maintain a secure end to end encrypted connection.
The usability issue is a huge ongoing problem but there is a tendency to want to talk about everything but usability. We are having an animated discussion about the paint scheme while the barn is on fire.
[1] https://www.ndss-symposium.org/wp-content/uploads/2018/03/09... | When SIGNAL hits the Fan: On the Usability and Security of State-of-the-Art Secure Mobile Messaging
> Criticizing a security-sensitive tool like Signal is tricky, as it might be misconstrued as a call to abandon it, and move to alternatives that might be in fact worse. But here, at a hacker conference and with little risk of causing confusion and diverting users towards less secure platforms, can we please have an honest conversation about Signal's problems? And how 5 years after that blogpost, moxie's centralization has not solved them?..
Apparently the good intent they assume in a hacker conference does not extend to a hacker forum.
Their main complaints are 1) Lack of good clients, driven by a mostly closed ecosystem 2) Lack of good federation which brings down the whole network occasionally.
These are hardly knocking anything related to the security that Signal provides, and definitely does not count as "Bitching", as these are real problems that are absolutely good things to fix on top of a fantastic product.
That would be because this isn’t a hacker forum in the sense the OP was using. The OP was using hacker in the classic sense, security folks, the culture is different within that space compared to this one. (Not better or worse mind you just different with different values and understandings)
Really? I'd say that the classic meaning of "hacker" is what we have on HN. http://www.jargon.net/jargonfile/h/hacker.html
Yes, some are trying to sell themselves, which may be distasteful to you but people need to eat.
Others are activists, pushing their views.
Others here are just reading and occasionally commenting, like myself.
But there are also a lot of very passionate and smart people here who are pushing boundaries and limits with what they can do in terms of hardware and software.
https://web.archive.org/web/20071025200829/http://listserv.l...
I would disagree.
Both of these are very conscious, deliberate choices on Signal's part though. You can't "fix" them without fundamentally changing what Signal is trying to be. Demanding "fixes" for things without thinking about, or acknowledging the reasons why the current state of the world is how it is is just self-entitled "bitching".
"I believe signal could have been as resoundingly successful in bringing e2e encryption to the masses as it was if it had done X and Y differently and tweaked Z." Is quite different to the critics around here who filled a page with comments without anyone acknowledging that they did pretty good in this one dimension. (Did ok in some others too, imho, but this one dimension is off the damn charts and there can be zero argument about that. They did it when it hadn't been done). So yeah, go right ahead, bitch all you like about my bitching about the bitching going on about signal. Please do. Nobody is being abused or disrespected here except maybe Moxie. I reckon it's happening to Moxie. Often.
From "You can grumble all you want in this article but those complaints pale in comparison to Signals contributions which are above your trivial reproach."
To "No product is above reproach, your complaints are entirely valid and I was saying this all along."
It's also possible I just missed the entire point of GGP entirely, for which I apologize if so.
> those complaints pale in comparison
> Signals contributions which are above your trivial reproach
There's the problem. I never said that or indeed anything like it. Quotes are really out of line there. Eg Never mentioned TFA. Never said complaints were invalid, never described all reproach as trivial in comparison.
> your complaints are entirely valid and I was saying this all along.
Nope not that either. Actually read it again maybe, just what it actually says?
When considering criticism of decisions that led to a billion people using e2e encryption and not mentioning that those decisions directly led to a billion people using e2e encryption then yeah, maybe think about whether that criticisim has been well thought out. At the time of writing there were about 50-100 comments all critical of signal policy and app functioning with nobody mentioning even once that maybe some aspects of that policy, yeah, they actually worked a little bit in a way that was pretty useful.
>It's also possible I just missed the entire point of GGP entirely, for which I apologize if so.
Fair. I'm sure that's general it should be and not directed to me.
Those might be security adjacent, but i'm not sure i would call them core security concerns.
and people who need E2E and are sufficiently knowledgeable about it don't use it either, for a number of reasons
it's a for-profit, centralized, closed-source product for privacy larpers
I think it's good to take a look at Signal, recognize that it's better than what came before, and still come to the conclusion that it could be better. Signal is far from perfect despite its achievements, and today, years down the line from its original success, there is much room for improvement (or, barring that, replacement).
The arrogance of the owner directly transfers to the arrogance and lack of control in the software which is fundamentally limiting its usefulness for everyone.
Life is about compromise. Complaining that someone else's compromise doesn't work for you is not particularly productive.
This idea that "someone built a thing, has strong ideas about what that thing should look like, and some people don't like that because they don't share the same values" being somehow "not ok" is peculiar to me because it's at the very heart of fundamental freedoms around speech / association etc. If you don't share Signal's values, or disagree with how they balance competing interests, go use something else!
This is not what the OP said. It's not just opinions. You are forced to use the only client and the only server. You are forced to not have backups, and so on. You are forced to use an Android or iOS phone (security? really?).
This is a fancy way of saying that the protocol is private and that their instance of the server has a ToS. There's also nothing stopping you running your own server instance (I know of a handful of private Signal server deployments).
> You are forced to not have backups
I literally juse restored my signal backup to a new device in the last 10 mins. ¯\_(ツ)_/¯
> You are forced to use an Android or iOS phone (security? really?).
I'm interested in hearing about what other client platforms they should invest in supporting that would increase the "security" of their users and service.
What's frustrating is that these sorts of rants can generally be summarised as "I want to use someone else's service on my own terms, even if the service owner explicitly doesn't want that".
No-one's forcing you to use Signal.
> This is a fancy way of saying that the protocol is private and that their instance of the server has a ToS.
No, this is a "fancy" way of saying that they are actively fighting against decentralization. It makes me suspicious of their intentions, to be honest.
> I'm interested in hearing about what other client platforms they should invest in supporting that would increase the "security" of their users and service.
How about a normal desktop GNU/Linux client? Is Android more secure than Linux? It depends on what threats you want to defend from, and Signal developers think that Google/Apple are not my threats. They force their own threat model on me. It makes me suspicious, again.
I don't really see them "fighting" anything? They've made a decision that they want to build a centralised service, and as far as I can see they've been pretty open about why they want that and quite happy running a centralised service. Are they going round trying to convince other people to choose against decentralization in their systems?>
If anything, the "fighting" here seems to be from people who really really care about decentralization and really wish Signal would just adopt their value system and do what they want, as though it's some sort of objective good.
> They force their own threat model on me. It makes me suspicious, again.
This is true for literally every company running any service you use. The people who pay for, design, engineer and run a service "forces" their threat modelling, feature prioritisation, colour scheme etc. on you. If you're suspicious about it or don't like it, simply stop using it.
Yes? For a while moxie would show up in every matrix topic to talk about "But matrix is federated and federation is slow moving and therefore bad". The most commonly quoted argument against decentralisation is hosted on signal.org: https://signal.org/blog/the-ecosystem-is-moving/
Also, grapheneOS can be 100% google-free.
Since Signal doesn't federate, your own server instance is about as useful as a glass hammer.
To other people, it's quite useful.
I agree with your other points, but not this one. Mobile OSs are so ahead of the competition in security it is not even funny. Like, as much as I like my linux systems, they are a huge pile of vulnerability not even making the task of a hacker hard.
As I wrote in this comment in the past [1]:
> Additional irritants that nobody in the development team has thought about for years:
> * I decline Signal’s prompt to turn on notifications with the “Not now” button (there is no “No thanks” button). It responds with “We’ll remind you later” and nags me again in a few days.
> * I decline Signal’s prompt to share my contacts with it using the “Not now” button (there is no “No thanks” button). It responds with “We’ll remind you later” and nags me again in a few days.
> Signal may be good at security, but whoever designed the app has no respect for users’ time, and it doesn’t seem like they respect a user’s privacy choices either.
Siloing is bad.
The other, super-underrated feature of federated systems is that antagonistic parties are willing to use them together. For example, the US military, Russian government, major international banks, Google, Facebook, etc ALL use email and happily exchange messages over SMTP. There's no centralized service you could get all these parties to agree to use (not even Signal).
The result of this is that everyone has an email address, and that makes it the universal standard for business-to-business communication. I can loop in any number of parties on a single thread from all over the world and it just works.
My startup Shortwave is trying to build a messaging future that is email. We're trying to evolve and upgrade email to have the look and feel and features of a product like Signal, but with all the universal, federated goodness of the global SMTP network. It's a long project -- federated systems evolve slowly! -- but it's the bright open future I think we need. I go into some detail here: https://www.shortwave.com/blog/future-of-messaging/
> My startup Shortwave
Sounds like disclosure to me.
But as far as holding conversations, it worked alright, though I missed having a typing indicator.
Please don’t. Email is not a chat.
But overall less is more here. There is certainly a place for real time messaging/chatting/rich collaboration services as well, but they aren't "electronic mail". The focus should be on making a standard and then model implementations that work very well.
Please don't. Current email is a mess. One person's email client will set the email background to dark gray and another person's email client will have a dark grey background and the result will be unreadable. One person's email client will put the quoted text at the bottom and another person's client will put the quoted text at the top and the thread will be unreadable. A sender's email client will use quotes in a way which a receiver's client doesn't understand and the receiver's client will show a thread view where each message in the thread also contains a copy of all previous messages in the thread. The sender's email client will use a symbol font which the receiver doesn't have so that symbols look like random letters to the receiver.
Email is terrible. It does need to be radically overhauled. The lack of cryptography is far, far from its only problem.
Plus there's the spam problem, which means you won't be able to send email reliably unless you're a major company. It's federated, but only multinationals are allowed to play.
That might be true. But I feel like a lot of email proponents have this idea that email is actually pretty good, when in reality, email is an unmitigated disaster and sorely needs drastic changes on the technical front.
I just wish that the people who care about federation and asynchronicity weren't also the people who delude themselves into thinking that email is fine the way it is. (Case in point: my comment about the problems with email is downvoted, presumably by the exact kind of people I'm talking about.)
What is the point of any of that for 1-to-1 communication?
On the other hand, XMPP is a lot faster.
How well does this approach work when communicating outside your organization with non-shortwave users? Seems challenging to degrade the experience gracefully.
This already exists. It's called Delta Chat. Please don't make your product incompatible.
Three, actually; the third is that email is an asynchronous, store-and-forward system. That feature makes it unsuitable as the basis for an "instant chat" system. It also makes it challenging to put e2e encryption on email.
Asynchrony is the feature I most value in email. I can send you a message if you're in the bath, if your device is switched off, or if you're AFK for the next 3 months. You can read it on your desktop, mobile device, or in a web cafe. I don't use chat, and I don't like SMS (which anyway only works with a SIM, so on a mobile phone; and your identity is tied to a specific SIM).
The problems with email, as I see it, are:
- text/html. HTML email has always sucked. It's the devil to craft HTML that works in programs like Outlook. And it's full of vulnerabilities.
- Encryption. You can't e2e-encrypt email headers, because they're needed by intermediate nodes for routing. GPG/PGP has a horrible trust model, that deters people from using it (I've never really looked into S/MIME).
7 people tried to talk and were rushed/talked off topic
* you can't download the APk
* yes you can
* telegram lets you download the apk and it's on fdroid* yeah would be nice if signal was on fdroid
--
* there is wire... you should know there is wire
* moxy complained about the update problem... and he was right
* tor does this better
--
* I don't want to use my phone number (rants over why he needs it)
* signal is working on it
--
* E-Mail comparison isn't fair. it's survivor bias, many others failed
* signal has good cryptography and has a good usability
--
* there are other third party clients that just work and it's ok
* it's not that frowned upon, but they are hard to maintain because signal is a moving target
--
* clearos has signal fork called ClearSIGNAL I wonder if this will be shut down winkwink
--
* signal has too much of a silicon valley vipe for me
---
This wasn't the Q and A we were missing.
This talk wasn't what was promised and most talking points he had were easy enough to counter. But yeah signal clients that aren't signal would be nice. Kind of
Edit sorry for the horrible formatting
Matrix is so so much better in that regard. I can communicate without any 3rd party needing to be trusted. The areas where I need a "3rd party" (the server and client code) are effectively diluted by the fact that thousands of eyes pore over it. Rather then trust in a single person (Marlinspike), instead I just have to trust the person I'm actually talking to.
And the Matrix team have done nothing to make me question their motives.
That's the hard privacy-killing argument of corporations. And only cultural change can help it.
So much for privacy.
anyway, I hear they're working on it.
To remove that functionality would be equivalent to removing the ability to look up if a Signal message can be sent to a particular number. At least as long as phone numbers are used as the sole identifier for Signal accounts—another decision that has been debated into the ground, of course, but was done for understandable reasons.
that is mostly a UX problem, not a technical problem: people are surprised that signal tells others that they created an account, and this isn't a pleasant surprise IME. doubly so (more, actually) if you've got a stalker who has your phone number.
Privacy != Anonymity
If you live in a village where everybody knows each other what happens inside your house can be private even if everybody knows you live there.The other way around you could be at a nightclub in a big city where nobody knows you and do the most i timate stuff publicly (but protected by anonymity).
Of course if you have privacy and anonymity what you do will have even stronger protections, which could be especially useful in the internet, where the biggest part of our conversations is not ephemeral but persists. But to defend Signal here, this is actually something you could choose with their disappearing messages.
I have found that Signal strikes a good enough balance with E2EE that I can easily recommend Signal to anyone -- I do not find the same to be true of Matrix. While I believe Matrix to be a better choice for freedom and privacy I do not see it as a good option for non-technical users. Even for technical users I feel it can be very confusing to use unless you are already familiar with the Matrix ecosystem, jargon, etc. With Matrix, the overhead to manage sessions and your security is much higher than Signal. Sure, it's unfortunate that you have to place some trust in Signal, but it's far less confusing than having to manage your own sessions.
In my subjective and probably biased experience, Signal feels as easy as iMessage but still provides greater privacy than most other platforms (not Matrix, obviously).
I really like Matrix for myself and for dev communities. But I have a hard time seeing a future where Matrix becomes a mainstream personal messenger until the experience feels a bit more hands-off for non-tech users.
Started using Beeper which is built on top of the Matrix protocol. Even with this nice abstraction app, there were several steps to set up and then connect to the various bridges they have. They're still very much a beta product.
Isn't Signal just as tricky to manage if you want to have multiple sessions?
Without doing that, you can never be sure if there is a MITM attack. Not with Signal, not with Matrix, not with WhatsApp.
EDIT: MITM may not be the best description, let's say: "you cannot be sure, that you talk to the correct person."
I'm not versed well enough in network theory to decide if that's a consequence of federation or if it's just an oversight. I'm also not enjoying the wasted bandwidth of base64 encoding binary data in JSON, the encryption is inherently wasteful to make it easier to use for web developers.
I do prefer the ideas and concepts of the Matrix ecosystem, but Signal does privacy better in pretty much every way except for them requiring a phone number.
Do you have more details on this? Matrix being distributed of course will not "tumble" everything through a single service, sure, is that what you mean or other issues?
What I find particularly strange is that my messages also contain the event identifier a message is a reply to outside the E2EE envelope, as well as the message type for example. If you can get your hands on a database, you can find reply messages and see the messages part of threads without having to decrypt anything. I'm not entirely sure why the server would need this information, perhaps for making notifications work efficiently?
You can see this for yourself if you enable dev mode in Element, hold/right-click a message and hit "show source". You can also compare that to the result of "show deceypted source".
All of this metadata is being transmitted over HTTPS, of course, unless you're using some local devices setup. It's not literally plaintext but the envelope stored on the server contains much more message details than Signal's.
You may not like MobileCoin (or perhaps not like cryptocurrencies in general) but to call it "shady" is inaccurate.
I like Signal because it is a fairly pure messaging app. Admittedly, introduction of Mobile Coin has marred that though. I want something analogous to SMS but is E2E encrypted. I'm personally not intentionally trying to evade state governments, I'm concerned about Comcast.
My favorite Signal feature is automatic deleting messages. I can have ephemeral conversations with people about politics, a health issue, etc and generally trust that it won't be on their phone later. When that feature rolled out, it was controversial. The security types complained that it provided a fake assurance of privacy since there was nothing stopping screenshotting or simply taking a picture of your phone. It reminds me of the federation discussion in that I understand the concern from security pureists, but Signal still seems like the better option than an FB managed app or SMS while still providing something my parents can easily use.
There’s a pretty interesting irony, or a joke, buried somewhere in the fact that those living in authoritarian regimes use Signal to evade the regime, while those of us living in the “free world” use it to not primarily evade state owned institutions but the private for-profit institutions that start doing very similar things to the regime.
Here’s an attempt at a joke:
Q: what’s the difference between your private communications being intercepted in Iran and the US?
A: in the US it increases the value of your stock portfolio
https://www.nytimes.com/2001/07/26/world/union-says-coca-col...
https://colombiareports.com/terror-for-profit-colombia-charg...
XMPP has a variety of clients for about all platforms, is federated, can (optionally) be e2ee. Its most used client on Android is user-friendly and has built-in (optional, again) tor support. On a cheap vps you can easily run a server with many users. I think it deserves a little more love than it receives.
Random tangent: I feel like XMPP is everywhere but nobody really talks about it. It just quietly works and stays out of the way.
Care to elaborate?
It’s not as bad on mobile (I can only talk about Signal here, not Matrix), as clients are far more constrained, but once again Signal has a slow Android client (every action only happens after a noticeable delay) while the biggest XMPP client Conversations is instant.
[0]: I tried a beta version that felt like an alpha, but OTOH the last time I tried it, it seemed reasonably stable.
Let's make using and building on internet standards popular again.
It is probably due to XMPP's lack of popularity, but FWIW I have been using my XMPP for about 4 years and have not received a single unsolicited message yet.
The wider audience wants to be able to hand out their contact details at a bar and know they'll be able to block the person if they turn out to be a creep.
Or they want to be able to block their annoying ex, that crazy QAnon fan cousin etc etc.
This is a 100% must have feature, and yet it's treated like an optional feature.
There's so many features like this - it's like people using XMPP have never looked at how most people use messaging.
However I doubt this is the reason why the most popular messengers do not comply with the XMPP standard today.
Whatsapp also originally (or maybe still?) used Jabber. The whatsapp protocol was Jabber with binary tokenised XML, iirc.
I think XMPP is perhaps the best example of what Moxie was talking about in The Ecosystem is Moving: it's a super fragmented experience. Most users do not (and should not need to) know the technical details of how their server, or their friend's servers, are configured.
May I suggest you give it another try? It has been steadily working for me for a few years now. (Conversations/gajim/dino/siskin-im/beagle for the clients, and prosody server side)
> because their server hasn't enabled the necessary XEPs
Changing to a server that does is not a big deal, since most (all?) XMPP clients allow multiaccounting.
> it's a super fragmented experience
What you call fragmentation I would call diversity, and I think it is a good thing.
> Most users do not (and should not need to) know the technical details
I agree that a certain level of abstraction is necessary to use complicated stuff. However, I think not having the slightest idea of things work is a problem, and leads to alienation.
For me, the biggest blocker on XMPP is that OMEMO and multiple devices don't seem to get along. Matrix solves this with cross-signing, but I don't believe the OMEMO XEP addresses the problem in any way.
I think Moxie's article is directly a response to XMPP. But on the other hand, Matrix has managed to have both federation and rapid evolution, so he's just empirically wrong.
So imagine a world of half-baked, likely insecure clients popping up, creating confusion and chaos around what is a great tool / protocol.
It’s… hard.
So much of the NES's design is an attempt to distance themselves from the previous version. Front-loading makes it look like a VCR rather than an old game system, the box and cartridge art is actual art from the games (enlarged, but blocky) rather than images that are not part of the game, etc.
Of course, it's hard to measure apples to apples and see if open would be better, because nobody released an open console after that generation (Sega didn't put a lockout in the Genesis originally, but they added one in later revisions)
The only ones I can recall like that is SMB and Duck Hunt, but all others I recall definitely not. SMB2, SMB3, Megaman, Contra/Probotector, Zelda, Olympus, Parodius... all had specific cover art, often of the "over the top" kind.
It's a different business model. But it seems workable (see Bluetooth, USB, JVM), and it'd be more resilient than the current single-benevolent-vendor model.
I remember using TextSecure while rockin' a Whisper System shirt, cause it was the best way to show support, but now it's opaque updates to include cryptocurrency, chat stickers, and subscriptions.
Really though? From my perspective, it seems as though an option can either be a great academic solution or it can be widely adopted. I've used Signal service discovery to decloak a whole mess of colleagues. I'm talking about people who have firstname@aol.com email addresses. Good luck finding another messenger with penetration that deep and a material dedication to user privacy or security.
Alternatives exist, like Telegram I guess, but I perceive the list of viable alternatives to be very short. That's not to say we should accept Signal because it's inevitable, just that network size should be a strong consideration when considering how to advocate for changes or decide between potential alternatives.
Example: Signal requires a phone number as an identifier. Do we spend resources lobbying Signal to accelerate deprecation of phone numbers or advocating that people use other software? In my view, the size of the user base makes lobbying Signal worth the effort.
edit : in case people wonder "share your contact" is actually the only way an app can tell you if a friend from your contact book can be contacted through the app. It's a pretty important thing especially for the onboarding of new people.
You just put in their email adress, username or phone number and you connect. What’s the problem?
Then either you send him a SMS or email, saying "hey, when you're on signal, let me know". or you repeat the process every day until finally the person is on signal.
That's a crap experience for an onboarding to the platform.
I don't need help. I already want to use it the way I want to use it. Don't need to keep reminding me after every update or more than once or whatever.
How about a "No, and don't remind me again" option?
But yeah, I get what you are saying about most users.
Having to manually exchange usernames is a tradeoff I have mo problem making against having to provide my social graph to a corporate entity or having people able to do a basically public identifier lookup to my private life.
I'm surprised recruiters haven't started spamming signal yet - they certainly have my phone number in DBs against my will, and 1 has tried it on whatsapp.
I don't need notifications for Signal just like I don't need notifications for email just like I don't need notifications for anything besides reminders or alarms.
I don't want my life to be "oh shit I gotta check out this latest notification".
Just because "they" don't see it that way doesn't mean "they" shouldn't respect my denial. I have a lovely experience, in fact! :)
YMMV, and I get that. Not knocking anyone who lives that way.
It's okay to praise Whatsapp for something they do right even if they don't do everything right. I suppose.
I strongly believe in federation and open client ecosystems. Matrix is ideal for me but people don't seem to like it. I'm kinda hoping that signal will change now that Moxie is gone.
For me, comparing Wire, Signal, Threema as the most mature and stable e2ee messengers that have any kind of network effect (so people will grow the network beyond just talking to this weirdo called Aachen), Signal has by far the largest network effect and by a very small margin the best user experience. My family is on Signal now and I was regretting not going for Wire (which has more features and fewer connectivity problems) until I needed to use Wire on Android again a few weeks ago and the Android user experience turns out to have degraded severely.
The only realistic alternative I'd see to Signal, Wire or Threema (all centralized, though Wire has some enterprise on-prem thing I'm not familiar with) is self hosting something that just uses TLS to the server, but then you're always going to be on call and they won't use it with anyone else, also because you can always read all their messages. A friend has a matrix server (UX on Element is awful and buggy as heck) and every few weeks there's some problem and we temporarily fall back to Wire, and when that doesn't work, back to Signal, and when that doesn't work, calling.
I don't have the energy to push them to move over especially because they also have their circles that use WhatsApp. So I decided to just set up Matrix Bridges and get all that shit (WhatsApp, Telegram, Signal, Discord) off my phone, I use them all through Element now.
But I'm not going to do free promotion for what is yet another walled garden.
PS: Element works pretty well for me, and it gives me the added benefit of having all my chats stored in one place. Also gives me the ability to read chats that have been deleted by the user, make copies of what people put in their WhatsApp 'status updates' etc.
Don't trust Moxie; don't trust the server side of Signal.
Besides, it's their service, they get to say who and how they connect.
Which leads to one of the selling points of Signal: that the client is designed to expose as little metadata as possible to the server. Sure, the Signal servers could be slurping up IP addresses and timings despite advertising that they don’t. But I can’t think of a single alternative service that can guarantee otherwise, and that problem is compounded by clients that leak much more metadata than Signal.
I'm pretty sure I can check what code my XMPP server in my room runs. Not a freedom you have when using something like WhatsApp or Signal.
This comes across as dismissive of the criticisms outlined by GP in favor of more general critiques about owning your own data. Yes, "The cloud is just someone else's computer", but GP gave specific criticisms about Signal.
This would be no different from someone replying to a criticism about Telegram ("They rolled their own crypto; Don't trust the server side of Telegram!") with "Don't trust the server side of any service.". Yes, it's true, but it doesn't address the issue raised.
The difference compared to your analogy is that Telegram’s self‐rolled crypto is a problem many messengers don’t have, and it can’t be mitigated by the client.
Whereas the possibility of malicious things being done on Signal’s server end is a problem shared by every messenger, and Signal works hard to mitigate this by pushing smarts like contact handling entirely to the client side.
I also don’t see why you brought up “owning your own data.” I already discussed that the same “don’t trust external servers” axiom applies to self‐hosted federated systems as well.
Honestly, Signal was too unreliable and hard to use for me. I've lost too many messages, had issues with multi device use (with messages not syncing correctly or not being delivered everywhere). Security is cool but I need more reliability. Also my threat model is not that high.
They just gotta work on reliability and some more joy in the UX for regular folk. Might not be easy but I've seen too little progress in that direction over the years and I don't feel it's high on their priority list. At least that's the optics from a distance.
Nowhere near "too often", though.
Telegram >is< very – very, very – shady but it's hard to argue with the extreme polish and attention to detail with which all of it's apps are made.
Signal does not even come close in terms of user experience (neither does Matrix) and Signal also does not seem to strive to catch up. Their position seems to be that security as a feature has to be enough.
I'd love to have an alternative to Telegram, but Signal ain't it.
https://signal.org/blog/the-ecosystem-is-moving/
I've thought he's wrong for a while. The problem is not that you can't innovate within the context of a (well designed) federated system. If that were true the Internet would still be using telnet, rlogin, finger, Gopher, and vanilla ftp.
The problem with decentralized and federated systems, as I've repeated ad nauseum, is lack of an economic model. It's the same as the problem with any kind of consumer-oriented open source. IMHO every other explanation is mental contortions to avoid looking at the economic factor.
The innovation isn't happening because producing high quality software with support for multiple platforms, diverse network environments, etc. is fabulously expensive yet we pretend it's something hobbyists (who don't have trust funds) can do in their spare time.
Centralized systems can have their choice of viable economic models: commercial software rental (SaaS), non-profit fund raising, free core with paid upgrades, advertising, and of course less savory ones like surveillance and pay-to-play addictionware.
You can try to raise money for clients/nodes to run in decentralized and federated systems, but since there's always more than one and very few people pay for anything unless compelled there's always going to be too little funding to make any of them great.
For a little while I was optimistic that cryptocurrency and tokenization might provide a mechanism, but then scammers and gamblers destroyed that ecosystem.
Really? Supporting SailfishOS won't move the needle on Signal adoption. Just say the truth: you want the ability to hack around with the protocol and clients, for fun.
What you're looking for might be WeChat (this is definitely the first and hopefully will be the last time I recommend that)
On a less sarcastic note, Threema makes a point of running in Switzerland. Not that they're friendly with military powers other than NATO, but (per your desire) it's slightly better than running on US/UK infrastructure directly.
https://spec.matrix.org/v1.3/client-server-api/#voice-over-i...
Excited to know it’s on the way though.
Everyone else is out to get them but they are using this brand new 1337 h4xx0r technology called E2EE®™© which keeps the Bad Guys™ away.
Meanwhile, I'd just like to have a messaging service that I can use on multiple devices and which isn't tied to my phone (number), and which doesn't have a trash client.
Then start a PM chat and expect I have any idea whom I'm talking to. Sure enough, once they send me an actual name I know them, but...
It’s as if the people involved with Matrix don’t really know what is available for XMPP, or have studied its history to see what is in store for their own efforts.
I have a friend that was seriously trying to create a service backed by Matrix. He saw it as a way to bring e2ee to more people. Yet recently, when I revisited XMPP and discussed it with him, the more I dig into XMPP, the more I’m scratching my head — why didn’t we just start with XMPP?
Instead, Matrix is an entirely different architecture with different tradeoffs which you may or may not agree with.
The main differentiators are:
* It's a protocol for replicating conversation history; not for passing messages.
* You get eventually consistent conversation history, as well as decentralised key-value store for metadata about the room.
* Rooms are entirely decentralised over the participating servers; there are no single points of failure/control in a room.
* It automatically heals after network partitions
* It's a single monolithic spec
* E2EE is on by default.
If anything, Matrix is more like NNTP than XMPP.
Now, you're welcome to dislike Matrix and build on XMPP (or SMTP or NNTP or SIP or MSRP or IRC or whatever other messaging protocol floats your boat) instead, but it's completely and utterly wrong to claim that Matrix is just a reinvention of XMPP by people who don't understand XMPP, or a marketing gimmick.
I didn't think about the replicated conversation history and did not know about the decentralized rooms (though looking back, I can see what you mean by that if XMPP rooms are tied to a JID). Those kind of properties seem to work better for some ideas of mine's, though there are others that XMPP still seem to be better for other ideas.
Standardization is much more important than which encoding is popular right now.
But still, XML is easily compressed, parsers are much faster than required for IM and XMPP servers and clients are much more memory and CPU efficient, XML or not.
When I looked into what it would take do commercial home servers, I found immature implementations that fall over while ejabberd has been battle tested on 2 million concurrent users on a single instance.
Best I can tell is that Matrix has better marketing. While Google is scaling back in XMPP for gtalk because of spam and lack of participation from other companies, Matrix is seizing mindshare as being newer and “better” and shinier. (And if they get big enough, it will also suffer from spam …)
I noticed that XML allows for pointing to custom schemas (vis semantic web) and feature discovery. It is what allows developers to iterate on extensions without breaking compatibility
As far as efficieny, XMPP powers some very large deployments: Apple Push Notifications, Google GTalk, even WhatsApp is a modified XMPP.
If only we had figured out how to get them to switch from TikTok and WhatsApp to Signal I'm sure we'd be Gucci.
/s
Almost no one uses Signal outside of your social bubble.
> Almost no one uses Signal outside of your social bubble.
There is evidence support that claim. From [0]:
"25.97% of participants wanted to switch to other apps (at least partially) due to the update, but only a quarter of those succeeded."
"Only 0.5% of participants uninstalled WhatsApp. The data shows how installing a new app is easy, but leaving an app is not, mainly due to strong network effects, differences in functionality of different apps, and feeling a loss of control over the distribution of contacts across apps."
So that wasn't the so called 'mass migration' that was religiously believed by the Signal fans here. In fact, they are still using WhatsApp or Telegram.
[0] https://medium.com/@carlagriggio/the-great-messaging-app-mig...
Some people refuse to use Whatsapp because of privacy and general evil monopolist issues and Telegram also has also been getting a bad reputation for hosting hate groups and such. So if you want to get everyone on board, Signal is the neutral territory to go for.
Signal is absolutely mainstream, at least here in Germany. My 60-something landlord uses Signal to communicate with me.
This reads like a Linux user who gets frustrated when people use Ubuntu. You like Matrix? Cool, use it, but I for one don't give a damn about your self destructive purity spiral.
Currently they're pretty far off something robust and usable by relatively tech savvy folks let alone the masses, but the direction is sound and I'm sure they'd be happy for help.
I really like signal. I send a message and the other person receives it. They send me one and I get it. Rarely is it down for me and I use this app as my primary means of communication with a number of people. Is it perfect? No, but it is mostly there.
My personal wants:
Don't use phone numbers - though I totally get why they chose to and I'm okay with that. But move on. At the very least let me use one account on multiple phones - there are far too many of us that have two or more phones.
Some sort of mesh operation. If I'm on the same network as someone, my messages should go straight to them.
But, you know, as long as Signal doesn't degrade I can live with the features it currently has and be perfectly fine and I'll continue to donate.
I'm currently running Signal on OSX and it has been open for 7 days. It has 5 processes, that combined are using 440MB. This is a lot, but an order of magnitude smaller than rysiek claims.
Thought I'd look at other electron apps I have running. Slack is using ~700MB and VSCode is using ~1.4GB.
As far as I can tell, if you want to do fully open and parity, you got either IRC, the joke being still lack of parity, no client can agree on using the same E2E encryption method, etc. Or XMPP, once again, 5million extensions to the spec (the XSF recommends reading through 23 seperate RFCs to get an idea of how to implement a client).
- - -
So, if you have issues with the current options, and concrete ideas of how to solve them, please free us all from the hell that is current open communications. This isn't a "just fork it", its an earnest plea.
Fact check:
The XMPP core protocol is split into three RFCs, one describing the fundamental building blocks of the protocol (RFC 6120, "XMPP core") and the second describing how to compose these for instant messaging (RFC 6121, "XMPP IM"). Finally, there is an additional short RFC which describes the address syntax and rules (RFC 6122).
These documents are stable, and need to be updated rarely. Other things such as audio/video calls, file transfers, push notifications and such, are defined by the XMPP Standards Foundation (XSF), as I imagine you know, in documents known as "XEPs". These have enabled the evolution of the protocol over the years, and are why XMPP didn't get stuck frozen in time in the early 2000s.
People like to point at the "5 million" XEPs (actually, 468). However the truth is that these are not required reading. They are not all applicable to IM clients (e.g. XMPP is used in IoT and other places), and many are simply proposals/experiments that didn't take off (XEPs have a lifecycle, including states such as "proposed" and "stable"). The XSF is a place of sharing and collaboration, and these proposals are a natural side-effect of that process.
The actual required reading is published annually in the "compliance suites" which describes what implementations are expected to be supporting in any given year. This promotes interoperability, encourages regular reviews of the ecosystem, and helps developers to discuss and plan their roadmaps. The 2022 document is here: https://xmpp.org/extensions/xep-0459.html
An alternative resource is the protocol overview on modernxmpp.org: https://docs.modernxmpp.org/client/protocol/
Why is all this relevant? Because, although I don't claim XMPP to be perfect (what software/protocol is?), I think this has been a pretty successful model that has stood the test of time and continues to deliver sensible community-driven evolution. The Matrix model is extremely similar (they have "MSCs" instead of "XEPs", and they regularly release versioned documents, though not strictly on an annual basis), IRC folk are trying something with IRCv3. Open protocols and ecosystems are hard work, but they are worth it.
This isn’t strictly accurate. Matrix’s MSCs are effectively proposals to update Matrix’s monolithic spec, and once they are merged into the spec (or closed) they are discarded. So someone reading the spec should never have to mess with MSCs (unless they are implementing something experimental); this is a very fundamental difference to IETF RFCs or XMPP XEPs.
Every now and then, when a new compliance suite is published, I'd need to update the one concatenated document aka. monolithic spec. A new compliance suite in XMPP "activating" a XEP is like "merging" an MSC. For as long as a XEP is not part of the compliance suite, it's not part of the monolithic spec (it's still just an MSC) and you don't have to mess with it.
The only real difference is that the current version of XMPP spec is a document with links to other documents whereas the current version of Matrix spec is a document with links inside the document itself.
also 6122 is replaced with 7622, updated rarely, but updated often enough it seems.
I never mentioned "core" for a reason, I used the words "to get an idea of how to implement a client" for a reason. perhaps "recommend" is wrong, but they still list 23 RFCs as relevant.
And I'm talking clients mainly as in pre-existing ones, where every landed XEP might need to be implemented if its codified for a given year, even if its removed the very next year.
And by fact of XMPP being still updated, means parity chasing is still happening.
I'm eager for IRCv3 to end as opposed to becoming a living specification, because no one of any popular client seems even slightly interested in chasing parity anymore, the constant slow trickle of things to change must be so insanely wearing.
I don't disagree with "its the best we've got" but when other areas of software development have like, 20 best-we've-gots, but live text communication has 2 best-we've-gots, I would love to see that change, despite not having the skills to do so (but I plan to try regardless!)
Patterns why none of these chat solutions really stick long:
- Lack of standardization and ecosystem. There are multiple standards of course. But unlike email, none of the standard based products ever managed to become entrenched enough such that the rest of the market could not afford to ignore the standard. Jabber for example never really ended up mattering because at no point did it get over ever a percent of user adoption. Email had the advantage that you could email the whole world or only people inside a single company with corporate mailing systems. By the time MS figured out that they wanted in, they tried really hard to change that but never really were able to make people use their protocols rather than SMTP for delivering emails. For better or worse, that's how mail gets delivered.
- Walled gardens where companies jealously aim to keep all competitors outside. Microsoft, Facebook, Google, Yahoo, AOL, etc. each had a go at this space with long forgotten products. And some of the products that disrupted those are also long gone.
- Reinvention of the same wheels over and over again. It's disgusting how close e.g. ICQ was in functionality to things like Signal and Whatsapp. That was in the late nineties! This space is running around in circles. Arguably it had some useful features that some contemporary products still lack.
- Federation is consistently rejected as a feature by new players and a contributing factor for their inevitable demise; even if initially successful. What matters more to people is who they can chat with than what the feature set is when they are chatting. Whatsapp cleverly capitalized on that end ended up disrupting lot of entrenched things simply by offering wider access to essentially everyone with a phone, which at this point is most of the planet. Of course, whatsapp's popularity has suffered a lot in recent years courtesy of Facebook doing what every other big company has done in this space historic: get overly possessive and throw out the baby with the bathwater. Signal is backed by the Whatsapp founder. And ironically repeats most of its mistakes.
- Users inevitably try out a new app and as they move, some apps go in and out of favor. And since they don't federate, users go where the other users are.
Wake me up when Telegram, Whatsapp, Signal, whatever the hell Google is calling their chat app this month, iMessage, etc. can talk to each other. I have close to a dozen chat and messaging apps on my phone and they all get used. It's beyond ridiculous. All proprietary walled gardens with enough people in them that I somehow need to be there as well.
That's why email is still a thing. Because when you have to reach somebody, you send them an email. Instead of playing roulette with your selection of chat apps to see which one of those might get a response. Pun intended of course, chat roulette was a thing at some point.
The only standards I know of are XMPP/Jabber and IRC. XMPP has seen widespread adoption when Google and Facebook started offering it. Then they stopped doing so probably because interoperability is hard AND is counterproductive to their business incentives since users could very easily switch to a different provider instead of being locked into your walled garden.
Hopefully we will see interoperability and adoption of internet standards again if companies are forced to (DMA) or users start making standards compliance a hard requirement.
I choose to delete every walled garden messaging app and started using XMPP exclusively. Since I'm not reachable on anything else about 20 of my friends and family members now have reachable XMPP addresses and they make up >90% of my messages.
Worried about traffic analysis? Well, in that case don't trust Signal and send encrypted messages regularly (including fake messages) to some Usenet group, using mixmaster or Tor.
In the end, though, I only ever received a single PGP‐encrypted mail from a single person.
These days, I have over a dozen reliable Signal contacts, nearly all with safety numbers verified in person, and have sent to or received from them hundreds (perhaps thousands) of encrypted texts and voice messages, and dozens of encrypted audio calls. The majority of my immediate social circle doesn’t use Signal (and some have tried and rejected it), but a sizeable chunk does use it, including non‐family.
When it comes to volume and quality of E2EE communication in my daily life, I cannot call PGP anything but a failure, and I cannot call Signal anything but a success.