"Ich habe nichts zu verbergen und keine Geheimnisse vor WhatsApp/Facebook/Google".
Das ist ein Trugschluß, denn:
"Es geht nicht um Geheimnisse, sondern um Freiheit, rechtsstaatliche
Sicherheit und selbstbestimmtes Entscheiden über eigene Daten."
The core specifications for XMPP are developed at the Internet Engineering Task Force (IETF) - see RFC 6120, RFC 7590, RFC 6121, and RFC 7622 (along with a WebSocket binding defined in RFC 7395).
The XMPP Standards Foundation develops extensions to XMPP in its XEP series. This page lists Draft and Final XEPs as well as experimental proposals that are currently under consideration.
Good places for developers to start are the compliance suites, as well as the technology overview pages.
Like many people, I recently have been re-discovering the XMPP messaging protocol and ended up running my own server. In fact, this blog is essentially a result of that effort, though it functions independently from the XMPP service.
Repository with copies of my XMPP server configuration for public interest / investigation.
Notes on this setup
- Database backend: PostgreSQL
- Admin web interface and API are disabled
- In-Band registration and web registration are enabled
- Captchas enabled
- Nginx is used as HTTP / Websocket Proxy
- Port 5223 used as TLS port for "XMPP over TLS" feature (Port 443 is forwarded to 5223)
A free and open-source XMPP chat client in your browser
Available as overlayed chat boxes or as a fullscreen application. See inverse.chat for the fullscreen version.
A plugin architecture based on pluggable.js
Single-user and group chat
Contacts and groups
Multi-user chatrooms (XEP 45)
Chatroom bookmarks (XEP 48)
Direct invitations to chat rooms (XEP 249)
vCard support (XEP 54)
Service discovery (XEP 30)
In-band registration (XEP 77)
Roster item exchange (XEP 144)
Chat statuses (online, busy, away, offline)
Custom status messages
Typing and chat state notifications (XEP 85)
Desktop notifications
File sharing / HTTP File Upload (XEP 363)
Messages appear in all connected chat clients / Message Carbons (XEP 280)
Third person "/me" messages (XEP 245)
XMPP Ping (XEP 199)
Server-side archiving of messages (XEP 313)
Hidden messages (aka Spoilers) (XEP 382)
Client state indication (XEP 352)
Last Message Correction (XEP 308)
OMEMO encrypted messaging (XEP 384)
Supports anonymous logins, see the anonymous login demo.
Translated into 29 languagesPublic Jabber Chat rooms
Christopher Muclumbus: A listing of public XMPP/Jabber chat rooms/groups.
OMEMO was implemented in the Android Jabber Client Conversations as part of a Google Summer of Code project by Andreas Straub in 2015. The basic idea was to utilize the encryption library used by Signal (formerly TextSecure) for message encryption. So basically OMEMO borrows almost all the cryptographic mechanisms including the Double Ratchet and X3DH from Signals encryption protocol, which is appropriately named Signal Protocol. So to begin with, lets look at it first.
This is a web service for checking and visualising compliance status of XMPP servers, with XEPs (XMPP Extension Protocols), made as a part of Google Summer of Code 2018 for Conversations.im by Rishi Raj. The code for this website, along with a command line tool to check compliance of your server locally, is available under a BSD-3 License on Github. If you want to contribute to the project, read our contributing guide
aenigma provisions a fully functional and out-of-the-box secure XMPP server you can get running today.
It does for XMPP what Mail-in-a-Box has done for email, Streisand for VPNs, and Easyengine for wordpress.
The installation takes you on a 15 minute, clearly worded, step-by-step setup and takes care of everything automagically.
This is a guide to set up a modern XMPP server focused on security and mobile messaging. The whole guide assumes Debian stable running on the server, the fact that you will end up hosting a few of your friends and that you have some basic skills working on a linux command line. Please note that if you’ve followed this guide in the past you might need to have a look at the update considerations
I've published a new HOWTO on my website:
Enrico already wrote about the Why (and the What, Who and When), so I'll just quote his conclusion and move on to the How.
I now have an XMPP setup which has all the features of the recent fancy chat systems, and on top of that it runs, client and server, on Free Software, which can be audited, it is federated and I can self-host my own server in my own VPS if I want to, with packages supported in Debian.Matrix is an open standard for decentralised communication, providing simple HTTP APIs and open source reference implementations for securely distributing and persisting JSON over an open federation of servers.
The Kontalk Network is a community-driven instant messaging network designed for smartphones and tablets.