XMPP at 25: The Case for Open Messaging
- XMPP, the open messaging standard originally known as Jabber, has existed for over 25 years and is being cited as the structurally sound alternative to closed platforms such as
- Critics argue that Element's Matrix protocol, despite its open-source codebase, functions as a single-vendor standard because key governance positions are held predominantly by
- The XMPP community is actively developing features including message replies, multi-image sharing, and OAuth support, while exploring a return to the IETF under the working title
A communication protocol that predates the modern smartphone is being held up as the most credible answer to an increasingly urgent question: who controls the infrastructure through which we talk to one another? The Extensible Messaging and Presence Protocol — XMPP, originally known as Jabber — has existed for more than 25 years, outlasting venture-funded rivals and entire technology cycles, and its advocates argue it is precisely that endurance which qualifies it as genuine digital infrastructure.
The infrastructure argument
The case for XMPP rests on an analogy to physical infrastructure. A municipality might hire a company to build a road, the argument runs, but it does not allow that company to own the road in perpetuity. The same logic should apply to digital communication: profit-oriented companies may be permitted to build and even operate services, but they must be easily replaceable. That replaceability, the argument holds, can only be guaranteed through open, independently governed standards — not through the adoption of any single company's published API, however openly documented that API may be.
The distinction matters most when applied to platforms that style themselves as open alternatives. Element, formerly known as Riot and NewVector, develops an instant messaging product featuring self-hosting and federation, capabilities superficially similar to those offered by XMPP-based solutions. However, rather than adopting XMPP, Element published its own API under the name Matrix. Key leadership positions within the Matrix Foundation are, according to available information, predominantly held by current and former Element employees, and getting outside contributions accepted into the specification has been described as notoriously difficult. European public administrations, in their push for digital sovereignty, have been criticised for procuring such single-vendor platforms, conflating an open-source codebase with a genuinely open standard — a conflation the advocates of XMPP argue is a category error with long-term consequences.
How XMPP differs
XMPP originated as an open-source community project before being brought to the Internet Engineering Task Force and standardised as RFC 3920 in October 2004, with subsequent revisions in March 2011. The protocol's design places governance in the hands of the XMPP Standards Foundation, which does not write extensions itself but provides the organisational framework for developers to propose and standardise their own, known as XMPP Extension Protocols, or XEPs. That process has not always been smooth: XEP-0198, a mechanism crucial for preventing message loss on mobile devices, was stabilised in 2009 but did not gain widespread implementation until 2014 to 2015. End-to-end encryption via OMEMO gained traction from 2016 onwards. Critics and proponents alike acknowledge the protocol's transition into the mobile era was rocky.
The contrast drawn with Matrix is instructive. Despite both protocols dating to roughly the same era — Matrix emerged around 2014 — JMAP, a modern email protocol that went through the IETF process after originating at Fastmail, now has at least three independent server implementations and numerous independent clients. Matrix, by the same account, remains predominantly served by a single reference implementation, with a second alternative still in early stages. Operating that reference implementation is described as resource-intensive, presenting barriers to self-hosting for smaller organisations. Element sells closed-source plugins to address performance shortfalls.
Where XMPP stands today
Modern XMPP clients, including Dino on Linux and Conversations on Android, are described as feature-competitive with alternatives built on proprietary protocols. Recent additions include emoji reactions, cross-device read-state synchronisation, and time zone indicators. A mechanism called channel binding, designed to prevent certain machine-in-the-middle attacks, was noted as having become practically relevant following a reported state-sponsored attack on a public XMPP provider. Looking ahead, the community is developing experimental XEPs for message replies, gallery-style image sharing, and OAuth support, while also exploring the possibility of returning to the IETF with a revised specification informally described as XMPP 2.0.
Widely cited privacy-focused messengers such as Signal, Wire, and Threema are acknowledged as offering stronger ethical credentials than their mainstream counterparts. However, the argument against them is structural rather than behavioural: they operate as closed, non-interoperable systems, meaning that if any one of them were to shut down its servers or exit a given jurisdiction, users would have no recourse. Signal's payment of close to a million dollars annually to its chief executive and its use of Amazon Web Services for server infrastructure are noted as points of concern. None of this constitutes wrongdoing, but the absence of federation means there is, as the argument frames it, no hedge in place if circumstances change. As questions about who controls digital systems grow more urgent, the case for protocols that structurally preclude single points of failure becomes harder to dismiss.
The central implication is political as much as technical. In an era in which European governments are reconsidering their dependence on American technology platforms, the risk identified is that they replace one form of lock-in with another — swapping US corporate control for European corporate control, rather than pursuing the collectively owned, interoperable infrastructure that open standards alone can provide.