10 ms·
XMPP: Admin-in-the-middle
- po1nt 5y agoI wanted to change Matrix for XMPP, now I have one less reason to do so.
- topdancing 5y agoMost of the problems described here also apply to Matrix. Also came up on Reddit: https://reddit.com/r/PrivacyGuides/comments/qkhqf7/xmpp_admininthemiddle/ https://reddit.com/r/PrivacyGuides/comments/qkhqf7/xmpp_admi...
- Semaphor 5y agoIf only Matrix had nice clients like Conversation or Gajim instead of all those mIRC and Discord look-alikes.
- ptman 5y agoWhich matrix clients have you tried? Fluffychat?
- Semaphor 5y agoI tried elements and looked at all the screenshots of non-alpha clients on https://matrix.org/clients/ https://matrix.org/clients/ Fluffychat would be okay for mobile. But that still leaves me without a primary client on my Windows PC.
- edhelas 5y agoThose issue applies as well to the Matrix network since the global architecture is similar :)
- MattJ100 5y agoBasically all the issues listed in the article apply equally to Matrix, and most other communication platforms too. There are some alternatives that overcome most of the issues with a "serverless" approach (hint: no practical communication protocol on the internet is ever truly serverless), such as Briar. However they generally have UI/UX and feature limitations that are impractical barriers to mass adoption. If you're concerned that your communications may be specifically targeted, you should definitely consider carefully what solution meets your needs and security in the context of your threat model. Sometimes this might be self-hosting, or a pseudonymous XMPP account accessed via Tor, Signal or Matrix, or Briar, or something else. What we need are good factual unbiased guides to inform people about the practical and security properties of various options. Unfortunately this article is not in that category.
- southerntofu 5y agoIn matrix, not only can your homeserver usually impersonate you, but most information/history in rooms is considered public and archived forever. I haven't followed recently if there were mitigations on this topic, but that was historically one of the reasons many activists stuck with IRC/XMPP who support ephemeral discussions and/or an explicit data retention policies (eg. keep the latest 20 messages in this room so newcomers can have a little backlog). In case that wasn't clear, in the XMPP model, the backlog for a room is kept on the room's server, not on every individual home server. In matrix, all data is replicated on all servers (which eats massive server resources, although newer implementations like conduit seem to improve on that) which greatly increases the possibilities for a bad actor to find their way to these conversations.
- gefhfff 5y ago> who support ephemeral discussions and/or an explicit data retention policies Matrix's variant of that: https://brendan.abolivier.bzh/matrix-retention-policies/ https://brendan.abolivier.bzh/matrix-retention-policies/ > In case that wasn't clear, in the XMPP model, the backlog for a room is kept on the room's server, not on every individual home server. In Which makes your history dependent on a plethora of different servers. Result: very bad usability > replicated on all servers No, this is misleading. It is replicated between servers that have users participating in the conversation, i.e. know the conversation anyways > which eats massive server resources I'd like to have a source for that. To my knowledge Matrix cryptographically verifying actions between servers (prohibiting various bad actions due to the decentralized nature of rooms in Matrix) and the implied DAG is really what needs resources
- Semaphor 5y agoThe article is a weird mix, partially very relevant information [0], partially just saying "using XMPP without E2E encryption is… not E2E encrypted" which is a weird ting to get worked up about. Maybe I’m missing something here? [0]: And honestly, something I have not thought about. I host my own XMPP server (Prosody) with only 2 accounts, mine and my wife’s, so it doesn’t affect me. But obviously you can’t expect everyone to just host their own server.
- rvz 5y agoSo the hype around XMPP is no better than Matrix then. Oh dear. Going to keep using Matrix then.
- edhelas 5y agoSo the hype around Matrix is no better than XMPP then. Oh dear. Going to keep using the IETF XMPP Standard then.
- gefhfff 5y agoMatrix has introduced some really neat innovations compared to XMPP: - decentralized conversations instead of centralized ones - MEGOLM - Cross Signing - monolithic protocol (i.e. one true way of doing things officially) - easy sync of (encrypted) history between sessions These are reasons why people use Matrix and not because of misinformation about how private it is
- topdancing 5y agoIf there's anything that's overhyped these days, it's Matrix. https://news.ycombinator.com/item?id=27557113 https://news.ycombinator.com/item?id=27557113 was so brilliant at capturing my own thoughts/concerns on it.
- lmm 5y agoI think that bit of history shows what a false idol extensibility is. 20 years of extension and improvement has resulted in a chat system that is still staggeringly worse in practice than its competitors of 20 years ago. (Seriously, XMPP is still worse than AIM for actual day-to-day use). Look at XML vs JSON for another example. A simple standard that has no improvement path except completely replacing it turns out to be much more usable than an extensible, upgradeable standard.
- topdancing 5y ago> Seriously, XMPP is still worse than AIM for actual day-to-day use Have you actually tried the modern clients like Conversations/Dino? I've been running a private XMPP server for friends for the past couple of years and the only way to describe it is rock-solid.
- MattJ100 5y agoThe main problem with this article is that all the points apply equally to other services, but the article frames it such that it implies the problems are unique to XMPP. Half the article is dedicated to obsessing that the server can see your IP address. This is true of every internet service, and is how the internet works. Tools to solve this (e.g. Tor, VPNs) are well known and established solutions if you need to hide your IP from websites and services you use. Common alternatives to XMPP that people may recommend include Signal and Matrix, but both certainly see your IP address just as easily. XMPP uses passwords for authentication, rather than phone numbers. Since the server needs to use the password to verify you are you, there should be no surprise that it is sent to the server when you create your account or change your password. Just like any website or service that utilizes passwords for authentication. Pretty much everything else listed is solved by verified end-to-end encryption, which is the primary solution to these problems regardless of any platform or protocol you use. Again, not a problem with XMPP specifically. Instead of focusing on helping educate people sensibly about these things, the article seems to be a lot of biased scaremongering. Full disclosure: I'm actively involved in various XMPP projects, including the XMPP Standards Foundation, Prosody and Snikket. Obviously I have a very keen interest in protocol design, secure online communication and the various available platforms/tools.
- southerntofu 5y ago> Tools to solve this (e.g. Tor, VPNs) are well known and established solutions if you need to hide your IP from websites and services you use. So true, yet some clients might still leak information. For example WebRTC leaks in web browsers is a real concern (which is why Tor Browser disables WebRTC entirely, except maybe in unsafe mode?). I also heard some mobile/desktop clients have such leaks when it comes to VOIP, but i didn't try to reproduce yet. This would be worth investigating with wireshark and a couple of volunteers. > not a problem with XMPP specifically. There is one problem the author mentioned which applies to XMPP but not to email/ActivityPub: presence tracking. So your own server/admin will know when a client-to-server (c2s) connection is active, but in the XMPP ecosystem it's rather common for clients and servers to advertise the presence status (online, away) to the entire world, and that's a huge metadata leak. Maybe something to investigate in the future.
- southerntofu 5y agoThese points are good to know, but as others pointed out they apply to email, Matrix, ActivityPub and other federated protocols. I believe we have published a rather comprehensive security/privacy FAQ here: https://joinjabber.org/faqs/security/ https://joinjabber.org/faqs/security/ Let me know if you find some information missing in there! PS: I don't understand why the infosec-handbook.eu article appears posted on november 1 2021. It was published in August 2018, see also: https://web.archive.org/web/20201208132104/https://infosec-handbook.eu/tags/xmpp/ https://web.archive.org/web/20201208132104/https://infosec-h...
- infosechandbook 5y agoHi, authors here. > I don't understand why the infosec-handbook.eu article appears posted on november 1 2021. It was published in August 2018 We fully revised this and other articles as mentioned on our website. The article itself contains a note that it was republished.
- captainmuon 5y agoI was not really expecting XMPP to do anything else by default, to be honest. If you want end-to-end encryption, the hard thing is to do the initial key exchange in a way that the server can't just MITM. It is extremely rare that somebody compares the "security numbers" of services like Signal to be sure there is no interposer. One solution might be to do key exchange by a completely separate third party. Or, instead of running your own server, you could just move the server completely into the client (and maybe have an external server only to buffer encrypted messages while you are offline). I wonder, is it possible to send P2P data from one cell phone to another nowadays? It used to be impossible to have any incoming open port, but I think in some circumstances you can use CGNAT hole punching, connect to other users on your carrier directly, or even use IPv6?
- MattJ100 5y agoThe problem with pure peer-to-peer communication is that it is unreliable due to IP address changes and NATs, requires you to always be online (or at least both be online simultaneously) and also exposes your social graph to your ISP and any other intermediary on the network path. Some of these can be fixed by adding servers into the mix (such as discovery/rendezvous servers, or Tor), but that doesn't solve everything.
- MayeulC 5y agoUse a STUN server to assist with NAT traversal. Some DHT swarms can also assist with that. Or use a VPN or VPN-like network, like TOR, yggdrasil, IPFS p2p, etc. Some are explicitly designed for that kind of use, and can form a mesh network with peers that are physically close. Unfortunately, for yggdrasil that means mostly Apple's Airdrop, though that should be possible with the more recent wifi NAN "neighbour area network" (wifi aware) and P2P.
- underatree 5y agoIs there a better alternative that meets the following constraints: * standards based: i.e. it has demonstrated commitment to openness and universality * multi stakeholder: i.e. it has momentum * can self host: i.e. power can reside with communities * has clients that support encrypted video chat: i.e. I can use it today. XMPP does that.
- gefhfff 5y agoMatrix
- zaik 5y agoWhy should I use Matrix over XMPP? All the problems mentioned in this article also apply to Matrix.
- gefhfff 5y agoMatrix has introduced some really neat innovations compared to XMPP: - decentralized conversations instead of centralized ones - MEGOLM - Cross Signing - monolithic protocol (i.e. one true way of doing things officially) - easy sync of (encrypted) history between sessions These are reasons why people use Matrix and not because of misinformation about how private it is Also: afaik not everything applies to Matrix, e.g. a widely used server logging passwords or a server being able to manipulate chat rooms that extensively
- zaik 5y agoMEGOLM seems to be encrypted group chat. OMEMO already provides that. Cross signing OMEMO keys would be nice indeed. Not sure what a session is or why it needs sync. XMPP is decentralized, maybe even more than Matrix, since almost everyone uses the official server matrix.org. I'm not sure if all of this is reason enough to switch to an non-standard protocol, fragmenting the small space of open IM protocols even further. It would be better to implement those features using existing Internet Standards.
- upofadown 5y agoThis article triggers one of my current pet peeves. It treats privacy and anonymity as more or less the same thing. Anonymity is a sort of privacy related to identity, but it is not required that you are anonymous to have privacy. Everyone can know that I am sending encrypted messages to other people but those messages are still private. Anonymity should be discussed as a special case. Having said that, XMPP can be quite anonymous in practice. There are public XMPP servers running on hidden services. XMPP servers do not insist that you give them any personal information at all. In particular they normally do not require a phone number.
- ruslan 5y agoI wonder why did they choose to investigate plain text connection to XMPP server instead of SSL or TLS ? As far as I recall there's "starttls" command on standard 5222 port, after that things get encrypted and all their tcpdump tricks fail. Almost none of the XMPP clients use plain text connection nowadays.
- ruslan 5y agoAnd, by the way, federated servers use SSL/TLS as well. Of course server admins can do verything, like peer into your traffic or grab passwords from database, because they are admins!
- infosechandbook 5y ago> Almost none of the XMPP clients use plain text connection nowadays. Everything shown in the article works with or without TLS enabled. It doesn't matter. The server-side party sees cleartext XMPP packets passing the server. > all their tcpdump tricks fail There are no "tricks" in the article. It is just capturing network traffic. The point here is that XMPP traffic isn't magically invisible to third parties that observe the network traffic as some people claim.