Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

E2E encryption should be part of the main protocol spec and mandatory. It's 2026 now. Nobody needs a messenger that isn't encrypted.
 help



> Nobody needs a messenger that isn't encrypted.

Businesses want to analyze internal company messages. Chat protocols / platforms need to make inroads with one of the core audiences for online chat. Those are largely taken right now, (slack/teams business, discord gaming/oss). If it is personal/small group messaging, several E2EE options already exist, though I understand Jabber/XMPP is trying to be in the chatroom genre


You can do E2E encryption for organizations, you just establish all conversations as at least 3-way conversations: the two members of the org, and the org itself. You let the server refuse to host any conversation it isn't privy to, and then apps that support organization mode automatically add the org listener, and users using third-party clients can add it manually.

E2EE has well known issues for scaling, which is why it's found primarily in small group / personal chat

The org can just host non-E2EE XMPP, and it'd be the same as this wrt trust, easier to implement too.

There is literally nothing about enterprise inspecting proxies that requires the client operate without default and always on crypto. That makes no sense at all.

The way businesses handle this is by installing a certificate they manage and deploy to their proxies.


one does not typically do data science on message content by capturing it at the proxy, go to the database and dump the data set

Not every messenger needs to support every use case

you'll need one major group if traction is the goal, which seems to be what the posted link is really after

chat is network effect, so a chat app needs to answer "which network of people" if the creators about traction?


True, segmentation is already happening with users choosing apps based on geography, age, and sometimes by social group. It’s possible to target and win over a select group of people if you have a compelling feature or an experience that’s geared towards their needs. You just have to decide who you are focusing on.

I can easily imagine a future where people switch between three messengers, one for general communications with acquaintances and family, one for work, and one for their social circle. Many already do this with social networks.


text, slack, discord for those three already (for me); none were my choice, unlikely I would chose any of them given better options, yay capitalism!

I disagree. XMPP wasn't designed for it, and there are already others that have done E2EE better, while still having some downsides. The only way XMPP has an edge is by not doing E2EE.

E2EE will never be the default, because people lose their devices all the time, and don't want to lose message history.

WhatsApp doesn't even have the option to disable e2ee anymore and it's doing just fine, despite their best efforts to screw over their customers.

WhatsApp depends heavily on centralization.

Who are those people having lot of time to re-read their old message history? I assume most people only read last several messages in a chat. This matches the real life conversations which are not stored anywhere. However, police will definitely be happy to discover that your many years messaging history is intact.

I would rather want a feature, like Telegram has, where you can set auto-delete of all messages older than N days.


>Who are those people having lot of time to re-read their old message history?

Everyone who has to, say, prove that they kept paying their rent for a year without interruptions. You sent a photo of your money transfer from the bank app to your landlord, and he sends the "received" screenshot from his bank app.

Moreover, a lot (even most) people make personal notes by sending messages to themselves.


For me searching my old messages is really useful. I don't scroll back through history but I'll search for things like "plumber" to find the number of a plumber a friend texted me a while back.

>police will definitely be happy

Most people trust the police. This might not be justified in your state, but most people still do.


the only people that really trust the police are ones that never actually had to deal with the police (which may be a whole lot of people). however, if you ever have an unfortunate situation to have a run in with the police, there is a good chance you will not be all that trusting any longer. people trust the idea of police more so than anything else

Well, true. But even so, having the history intact is also a way to remove suspicions from yourself.

"Where were you during the event X? I was very far from the place you are interested in, as can be proven by this photo, sent to my grandma, have a look at the history in her phone."


It's the default/only option for popular apps like Signal or WhatsApp.

If message history is important it should be backed up on the receiver's end after decryption, like WhatsApp and signal do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: