this post was submitted on 19 Jul 2025
280 points (93.8% liked)

Technology

78121 readers
2670 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] eleitl@lemmy.zip 4 points 5 months ago (33 children)

What's the protection in the clients assuming compromised infrastructure, like e.g. in https://notes.valdikss.org.ru/jabber.ru-mitm/ ?

[–] poVoq@slrpnk.net 14 points 5 months ago (30 children)

Significant improvements to certificate pinning and validation have been added to all major XMPP clients as a result of this incident, but it should also be clear that hosting a server on infrastructure under control by an antagonist government (see also Signal) is a very bad idea and hard to mitigate against.

[–] rottingleaf@lemmy.world 6 points 5 months ago (9 children)

Signal doesn't suffer anything worse than DoS if a hostile party controls the central service. That's its point and role. It's based on the assumption that such hostile parties as governments don't like DoS'ing central services, they prefer to be invisible.

For other points and roles other solutions exist. One can't make an application covering them all, that never happens.

Briar again (I've finally read on it and installed it, and I love how it works and also the authors' plans on the future possibilities based on the same protocols, but not for IM, say, there's an article discussing possibility of RPC over those, which, for example, can give us something like the Web ; I mean, those plans are ambitious and if I want them to succeed so much, I should look for ways to defeat my executive dysfunction and distractions and learn Java). Except it would be cool if it allowed to toss data over untrusted parties, say, now if two Briar users in the same group are not in each other's range, but there's a third Briar user not in that group between them, their group won't synchronize (provided they don't have Internet connectivity). If one could allow allocating some space for such piggybacked data, or create some mesh routing functionality, then it would become a bit cooler.

[–] poVoq@slrpnk.net -2 points 5 months ago (2 children)

You are very naive if you think that is all the US government can do in regards to Signal, but suit yourself 🤷

[–] rottingleaf@lemmy.world 6 points 5 months ago (1 children)

OK, so what else in your opinion can it do?

[–] RaivoKulli@sopuli.xyz 5 points 5 months ago

Anything that's been proven/confirmed?

load more comments (6 replies)
load more comments (26 replies)
load more comments (28 replies)