XSF Discussion - 2017-02-17


  1. SamWhited

    I wonder if we could use this for gathering IPR releases from people automagically (and only the first time for all future submissions): https://cla-assistant.io/

  2. moparisthebest

    Hmm I don't think I ever did that

  3. SamWhited

    Oops…

  4. Ge0rG

    moparisthebest: > so based on a clients support or mix or not, could a server allow them into a mix channel if supported or throw them into some type of muc compatibility layer for the mix jid if not? This is exactly what I'm asking for for half a now! :)

  5. jonasw

    hyvää päivää, guten morgen, god morgonen, good morning, bonjour!

  6. Ge0rG

    jonasw: you forgot the UGT zone reference 😜

  7. jonasw

    I was busy with remembering swedish and french ;-)

  8. jonasw

    *(UGT)

  9. jonasw

    moparisthebest: would you prefer language comments to your XEP(s) as comments on github, PRs or via email?

  10. nyco

    @all how much have we (the XMPP communities) discussed around zero-knowledge messaging in the past?

  11. moparisthebest

    jonasw: any are fine but PRs are probably the least work for me so I'd prefer those :-)

  12. moparisthebest

    nyco: what is that? Haven't heard that term applied to messaging before...

  13. nyco

    moparisthebest, well that is indeed the same, but applied to messaging, some pretend to do that, not sure of the details

  14. moparisthebest

    It doesn't quite make sense to me when applied to messaging, remote file storage yes, messaging no...

  15. nyco

    basically no metada that allows to build some social graph?

  16. moparisthebest

    Ah so it just means protecting metadata from the servers?

  17. nyco

    moparisthebest, maybe more, as I said, not sure about the details

  18. moparisthebest

    That seems impossible with xmpp

  19. nyco

    so, for XMPP, for example it could be with MAM nor Offline

  20. nyco

    and anonymous connections

  21. moparisthebest

    That's just data

  22. nyco

    plus some kind of encryption

  23. nyco

    and no logs

  24. moparisthebest

    And yea so listening via tor

  25. nyco

    tor is just blurring tracks, not removing them

  26. moparisthebest

    No logs isn't something enforceable though, it's just trusting people...

  27. nyco

    so not zero-knowledge, but minimal-knowledge, indeed

  28. moparisthebest

    The only metadata free type of messaging I know about just kind of publishes huge blocks of encrypted data at regular intervals to something public

  29. moparisthebest

    So it's not instant messaging, more like email

  30. nyco

    interesting

  31. moparisthebest

    And a lot of wasted data and such but point is an onlooker doesn't know who the data is for, how much, or if it's actually anything at all

  32. moparisthebest

    Now what was that called.....

  33. nyco

    so, how about some sort of guidelines document, where we describe how to do: minimalist logs, no offline, minimalist mam, e2e encryption, perishable messages

  34. moparisthebest

    Is offline/mam a problem with e2e?

  35. nyco

    not sure about this question: I guess it is needed to buffer some messages in case the guys are not online, for later reading?

  36. nyco

    "buffer", like in "temporarily store"

  37. moparisthebest

    https://en.m.wikipedia.org/wiki/Ricochet_(software) that's one solution

  38. moparisthebest

    Xmpp could be used the same way

  39. moparisthebest

    Where each user has their own server listening on a .onion domain

  40. moparisthebest

    I didn't read this yet but a paper about metadata conscious instant messaging http://jmlr.org/proceedings/papers/v48/fanti16.pdf

  41. moparisthebest

    Another https://www.cs.cornell.edu/~tyagi/papers/stadium.pdf

  42. moparisthebest

    https://www.microsoft.com/en-us/research/video/charles-river-crypto-day-building-anonymous-messaging-systems-that-hide-the-metadata/

  43. nyco

    oh nice

  44. nyco

    doing "fast search engine based research" in parallel: some instant messaging apps pretend to do zero-knowledge, but this is just "hey we can't read your stuff, you are protected from us"