537 karma · joined May 29, 2016
There was a talk at FOSDEM about that.
Ltt.rs has support for both UnifiedPush and FCM and is fully open source. The code difference between UP and FCM is very very minimal since - as I said - both are just WebPush endpoints.
* The auth tag truncation was 'silently' introduced in the spec. It wasn’t. The author retracted that but only barely
* ominously pointing out that Conversations has a SASL implementation (In fact Conversations can use that to detect some MITM attacks; which is pretty cool)
* ominously pointing out that Conversations has a certificate parser (yes and so does almost everything that uses TLS)
Signal, Matrix, Telegram, XMPP; Use whatever you want. But there is a lot of FUD if not outright lies in that blog post. The author looked at Conversations for all but five minutes, desperately trying to dig up some dirt.
> https://notes.valdikss.org.ru/jabber.ru-mitm/
With an up to date Conversations on a modern server we have a pretty good chance to detect or prevent that style of attack due to a mechanism called SASL Channel Binding.
That's funny because it's true. To add to your list: JMAP (https://jmap.io/) has namespaces too.
Even if I break my promise you could just use a fork of my app since XMPP servers don’t prevent third party clients from connecting.
¹: I don’t have to either because I have a working business model that’s not a ponzi scheme
This would allow you to use the api with any JMAP client like Ltt.rs for example.
Nobody says you need to implement all of JMAP (from a client perspective). Just implement Email/query Email/get
> Support for encrypted two-party calls that are compatible with Conversations should be ready by the end of this year or early next year.
Exactly a year ago I made the same announcement with the same timeline for Conversations. In the end it took me until ~April of this year and I giant kick in the butt from a global pandemic to finish it.
Let's hope that they beat my timeline.
Models like these existed. Flattr and Liberapay. The latter had to switch away from the pooling model because turns out when you do the pooling you essentially become a bank and that’s difficult to do legally.
Those models only work if users actually visit your website or your Github. I’m developing an app targeted at end users and I bet 90% of them have never been on Github or even know what that is.
One could potentially write JMAP as a proxy to an existing IMAP server (just like your 'imap-api') therefore the current lack of JMAP servers doesn’t really matter.
I have written a lengthy article in 2016 in the state of mobile XMPP: https://gultsch.de/xmpp_2016.html
The situation has only improved from there.
Sadly the server support isn’t really there yet. The support for Cyrus hasn’t been released yet (you need git) and some vital functionality like push [3] is still missing. Also no word from Dovecot yet.
[1]: https://github.com/iNPUTmice/jmap
Personal side note: I’m not a fan of branding open source apps. It delays security updates and waters down the original brands; Riot and K9 have good reputations; Why not utilize those?