6 ms·
> With XMPP and federated messaging servers they would have at least working infrastructure within their country. Why do you think this is true? I can't see ho
by moxie 10y ago
> With XMPP and federated messaging servers they would have at least working infrastructure within their country.
Why do you think this is true? I can't see how federation is an answer to censorship. They would simply censor access to all the XMPP providers, just as they're censoring access to all the non-federated messengers.
Is your idea that people would spin up new providers so quickly that the censors wouldn't be able to keep up? Every time people switched, they'd have to rediscover their entire social network all over again, and there's an asymmetry between how difficult it is to get everyone over to different hosts while rediscovering where everyone is vs how easy it is for the censors to add a single line to their block list.
It'd be way easier just to have a centralized host and have people switch VPN providers as they get blocked, since then they don't have to rediscover each-other, but that isn't a great user experience either.
Just like with metadata hiding, really effective censorship circumvention is going to require new protocols and new techniques, so we're going to be more likely to see those emerge in centralized rather than federated systems (that are by their nature difficult to update). I think we'll be able to respond in Signal very quickly.
- Zash 10y agoTrue, neither architecture will ultimately solve the problem of an attacker having absolute control over the lower layer. No way around it. Federation does has the nice property that it gives you some choice over who controls the infrastructure you use, but in this case it would mean moving to a different country.
- SamWhited 10y agoThey could also sensor all email providers, or try to block all SMS providers, but historically we've seen that this is much more difficult than you make it out to be. It's not a silver bullet of course, but it's evident that federated architectures are harder to kill (see eg. Egypt attempting to censor emails and SMS's a while back, or Syria before that [and probably after too])
- moxie 10y agoCan you provide specific historical examples where censorship of federated protocols was difficult or impossible for technical reasons? I can't see how there is anything technically difficult about it. To the extent that services aren't censored, it's usually either because they're not encrypted (so no reason to block them) or because they're too popular to get away with blocking.
- SamWhited 10y agoAs I said, it's not impossible, nor is it difficult for technical reasons, it's just more difficult because there's more stuff to block, and you'll never find every little server setup by a few activists to access the network. With proper encryption (or even basic TLS to the server) it also becomes difficult to do deep packet inspection (which is hard to do in the first place). The example I gave before also still stands: Look at the last time Egypt tried this. They attempted to block email and SMS temporarily and various activist groups just setup their own servers to get around it. Not every random user can do this of course, but it's important that at least some activists can.
- moxie 10y ago"Various activist groups" setup their own SMS service? If all you want is for a few hundred people to be able to communicate, you don't need a federated protocol, you just need a VPN. It is much easier to use a centralized service and access it with a VPN than to use a rotating set of hosts across successively blocked federated services. At least when the VPN gets blocked you don't have to rediscover your entire social network when you start using a new one.
- apichat 10y ago> They would simply censor access to all the XMPP providers First we already know this situation with email, and we see that as a federate protocol email is not censorable. At least not as easy to censor as Signal is. Secondly it's not possible because their is not a finish list of providers. By the way 1) everybody should-could be its own provider 2) everybody must use its own domain name DNS to make addresses like greeting@name. Solution for 1) https://yunohost.org https://yunohost.org & https://wiki.debian.org/FreedomBox https://wiki.debian.org/FreedomBox & http://modoboa.org/en http://modoboa.org/en 2) for this point see https://account.conversations.im/domain https://account.conversations.im/domain AND if the DNS is to centralize lets see for GnuNameSystem https://gnunet.org/gns https://gnunet.org/gns for the address like greaing@name see https://linuxfr.org/users/apichat/journaux/salut-toto-salutation-regle-editoriale-et-nom-sur-internet https://linuxfr.org/users/apichat/journaux/salut-toto-saluta...
- moxie 10y ago> Secondly it's not possible because their is not a finish list of providers. By the way 1) everybody should-could be its own provider 2) everybody must use its own domain name DNS to make addresses like greeting@name. Just to be clear, this is never going to happen. We do not live in a world where computers are for "computer people" anymore. I've been running my own mail server since 1995, and I would not wish it on anyone. Running my own mail server has not helped me with: 1) Metadata protection. Every email that I send or receive either has Google or Yahoo on the other end of it. Running my own mail server does not help me "own" my data at all. 2) Data protection. Federated protocols can almost never change (look at the history of IRC, XMPP, SMTP, HTTP). Email is stuck in time, which is why emails are still not encrypted. WhatsApp, on the other hand, had the freedom to deploy e2e encryption to over a billion people very quickly. 3) Censorship circumvention. Email is very easy to identify and filter using DPI. In a world where people are only doing host-based filtering, blocking 100 or 1000 hosts is no more difficult than blocking one. Whether or not there is "a finished list," if people can discover these services, so can the censors. It is much easier for the censors to add a single line to a block list than it is for people to switch to an entirely different provider with an entirely different namespace and try to rediscover all their friends. If your idea is that every time a host gets blocked, everyone could move to a new one and somehow rediscover their entire social network, it would be way easier just to use a centralized service and access it with different VPNs as they are successively blocked instead. That would prevent you from having to rebuild your entire social network each time, but is still a terrible UX.