Email or username:

Password:

Forgot your password?
Top-level
Bindestrich

@wjmaggos depends on your threat model. I don't think the average user should be required to know a trustworthy admin. matrix is an option if you care for that.

6 comments
william.maggos

@Bindestriche

couldn't the people who run Signal instead run a Matrix server, along with Mozilla and Automatic etc? isn't that our better future, FOSS decentralized tech and lots of companies with principals that run these servers and we pay them a sustainable rate?

Bindestrich

@wjmaggos security in a decentralized service is hard. That is why email is the mess it is. if you don't want to cut of people, you need to use the lowest common denominator, which often is out of date and insecure

Bindestrich

@wjmaggos federation adds complexity which is the enemy of security. there is a reason why mastodon dm's are not end2end encrypted and it is not that msto defs are lazy.

Charles OuGuo

@Bindestriche @wjmaggos A good example of this: Matrix still hasn't rolled out fixes to all the Nebuchadnezzar vulnerabilities (homeservers control group membership and can add/remove members at will): nebuchadnezzar-megolm.github.i

This is in part because fixing anything in a decentralized system is hard! Fixing these required, AIUI, a protocol change, which is a nightmare when you don't control all the servers and clients.

Bindestrich

@wjmaggos getting back in the habit of paying for online services with money instead of data is a good development. but choice of provider is not a silver bullet. there are good reasons why we have central food health inspections. checking if a provider is trustworthy requires a skilset that should not be necessary to just use a messenger. just as I don't want to bring a lab in a restaurant just to know the food is save to eat.

william.maggos

@Bindestriche

there's two ways to ensure good service, democratic oversight/control or economic competition. neither are perfect. Signal seems great right now but I don't see the incentives for that to maintain.

I guess there's also dog fooding, that the people who rely on something have the power to keep it good. the model of lots of FOSS projects and Wikipedia I guess.

Go Up