• ProdigalFrog@slrpnk.net
    link
    fedilink
    English
    arrow-up
    34
    ·
    edit-2
    1 day ago

    Slrpnk hosts an XMPP/Jabber for our users, mods and admins to communicate. Its worked pretty darn well for the past couple years, with very low resource needs.

    The clients are pretty slick now too, such as Cheogram or Monocles for mobile, and movim is an excellent web app with support for group calls.

    I’d certainly recommend it over Matrix/element.

    • Ulrich@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 hours ago

      The clients are pretty slick now too, such as Cheogram or Monocles

      I wouldn’t call either of those, or any other XMPP clients “slick” and it’s my biggest complaint about the protocol.

    • muppeth@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      11 hours ago

      Not to mention you can run a server on anything pretty much and for surprisingly big amount of users. Toaster or potatoes will do just fine.

      • poVoq@slrpnk.net
        link
        fedilink
        English
        arrow-up
        14
        arrow-down
        2
        ·
        1 day ago

        Significant improvements to certificate pinning and validation have been added to all major XMPP clients as a result of this incident, but it should also be clear that hosting a server on infrastructure under control by an antagonist government (see also Signal) is a very bad idea and hard to mitigate against.

          • poVoq@slrpnk.net
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 hours ago

            Their server infrastructure is (run by Pentagon and NSA best buddies AWS).

              • poVoq@slrpnk.net
                link
                fedilink
                English
                arrow-up
                2
                arrow-down
                1
                ·
                edit-2
                2 hours ago

                The infrastructure is under control of an antagonistic government, yes. Hetzner is also technically a private company, but they obviously willinhly complied with requests from the German government.

                • Ulrich@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 hours ago

                  And what are the implications of that control? It doesn’t mean they can access anything on it. Especially not data that doesn’t exist.

                  • poVoq@slrpnk.net
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    arrow-down
                    1
                    ·
                    2 hours ago

                    They have live access to all of the metadata and can easily correlate that with phone numbers that Signal stores and shares on request of governments. Just because Signal claims they don’t store anything doesn’t mean that the ones that 100% run all the servers Signal uses don’t access and store anything. You are being extremely naive if you believe Signals BS marketing.

        • rottingleaf@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          1
          ·
          1 day ago

          Signal doesn’t suffer anything worse than DoS if a hostile party controls the central service. That’s its point and role. It’s based on the assumption that such hostile parties as governments don’t like DoS’ing central services, they prefer to be invisible.

          For other points and roles other solutions exist. One can’t make an application covering them all, that never happens.

          Briar again (I’ve finally read on it and installed it, and I love how it works and also the authors’ plans on the future possibilities based on the same protocols, but not for IM, say, there’s an article discussing possibility of RPC over those, which, for example, can give us something like the Web ; I mean, those plans are ambitious and if I want them to succeed so much, I should look for ways to defeat my executive dysfunction and distractions and learn Java). Except it would be cool if it allowed to toss data over untrusted parties, say, now if two Briar users in the same group are not in each other’s range, but there’s a third Briar user not in that group between them, their group won’t synchronize (provided they don’t have Internet connectivity). If one could allow allocating some space for such piggybacked data, or create some mesh routing functionality, then it would become a bit cooler.

          • poVoq@slrpnk.net
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            4
            ·
            1 day ago

            You are very naive if you think that is all the US government can do in regards to Signal, but suit yourself 🤷

              • poVoq@slrpnk.net
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                12
                ·
                1 day ago

                A lot, but please educate yourself, this topic has been extensively discussed here and in other places.

                • rottingleaf@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  12
                  ·
                  1 day ago

                  A lot, but please educate yourself,

                  Thanks for the advice.

                  this topic has been extensively discussed here and in other places.

                  This is noise, not an argument.

                  I dunno what’s the purpose of this comment. I asked for specific things, not for noise.

                  • jet@hackertalks.com
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    edit-2
                    15 hours ago

                    Whenever anybody on the internet tells you to educate yourself, but refuses to provide the information they allude to, they’re lying. They know they’re lying.

                    Signal has issues, like SVR… which are worth discussing on their own without this weird vague eliteism

        • eleitl@lemmy.zip
          link
          fedilink
          English
          arrow-up
          5
          ·
          1 day ago

          End to end encryption between clients (also for groups) seems to partly address the issue of a bad server. As for self-hosting, any rented or cloud sevices are very vulnerable to an evil maid. So either in-house hosting or locked cages with tamper-proof hardware remain an option.

      • ProdigalFrog@slrpnk.net
        link
        fedilink
        English
        arrow-up
        6
        ·
        edit-2
        1 day ago

        I’m afraid that’s quite outside my field of expertise. I can only report how my experience on XMPP has been as a user, though perhaps @poVoq@slrpnk.net, who hosts it, may be able to weigh in on that. Edit: ah, I see you already have 😄

        Though from my untrained eye, it seems that Jabber.ru was compromised due to not enabling a particular feature on their server

        “Channel binding” is a feature in XMPP which can detect a MiTM even if the interceptor present a valid certificate. Both the client and the server must support SCRAM PLUS authentication mechanisms for this to work. Unfortunately this was not active on jabber.ru at the time of the attack.

        And it seems that hosting it externally on paid hosting service (hetzner and linode) left them particularly vulnerable to this attack, and tgat it could’ve been mitigated by self hosting the XMPP locally, as well as activating that feature.