7 ms·
These would be my concerns about potential differences between Signal and an 'Easy XMPP' client; would someone who knows Signal say whether these are accurate?:
by hackuser 10y ago
These would be my concerns about potential differences between Signal and an 'Easy XMPP' client; would someone who knows Signal say whether these are accurate?:
* Signal users are not anonymous; Signal requires users' phone numbers.
* Signal is centralized. Is there a way to run your own Signal server?
* Signal uses Google Chrome on the desktop (and Android?) and Google Play Services (or some part of them) on Android (I don't know about iOS). Whatever you think of Google's intentions, they are one of the leading surveillance organizations in the world. Signal users must trust Google.
* Is Signal's system (not user data) fully open and transparent, end-to-end?
* Would I need to trust Signal more than I would need to trust Jabber?
----
EDIT: I came across this comment from Moxie in late 2015 which addresses some of these issues and provides a broader view:
https://news.ycombinator.com/item?id=10665520 https://news.ycombinator.com/item?id=10665520
If we were going to rank our priorities, they would be in this order:
1) Make mass surveillance impossible.
2) Stop targeted attacks against crypto nerds.
It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions.
If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number.
If you don't want to run Chrome, use Chromium instead.
If you don't want to use Google Play Services, use GcmCore.
The world you want this software for is not the world that everyone else lives in. You can certainly make it work in that world with a little effort, but because of how we've prioritized our objectives, that's not the default experience.
- voidz 10y agoI think Google is only used to send empty notifications to android and chrome devices, right? IOS too, maybe? Not that this nullifies your point about Google. There's just not much for them to collect if what I asked is correct.
- techphys_91 10y agoThis is my understanding as well. However even this requires you to have various google-parts installed on your phone. These can be fairly obtrusive with permissions and such.
- hackuser 10y agoMy understanding is that Play Services sends information about the user to Google periodically.
- kuschku 10y agoCorrect. And Signal’s .apk includes a Google library for cloud messaging, but that library also collects information about the user and sends it to Google, even if the user does not have Google Services installed.
- codeka 10y agoWell you still need to trust that Google/your device manufacturer isn't simply reading everything on your device's screen.
- ge0rg 10y agoSignal requires users' phone numbers. True for Signal. XMPP is using JIDs which are functionally comparable to email addresses, and similarly anonymous (or not). Is there a way to run your own Signal server? The Signal client is open source, the server mostly so. You could create your own semi-Signal community, but it would not be able to talk to official-Signal users. XMPP is designed for federation by default, and you can run your own server, akin to email. Though some server operators decide to disable or cripple the federation feature (Facebook, Gmail). Would I need to trust Signal more than I would need to trust Jabber? This is a complicated matter. You need to trust the server operators to handle metadata in both scenarios, but you can run your own server with XMPP. You need to trust the client developer, which is Signal in one case, or the developer of your choice (or yourself) in the other. You need to trust the device manufacturer/Google in both cases.
- gurrone 10y agoWhat is this constant rumor about that Google killed XMPP federation? I think they killed the XMPP support in their own clients, but in general they still provide the service. I've at least three active @gmail.com XMPP accounts in my roster on a private server. I've read some rumor that they do not do TLS for server2server traffic, but in the end if you use XMPP on your desktop you most likely use OTR.
- SomeCallMeTim 10y agoI think it's more than a rumor. As far as I know, Google stopped allowing new XMPP servers to federate, because almost all of the new servers that were trying to were sending spam. It's possible that they grandfathered you in, if you were already federated when they put on the breaks, and your server wasn't guilty of sending spam. Or it's possible that I'm wrong and they just got really aggressive about banning new servers if anything even remotely spammy came out of them, and it's really the spammers complaining that "Google won't let anyone new federate."
- ge0rg 10y agoIn 2013, the xmpp community decided to enforce TLS on all server-to-server links [0]. Google still doesn't support this, essentially preventing non-gmail users to communicate with them. While OTR is a possible solution, it has its own can of worms (multi-device, offline use). Besides of this, Gmail xmpp silently fails if the other party upgraded to hangouts. [0] https://github.com/stpeter/manifesto/blob/master/manifesto.txt https://github.com/stpeter/manifesto/blob/master/manifesto.t...
- geofft 10y ago> Is Signal's system (not user data) fully open and transparent, end-to-end? I believe that it is not transparent in the usual sense, because the server-side component is has no source available, but also that it does not need to be transparent in a cryptographic sense: the amount of information known by the Signal servers is minimal, and doesn't include messages, contact graphs, or even which users are communicating with each other. It does include what users they have and what phone numbers, and when they log in / where from: I assume they could also learn whether someone is using Signal at a given time and how much (from bytes transferred) but nothing more interesting about the conversation. I believe the use of Google Cloud Messaging is the same way. I haven't looked into the protocol myself and I'm not sure if all of this is true. In particular, while OWS says they don't have any "records" of who a user is communicating with (https://whispersystems.org/bigbrother/eastern-virginia-grand-jury/ https://whispersystems.org/bigbrother/eastern-virginia-grand...), I'm not actually sure if this means they're just not logging it, and a system could be built to record this.
- problems 10y agoSo how about comparing rather than with Signal, instead with Conversations (https://conversations.im/ https://conversations.im/) It's XMPP based and offers many Signal-like features. Seems very similar to the goals of this.
- Sanddancer 10y agoYou're fighting the wrong battle here in order to get people to use better tools. Most people don't care if it's Free Software or not. They want something that's simple to use, and offers reasonable security. Right now, XMPP is not, due to the awful clients out there, and the attitudes towards any sort of comparisons with products that they are less philosophically aligned to. This is perhaps the biggest problem Free Software programs have when you start treading away from things like a browser. There is a huge hostility to ease of use and building things that are Powerful Enough. People don't care if you have a lisp scripting language embedded in your app, they care about how long it takes to get started doing the stuff they care about with your software. Until usability becomes more important, then XMPP isn't going to gain traction.
- deavmi 10y agoI don't trust Signal. I feel better with XMPP. Relying on one central server is bad (unless you can run your own). That's why federation in XMPP is good. Spreads out the change of anti-privacy issues in terms of just using normal encryption.