My understanding is that Signal (the app) is private, not anonymous, centralized, and closed.
The underlying protocol is open and could be used for an open ecosystem, but I didn't think Signal aspired to do that.
My understanding is that Signal (the app) is private, not anonymous, centralized, and closed.
The underlying protocol is open and could be used for an open ecosystem, but I didn't think Signal aspired to do that.
The important distinction is that it's not decentralized like XMPP or email, which is a conscious decision: it would become very difficult to change it to add new features and they'd be left behind by closed-source competitors (see: XMPP).
XMPP is underrated. A lot of people are imagining Pidgen in 2011, but the protocol has been extended, the actively developed clients are good, and it avoids the heavier parts of Matrix (both client and server side.) I wouldn't be surprised if Slack's replacement when Salesforce inevitably fucks it up will be XMPP based rather than Matrix.
Even if Google Talk kept XMPP, they weren't going to save it, cause nobody used Google Talk. Facebook was by far the biggest XMPP-supported platform (though it wasn't federated), and they stopped probably cause they didn't see enough clients. Even Slack supported XMPP for a while, did you use that?
You are right about that. There used to be an open source build called LibreSignal
Moxie Marlinspike made clear [1]: You may inspect the code. You are even allowed to compile it. You are not allowed to connect your self compiled client to our message servers. We are not interested in a federated protocol. Make sure your fork creates its own bubble that does not overlap with Open Wisper Systems. Stop using the name Signal.
[1] https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
https://github.com/signalapp/Signal-Android https://github.com/signalapp/Signal-Server
There are forks like Session which doesn't require a phone number to sign up
The status of open source, privacy respecting messaging apps looks really healthy to me, compared to where we've been over the past 30+ years (thinking starting with ICQ.) Signal was a big leap toward getting average people using much more secure messaging, although it is pretty clear even most 'tech' people don't grasp what is going on or why it is important to be able to use e2ee separate from a combined client+server provider.
In fact, in this thread they are discussing how you can, with Molly, use both the official and staging servers with the same number: https://community.signalusers.org/t/signal-fork-with-passphr...
A mod recommends Molly here: https://community.signalusers.org/t/how-to-use-signal-on-3-d...
A list of forks: https://community.signalusers.org/t/list-of-unofficial-forks...
And here's people arguing: https://community.signalusers.org/t/on-forking-signal/31651/...
As far as I can tell, Signal's policy is more "Do what you want, but server costs are high so we don't want to pay for your product. But if you do, here's all the code to give you a start." That's a very different policy from blacklisting.
And as I keep asking others, what's stopping everyone from making a federated Signal? If you can use the same account on both the production/official server and the staging server, why can't you on the production server __and__ a community federated server?
And if they ban you from the production server, so what? Now you're on par with literally every other federated service. Like what is Signal going to do? Stop open sourcing code? That'd be like trying to kill a mosquito by stabbing yourself in the heart. If they're willing to do that, I'd rather it be sooner than later anyways.
So I want a source because I just don't get what you all are complaining about. Is it just that someone else didn't make the thing you want? Sure, I get frustrated, but the comments more come off as Signal being nefarious and I just don't see Signal acting in any way malicious. In fact, hosting links to forks and being a common place for those forks to discuss seems like they are actively supporting them.
Moxie wrote several articles about this and expanded on this idea in his conference talks. You are very welcome to take the code and write your own messing system, but do not connect to Signal's servers because that costs them money and they will need to take action, sooner or later.
They were very clear that LibreSignal had no future. They have also been very clear that they discourage any non-official distribution of builds. They have repeatedly told the F-Droid project that they will not publish using their reproducible build system, and any user doing the same will be kindly asked to take down their copy. The F-Droid project has complied.
This seems to be a strange thing to discuss. If the above links are representative it may be a popular subject among a subset of users, which seems misguided. Signal does not wish to be xmpp or matrix and neither should they. It must be their right to decide. There are so many chat software projects. If you don't agree with the goals of one of them, you energy is better spent elsewhere.
Signal has consistently focused on helping /most/ users do what they want with the app without sacrificing security. This change - away from requiring phone numbers - helps plug one of the biggest criticisms, both on the security and product side. Nothing about their mission requires federation, so I respect that they haven't sacrificed their mission in order to do it.
And talking about that: does federation work properly yet? I used a third party provider and it made my life miserable.
I am all for federation, but in my experience the "federated" part of matrix was a lot worse than the jabber one they want to replace.
But yes, it's also very hard. The bitcoin protocol didn't start out that way. It took a lot of knocks and bruises to get to the point they could upgrade all the servers in the federation.
Interestingly, the method bitcoin came up with allows protocol changes to fail, meaning the bulk of the federation never takes them up. Everyone gets a vote, and it only succeeds if the bulk of the federation upgrades. Perhaps from Moxie's point of view that's unacceptable, as it means he is no longer the dictator of the protocol.
Nonetheless, it is possible to design a protocol so it can be upgraded relatively quickly. Even if you don't do add "quick transition" features to a protocol transitions can still haven. IPv6 will replace IPv4. But as Moxie says, it's painfully slow.
It's private, centralised and the network is closed (e.g.: non-federated), but the source code is public and open source. I think that for the server implementation they do code dumps every once in a while, rather than continuously keep it public.