Take control of your data, join the tech chat. Host an XMPP server and leverage end-to-end encryption for your personal data

  • litchralee@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    31
    arrow-down
    6
    ·
    edit-2
    13 days ago

    When I see E2EE and XMPP mentioned, I think of this blog post by Soatok, outlining some very odd cryptographic choices in XMPP + OMEMO: https://soatok.blog/2024/08/04/against-xmppomemo/

    I would very much like to see a richer playing field than just Signal for private messaging, but it’s a tough nut to crack. For exactly which aspect that turns me away from XMPP for E2EE, I think this nails it down:

    you only need check whether OMEMO is on by default (it isn’t), or whether OMEMO can be turned off even if your client supports it (it can).

    When the competition is Signal, these sorts of details matter a lot.

      • StarkZarn@infosec.pubOP
        link
        fedilink
        English
        arrow-up
        7
        arrow-down
        1
        ·
        12 days ago

        This is also a great article! Thanks for the link.

        One cool point in favor of XMPP is that in a public setting (MUCs), there’s community. Moparisbest is an active participant in several of the MUCs that I’m in. Very cool!

    • StarkZarn@infosec.pubOP
      link
      fedilink
      English
      arrow-up
      7
      ·
      13 days ago

      This is great, I have not seen this post before. Thank you for sharing.

      You make an excellent point here, that the burden of security and privacy is put on the user, and that means that the other party in which you’re engaged in conversation with can mess it up for the both of you. It’s far from perfect, absolutely. Ideally you can educate those that are willing to chat with you on XMPP and kill two birds with one stone, good E2EE, and security and privacy training for a friend. XMPP doesn’t tick the same box as Signal though, certainly. I still rely heavily on Signal, but that data resides on and transits a lot of things that I don’t control. There’s a time and a place for concerns with both, but I wanted to share my strategy for an internal chat server that also meets some of those privacy and security wickets.

      • mistermodal@lemmy.ml
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        4
        ·
        13 days ago

        Never cared for the way this fellow tries to argue that everything is too difficult to be useful. I’ve gotten plenty of friends and family on XMPP and the clients that don’t have encryption on by default are easy to remember. Really blowing it out of proportion.

        Honestly, what do security researchers like this even know about normal people? They sit through all kinds of inconveniences to use Facebook. This is a thought experiment.

        Some of these are valid criticisms, of course, a lot of XMPP stuff feels like it from the 2010s. It’s still the only real option. Matrix client or server is bloated garbage, theu moved server fixes into a walled garden, its development is dependent on funding from the USA National Endowment for Democracy technology fund. Signal has similar funding issues and is very shady with its centralization, trust issues, demanding phone numbers. Sets users up to leak all kinds of stuff in notifications like Matrix.

        The strange insistence that only Signal meets their requirements makes me skeptical, as does the way they have operated in Github threads. They seem like an emotional nightmare to work with.

    • Swedneck@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      2
      ·
      12 days ago

      have you looked at simplex? at a glance it seems robust and it actually works without much fiddling which is nice.

      • StarkZarn@infosec.pubOP
        link
        fedilink
        English
        arrow-up
        1
        ·
        12 days ago

        I have experimented with Simplex, but it feels less tuned toward hosting federated infrastructure and more tuned toward participation with the greater network in a pseudo-anonymous fashion.

        Adoption is also always a hurdle with any ecosystem like this, and XMPP is certainly ahead of Simplex in that avenue.