8 ms·
Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kickin
by kiwidrew 6y ago
Yet another "Matrix isn't mature enough so just give up and use a centralized service" post that completely ignores the fact that XMPP is still alive and kicking. With multiple independent implementations (both client and server) that all work together pretty decently.
We're never ever going to tear ourselves away from this death by centralization if we keep inventing excuses for why we don't use the federated/distributed systems that we already have!
Edit: for those who are interested in using XMPP in 2021, there is a good list of public servers available at https://list.jabber.at/ https://list.jabber.at/ and a list of clients that support modern OMEMO end-to-end encryption at https://omemo.top/ https://omemo.top/
- vasco 6y agoHow much of the daily volume of internet chat-type messages do you estimate flow over XMPP versus alternative protocols and proprietary implementations?
- twelvechairs 6y agoI think it would be better if you made your point rather than asked it rhetorically. To me your argument reads like 'internet chat is currently proprietary so it always will be' but maybe I'm missing a step you'll need to fill in.
- vasco 6y agoAnd I think part of internet discourse should allow to posit questions without actually having a big point to make. Why is it necessary to pontificate about everything? In any case, if you want a point, whenever technical people bring up the technical superiority of X protocol or tool in a discussion, I like to ask myself this question. How many people actually use the thing that someone is telling me is so much better for the world? If it's so good, why is nobody using it for practical things? Have they used it before and there's a decline, or is it a new up and comer and it just hasn't caught on? I think just asking the question sparks a valuable train of thought.
- rapnie 6y ago> In any case, if you want a point, whenever technical people bring up the technical superiority of X protocol or tool in a discussion They are not talking about "technical superiority" though, but about "alive and kicking" and "work together pretty decently" and you followed up with a question of daily volume as somehow being the indicator of the maturity of the technology itself. There are multiple reasons for a lack in adoption, of course. Network effects, FOMO and walled gardens, financial might and power of dominating competitors to name a couple besides just the quality of the tech itself. And it doesn't help when many people off-handedly state the technology is not good, because it is not yet as broadly adopted as the centralized giants it is trying to be an alternative too :)
- twelvechairs 6y agoIts not really a question though when everyone already knows the answer. The 'why' you have here is a more open question and there's a lot in there. Companies trying to make money from it, users not having seen many real privacy implications on a wide scale, police presence being up and down etc. etc.
- kiwidrew 6y agoNot nearly enough. Based on some yearly port-scanning surveys [1], the developers of the Prosody XMPP server think there are over 50,000 servers running Prosody (out of a total of over 85,000 XMPP servers). There are a handful of large public servers and then what I imagine would be a very long tail of tiny private servers. [1] https://blog.prosody.im/2020-retrospective/ https://blog.prosody.im/2020-retrospective/
- pabs3 6y agoIn my experience, IRC is more active than XMPP. I only get XMPP traffic from spammers and during open source conferences, whilst IRC is active daily.
- southerntofu 6y agoI would say XMPP may be the most widely-used chat protocol on the Internet. And it has many more uses, as it's a generic federated PubSub platform. Facebook, Whatsapp and many other popular proprietary solutions use the XMPP protocol. Even games and gaming platforms like League of Legends or Nintendo use XMPP. So do Firebase and others. I'm not arguing in favor of these corporations. I'm a proponent of non-profit federated networks like the Jabber federation (based on XMPP protocol). Not that XMPP is better than ActivityPub/Matrix in all regards, but it has stable standards, rock-solid implementations with very good scaling stories, and there's a vibrant non-profit community working on: - better, modern clients for chatting: Conversations, Dino.. - unified branding/UX across platforms with Snikket client/server distribution - social networking: Movim (web), salut-à-toi (multi-platform) - decentralized forging to replace github: salut-à-toi uses it for own development - onboarding people with prosody's mod_invite - federated chat over tor onion services with prosody's mod_onion Matrix, SMTP and ActivityPub have other strong points going for them, but i could argue most of the Matrix criticism in the article does not apply to the Jabber ecosystem. Disclaimer: i'm a happy Jabber user and contributor to the https://joinjabber.org/ https://joinjabber.org/ project (a new born in the ecosystem)
- atoav 6y agoAs someone who in principle would like decentralized/federated cryptomessengers to win what usually blocks me from using them (over Signal) is that most of the people I would contact via messenger are not tech-savy. To make them switch the messenger has to be easy to setup and feature wise it has to be so promising that they don't feel like I lured them into something half baked. While being federated is a huge plus for me, it still needs to be a good and usable messenger on all other fronts. If I can't imagine my mother using it, you are doing something wrong. I am not usually of the "software must be usable by a baby"-front, but for a messenger adoption is key, and unless I only talk to my nerd friends it needs to be both simple and at least up to task with Signal (videocalls, groups, easy to find contacts, ...)
- leokennis 6y agoExactly. When network effect is in play, the bar for adoption must be set incredibly low. There is no way any of my non-tech friends is going to spend even 5 minutes investigating “XMPP” or whatever. If it’s anything more than open app >> fill in phone number or create account >> see list of people to chat with, it’s already dead in the water.
- apichat 6y agoQuicksy is made to be as easy as you say to get an XMPP account and automatically recognize contacts : https://play.google.com/store/apps/details?id=im.quicksy.client https://play.google.com/store/apps/details?id=im.quicksy.cli... https://quicksy.im/ https://quicksy.im/
- AmericanChopper 6y agoPeople who make these sort of comments strike me as the same sort of people who box tick features in software development without ever giving consideration to UX. There’s always an open or decentralized alternative to whatever big bad closed/proprietary thing is being complained about. You can usually contrive together an argument for how it almost has feature parity. But only if stick your fingers in your ears and wilfully ignore the fact that the user experience is almost never up to scratch.
- Phenix88be 6y agoXMPP is nice, but I have never see regular folks use it. Only tech peoples. The fact that you can't "install and go" is killing decentralized solution because when you ask regular folks the "server url" (or even to choose on a server list), they give up because it's too complicated already. It's already HARD enough to get them on Signal because they can't just click on the "Connect with Facebook" button. I got my mom on Signal and she actually converted other people to use it because it was not much harder than Whatsapp to set up. XMPP nerver killed MSN back in the day's for the same reason...
- m4lvin 6y agoI use XMPP with "regular folks". At least on Android it works well to point someone to https://play.google.com/store/apps/details?id=im.quicksy.client https://play.google.com/store/apps/details?id=im.quicksy.cli... and that's it.
- kitkat_new 6y agodo you also use encryption with "regular folks" and verify each others devices?
- apichat 6y agoYES ! first it automatically trust the devices but if you want you can improve it with manual verification : https://gultsch.de/trust.html https://gultsch.de/trust.html "TLDR: Automatically trust all new devices of contacts that haven’t been verified before, and prompt for manual confirmation each time a verified contact adds a new device."
- _trampeltier 6y agoThat's the cool thing with Threema. If you verifyed the contact is so prominent, everybody want to verify each others key, even people who don't understand the concept. In Threema it is not hidden somewhere, it's just allways visible on each single contact with green or red dots.
- johnchristopher 6y ago> if we keep inventing excuses The article brings valid points that are not invented.
- dudus 6y agoThat's is so not what he says though. He says Matrix is not there yet, nowhere he says to give up.
- apichat 6y agoTo easily get regular folks onboard you should recommand Quicksy (a Conversations spin off made by the same developper) : https://play.google.com/store/apps/details?id=im.quicksy.client https://play.google.com/store/apps/details?id=im.quicksy.cli... It's as easy to use and to automatically recognize contacts as Whatsapp and Signal but it's federated to XMPP. And people who don't use Quicksy host service can register to be easily recognize as a contact : https://quicksy.im/#get-listed https://quicksy.im/#get-listed
- stonesweep 6y agoYou've commented at least 3 times pushing this service. From their home page: > We charge a small fee to enter your Jabber ID and phone number into our directory. This cross financing allows us to make Quicksy completely free for its users. If you are a paying customer of the conversations.im hosting service, you can enter your number for free. As stated on their home page, it's a fork of the Conversations (conversations.im) client with contact discovery which they're selling. > Quicksy is a spin-off of the popular Jabber/XMPP client Conversations with automatic contact discovery. So it's just a conversations.im client trying to make a buck with a contacts service based on what I can see. Edit: in context in case you didn't know, Matrix (at least via app.element.io -> vector.im) has a contact discovery service, and it already works with phone numbers and email addresses using a blind one-way lookup for privacy.
- emptysongglass 6y agoThis is a misunderstanding. Quicksy is free for anyone who signs up. And I'm not that commenter.
- oblio 6y agoIsn't XMPP a horribly designed protocol and not very good for mobile devices, though? I'm not someone implementing XMPP but I remember reading articles about it back in the day and I recall hearing that the consensus that it's not a good protocol for mobile. Mobile being probably 95% of messaging traffic.
- apichat 6y agoThe mobile problem for XMPP is solved since 2016 : https://gultsch.de/xmpp_2016.html https://gultsch.de/xmpp_2016.html
- DyslexicAtheist 6y agothat leaves the problem of p2p being an overlay network and as such not being a solved problem for network operators (especially in wireless networks). http://www.spice-center.org/files/publications/90-305-1-PB.pdf http://www.spice-center.org/files/publications/90-305-1-PB.p...
- Jiejeing 6y agoWithout the optimizations added since 2016, it is not a great protocol for mobile devices, but only because mobile devices are stupid and equate a background TCP connection with something bad and battery-heavy. That means they make it much more difficult (or impossible re: iOS) to do so. That means apple & google are effectively dictating how you can use TCP (i.e. not outside of HTTP and friends), and everything is now terrible.
- oblio 6y ago> That means apple & google are effectively dictating how you can use TCP (i.e. not outside of HTTP and friends), and everything is now terrible. Ok, but this is our reality. Windows has been the dominant desktop OS since 1995 or so (and MS-DOS was the one from 1985 until 1995 or so, from the same company). Linux has been dominating the server space since about 2005 or so. iOS and Android have dominated the mobile since about 2010. I'm not holding my breath for any of these OSes disappearing from their niches before I die...
- DyslexicAtheist 6y agothere are 2 (maybe more?) ways in which matrix/riot (theoretically) could "compete[1]" against Signal, but are an utter failure on both accounts: 1) UE / ease of use for non-tech savvy users 2) a "killer feature" that gets people talking While 1) is a no-brainer, 2) is a more difficult. What does matrix offer to users other than "decentralization" (which is great for people on HN who like tinkering, but a usability drawback due to bootstrap time of joining a p2p network, and p2p in itself not offering a __security__ advantage[please ask to see the threat model when there are blanket claims that p2p is more secure]). Signals claim to fame comes from actual subpoenae that returned no usable metadata. Matrix (so far) has never been tested in adversarial conditions[citation needed]. While matrix's e2ee is an often talked about feature, it is not part of most matrix-implementations. Only riot claims it does e2ee however the claims on voice security are vague. Not clear if p2p or multiparty voice are E2E encrypted. Also you can optionally encrypt text chat rooms (which means it's not the default and so it's either not used by non-tech savvy users and those who rely on it risk getting exposed due to the extra steps it takes). I'm excited for decentralized technologies[3] but Riot is not in a state (yet) where I'd recommend it to exposed groups or individuals. So if neither e2ee is properly implemented, nor does it offer some radical new feature, nor is it actually more user-friendly - then why should anyone bother with it? [1] compete = moderate attempt in getting a name for itself considering that Signal is stealing all the attention in comparison to all other "secure" messengers [2] https://www.documentcloud.org/documents/3120046-Open-Whisper-Documents-0.html#document/p4/a320485 https://www.documentcloud.org/documents/3120046-Open-Whisper... [3] cwtch: more bleeding edge than matrix, potentially buggy and certainly not ready for prime-time but they understand that: "your threat-model isn't my threat-model" https://docs.openprivacy.ca/cwtch-security-handbook/risk.html https://docs.openprivacy.ca/cwtch-security-handbook/risk.htm...
- kitkat_new 6y agoyour evaluation is really out of date
- kupfer 6y agoI'm surprised to hear xmpp on mobile works for people. I tried a few times with a friend. I'm on Android, she has an iPhone. And it always was too unreliable. The worst part is that half of the time messages are not delivered or very late. But there are also problems with attachments. We tried different clients and servers.
- southerntofu 6y agoYes it works, there's a bunch of standards (XEPs) describing how a client/server should handle unreliable connections, push notifications, etc. However, not all servers respect these. If you're setting up your own, it's easy to enable though. Also a problem is iOS clients. Developing on iOS requires lock-in into the Apple ecosystem and most XMPP folks are free-software people so nobody will bother to buy Apple hardware/software specifically to develop for their closed ecosystem (i.e. unpaid labor for a multi-billion corporation), although i'm sure a lot of folks would be happy to do just that if that was sponsored work (donations, grants). On Android, Conversations (or its forks Quicksy/Snikket) is the best. ChatSecure on iOS has been buggy for years (every time i tried with someone with an iPhone), but nowadays Siskin appears to be a good iOS client, though i haven't had the hardware/system to try it myself.
- AshamedCaptain 6y agoAnd I cannot emphasize how nice it is that I have a selection of Jabber server implementations ready to use, and that using a version that is a couple of years old (say, from Debian stable) is not an automatic death-by-ostracization sentence.
- jasode 6y ago>Yet another [...] post that completely ignores the fact that XMPP is still alive and kicking I didn't downvote but your comment doesn't help me because it's what I call "generic & enthusiastic evangelism" that does not actually engage any of the concrete arguments in the blog post. An example of another comment that does try to address the author's issues is the one from arathorn[1] and I hope that one gets upvoted to more visibility. As an example of a concrete point you didn't engage with, he worries about the reliability scenario of sending a critical message such as "my car broke down". You cite a link of XMPP servers. But here's another list of servers where many are colored pink (they're no longer online): https://www.jabberes.org/servers/ https://www.jabberes.org/servers/ How does the average person curate your list and avoid choosing a server that will be offline pink in the future? Non-techie people don't want to keep switching servers because somebody quits their hobby of running a XMPP server. That's an example of why directing friends & family towards Signal is less of a cognitive burden. The author also mentions ease of voice & video calls on Signal. The cheerleading "XMPP is alive and kicking" doesn't address that either. [1] https://news.ycombinator.com/item?id=25977828 https://news.ycombinator.com/item?id=25977828
- kiwidrew 6y ago> generic & enthusiastic evangelism I'm sorry my post has come across that way. I simply wanted to point out that framing the argument as "Matrix vs $PROPRIETARY_SERVICE" is unhelpful at best. As an actual user of XMPP who has managed to get (some) of my contacts to join me in this brave old world of federation, I get frustrated when the conversation turns to "Matrix vs $CENTRALIZED_SERVICE_OF_THE_DAY" -- it's a false dichotomy that ignores that fact that 20 years later XMPP is still here and still hasn't died. IRC and SMTP are the only other standards for messaging that can claim that kind of longevity. Of course XMPP is not perfect. But it's what we have to work with, and throwing our hands up in defeat and crawling back to the centralized platforms that keep letting us down is not the way forward.
- foolmeonce 6y agoHmm.. I couldn't send "my car broke down" on Signal because it's one service was down for reasons entirely unrelated to my use. One can use email and have an address at Google and one at work, and know these data points for a friend. One can use a phone and have multiple service providers (in some countries multiple sims for costs, in others legacy landlines.) One can use WhatsApp, Signal or Slack and then you need to synchronize on an entirely different backup service. None of them have the POTS guarantee and for the most part we (at least in my age demographic) don't even trust the POTS service with non-redundant numbers.
- zaik 6y agoI never really understood why Matrix invented their own thing instead of building on an already existing IETF Internet Protocol. Surely an "eventually consistent database" can be built on top of XMPP? It's just message passing. When evaluating WhatsApp alternatives, this somewhat made me choose XMPP over Matrix. I recently uninstalled WhatsApp, Telegram and LINE (felt pretty good) and now use Conversations with most of my friends and family who were kind enough to try it out. Apparently Quicksy is free in the Google Play Store which is good news because nobody was willing to pay 2.50 EUR for Conversations and installing F-Droid just to install another app was quite a hurdle.
- rcxdude 6y agoIt's a fundamentally different approach. You could in theory build it on top of XMPP, but it wouldn't actually interoperate sensibly, so what's the point?
- lapinot 6y ago> It's a fundamentally different approach. Is it? (genuinely curious) Can't one see the matrix server-server state synchronization protocol as a transport layer for MAM archives? And pubsub nodes in XMPP are very matrix-room-like. This could be an XMPP extension allowing to multi-home pubsub nodes. Also, there are recent matrix proposals [*] for representing several things (groups and user profiles) as rooms. Given the analogy room=pubsub, the user-profile-as-room seems to be the same thing as XMPP's PEP (used to share personal data, like public keys or avatar). And the group-as-room would be the MIX proposal. [*] https://github.com/matrix-org/matrix-doc/blob/matthew/msc1772/proposals/1772-groups-as-rooms.md https://github.com/matrix-org/matrix-doc/blob/matthew/msc177... [*] https://github.com/matrix-org/matrix-doc/pull/1769 https://github.com/matrix-org/matrix-doc/pull/1769*
- lapinot 6y ago> I never really understood why Matrix invented their own thing instead of building on an already existing IETF Internet Protocol. Indeed. For sure XMPP has ugly corners (disclaimer I never implemented anything, mostly read some XEPs). I believe parts which are quite clean are the pub/sub part and the message archive (MAM). Afaik the current group chat extension (MUC) isn't so great (once you try to add history multi-device) and some people are trying to refactor it on top of pubsub (MIX) but it's not very active. The matrix team clearly had precise ideas about the right way to do federated group chat and in fact (again afaik, my matrix knowledge is dated) their "rooms" seem to be quite flexible by not being completely tied to a particular server (several servers participate in hosting a room). Imho matrix has an edge in designing this from scratch and already knowing what the hard parts are from the beginning and i hope the good ideas will come over to XMPP. Perhaps some day an XMPP server will support matrix, making more clients available to the network (well integrated clients on every plateform is the real hard part for every distributed network).
- nednar 6y agoEmail is another decentralized, distributed system that is often ignored. The only real difference between chat and email is that the interface makes it seem like chat is quicker. Nothing stops us from writing such interfaces for email as well, though.
- lapinot 6y agoFor anyone wondering, there's https://delta.chat/en/ https://delta.chat/en/. Discussed here days ago https://news.ycombinator.com/item?id=25893626 https://news.ycombinator.com/item?id=25893626.
- Hjfrf 6y agoFacebook messages are emails, I believe. At least an email to the user's @Facebook email address gets picked up in messenger.
- codethief 6y agoI think some distinction is needed: The email protocol allows decentralization (in the sense of federation) and, theoretically, even full distribution if everyone were running their own mail server. But in practice, none of this is the case and email is one of the most heavily centralized systems humankind has come up with. Back in 2016 I came across a computer science paper where the author had studied the decentralization vs. centralization phenomenon in various cases (not just in IT but also in real-life social networks, economic dependency graphs etc.) and concluded that every man-made decentralized system will eventually exhibit centralization to some degree as it will develop nodes that have orders of magnitude more edges than the average node. It seems to be a very natural phenomenon. I wish I remembered the author or the title…
- thekyle 6y agoOne problem with email is that it lacks typing indicators, read receipt, and other niceties that people have become accustomed to. There can also be a bit of a delay between sending and receiving messages on different email providers.
- kiwidrew 6y agoYes, email and IM do have a lot in common -- in particular, XMPP is best visualized as an IMAP-like client/server protocol plus an SMTP-like server/server protocol that both share an XML schema (ugh) for describing the messages akin to how MIME (another ugh) functions for email. As another commenter has pointed out, Delta.chat shows just how closely an email client can mimic the chat/IM interface.
- Macha 6y agoMatrix today is more accessible than XMPP today. Matrix today has more communities than XMPP today. It's a pity that XMPP's hopes were dashed by the EEE of Google and Facebook, but I think if we want to make people move towards a decentralised protocol, we need to pick one, and I don't see a reason to spend my energy on reversing the direction of XMPP when Matrix is heading in the right direction.
- px43 6y agoCan XMPP do encrypted group chat yet? I ran a medium-small sized XMPP community for many years, and eventually the community abandoned it and went back to IRC because it had better client/bot support. Matrix has a really good solution for end to end encrypted group chat, so I haven't seriously looked back at XMPP since then. They were the first ones with a decent solution to the most important feature I needed in decentralized group messaging, so they won IMO. I tried a couple times to build out my own clients/bots etc for XMPP, and it just seemed way overly complex. I had to bundle something like 30 megs of jar files for a simple hello world app. Also some silly things like ejabberd refusing to hash passwords in their user database because they were "already encrypted with SSL". It was all just a frustrating mess, and a security nightmare. Matrix, with Element, has a pretty web frontend that does encrypted messaging right. If XMPP has anything like that, please do let me know, but every time I've glanced back at it, it seems stuck in the stoneage of messaging apps, still working on getting a committee together to form the standards for even the most basic functionality that everything else had 10 years earlier.
- southerntofu 6y ago> Matrix has a really good solution for end to end encrypted group chat It's basically the same encryption scheme as Jabber/XMPP uses with OMEMO. The two were developed around the same time. On Jabber existing rooms need to be set to "members only" and "non-anonymous" for encrypted groupchat to take place because Jabber multi-user chats enable using nicknames (only the MUC operators know your address) which prevents clients from querying each other's key. > I had to bundle something like 30 megs of jar files for a simple hello world app. That sounds horrible. There's pretty good XMPP libraries around nowadays, like slixmpp if python is your thing. There's also a WIP Rust xmpp library if you'd rather. > Also some silly things like ejabberd refusing to hash passwords That sounds creepy. However, prosody does that very well though. And it seems ejabberd supports SCRAM authentication since 2007? > Matrix, with Element (...) If XMPP has anything like that ConverseJS is a web-based Jabber/XMPP client that does encrypted groupchat. It's supported by other clients as well (such as Conversations on Android). Movim, the more popular Jabber web client (because it has social features) does not support OMEMO yet unfortunately. ConverseJS may not be as user-friendly as Element though because they don't have (yet?) the $$$$$$ of VC/government money matrix has. > still working on getting a committee together to form the standards There is a bureaucratic tendency around the XMPP Standards Foundation, because standardization is very important to avoid lock-in. However client devs have pushed features before/meanwhile publishing specifications and bureaucracy does not seem to be a concern for (some?) devs in practice.