Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Admin, DevOps, Security
  3. Chat Protocols and Apps
  4. THE CHAT PROTOCOL OF THE FUTURE

THE CHAT PROTOCOL OF THE FUTURE

Scheduled Pinned Locked Moved Chat Protocols and Apps
29 Posts 8 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

    @kkarhan @tapafon

    the scope is that western democracy is in a state of freefall and we are actively losing ground to fascist oligarchs in both the US and EU.

    in such a scope, cute toys like OMEMO and IRC's blowfish scripts and things of the same shape like Matrix's OLM/MegOLM do not provide an acceptable level of personal assurance.

    telling people to depend on these technologies as a security engineer is malfeasance.

    Signal also is not truly good enough (because it is proprietary), but it is at least accessible to non-technical people and cryptographically sound.

    the real answer is Tox, but somebody needs to build the plumbing to make it accessible to non-technical people.

    tris@chaos.socialT This user is from outside of this forum
    tris@chaos.socialT This user is from outside of this forum
    tris@chaos.social
    wrote last edited by
    #21

    @kkarhan @tapafon@soc.ua-fediland.de @ariadne Isn't Tox that P2P thing? There's @cwtch developed by amazing folks like @sarahjamielewis

    ariadne@social.treehouse.systemsA 1 Reply Last reply
    0
    • tris@chaos.socialT tris@chaos.social

      @kkarhan @tapafon@soc.ua-fediland.de @ariadne Isn't Tox that P2P thing? There's @cwtch developed by amazing folks like @sarahjamielewis

      ariadne@social.treehouse.systemsA This user is from outside of this forum
      ariadne@social.treehouse.systemsA This user is from outside of this forum
      ariadne@social.treehouse.systems
      wrote last edited by
      #22

      @tris @kkarhan @cwtch @sarahjamielewis yes. Cwtch would also work, but I am less familiar with it. It also needs plumbing for non-technical people.

      BBM worked with fingerprints back in the day because PGP fingerprints were 32-bit at the time. Asking non-technical people to memorize 100s of bits of public key material isn't going to work.

      kkarhan@infosec.spaceK 1 Reply Last reply
      0
      • kkarhan@infosec.spaceK kkarhan@infosec.space

        @tapafon @ariadne @Monal personally, It's best to trust noone…

        @monocles for examole is a good client and they certainly do iffer a great service but I don't expect any admin if any server to choose death or prison over snitching.

        monal@fosstodon.orgM This user is from outside of this forum
        monal@fosstodon.orgM This user is from outside of this forum
        monal@fosstodon.org
        wrote last edited by
        #23

        @tapafon @ariadne @monocles @kkarhan sure, but you talked about honeypots and controlled opposition and that's normally not true for the people I mentioned.

        Also, albeit a bit philosophical, you always have to trust someone. You seem to make the cut at the client side (so you trust the client developers to not sneak some surveillance code in) and I make the cut somewhere on the server side, not trusting all servers, but some 🙂

        ariadne@social.treehouse.systemsA 1 Reply Last reply
        0
        • monal@fosstodon.orgM monal@fosstodon.org

          @tapafon @ariadne @monocles @kkarhan sure, but you talked about honeypots and controlled opposition and that's normally not true for the people I mentioned.

          Also, albeit a bit philosophical, you always have to trust someone. You seem to make the cut at the client side (so you trust the client developers to not sneak some surveillance code in) and I make the cut somewhere on the server side, not trusting all servers, but some 🙂

          ariadne@social.treehouse.systemsA This user is from outside of this forum
          ariadne@social.treehouse.systemsA This user is from outside of this forum
          ariadne@social.treehouse.systems
          wrote last edited by
          #24

          @Monal @tapafon @monocles @kkarhan you don't have to blindly trust clients that are libre, as they will get audited.

          kkarhan@infosec.spaceK 1 Reply Last reply
          0
          • kkarhan@infosec.spaceK kkarhan@infosec.space

            @ariadne /me laughs in #PGP/MIME & #XMPP+#OMEMO

            wojtek@social.vivaldi.netW This user is from outside of this forum
            wojtek@social.vivaldi.netW This user is from outside of this forum
            wojtek@social.vivaldi.net
            wrote last edited by
            #25

            @kkarhan @ariadne riiight… because OMEMO works so well! /s xDDDD

            kkarhan@infosec.spaceK 1 Reply Last reply
            0
            • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

              @tris @kkarhan @cwtch @sarahjamielewis yes. Cwtch would also work, but I am less familiar with it. It also needs plumbing for non-technical people.

              BBM worked with fingerprints back in the day because PGP fingerprints were 32-bit at the time. Asking non-technical people to memorize 100s of bits of public key material isn't going to work.

              kkarhan@infosec.spaceK This user is from outside of this forum
              kkarhan@infosec.spaceK This user is from outside of this forum
              kkarhan@infosec.space
              wrote last edited by
              #26

              @tris @tapafon @cwtch @sarahjamielewis @ariadne Until then, there needs to be something that actually works, is easy to self-host and transition to as a first step.

              • Granted, one could do a fully-decentralized system to a degree, but either way anything would necessitate teaching #TechLiteracy to the people.

                • Otherwise we run into the same problems #GnuPG and Finale did.

              Call me weird, but that's sadly not a new problem either!

              kkarhan@infosec.spaceK 1 Reply Last reply
              1
              0
              • kkarhan@infosec.spaceK kkarhan@infosec.space

                @tris @tapafon @cwtch @sarahjamielewis @ariadne Until then, there needs to be something that actually works, is easy to self-host and transition to as a first step.

                • Granted, one could do a fully-decentralized system to a degree, but either way anything would necessitate teaching #TechLiteracy to the people.

                  • Otherwise we run into the same problems #GnuPG and Finale did.

                Call me weird, but that's sadly not a new problem either!

                kkarhan@infosec.spaceK This user is from outside of this forum
                kkarhan@infosec.spaceK This user is from outside of this forum
                kkarhan@infosec.space
                wrote last edited by
                #27

                @tris @tapafon @cwtch @sarahjamielewis @ariadne as for #BlackBerryMessenger: That shit had #Govware #Backdoors (otherwise it would've never been legal in most juristictions!)…

                Link Preview Image
                BBM (software) - Wikipedia

                favicon

                (en.wikipedia.org)

                1 Reply Last reply
                1
                0
                • ariadne@social.treehouse.systemsA ariadne@social.treehouse.systems

                  @Monal @tapafon @monocles @kkarhan you don't have to blindly trust clients that are libre, as they will get audited.

                  kkarhan@infosec.spaceK This user is from outside of this forum
                  kkarhan@infosec.spaceK This user is from outside of this forum
                  kkarhan@infosec.space
                  wrote last edited by
                  #28

                  @Monal @tapafon @monocles @ariadne neither should one trust the infrastructure either...

                  1 Reply Last reply
                  1
                  0
                  • wojtek@social.vivaldi.netW wojtek@social.vivaldi.net

                    @kkarhan @ariadne riiight… because OMEMO works so well! /s xDDDD

                    kkarhan@infosec.spaceK This user is from outside of this forum
                    kkarhan@infosec.spaceK This user is from outside of this forum
                    kkarhan@infosec.space
                    wrote last edited by
                    #29

                    @ariadne @wojtek not great, but not terrible either.

                    • nit logging comms is a feature!
                    1 Reply Last reply
                    1
                    0
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups