p.enthalabs

Jabber/XMPP: 25 Years of Digital Independence

gultsch.de · Read Story HN original

Comments

> Matrix reinvented the wheel as a rubber-tyred metro. On paper, it provides real benefits, such as climbing steeper inclines, which are then used to aggressively advertise and lobby local governments to buy in. But in the end, the municipality gets locked into a single vendor.

I stumble upon Matrix from time to time, but Jabber I haven't really seen anywhere in the past decade after my internet friends moved to IRC. Are there any bigger communities still using it? Back in the days Facebook Messenger was backed by it, so maybe there's still some bigger entity using it as a backbone for something?

XMPP these days often gets used as a friends-and-family style messenger (Think WhatsApp, iMessage, Signal replacement) rather than something communities would use (Discord/IRC). A lot of users of XMPP are also out of the public eye. NATO, police forces and intelligence agencies use it. The community style channels are supported though and a search engine for them can be found here: https://search.jabber.network/channels/1
Yeah, I use it as a messenger for my wife and I.
> NATO, police forces and intelligence agencies use it

Is there anywhere to read more about this?

The existence of "XEP-0365: Server to Server communication over STANAG 5066 ARQ" suggests military usage. Isode advertises XMPP as "The NATO Standard for instant messaging" (https://www.isode.com/secure-xmpp/) and it is one of their core offerings. I remember seeing NATO command posts using IRC long ago - makes sense because it is ultra light, and therefore usable on extremely low bitrate degraded links... XMPP seems to be the successor for that purpose.

https://www.sigidwiki.com/wiki/XMPP_trials says "On shortwave, you can see the military use this protocol. They are known for using MIL 188-110A Serial HF waveform (fixed 600bps/S) and 6-bit code clear text with dual bursts of STANAG 4539 and STANAG-5066 as for XMPP Multi-User Chat (MUC) messages, over a bandwidth of 34 kHz. Multi-User Chat (MUC) is a central service for military communication. [..] XMPP is widely used for military deployments, where operation over constrained and degraded networks is often essential, particularly for tactical operation"

Thanks! That was exactly the kind of "hidden usage" I was interested in as it seems to not be publicly used by a lot of people these days (As you can see by the user numbers on https://search.jabber.network/channels/1).
Spam is an issue which also drives people off public federation.
Jitsi Meet still runs on XMPP, Prosody handles the signaling. WhatsApp also started life as a patched ejabberd.
WhatsApp is still based on XMPP unless things have changed a lot recently.
I don't consider WA a product. I don't consider it a viable product. Post-2014/Zuckerberg. Who cares if it's XMPP, it didn't federate
Unfortunately it's the de-facto messaging app for normies here, most of whom won't be willing to install another app for just that one weirdo.
The open protocol variant of that is called OMEMO. Same double ratchet and implemented using Signal's library (the same as used by WhatsApp) in many XMPP clients
> the same as used by WhatsApp

source? wouldn't that be a license violation?

WhatsApp paid WhisperSystems (the previous Signal company) for a commercial license. Same as Google. Dual-licensing their encryption protocol library was their main source of income back then.

AFAIK, even today you can fetch the WhatsApp Android apk, extract the zip and do a `strings classes*.dex | grep signal` to find class and package names matching the sources in the signal-protocol-java repository in the Signal GitHub.

The protocol is still their stripped down XMPP dialect, yeah. I meant the server side: they rewrote most of the original ejabberd over the years, but it stayed Erlang.
XMPP is somewhat popular on the fediverse, especially the Pleroma side. If you meet people there who want to chat elsewhere, they likely are on XMPP. Also if you have a Disroot account it comes with XMPP.
Its biggest issue is adoption because it's very solid otherwise and even supports stuff like screen sharing.
screensharing is ubiquitous at this point
I'm also working on experimental XMPP based remote desktop control for what it worth.
i set up a xmpp server a few weeks ago for agent orchestration and agent to human workflows. hadn't inatalled ejabberd in a very long time but feeling right at home.
And I haven't used XMPP for about 20 of them (sadly)
There was a time where both Google Chat (whatever it was called back then I lost track) and Facebook Chat were built on it. So you might have.
You're right. I know at least one company used XMPP for things like customer support chat too. So maybe I have. I just mean the last time I used it intentionally was a long time ago before I was worn down futilely trying to convince friends to use it instead of locked down chat apps.
That's fair, no worries.
Google Talk - and it was an actual federating XMPP server, in contrast to Facebook which merely allowed you to login with an XMPP client.
There was a point where Google and Facebook supported external clients, and then within the same year both Google and Facebook closed up to any external clients, then ultimately ditching XMPP.
It's a shame that we didn't get antitrust enforcement imposing interoperability requirements on them back then.
25 years of independence and, dare I say, irrelevance.
It was so cool when facebook, google and others used to use xmpp, at that time I used a single IM client https://adium.im
I had amsn when msn and yahoo messenger were the place everybody I knew was at.
I was on Miranda. It was tiny and portable (unlike Trillian) and could connect to pretty much every popular messaging service, including IRC. And in spite of being able to connect to everything, it used far lesser memory than even just a single instance of MSN and Yahoo. It was one of my go-to apps that I'd install on a freshly formatted PC back in the day.
This used to be one of the biggest Mac open source projects. I remember they demoed project builder (before Xcode) compiling it
Best chat client ever. Man we had it good back then.
One of my happiest open source memories was creating an Adiumy skin for my college and others actually downloading and using it. The app was huge. Those were the days.
Loved Adium and the community was great in building custom smileys (For the young people, that's how we called Emojis back in the days!), themes and dock icons.
I think Android still uses XMPP to delivery push notifications under the hood
Indeed. And on a Google-free Android phone the XMPP client Conversations can utilize its existing, permanent XMPP connection to deliver push notifications to other (mostly open-source) apps using an alternative to Google push (FCM) called UnifiedPush.

There was a talk at FOSDEM about that.

https://gultsch.video/w/gRGZqKKvNBvvMesyWNQzoK

Unless I'm mistaken, Apple's push notifications network ("APN") and a few other macOS/iOS under-the-hood things are also built on top of XMPP.
XMPP is the pinnacle of chat that just works. And it is champion by default, which is kind of the point here. All other popular systems and servers went defunct; it will never be taken over by BigCo and left to rot. Here's to 25 more years!
> XMPP is the pinnacle of chat that just works.

Not my experience. I had to give up on it since it was just completely flooded with spam, and unlike mail readers that have ways to mitigate it, XMPP clients were ill prepared. Might still work if you keep your address hidden, but as chat-like alternative to a public email it just stopped working years ago.

What do you mean? You have to accept a friend request before someone can message you. It's more spam-resistant than email, not less. That said, I don't know if there's anything that prevents spamming friend requests.
And how am I going to find the valid friend requests under the hundreds of spam ones? I used it just like a chat version of public email, for bug reports and such, so I don't know who is going to message me beforehand.
Fair enough. I've only ever used XMPP when Google chat used it and at work in the days before Slack.
You can mediate friends requests by having servers generate an invite link, you can generate QR codes your friend can scan on a side channel, ... There are ways
Or you can just show the welcome message from a new contact, just like anyone else does. Adding a 2nd factor here is the reason XMPP suck.
I think that's a symptom of the provider you chose, not the XMPP sphere itself. I've used Jabber/XMPP for just over 15 years and while I've seen plenty of bullshit going on in various highly popular MUCs (join-floods, phishing attempts and such) I've never personally been subjected to spam directed at me.
I have joined XMPP rooms via Matrix and have already gotten spam from XMPP this way
Which is surprising since XMPP allows you to hide your global address in public rooms and Matrix doesn't (unless they fixed it by now?).
> XMPP is the pinnacle of chat that just works.

No. It doesn't "just work". It very much depends on which subset of the XEPs all the parties in the chain support.

> All other popular systems and servers went defunct;

Well, in this sense it does just work :)

Unless you want to encrypt said messages. But I guess insecure communication beats no communication at all. (I also never had much luck with voice and video calls using XMPP.)
> XMPP is the pinnacle of chat that just works.

Except no.

You can't even have a conversation between Conversations and Fluux because OMEMO is enabled by default in Conversations and there is just no OMEMO support in Fluux - despite it being actually modern one.

Gajim works but Pidgin doesn't even show "I sent you an OMEMO encrypted message but your client doesn’t seem to support that". Just like images, which is a first party in Telegram and even WhatsApp.

So much for 'just works'.

And of course most XMPP clients which support OMEMO only support an old version of it, which is incompatible with the new OMEMO version, currently only supported by KDE’s own client—Kaidan. That also happens to be the only desktop client I feel like I’d actually enjoy using (if only I could use it to talk with people not using Kaidan).
FWIW Converse.js and Dino also support the latest OMEMO.
Oh, nice! It looks like Converse.js has added it just two months ago, but I haven’t been able to find anything for Dino (only complaints about as old as the latest release, about the newest OMEMO not being supported). Was it shipped very silently, or are they perhaps planning to add it in an upcoming release?
Looks like I might have been wrong about Dino, sorry about that.

I worked on adding OMEMO2 support to Converse.js via libomemo.js and I tested it against Kaidan.

Libervia (on which I'm working) does support OMEMO:2 (it was actually the first client to implement it) + legacy one + OX (OpenPGP) + OX for Pubsub (so you can encrypt everything pubsub related: blog, forums, tickets, etc). ()

Anyway, there is a discovery mechanism, and clients do adapt the version used by peers, so there is no incompatibility. Kaidan choose for a while to have only OMEMO:2, because resources are limited and they were going for the latest version first, but resource are limited for everybody, and it took times for others to implement OMEMO:2 too.

NLnet/NGI did (and still does) gave financial support on several XMPP projects (including mine, huge thanks to them), and, curiously, when there is money to help, implementations happen. That's problem nb 1 with XMPP: lack of financial resource.

(

) GUI (notably web UI) is being reworked, not stable yet, but the CLI is pretty solid.
Fluux is brand new and 100% vibecoded, so not surprising if it has some rough edges.
I regularly use IRC, XMPP, and Matrix. I think your description fits IRC better. XMPP kinda has a Plan 9 or Amiga type of vibe, cult following "ahead of its time", but never took off totally how people hoped, or didn't stay relevant at least.
> XMPP is the pinnacle of chat that just works

My limited experience is that it's not the case. When I tried to join a few rooms I got insulted because my client apparently used extensions that weren't supported by some XMPP enthusiasts' clients, so my client sucked and I had to change it and use an ugly one instead.

I'd rather get a feature-complete protocol than an extensible one, so that at least everyone can speak the same

That sounds like a problem with some assholes, not a problem with your software. I'm sorry assholes happened to you
Are there any XMPP clients with the UX and privacy of Signal?

All of them seem to look like they're from the 00s!

Thanks! Any good Android clients? "Conversations" seems to be the best and it's nowhere near the polish of Signal & Co. crashes often, UX is clunky, family will never stick with it.
What makes you think that? I haven't experienced, or heard of people having frequent crashes. Me and my family also use it to communicate to each other with no issues regarding the UI.
As a counterpoint, I use conversations literally every day, and cannot recall the last time it crashed. My partner and kids have used it for at least the last 7 or 8 years to communicate with me and each other. I don't claim there are no issues, but "crashes often" isn't something I would expect to hear about it.

I don't find the UX to be clunky either, but I acknowledge that could just be my familiarity with the program, so I would leave that for others to dispute.

Crashes?!? I've been using Conversations for a long time and can't remember any crashes. Something must be wrong with your setup.

For me, the bigger problem is that I was unable to get OMEMO + Apple Clients working properly. I think OMEMO 1 has some design flaws and hope that OMEMO 2 will fix those.

I ran into this exact problem. I needed to fork Conversations to add a lot of polish. My fork is definitely improved but still has a few rough edges I'm chipping away at.
Do you plan on contributing your improvements upstream, or is that not feasible for some reason?
Conversations doesn't crash at all for me.

And I moved to Conversations because I needed a client that wasn't as crashy as Xabber was for me.

Seriously? I'm not saying it's the best app around but the family uses Conversations and we never really have any real issues. Even for the septuagenarians in the family I just set it up once like 7 years ago and they still use it all the same.
I love XMPP and am hopeful for its future with what the teams behind Movim[0], and Fluux[1] are doing. It was a tremendous shame that Matrix didn't improve upon XMPP and instead did their own thing. I continuously wonder what would the XMPP ecosystem look like, if the millions of dollars of funding Matrix initially had (what a waste) went to XMPP instead?

[0]: https://movim.eu/

[1]: https://github.com/processone/fluux-messenger

It makes sense. It's old, crufty mix of extensions, which nobody actually wants to be that modular for a chat client, because that just gets you into mess of what server/client supports
> mess of what server/client supports

If you allow for independent implementations of the protocol this will always happen. Also, inventing another non-standard protocol creates even more incompatibility between clients and servers.

IRC and email worked out pretty well I think.
e-mail stuck in time still not enceypting by defaul
Yes if you never add new features eventually everyone crystallizes
Matrix is in the same place wrt feature mismatches. It's a quality of the problem, not of the solution. I actually think XMPP does a better, more structured job here.
XMPP leans heavily on capability negotiation and service discovery which makes it straightforward to degrade gracefully when feature mismatches occur. Matrix is significantly lacking in this regard.
Unfortunately, some of the features that can degrade are things like "the chat is actually secure."
I strongly prefer that with XMPP I can disable the encryption when it breaks to tell my friend I'm trapped under a boulder and bleeding out. With Matrix our chat is encrypted, I can't turn it off ever, if it stops working I can't communicate, my only option is to make a new room with encryption disabled and invite my friend hoping he sees the invite and accepts in time.
I want to see this movie

Edit: now I can't stop thinking about correlation vs causation - you being under the boulder bleeding out at the same time XMPP encryption suddenly stops working.

Physical hardware certificate thinggy which got crushed?

It's funny because I remember having an issue where my friend was sending me messages, and he couldn't read my messages, and my mobile client (Siskin) didn't let me turn off encryption for outgoing messages.
Recommendation: if you're trained under a boulder, use the device you're running an XMPP chat client on to call 911.
That's how RCS's Universal Profile is too though as far as I understand with the new encryption standards.

Id rather someone be able to reach out to me with a note the chat is insecure, rather than be unreachable at all

> Matrix is in the same place wrt feature mismatches.

not it isn't - still today there's no choice between incompatible room types or incompatible encryption algorithms and whatever else.

Calls are implemented differently across clients, threads only sometimes work. And, apparently from your comment, there's only ever going to be one encryption algorithm, because cryptography is a solved problem now?..
Don't Element Continuwuity, Synapse, Sable, FluffyChat and more all implement Matrix RTC, because this is most likely the future of video calls in Matrix (while not even officially part of the spec at this point)?

> And, apparently from your comment, there's only ever going to be one encryption algorithm, because cryptography is a solved problem now?..

That's not from my comment. If there will be another one it likely will be integrated into THE specification such that it will NOT divide the ecosystem into "I prefer MEGOLM" and "I prefer to implement new thing".