Option to ignore chat invites and being added to groups for a profile

If you create a new profile to manage your public broadcast channel, any subscriber can spam you with chat invites.

There could be a toggle in the profile settings for hiding and deleting all past pending and future chat invites.

While this is a good idea, the real problem to me is that a channel owner should be able to choose if he wants to be contacted or not. (or it should not be possible by default)

I’ve received my first Delta Chat spam only a few days after creating my account and it never occurred to me that creating a broadcast would make my identity public (which goes against a lot of the philosophy behind Delta Chat).

It also means that broadcasts are not usable for any high-profile person. The problem being that you could later become “high profile”. Say that you launch a public broadcast for a niche hobby of yours. You don’t expect more than a handful of followers and that’s the way it is for years.

Suddenly, you gain fame. You have more and more followers. But your hobby becomes highly controversial and, without intending it, you are the main figure for that particular hobby. Then it means that you are at risk on your own Delta Chat account. (as chat requests come with a message, you can be very easily harassed)

This is not hypothetical scenario. Political events have demonstrated that it happens all the time and that it is very important to handle such scenario in any decentralized communication mean.

See Is spam on Delta Chat a known problem? [subscriber spam towards the broadcast channel owner] - #9 by ian

The Delta Chat way is that you are supposed to create one profile for friends, one profile for family, one for acquaintances, one for work and one for each broadcast channel that you manage. You don’t need more granularity than this and I don’t think it would be easy to rework various parts of the architecture and standards to cope with everything in a single profile. Note that disallowing invites and addition to groups would be a default for all but your family profile so it could also protect you if you participate in semi-private groups with less trusted people.

I imagine that channels are sent with emails, so it is impossible to hide the sender. However, it would be enough not to provide the public key of the channel owner to make impossible to write to him. Or am I wrong?

A subscriber completes a handshake with the owner

  • to get the encryption key
  • to confirm that they want to receive messages
  • to be able to unsubscribe later
  • to be able to place a reaction emoji on a message from a restricted set as feedback (ArcaneChat-only feature so far)

If I post my contact link on the internet, and I am being spammed, I can regenerate a new QR code to avoid future spamming from the old link.

Idem for Channels : I can regenerate a new QRcode for the channel to avoid more people joining the channel.

However, what about people who are already in the Channel (or who chat with me) ? They have my contact, so they can share my contact link on the internet and I will not know who has done it (for channel, it seems it is not possible to share a channel we have subscribed).

My intuition was that Channels were, in fact, encapsulated in a dedicated profile to avoid leaking your contact.

That’s how I would have done it and, without looking at the code, the kind of solution I assumed to be implemented.

In the cybersecurity industry, you simply cannot assume that people will use your tool “in a good way”.

Also, as I tried to convey in my scenario, you cannot always predict how the situation will evolve. A private/local channel could become a national sensation over time. Your requirements may change. Your government may change.

Those are important considerations for people designing tools for secure communication. You simply cannot assume anything and should be very transparent about any shortcomings.

For example, this is something where I do trust the Signal project (even if I strongly dislike their centralized approach).

Delta Chat advertises two main aspect : decentralized and secure.

I’m kind of a decentralization expert and I admit that what I’ve seen so far is really good, really innovative (and impressive given the very few person developing DC). I do really appreciate. But I still need to be convinced by the “secure” part, which is not only about the code but also the whole philosophy.

I give it some thought and I believe that just ignoring chat invites for a given profile is not acceptable for high profile channel.

Since I’ve started this channel, only as an experiment, followers have started to message me on Delta Chat. It makes sense. It’s just there. What they have to say is often interesting. I cannot “block” them (they are good/genuine persons). I don’t want them to be ignored (their reaction makes sense, I feel bad for them typing that just to be sent into the void). But I cannot accept the chat (because else, I will spend my life chatting. I’ve a strong policy of keeping chats for close friends and family).

I believe that the only acceptable way to have a popular channel is to prevent followers to contact the owner.

At first, this could simply be a UI thing: just hide it. This will not prevent spammer from reaching you but, at least, it will make the experience coherent.

Ploum, are you not trying again to bend a tool for something it was not intended in first place ?

I mean : Delta chat is (at core) a CHAT application. Designed to allow two-ways communications.

If you want just a tool to announce blog posts, there is already :

  • your RSS
  • your email-list (using a “no-reply” email address)
  • your mastodon account
  • your gemini
  • maybe Signal or SimpleX chat canals

And your blog posts are often shared by other users on plateforms like journalduhacker, linuxfr.org and etc.

I mean : maybe you should post a blog-post or a mastodon-post with a QRcode to a RSS app (the one you prefer) and a second QRcode to add your RSS to the App. A brainless quick way to convert users to RSS, without them stopping at the step '“which RSS app should I select ?”

That’s a very fair question. If DC was existing in a void, I would clearly agree with you.

But, since the advent of Telegram channels, some normalization happened.One of the main point of a “channel” is that you can’t know nor contact those managing the channels.

see Telegram Channels

Signal also had channels (not sure it still exists) and the main point of channels is to be a one-way communication. You can’t contact the owner of the channel.

When you think about it, it makes sense : if you want discussion, make a group. If you want feedbacks, make a group. Unlike a group, with a channel, people are forced to react to you privately. So they will. It means that any channel with more than 100 subscribers will be a real chore to maintain : each new message will generate some feedback.

I’m already witnessing people reacting with multiple posts eventhough I didn’t accept their first conversation. They just continue posting as if they had a one way communication toward me (which is, in fact, the case as long as I don’t block them)

I cannot imagine having a channel with 1000 subsribers (which is a normal usecase for lot of channels).

I hear that it might not be a good tool for that. But then, I wonder if it is good for any use at all as soon as you reach 100+ subscribers.

I’m one of the people who randomly sent you a message from the Channel, my apologies I did not realize it would annoy you. A valid use case is mine - as a relay operator, the users are subscribed for (very infrequent) service messages - rebooting, upgrading, etc. It is my intent that the user have the ability to reply directly to me, the sysop, from that Broadcast Channel message. Nobody ever has (yet), which speaks to the different use cases of this feature.

My personal take is what you perchance think of as spam, I see as enthusiastic followers who thought you were looking for a conversation, using their (very niche and growing) chat app. It’s hard to find DC users out there, you accidentally put yourself in the spotlight for thirsty chatters by posting a group link. A miscommunication between the creator and the consumers as to intent and outcome.

I don’t want to imply to you annoyed me. Your message was perfectly valid and reasonable and the system encouraged you to do so.

It is just that I’ve received more than 10 messages from people I didn’t know in the same hour after posting a message. All of those were, in isolation, sensible (except one). But receiving all of them in what I thought was a private space is disturbing for someone like me who don’t like to chat with strangers. Replying to them correctly would also have taken me much of my time. If I answered, it would also implies that people can send me a message and I will reply. And that number of people connected with me would grew with every post to quickly make Delta Chat totally unusable for me. (as I’m an inbox 0 man, it is in fact already the case for me). So it is not you, it is the number. A number that was encouraged by the design of the tool.

I also hear that it is possible that I didn’t receive spam. I don’t know. The message that launched this thread was without any context, on a subject not at all related to my interests. It sounded fishy. That person tried multiple times to talk to me with his subject. So, it is possible it is not spam but someone looking for anybody to chat.

I may perfectly hear that Delta Chat is not for me, at least not for any public communication. I may had wrong expectations about channels.

If this is the case, no harm was done (I was experimenting anyway). But I believe that my experience can be valuable to DC. At the very least, when creating a new channel, it should be said that “Members of the channel will always be able to contact you privately”.

The bigger picture would be to analyse if I’m a edge-case or if channel owners are mostly, like me, looking for privacy. The question should at least be consciously answered.

Telegram is a centralised servers solution.

Delta Chat is basically emails re-skinned as chat. Nothing prevent your readers to reply. Even with the mail-list of your blog, the mail-client of your readers does not prevent them from replying. Oh, you will never get the reply (as your mailing list is a “no-reply” address) but they can still hit the “reply button”.

With Delta chat : Just create a new profile, name it “no-reply Ploum” (so your subscribers will understand it is pointless to contact you), desactivate the notifications and put a message expiration period. You are “anonymous” (if you don’t put your real name).

Delta chat need to be approached differently from other messaging apps (the latests using a single account and implementing anti-spam features) : you must take advantage of profiles. One profile for your family and discussion group, one profile for channels, etc.

An option “does not allow to reply” would be difficult to implement in Delta chat: if you want exactly the exact features of an RSS… just use and promote RSS ! I agree with Punkero : replying to the admin of the channel is a feature, not a bug, it can be really useful.

Actually, it would be quite easy to implement, but that’s probably a different feature request.

Basically, your client could keep track of who you have invited to chat and who you share a group with and it could automatically throw away any and all emails that arrive coming from outside this flow (i.e., such as via a channel). A huge drawback would be that normal people couldn’t contact you via a vanilla pgp vcard either, so it’s not acceptable.

A different workaround would basically boil down what we have recommended multiple times here an in the other topic: creating a new key pair for each group and channel (either completely independent ones to maintain anonymity or subkeys to prove that you are the same person). We might reuse the same single chatmail account address for multiple keys in such cases when it becomes a scarce resource later, but that’s a technical detail. Also, the user interface could completely hide such (sub)keys and just use it for sending, reception and ignoring replies under the hood.

As a completely different alternative, perhaps we could introduce subaddressing to chatmail accounts and you could vary the nonce suffix of your localpart between each group, each channel and each direct message so that nobody could contact you without your consent even if they know your single key pair. You would probably still have a main suffix that you distributed over vcard files and QR codes privately for compatibility with vanilla encrypted email that you could rotate if you ever get spam.

As I said previously: as I’ve some experience in cryptography, I totally assumed this was the case.

Not doing that means that your DC identity is as secure as the weakest device of all the persons you ever got in touch with. This is really bad from all security/privacy/harassment perspective. You are just one bad breakup away of throwing your whole DC account. (unlike Signal, it is by design, really easy to create new DC accounts. So you can easily harass someone, even automatically)

In all honesty, I’ve the feeling that DC is not “secure” yet and should never be recommended to people who need security (for now, I understand that this is heavy WiP)

Not anymore. Delta Chat is a pure messaging solution which uses some emails protocols as it’s transport layer. But it is not email anymore: you don’t have an “email address” to share (the underlying address might change anytime). It is not email, it’s a whole new thing.

(in fact, from what I’ve seen so far, the underlying email parts could even be replaced by XMPP without changing anything else and it would probably work well, albeit as a totally parallel network)

Delta Chat is still email. It is basically evolved email with forced PGP (via autocrypt, it is written in the FAQ) and possibility to migrate your identity from one server to another (chatmail relays). Chatmail relays are just mail servers with a custom config. That’s all.

If you refuse to aknowledge Delta as email, you can not aknowledge the current limitations of Delta chat. Delta team is still working on fixing the limitations of classic email, but the path is a long way.

You have an email address, it is just hidden from you in the client. It can change, but only if you change your relay, and your new email address is then sent to your friends. When you share your contact link, you are basically sharing your current email address (it is written in plain text in the contact link, at the end of the link, before you username), and it is what you did by sharing a link on the internet (mastodon) and then being surprised people are sending mails (deltachat messages) to it.

Actually, you must expect defaults of classic email to exist in Delta chat (yet they are still working on improving them). If you share your classic email address on the internet, it will be spammed, same for Delta chat. If your friends’ contact list is leaked, your classic email will be spammed, same for Delta chat.

I agree the communication of the webiste and of the FAQ could be better. There are miscommunications.

That has been the main problem of emails for the last 25 years and the main reason why people are looking for alternative to email.

There are also tons of solutions that have been applied to email to counter that: bayesian filters, DKIM, Dmarc, blacklisting servers, etc.

The main concern that started this thread was “can I not receive spam on Delta chat?”.

Your main argument is “DC is like email but without any of the spam countermeasure”.

So, in clear: there’s a huge hole in DC regarding to spam. The only reason nobody talks about it is because DC is completely unknown yet. But as soon as it will have some little popularity, DC users will be flooded with spam. In fact, as soon as an user with a little audience (myself) came in, the spam question was raised.

My take is that, unlike email, this should be addressed beforehand when designing the protocol, not when it happens as an afterthought.

Except it is not an argument. I didnot try to prove you anything. Maybe I misunderstood your older messages, but it seemed to me like you used and made assumptions about delta chat without having read the faq before (you posted a channel link on the internet and expected your profile to be 100% private). I just explained what is the current situation of Delta chat, why you are receiving spam, and that there are other solutions (RSS) which are actually far better for what you are trying to achieve (announce your blog-post without being contacted back).

I am ok there are still holes in Delta chat, I am not defending Delta chat, I’m just explaining the current technological situation.

I highlighed the problem of spam via the “Share contact” feature (linked to your problem) at the end of Is spam on Delta Chat a known problem? [subscriber spam towards the broadcast channel owner] - #15 by lucarne

Delta chat is still being worked on, and we hope it will be better in the future.