← Back to context

Comment by AceJohnny2

1 day ago

"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/

That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/

In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardize and document, 3- I reserve the right to change the deal for whatever reason if I ever feel the need" which is not a good look

  • Matrix is a vastly different protocol with vastly different privacy implications. Things like leaking reaction metadata outside of the encrypted envelope (though there finally is an MSC to fix that) should make that obvious. Matrix is cool tech and I use it every day, but comparing Matrix to Signal doesn't make much sense. You can't do what Signal does with Matrix or XMPP, simply because the lack of federation affords privacy and security advantages that federated protocols cannot support.

    As for Moxie's post: all three points feel completely valid for a service they're offering for free. Moxie does know better than most users (most users don't know the first thing about software, programming, protocol design, or UX design) and it's a companies choices that drive users to their platform in the first place. Users who don't like it can choose from the dozens of other chat apps instead.

    As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix servers. On the XMPP side, there are two different methods of achieving E2EE communication, with seemingly no standard mechanism to support the use case "I want to log in to my chat on my laptop and be able to decrypt the messages in the group chat". I can't blame Signal for not wanting to deal with issues like that. One piece of server software, one set of client versions, with fixes ready to deploy when they're called for: Signal's current design saves a lot of time and effort.

    As for the third point, that's part of the reason I use Signal in the first place. I like federated networks as much as the next nerd and I like open standards even more, but the decisiveness behind the company, even when I disagree with their decisions sometimes, is what makes it clear what you can and cannot expect.

    On the XMPP defence: yes, I believe what they are saying, XMPP could in theory be a good product, just like Matrix could be, and like Signal is. However, currently, it isn't. XMPP is currently losing in terms of public marketshare to Matrix, which I also wouldn't exactly call a great success.

    • > As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix servers.

      could you expand on this in detail?

      1 reply →

  • As a former XMPP believer, I will say that the extremely fragmented capability state of the XMPP ecosystem, whatever people may claim, is the exact proof that vindicates Signal's position.

    • As a XMPP user in the modern times, XMPP ecosystem and its alleged fragmentation affects me and my users about… never. Every major platform has at least one decent client that support all essential features (reactions, message corrections, A/V calls, easy onboarding, modern encryption, …) and every one of them receives a healthy flow of contributions. Client developers talk to one another, coordinate protocol discussion and features roll-out (reactions for instance didn't happen "overnight", but pretty close).

      I'm certainly not willing trade a theoretical minor annoyance in exchange for my (literally) vital messaging needs to be subject to enshittification, or abuse by a single actor (which controls whether I can access the network, when, whom I can speak with, what features I am allowed to use, and whether it's time to rope me into buying some cryptoshitcoin).

  • what does debunked here mean? like I can right now go on websites with firefox or safari and they will not be displayed properly. I do personally think federation is worthwhile, but I think it's a bit much to say Signal only cares about power and that all their reasoning for what they did are debunked or w/e.

I've attended the eponymous CCC talk and I've never seen any other talk there where the Q&A section has just immediately turned into nearly everyone almost dunking on the presented ideas. It's a rather poor take (or at least "controversial" if you will).