6 ms·
I want to use Beeper, but funneling all my communications through hosted bridges (especially so Signal) is gonna be a nope, until they release more very deep te
by mcsniff 3y ago
I want to use Beeper, but funneling all my communications through hosted bridges (especially so Signal) is gonna be a nope, until they release more very deep technical and verifiable information about how on-device bridges work.
I'm big on unified messaging from the libpurple days, but now 99% of my chats are in Signal so perhaps I am just not the target demographic for this.
- Ambroisie 3y agoWhen looking at their bridge documentation for my own homeserver, I noticed that they do provide a way to self-host the bridges to be used with Beeper's homeserver as well. See https://github.com/beeper/bridge-manager https://github.com/beeper/bridge-manager
- raybb 3y agoYou may be interested in a feature in the new app: > On-Device Signal Bridge Haven't tried it yet.
- anyekwest 3y agoI use texts.com instead, honestly has worked better for me than beeper
- lrvick 3y agoBeeper at least has source code for the bridges, which you can have some hope is the same code that they run and that they don't get court orders to look at the messages. If they ever chose to implement remote attestation for bridges, and you chose to use an open source matrix client to control your local keys, there is at least a potential path for you to prove they can't look at messages so you don't have to trust them. You also have the option to self host bridges and take your ball and go home at any time, given that Matrix is an open protocol. Minimal lock-in. Texts.com by contrast is completely proprietary as far as I can tell, with no path to self host, so it is strictly worse than Beeper in every way in terms of transparency.
- batuhanicoz 3y agoOur code isn't open source but when you are using Texts, you are self-hosting it. It runs completely on your device!
- xniclb 3y ago[flagged]
- noahtallen 3y agomost software available is not open source. Any app you download from the iOS App Store might not even match what an entity claims to be its open source repository. Any app or service with a backend of any sort that you don’t host is not auditable by you. Self hosting is fantastic, but it is 100% not common and especially not something most people are interested in setting up. So your framing that this is objectively terrible either applies to nearly the entire software industry or isn’t a fair framing.
- lrvick 3y agoNot all open software is secure, but all secure software is open.
- lrvick 3y agoSo you tell user devices to run any code of your choosing, and no one but you is allowed to look at that code. Presumably you do not use reproducible builds, because almost no one does, so the choice of which code runs on user devices likely comes down to a single system administrator or release engineer. A court order or someone holding a rubber hose could instruct that release engineer to ship tweaked code to any number of devices that sets "42" as the random seed for private keys, allowing anyone with that knowledge to decrypt all messages in transit covertly. It would be in the best interest of your shareholders to lie if this was ever to happen. Without the code being open source, everyone should assume this is the case. Messengers are a massive target, and a target of that size on one person is certain to be exploited. One of core areas of my research is supply chain attacks, and you have no hope of providing strong defense against them without open source reproducible builds.
- erohead 3y agoOn-device bridging works like this https://blog.beeper.com/p/how-beeper-mini-works https://blog.beeper.com/p/how-beeper-mini-works. We'll put together a full technical deep dive for the real launch, this is just an open beta. Our signal bridge code is open source: https://github.com/mautrix/signal https://github.com/mautrix/signal You don't have to use our hosted bridges, we've made it ridiculously easy to self host: https://github.com/beeper/bridge-manager https://github.com/beeper/bridge-manager
- mcsniff 3y agoI really hope it will be possible to configure the Beeper app to use self-hosted bridges vs using a separate Matrix client. Having the features and polish of the first party app, but with a user-controlled backend (like how Bitwarden does it) would be great. BTW, I have a Pebble on my wrist right now :)
- erohead 3y agoThat's exactly what our bridge-manager repo allows you to do. Self-host the bridges yourself, use the Beeper client app.
- zufallsheld 3y agoWhat I'd really like to do (and the poster you responded to) is to connect your app to my own self-hosted matrix-server.
- notso411 3y agoGenuine question. Why do you do this?
- thatloststudent 3y agoNot the OP, but the beeper client looks better and has native GIF support, among other niceties that more "normal" users would prefer over other clients.
- traspler 3y agoI really hope that in the future such bridges can run in secure enclaves to protect the re-encrypt step.
- septic-liqueur 3y agoLol how'd you get 99 percent of your chats on Signal I envy you
- remotefonts 3y agoBetter selection/triaging of friends/contacts, perhaps.