User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1d
@feld @arcanechat @jae Or you have techy friends. But even if they’d agree, I’m not teaching my elderly relatives deltachat just to have to teach them something else when, not if it breaks accessibility.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
1d
@fastfinge @arcanechat @jae kinda ironic tbh as elderly users are one of the biggest success stories of Delta Chat especially as they never have to think about the concept of a username or password
2
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1d
@feld @arcanechat @jae You can do passwordless XMPP. Nobody does, but you can. And there's a standard for it. So when one or more people eventually do, it'll work in both apps that decide to do it, in the same way.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
1d
@fastfinge @arcanechat @jae "Nobody does, but you can." should be the tagline of XMPP honestly
1
0
2
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1d
@feld @arcanechat @jae And "Just use our client and our library and our invite links, because that's what openness means," can be the tagline of deltachat.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
1d
@fastfinge @arcanechat @jae the invite links situation is well under its way to being solved precisely because of censorship and single point of failure sorts of things

but anyway -- if someone already has Delta Chat app installed, they never actually access
i.delta.chat as the app intercepts the URL
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1d
@feld @arcanechat @jae That's good. Now once there's a viable implementation not using deltachat's libraries or controlled by deltachat, and a way for the two clients to negotiate capabilities so they aren't forced to just be identical, I can happily use and promote it. Deltachat has good ideas. It's just not safe for me, or anyone else with a disability, to risk becoming dependant on. Because "small open-source underfunded organization stops caring about accessibility" is a far more likely threat to my use-case than "government blocks my instant messenger". It's also a threat that has happened repeatedly, and will continue to happen.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
1d
@fastfinge @arcanechat @jae
and a way for the two clients to negotiate capabilities so they aren't forced to just be identical
Why is everyone SO obsessed with trying to build a messenger ecosystem with asymmetric features/capabilities?! What a total shit show that is for everyone -- developers and users
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1d
@feld @arcanechat @jae Because in the real world, everyone has different needs. My friends E-ink display can't show moving videos. My ESP32 controller doesn't run JavaScript, so can't participate in Deltachat Apps. My headless Linux box has no audio or video support, so can't do voice or video calls. I can't see images at all, so would prefer that servers not waste my mobile data by sending me avatars and pictures. The only way this can work if the protocol can communicate everyone's different needs and abilities, so devices don't get things they can't handle, users don't get things they don't want, and people don't get confused about what works and what doesn't.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
1d
@fastfinge @arcanechat @jae
My ESP32 controller doesn't run JavaScript, so can't participate in Deltachat Apps.
then all it has to do is ignore the messages related to it, they won't harm it

"be liberal in what you accept..."

I have custom bots/bot accounts. They ignore all the WebXDC messages without issue. I can even try to call them. They'll never answer, but it is completely harmless.

I literally don't get the issue here.

Let's say you have the same account accessible over Bitlbee, your phone, and some ESP32. Do you want it to expose the capabilities of the currently active device even though it's the same account? So what, someone might not have the phone button appear if you're not active on the right client?

That is a HUGE metadata leak. You absolutely should not expose that information. (Signal does right now, you can spy on people and see when they're using their phone vs their desktop)
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
23h
@feld @arcanechat @jae What I want is for my grandmother not to think she did something wrong when she sends me an app, and the connection never establishes. Or spend five hours troubleshooting her internet when she tries to call me and it doesn't work. Or for my app not to waste all of my mobile data because my cousin sent 54 photos to the family group. Without protocol negotiation, you can never be user friendly in these ways.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
23h
@fastfinge @arcanechat @jae

Grandma will just be calling when she gets "There was an error decrypting an OMEMO message addressed to this device." errors instead I guess?
Or for my app not to waste all of my mobile data because my cousin sent 54 photos to the family group.
Already possible to disable automatic attachment downloads in the Delta Chat app
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
23h
@feld @arcanechat @jae I mean sure. That's an actual problem that I can solve for her. Though these days it never really happens. The only protocol with that problem still is Matrix.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
23h
@fastfinge @arcanechat @jae I haven't used XMPP in probably 5 or 6 years, but I did just have a friend mention the OMEMO error yesterday
2
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
23h
@fastfinge @arcanechat @jae you know, XMPP could probably be good if someone produced a project implementing the XMPP core protocol and the important XEPs in one package with a clean JSON-RPC API so anyone could write a UI around it easily and then everyone has the same implementation so there are no compatibility issues and then people can focus on building highly polished UIs to their taste instead of toiling for years on protocol internals

if someone did that I bet XMPP would explode in popularity
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
23h
@feld @arcanechat @jae There are multiple libraries that do what you want. And they all work with one another. Pick your favourite and go. QXmpp if you like QT, slixmpp if you like Python, Martin for Swift...
2
0
0
0
User avatar
Phantasm @phnt@fluffytail.org
23h
@fastfinge @feld @arcanechat @jae
QXmpp if you like QT
Isn't that the meme KDE XMPP library that Kaidan uses and supports none of the OMEMO versions everyone else actually uses?
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
23h
@phnt @feld @arcanechat @jae I have no idea what Kaidan does. But from a brief glance as someone who doesn't use it, it looks fine.
1
0
1
0
User avatar
Phantasm @phnt@fluffytail.org
22h
@fastfinge @feld @arcanechat @jae There is an issue with Kaidan users where almost nobody can read their OMEMO encrypted messages, because Kaidan implements only some new-ish version of OMEMO and not the older ones used by other clients. So if you use Kaidan, you effectively can only talk to other Kaidan users when using OMEMO.

From a quick look a cmake files in Kaidan, it seems that it uses QXmpp. So unless they disabled some support, QXmpp isn't really usable in the real world. I don't think it is even compatible with Conversations. (Conversations holding back the whole ecosystem is another can of worms I'm not going into.)
2
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae correct it only implements OMEMO2 and they refuse to implement OMEMO1

also they had a cool bug recently where it told you that the OMEMO was successful when it only worked for one side

invent.kde.org/libraries/qxmpp/-/merge_requests/794
2
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae Most things only implement OMEMO2. 1 was deprecated years ago. Time to update your client.
1
0
0
0

User avatar
Phantasm @phnt@fluffytail.org
22h
@fastfinge @feld @arcanechat @jae Conversations doesn't support it, so it doesn't matter that other clients support it, if nobody on mobile can read your messages. Gajim doesn't support it either I think...

codeberg.org/iNPUTmice/Conversations/issues/55
3
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@phnt @feld @arcanechat @jae I've never even heard of conversations. Nobody I know uses it; we're all Monal or Siskin. They should really get on updating, though.
1
0
0
0
User avatar
Phantasm @phnt@fluffytail.org
22h
@fastfinge @feld @arcanechat @jae
What does OMEMO file attachments that the existing file transfer over HTTPS doesn't give you?
The server having no idea what the contents of the file is. What's the point of an encrypted chat when you can leak valuable metadata by accidentally uploading an unencrypted attachment over an encrypted HTTP connection.
I've never even heard of conversations. Nobody I know uses it; we're all Monal or Siskin.
It's the only usable XMPP client on Android. Almost every other XMPP client on Android is forked from it.
2
0
1
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae I think it's really funny that there are multiple XMPP projects right now flirting with implementing PGP instead of OMEMO
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae I suspect PGP is the future. OMEMO is just kind of a crappy design. The issues with it were mostly solved, but they're just not worth it. As Matrix is also discovering. Though I don't know enough about cryptography to comment on the security trade offs, just the UX ones. There's some guy who runs a furry blog with opinions who's name I honestly can't remember. I'll leave that to him.
:niggafurry@eientei.org:1
1
0
1
1
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @phnt @arcanechat @jae I know who you refer to and they shall not be named for fear of invoking their ... wrath?

They hate PGP because of the legacy baggage that has historically caused all sorts of bugs and security problems, but if you do it like DeltaChat and you only support the absolute minimum of the spec that you need and you're done. That's what the XMPP community should do too because it works very well.

I'm just not convinced that E2EE is possible on the fediverse because you have the issue of "where do the keys get stored" -- in your browser session? On all your clients/apps? How do you synchronize them? yuck yuck yuck
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae Use the FIDO stuff and have everyone store it on their YubiKey or as a passkey. The advantage is that everyone is forced into having a hardware 2fa device. I'm...mostly half joking.
1
0
1
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @phnt @arcanechat @jae I only do ssh with my yubikeys so I'm already on board with this idea but yeah...... kind of an intractable problem
0
0
1
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@phnt @feld @arcanechat @jae I mean in an ideal world, everyone just runs their own server they trust. But yes, in the actual world, OMEMO encrypted file uploads should be supported.
1
0
1
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae What this thread has ultimately proved is that what we need is E2E for Activity Pub. Then we can all just IM over the fediverse. Equally unblockable because it's just HTTP to random places. And with none of my concerns around centralized control, and none of the XMPP baggage, and not trying to synchronize an entire dag the way Matrix does.
1
0
0
0
User avatar
Phantasm @phnt@fluffytail.org
22h
@fastfinge @feld @arcanechat @jae There's already a draft spec for that. Issue is that nobody thought about key distribution yet, which is the hardest part of it (as proven by both XMPP and Matrix).

Spoiler alert: Barely anybody will be implementing it anyway.
github.com/swicg/activitypub-e2ee
2
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae they can just use autocrypt v2 which was designed to solve this exact problem for all protocols interested in secure key distribution/exchanges, ratcheting, etc without any centralized servers involved

hopefully that's what happens, it would be good for the users


edit: oh! I thought this was about XMPP not fediverse haha... yeah big doubt about this
0
0
2
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@phnt @feld @arcanechat @jae I mean, nobody is going to implement it without key distribution sorted out. But once it is, I see no reason why a bunch of people wouldn't. I'd be happy to get it into iceshrimp and the clients I use. And the loops/pixelfed guy has already talked about it previously. And Sharky/firefish/whatever it's calling itself today will implement it because they implement everything. Pleroma and gnusocial will say they're going to implement it, but never will, eventually leaving it up to Akoma. GoToSocial will implement it five years later. Mastodon will implement something shaped like it, but use entirely different encryption and key formats. But eventually, everyone will have some form of it, and will all be able to exchange encrypted IMs with each other.
2
0
1
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @phnt @arcanechat @jae
Pleroma and gnusocial will say they're going to implement it, but never will, eventually leaving it up to Akoma.
hey, get it right: Pleroma will never implement it because we experimented with it years ago and decided it's wrong and unfit for the fediverse :)

blog.soykaf.com/post/encryption/
1
0
2
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae OMG this article is infuriating! Why did this guy use real HTML headings, and yet also keep the markdown formatting? What is this weird combination of both HTML and markdown at the same time it's making me cry.
😆1
1
0
0
1
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @phnt @arcanechat @jae I think it's generated with Hugo, can't comment further. Sorry 😭

there's not much you're missing from the not-really-alt-texted images except they're from his visit to North Korea lol
1
0
1
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae Good lord. Did this guy move on to become a Lemmy dev? Because he seems like someone who has opinions about China.
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @phnt @arcanechat @jae nah he's a good friend of mine and has no fear. I think in another life he'd be one to go into war zones just to get some cool rare photos.
2
0
0
0
User avatar
Phantasm @phnt@fluffytail.org
22h
@feld @fastfinge @arcanechat @jae Ehm, not like there isn't one near ;)
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae ANOTHER LIFE. We're not sending him in to get blown to bits in this life. :)
0
0
1
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae Ah, okay. I tend to make moral judgements about people who visit North Korea. Largely because they tend to be Dennis Rodman.
0
0
0
0
User avatar
Phantasm @phnt@fluffytail.org
22h
@fastfinge @feld @arcanechat @jae
Pleroma and gnusocial will say they're going to implement it, but never will, eventually leaving it up to Akoma.
There are Pleroma Chats, so that could be used as some baseline, but chats and that spec aren't really compatible last time I looked. And my view is that there are already better ways for E2EE chats than the fediverse. You get identity isolation as a "bonus" and there's no X protocols + 1 competing over the same thing.

That said, if they do it properly, the server part should be rather simple as it should be the client doing all the work and the server should just send the messages to their destinations. However if the server will also hold the keys, or there will be only one key per user, than there's no shot I'm implementing this. Multi-device support is my requirement for even bothering with it.
Mastodon will implement something shaped like it, but use entirely different encryption and key formats.
Mastodon actually got a grant approved to implement that unfinished spec, so the ActivityPub thing will probably be happening again. Where Mastodon is actually what defines the spec.
2
0
1
0
User avatar
ffaw @ffaw@decayable.ink
22h
theres still gnusocial instances? If so I'd love to join it cause I found it very simplistic and nice to implement into ancient applications.
1
0
0
0
User avatar
Phantasm @phnt@fluffytail.org
22h
@ffaw @fastfinge @arcanechat @feld @jae gnusocial.jp is still around, but the guy hosting it has better things to do and doesn't have the money to host it, so it lives on some shared PHP hosting. Because of that it barely works.
0
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae
so the ActivityPub thing will probably be happening again. Where Mastodon is actually what defines the spec.
yeah remember when the AP WG recognized Pleroma was a major contributor to the fediverse and invited us to be stakeholders and asked us for input on important far-reaching issues and proposed changes to the entire fediverse? Ahh wait that never happened they just ignore us and it's not worth any of our time to try to force our way in and argue just to be told "well Mastodon is doing it this way anyway, so that's the spec now"
0
0
2
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae from 2022 which isn't that long ago in XMPP land
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
22h
@feld @phnt @arcanechat @jae No alt text? Really?
1
0
0
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @phnt @arcanechat @jae I did in an edit sorry, realized as soon as i hit the send button
1
0
1
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@fastfinge @arcanechat @jae @phnt alt-text in case your client isn't seeing it from the edit for whatever reason:

Hi Given the fact that this project made a huge progress the last years with great features, we tried to port Shmoose away from Swiften and also use qxmpp. During this, we discovered that the current omemo implementation in qxmpp is 'v2 only' which in turn has the side effect that it is currently not compatible with all the other major xmpp clients. Do you have a plan how to handle this? There are e.g. omemo pyhton implementations available which handles both, v1 and v2 of the omemo protocol transparent to the using product. Best regards Geobra
0
0
1
0
User avatar
Only 3 Easy Payments of $19.95 @feld@friedcheese.us
22h
@phnt @fastfinge @arcanechat @jae see, this is extra fascinating to me because my experience with XMPP clients in iOS/MacOS was that they are universally terrible (maybe Monal is better now, but it was SO UGLY for years and years)

Everyone just said "lol, get an Android XMPP is great here we have Conversations it's so good"

and they're right, it
is a good client. Very high quality.

But that client is dead in the water these days and still only supports OMEMO v1

so... the XMPP ecosystem continues to be irreparably fractured.
0
0
1
0