Hacker Newsnew | past | comments | ask | show | jobs | submit | zajio1am's commentslogin

I have no problem with that with XMPP. Conversations automatically reconnects after each switch within few seconds, so it is transparent for users. On IRC that is huge pain, true.

Conversations also supports Android's/Google's push notifications.

I use XMPP (with OMEMO) extensively and my main problem with it is absence of some basic key trust chains and bad handling of group chats

1) With OMEMO, each client/device of a user has its own key, but there is no trust relationship between them or some common master key. I can verify and trust counterparty key, but then counterparty adds another client/device and i have to do manual verification again.

2) Group chats do not have group key, but one encrypt messages for each group member (pairwise), which means that everybody has to do key exchange with everybody. This does not scale, especially with 1), which means that even if membership is stable, new keys may appear. Some clients (Conversations) do not allow to send message to a group when they do not know some keys of some group members/devices, which is fail situation that happen pretty often.


1) I think that's by design: you've got two ways to use OMEMO, the "friendly (default)-way" (with BTBV, Blind Trust Before Verification), and the "paranoid-way" (where you verify each and every device). In the latter, you don't want your messages to be encrypted for a new, unverified device (as it could potentially be that of an attacker): you can either verify the new device yourself, or your contact can verify theirs and you verify them again. Like I said, that's not for everyone. And if you are not that paranoid, then verification is an afterthought anyway and you don't lose or gain much with verification anyway.

2) That's where MLS¹ kicks in, essentially a new encryption scheme that's suitable for large group chats. There are projects² for its adoption in XMPP. I have no strong opinion about MLS, but I tend to think that it's more for the gimmick and having XMPP score well in random protocol benchmarks: if you've got such a large groupchat that OMEMO doesn't scale anymore, you have a groupchat with so many participants that it is only private in name and more or less encryption doesn't matter.

¹: https://en.wikipedia.org/wiki/Messaging_Layer_Security

²: https://nlnet.nl/project/XMPP-MLS/


I've tried designing an E2EE group chat system before and ran into all of these. They're not impossible to solve but are very hard. Telegram's official docs shrug off multi-device E2EE too, calling it a "mess."

When i worked in small ISP, i did some stats on customer accounts (about 2k customers) and only about 10% was @gmail.com. But it was 5 years ago and in EU.

How many web.de and free.fr?

None/negligible. It was ISP in Czechia, about 50% was @seznam.cz, 15% together two smaller local freemails, 10% @gmail.com, 25% individual/unique domains.

Why? Here, being registered has significant benefits (direct benefits and health insurance paid by state) and minimal costs (once a month visiting labor bureau, doing some minimal effort) that only people i know that are unemployed and not being registered are ones with psychiatric conditions.


Well, loss of (control over) shared narrative was one of complains of the Church against the printing press ...


And institutional control of information didnt really start again until the Statute of Anne struck up a deal between printers and the state giving printers copyright over written works and the state the right to cencor and ban works the disapproved of nearly 250 years latter.

Radio gave us Demagogues like Father Coughlin in the US and Hitler in Germany, and we still havent dealt with the problems radio introduced when television came along and now we have the internet with social media, podcast, and algorithmic echochambers, and algorithm induced radicalization. Radio television internet any one is just as much a shock to society as print was and we still havent figured out how to adapt yet to any fully.


> AI will kill the internet because it is killing the incentive to make it.

You could make the same argument for Wikipedia (that webs get less traffic if people get their answers from Wikipedia article returned as the first from web search, which is based on internet sources).


But Wikipedia has done a good job of it. If Google's AI summaries could actually provide correct answers with verifiable sources without so-called hallucinations, it would be good. You could argue that people don't actually check Wikipedia's sources. That's because Wikipedia has built, and worked to keep, its users' trust. On the other hand, what is Google doing?


I don't think that follows. Wikipedia's sourcing rules overwhelmingly favor publications released for non-pageview-based purposes (academic writing, books), or journalistic productions (whose pageview-based revenue is almost entirely earned right after they're released, and where Wikipedia's reference to them is primarily of value later on). Also, Wikipedia's nature as a structured, not-seeking-engagement index of info means that a lot of people who seek it out are folks who wouldn't (for whatever reason) fall back to giving other sites pageviews if it didn't exist.


The replication crisis is not limited to psychology, that was just the first area where it was noted. I saw some meta-study comparing multiple social sciences and according to it replication failure in sociology and educational science was even worse than in psychology.


Unfortunately it also is present in medicine, chemistry and increasingly physics.


And now the union is an organization whose sole purpose is to ensure that management cannot do anything with it (as any significant reduction of expenses means significant reduction of workforce).


When we started wireless ISP in in early 200x, it was common to run 2.4 GHz links with 5+ km distance, having 24 dB antennas on each side. with the basic 17 dBm radio one was 20 dB over EIRP limit...

Here in Czechia, there was also another unlicensed band, 10.5 GHz, that has more sensible regulation - instead of EIRP limit, there was PA limit (power before antenna). So one can do long-range links with large enough antennas and most long range links was later converted to these. Unfortunately as this is local unlicensed band, radios for that were orders of magnitude pricier than generic wifi.


There are already semi-autonomous drones in Ukraine.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: