this post was submitted on 05 Jul 2023
-21 points (37.0% liked)
Technology
59181 readers
2931 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Exactly my point is that if it closes we will have to push for new apps anyway and it is better to do it now, before more users potentially use SIgnal and are left without their app.
Personally I don't think it's likely that signal will close, or that they will sell out. I think the more likely problem is the sort of thing I mentioned, that having a single dev team will be a bottleneck or will reduce user choice. The iOS backup thing I mentioned is one example of that. Usernames rather than phone numbers is another one. Having only one code base does make it easier to audit. And having one foundation in charge does mean there's an easy path to pay for those audits. But it is still a single point of failure.
To be clear- as single point of failure go, I trust Signal more than the next 10 put together. What I don't trust is the whole using phone numbers and SMS verification for sign up. And I would prefer their architecture was a bit more open/federated.
I disagree. There are many FOSS decentralized projects that are still running today, including XMPP, that are doing fine and make even better and more secure software than Signal. All centralized privacy apps so far closed or started sharing data with governments. Statistically that is far more likely scenario then a popular FOSS app to lack devs.
I agree that there's plenty of FOSS projects as good as or better than Signal from a crypto POV.
NONE of them are anywhere close to signal when it comes to number of users. And if your friends don't have it, then you can't talk to anyone on it.
And if your friend loses their phone and finds out they just lost all their chats too, they're gonna say 'fuck that, I'll just use iMessage so next time I don't lose anything'.
Why would you trust Signal more than XMPP that uses same encryption? I think people are just afraid of things they haven't heard of, even if they have been there for longer and have a better reputation. This is why marketing is the biggest business in the world, google and facebooks only revenue is selling ad space and they are richest companies in the world. Fight that marketing, learn a bit about XMPP and you will see it is far better than Signal.
I tried hard to push XMPP back in its day. Little success sadly, that was when IM was going out of style in favor of SMS. I kept using Trillian and watching as more and more contacts went offline never to return. Then Google announced they were killing their XMPP gateway and that was a nail in the coffin.
The bigger problem with XMPP was varying support of various XEPs leading to an uneven user experience with mismatched clients. That in itself was fixable, and not a problem for people like us, but it became a problem when trying to get 'normies' interested. Tell someone like us 'you can't video chat that guy, his client doesn't have calling capability' and that makes perfect sense. Tell an average person that, and they hear 'this system sucks and I can't count on it to do what I want, I should stop using it'. Then they go on Discord or iMessage or whatever, and it works right the first time every time, and they stay.
And therein lies the real problem. You and I can wax poetic about the pros and cons of this or that system and its security, but if I can't get my non-cryptohead friends to use it, then it's worthless.
And THAT is why Signal succeeded and XMPP failed. Because it's dead fucking simple to set up. Download the app, punch in the SMS security code, and you're online. Questions like 'choose which client software you want' or 'pick which instance you want to sign up with' kill adoption for average non-techie people. They say 'I don't know what to choose, I don't want to choose wrong and cause a bigger problem, so I'll just not choose and close this'.