this post was submitted on 05 Jul 2023
-21 points (37.0% liked)
Technology
59188 readers
2126 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
How do I trust a random XMPP server more or as much as I trust Signal to protect my data? You’re telling me if the government comes knocking for metadata on some user on a small server that the owner isn’t going to just give it away? What about anyone else on other connected servers?
You’re asking me to trust someone who hasn’t shown that they’re actively working towards privacy goals vs a centralized solution from a company that’s shown they care about privacy?
Either way, you have to trust someone to take care of your data and I do not trust a small server owner more than an entity that’s proven they do not give information to governments. Gotta pick one of two evils, I guess.
I never claimed that you should pick a random server. You can pick servers run by groups that have just as good record of privacy or even better or are run by the person you know or yourself.
When you have a decentralized service you can choose who you trust, you are not stuck with one corporation. Picking a completely random server is the worst possible example you could have chosen.
Maybe I’m misunderstanding XMPP but does it not federate? Does it not mean that on top of trusting my home server I have to trust the choice other people made with theirs?
Why would you need to trust their choice? The only data that is sent from your server to theirs is your username (called JID in xmpp terms) and E2E encrypted message. The worst thing their server can do to yours is to send you a message, if your server decides to pass it on.
Wouldn't you have to trust that they're not logging your IP and/or storing your messages?
XMPP clients support end to end encryption, so the servers only get encrypted messages. Also unlike Signal, XMPP clients support use of Tor to hide your IP.