3 ms·
> federated standard without control of client and server is going to evolve very slowly an fracture into incompatible pieces. Good answers : An Objection to ‘
by apichat 10y ago
> federated standard without control of client and server is going to evolve very slowly an fracture into incompatible pieces.
Good answers : An Objection to ‘The ecosystem is moving’ https://gultsch.de/objection.html https://gultsch.de/objection.html
Juste think about how the web and Internet evolved.
Juste think about how the web and Internet evolved
- sliken 10y ago"Just think about how the web and Internet evolved" What percent of DNS lookups use DNSSEC? What percent of email is e2e encrypted? What percent of NTP lookups are signed, encrypted, or trust worthy? What percent of HTTPS traffic would not die by a trivial downgrade attack? What XMPP client allows you to click on it in the apple/google play store, auto discover any contacts using it, and start chatting (with e2e) in 30 seconds? Are things getting better? Certainly, it's rather slow progress though. I don't see how signal could have gotten as far as has, as quickly as it has, without controlling both server and client, and skipping federated. Sure, by leading by example hopefully the bar is raised. All the signal compromises (controlling client and server, non federating, using GCM, requiring a sim, etc) seem to be well justified to get pretty good security to a large number of diverse people quickly. Sure federated would be great, as would be independence from the whisper systems servers which can be easily blocked (like in egypt). So sure hopefully someone comes up with something that manages the strengths of signals with federation and censor resistance. Not sure that will look much like XMPP though.
- tptacek 10y agoThankfully, virtually no DNS queries use DNSSEC. https://sockpuppet.org/blog/2015/01/15/against-dnssec/ https://sockpuppet.org/blog/2015/01/15/against-dnssec/