@Aaron 😂😂😂😂😂 the irony burns
People will continue to send e-mail. There is no way this goes away antime soon. People will send sensitive stuff via e-mail.
We can spend time discussing just how exactly people should not use e-mail, or we can build a system that works.
I like the ideas behind PEP and AutoCrypt. I'd like to see them implemented in more clients.
@jerry @rysiek @Aaron
I have a feeling that right now, SMTP has the biggest adoption of all federated messagning protocols, and the second place is far far behind. Of all the new communication protocols I've seen recently, they're either popular, or federated, not both. And trying to get your new protocol adopted not just by people for their private communications, but also by companies, govts, and orgs for their internal and external communication is going to be extremely hard.
It's freesoftware with multiple GUIs, and is quite similar to Briar. Except they do allow adding remote contacts (though sharing the pubkeyhashes to do so may not be practical for most), and they've made superficially different protocol decisions.
At the same time I don't know what I'd recommend instead. I like the freesoftware p2p, but Briar doesn't appear to fit my usecase (besides I'd prefer a smaller codebase to audit, it looks quite bloated).
Maybe I'll lean more on Matrix or XMPP? But then a loose the metadata encryption I'd love to play with.
Also RetroShare seems interesting, but also bloated.
I am not concerned about Briar's codebase. People working on it are as solid as they come, and Briar went through an audit already. More problematic is the model of establishing contact, which requires physical presence or a common friend. I like how secure it is, but I understand how annoying it might be at times.
For me personally Briar looks good.
@rysiek @alcinnz @jerry @Aaron
I'm not a fan of Matrix. From what I've heard, they have a terrible server implementation, and nobody else tries to make their own implementation because Matrix changes the s2s protocol too often.
Also, I've heard there's a thing called Secure Scuttlebutt, haven't looked into it, but it may be relevant here.
@Wolf480pl @rysiek @jerry @Aaron@boringpeople.org I do kind-of have questions about Matrix. From a distance it kind-of looks like they decided to reimplement XMPP with the latest fashion of JSON. And I still have to explore it's encryption situation.
As for SSB I'm starting to look into it, particularly with Git-SSB. And from what I've seen, the tech looks very elegant when dealing with group comms or reliability despite the clients. Though again I have to look at the encryption again.
First off I'm aware that the routing metadata is quite sensitive information, and am keen on seeing ways to encrypt it.
And second while I by no means think everything should be p2p, I do think messaging should be. This comes down to a concern that unless given a practical reason otherwise I worry everyone will use the same server.
As for the personal auditing, it's something I like to make a habit of. Not that I seriously trust myself to catch many or any issues, but nor do I trust enough auditing is done. And I be no means trust myself with auditting crypto, the most I really can do is say "yeah, that kinda looks like crypto". I'm glad you trust the devs.
FLOSS.social was launched on 1 April 2018 as a Mastodon instance for people who care about, support, or build Free, Libre, and Open Source Software (FLOSS). Of course, discussions aren't limited to just FLOSS -- let's share our unique interests! English is preferred for maximum conversation opportunities within the FLOSS community, but it is not required. Respect is required, however: Users on FLOSS.social agree to abide by the Contributor Covenant Code of Conduct. This service was installed and is maintained in part by Masto.Host with equipment located at OVH. You can support this instance financially through the Monthly Supporter Program, processed through CommitChange using the free software Houdini Project.