807 karma · joined January 27, 2021
0$ a month and no plan to grow.
XMPP is considered dead by many but I enjoy using it and bridging other IM services to it is fun. It helps me writing less crappy code at my day job, where I'm not a dev but rather a data scientist or something like that.
For fun I also made it a way to receive notifications on replies to my HN comments.
I'd be thrilled to receive contributions and feedback. ;-)
It's an XMPP server-side component that acts a client to various instant messaging chat networks, letting you use your favorite XMPP clients to centralise all your chatting needs. Some sort of "multi-device, multi-protocol chat 'app'". It supports
Happy to hear any feedback about it, or why it's a bad idea to use XMPP because it's obsolete (it's not), or why it's a bad idea to use these walled gardens anyway (spoiler: I agree).
I always find it funny when I read things like that about twitter, because I honestly wanted to see what it was several times and I swear I could never figure it out. I know I am most likely an outlier, and yes, I have a Linux server sitting below my desk (my basement is way too damp).
This is probably true for this specific case here, but my experience with fixing stuff in Linux is actually the opposite. I learnt a lot doing so, and learnt stuff that turned out to be later useful in very unexpected spots.
Back when I was a teen and using Windows, I've spent countless hours fiddling in stuff in regedit and other atrocities and it feels like I never learnt anything useful in the long run.
As an introduction language, I don't see why you would need to use decorators, generators or anything? You don't need to learn control flow, functions, variables, etc. You can perfectly write python without all the fancy stuff. In fact, there are quite a lot of data scientists who are paid to write python and don't know the first thing about concepts as seemingly basic as classes.
Removing deprecated stuff is… the point of deprecating stuff?
There is a lot of FUD about XMPP in comments on HN, and I feel bad for (potentially) doing the same thing about matrix, this was not my goal.
If you have E2EE but then one the two ends can be substituted for a new one, does it really qualifies as E2EE? If I have a hard requirement on E2EE, it probably means I don't want encrypted messages stored forever on remote servers, and easily decrypted on new devices. Or it can also mean I don't really understand what encryption mean, and I'm only interested in having a nice looking lock icon next to my messages.
>> If I sent encrypted messages to a trusted device of yours, I suppose I don't really want any new device of yours to get these messages. > I actually do > I am sure I do want E2EE.
Then what you are looking for is opengpg-type encryption (which is available via XMPP's most popular clients too). It's a lot less convenient to set up but this is how you switch from "device key" to "personal key".
> I have to also trust the servers of all my contacts. Where did I imply that?
Where did I imply that? I just gave you an example use case that is generally not tagged as E2EE but where no one but you and your contact can read your messages (self hosting).
> being able to read my messages on all my devices?
I can read all my OMEMO encrypted messages on all my devices. If I use a new device, I cannot read history. But that's because OMEMO isn't just for show (the nice lock icon), but actually something that makes it nearly impossible for anyone but you or your communication partner to read what you exchanged.
Also, most XMPP clients also allow to export local history, which could then be imported again, so if keeping all chat history really matters to you, it's also possible. But again, if you plan to store messages forever, you increase the chance of it being read by third parties significantly.
> safe from anyone being able to read my messages except me and my communication partners
If that is all that matters to you, facebook messenger has E2EE and it should suit your needs. It has the nice lock icon you're looking for. I think that who you talk to and how often you do is also rather important for privacy concerns, that's why I self host my XMPP server.
You seem to like the matrix protocol, where even if you self host, a lot of data is sent to the mother ship, cf https://hackea.org/notas/matrix.html
I agree that this does not create the best "user experience", but if that is what you are looking for, maybe you didn't want E2EE in the first place? It could be possible to have a XEP that covers "history syncing between my devices", but what's the point of E2EE if encrypted information can just be transferred and duplicated like this?
It's also possible to disable OMEMO if having history sync'ed on any new device is what's most important to you. It's not like messages are sent as plain unencrypted text (unlike email...), TLS is used. If you and the other end are on servers you trust (or own), there is little reason to use OMEMO anyway. Except that nice lock icon that supposedly means "safe" without really defining "safe *from what*".