@SwooshBakery624@programming.dev
Post #595560
2026-03-09 07:52 UTC
Replies (2)
-
@smiletolerantly@awful.systems 2026-03-09 07:59
Ha, thanks, I’d already read that. And I do, mostly, agree; the OMEMO implementation is not great both from the security perspective discussed in the post, as well as the UX (not being able to decrypt old messages on new devices at all). That being said, I primarily want a selfhosted, federated messenger which also takes privacy and security seriously, and at least for the former, XMPP is really refreshingly good.
-
@ProdigalFrog@slrpnk.net 2026-03-10 03:53
I want to point out that the author of that linked blog, Soatok, actually removed a response in the comments from an OMEMO developer which clarified some things (you can it read here), which personally I think was rather odd/bad faith of them to do. When asked about it, this was their response: “I’ll make an edit later about the protocol version thing, but I’m not interested in having questions answered. My entire horse in this race is for evangelists to f** off and leave me alone. That’s it. That’s all I want.” According to the OMEMO developer in his response, there’s nothing really wrong with OMEMO 0.3.0, as the dev considers it a stable standard that clients can safely implement, with newer versions basically being public beta releases toward a stable ‘OMEMO 2’ standard that can eventually replace 0.3.0. Also @smiletolerantly@awful.systems.