Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I feel like we should create an open source P2P chat messaging with encryption thats super easy to use so that these kind of laws become pointless. Empower criminals so that they cant use this excuse to target civilian infra.


Just run your own XMPP server in your own domain, use OMEMO for encryption and you're set. You can communicate with others on other servers, none of them 'publically available' and the TLA's can stare at all that encrypted gibberish 'till the cows come home. Even if they break into a single server they won't get access to the cleartext, for that they'll need to access the terminal devices - phones, browsers, etc.

This is how I've been communicating for years now, it works fine and does not feed any of the data parasites out there.


And what are you going to do when they write a law that requires ISPs to drop any packet that lacks a digital signature from a trusted hardware manufacturer?


We're not there yet, by far. Should that ever happen it will be circumvented just like nearly all technological measures are.


until there is a user friendly app like messenger or whatsapp, nobody is going to use these.


I don't think that's the issue, plenty are already. The issue to me is I'm not going to use something my friends/family aren't using. Maybe something matrix like where many clients are interoperable will work? I still think to take off it would need to support being a frontend for imessage/whatsapp/messenger too or no one will start using it, in a similar way to how imessage falls back to sms, this theoretical app could fall back to whatever shared app the two contacts have.


Matrix is overly complicated for the purpose and XMPP/OMEMO already are interoperable between many different clients. Just like all other communication systems it is the network effect which makes them usable. Tell your friends to install a client of choice and - for those so inclined - run a server or create an account on one. Keep your current W/app or Telegram or whatever active for now while you slowly move more communications to XMPP. Once you have contact with most of your friends and family via XMPP make it your default wat to communicatie, i.e. do not start conversations over the legacy apps and answer those who contact you over them through XMPP. You'll find that you'll end up using those legacy apps less and less. Keep them active if you want but don't initiate conversations over them and you'll be set for the moment using those services becomes untenable.

This is not just fiction, it is what I have done and am still in the process of doing, in my case moving from Telegram - I never used nor will I ever use things which requires accounts run by metafacebook or Google or Microsoft or any of the others.


Conversations on Android and forks thereof are comparable to eg. W/app. This is not a problem, at all.


The device is under the power of law. You can already see it on iOS and Android is pushing for it too.

You will only be allowed to install "approved" applications, your device, not your choice anymore.


Next, they will add some kind of verified signature that must be signed by a trusted third-party provider to the PWA spec and only allow the installation of such on Android


> open source P2P chat messaging with encryption

Tox/aTox [0][1] fits that description and both continue to be developed.

> Empower criminals so that they cant use this excuse to target civilian infra.

According to one webinar from CSIAC (2023) [2], XMPP is popular with Tox slowly catching up.

[0]: https://github.com/TokTok/c-toxcore

[1]: https://github.com/evilcorpltd/aTox

[2]: https://csiac.dtic.mil/wp-content/uploads/2023/03/CSIAC-Webi...


Tech is already there. It's just that it is 100 people use it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: