On 19.09.2017 11:37, Dave Cridland wrote:
> On 19 September 2017 at 09:21, Klaus Herberth <[email protected]> wrote:
>>> Hi Klaus,
>> Hi Andrey,
>>
>>> What do you mean by "libsignal"? There are at least 4(+1) libraries:
>> With libsignal I referred to your linked implementations of WhisperSystems.
>>
>>> Note, javascript favor is already available.
>> I know, but it is GPL and this doesn't work for everyone.
>>
>>> BTW, why is it terrible?
>> It's terrible, because the wire format of those implementations aren't
>> documented (as far as I know) and therefore it's quite hard to implement
>> such protocol by your own. I think a protocol should be like an Internet
>> Standard defined in RFC1310:
>>
>>      "In general, an Internet Standard is a specification that is stable
>>       and well-understood, is technically competent, has multiple,
>>       independent, and interoperable implementations with operational
>>       experience, enjoys significant public support, and is recognizably
>>       useful in some or all parts of the Internet."
>>
>> I think "multiple independent and interoperable implementations" are
>> currently missing for the "signal protocol". If we would have some kind
>> of documentation for the wire format and a clear hint in the XEP that
>> libsignal is needed it would be a great help for everyone who wants to
>> implement this XEP.
>>
> 
> I entirely and unreservedly agree with you.
> 
> For what its worth, the XMPP Council originally rejected this XEP
> because it was reliant on a single library; while we were assured that
> this was not the case anymore, and anyone could easily (I believe the
> word "trivially" was used multiple times) implement a fully
> independent implementation and have it interoperate, you are sadly
> proving that this is not the case.

You are only telling half of the story.

The original authors of the XEP worked on a follow up version [1] which
put the wire format into the XEP and was based (mostly) on the Signal
specification, which is a open standard [2]. The existing OMEMO
implementations could trivially upgrade to what is specified in [1], and
new implementations, like the one Klaus tries to write, could
reimplement everything from scratch (if they want), since the ultimate
goal of [1] was it to have all parts openly and well specified. Or, of
course, new implementations could reuse the existing
Axolotl/Signal/OMEMO ecosystem of libraries.

Sadly that change was torpedoed by a small group (including you).

- Florian

1: https://github.com/xsf/xeps/pull/460
2: https://signal.org/docs/

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to