Live data from Hacker News

Element – All-in-one secure chat app for teams, friends and organisations

element.io

111–119 of 119 posts

Re: Element – All-in-one secure chat app for teams, friends and organisations

#111
post #99

Earlier quoted context omitted.

Out of curiosity, why Signal and not Telegram? I don't know details about either, just that Telegram seems more popular with reportedly a better UI for non-technical people.

Apart from Telegram now having E2E encryption by default, it also invents its own weird and unverified encryption instead of using a more peer-reviewed and robust method. Signal's encryption tech has some strong guarantees and advanced the state-of-the-art when it first appeared. Worth noting that Matrix's crypto is also based on Signal's algorithm (but extended to support efficient encryption in rooms with a large n…

For the most part I think the fears over their crypto is overblown. But their behaviour over the years and not being secure by default means people shouldn't be using it just on principal.

Signal's double ratchet algorithm is easily the gold standard for now and there's little reason for anyone pushing a E2EE privacy narrative to not be using it.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#112
post #99

Earlier quoted context omitted.

Apart from Telegram now having E2E encryption by default, it also invents its own weird and unverified encryption instead of using a more peer-reviewed and robust method. Signal's encryption tech has some strong guarantees and advanced the state-of-the-art when it first appeared. Worth noting that Matrix's crypto is also based on Signal's algorithm (but extended to support efficient encryption in rooms with a large n…

> Apart from Telegram now having E2E encryption by default, it also invents its own weird and unverified encryption I was confused since the tone of that sentence sounded weird (Apart from , it also ), but I think it's a typo - I believe you meant to type "Apart from Telegram not having E2E encryption by default"?

You're right. :/ Too late to edit now.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#113
I have been experimenting with Element for some time. I made accounts for myself and family members on the German host privacytools.io. (I since learned Debian operates two distinct homeservers, on social.debian.org, but cannot tell which is for what.)

The UX is pretty good, but certain oddities stand out.

1. When visiting rooms, it spends a very great amount of time displaying a spinner instead of postings. It displays a banner offering to scroll back to the last read posting, but forgets that you have already seen later ones. It often displays a banner indicating some bot is operating, but no indication what it is for, or any way to control it or find out more.

2. Messages in the scrollback for private rooms are very often replaced with a note, "cannot get key"; and sometimes appear again, much later.

3. Element advertises an ability to conduct audio and video calls, but I have not succeeded in getting the other end to ring, in recent months.

4. There are supposed to be gateways available to direct Signal and SMS traffic to/from one's Matrix client, but I did not succeed in getting them to work--probably just because their documentation was wholly inadequate.

I spent quite a few months on a subscription to Purism's LibremOne homeserver, but abandoned it when it became clear they had no intention ever to maintain it.

I have not been able to determine whether 1, 2, or 3 above are the fault of my homeserver, or matrix.org, or the protocol.

A Matrix client should be able to work in multiple accounts / homeservers at once, as is done with e-mail clients, but I don't know of any that can.

It seems like it should be possible to run a homeserver on local equipment, tunneling to ports on a cheap VPS, but I have not found anything suggesting how.

Enlightenment on any of the above welcome.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#114
post #99

Earlier quoted context omitted.

Apart from Telegram now having E2E encryption by default, it also invents its own weird and unverified encryption instead of using a more peer-reviewed and robust method. Signal's encryption tech has some strong guarantees and advanced the state-of-the-art when it first appeared. Worth noting that Matrix's crypto is also based on Signal's algorithm (but extended to support efficient encryption in rooms with a large n…

For the most part I think the fears over their crypto is overblown. But their behaviour over the years and not being secure by default means people shouldn't be using it just on principal. Signal's double ratchet algorithm is easily the gold standard for now and there's little reason for anyone pushing a E2EE privacy narrative to not be using it.

It's sad that Signal has a horrible Desktop Client and isn't much to look at because the security and privacy features are good, if you disregard the forced cell phone number.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#115
post #107
post #84

Earlier quoted context omitted.

look at the setup steps and compare that with installing Signal app

Sure, Signal is simpler, but Matrix isn't harder than configuring a new email account on an free provider, and you still get the option of setting up your own if you want to use your own domain name. And I hate that Signal's identity is linked to a phone number.

> Matrix isn't harder than configuring a new email account on an free provider

You say that, but for a number of my contacts this is a significant hurdle... especially relatives.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#116
post #103

Earlier quoted context omitted.

I am talking about the insecure session red warnings in the room details and the notices aside messages of untrusted/unverified/forgotten session.

That is only the case when you have verified your friends keys (by qr code or emoji string). When one of your friends account is hijacked and has someone snooping on messages, you'd want to know that. Though I see it might be confusing at first for users to understand that they have to sign their devices. Currently, you have to login with a username/password and afterwards (optionaly) get one of your other devices to…

No, no, no. I have been toying my own Matrix instance and I registered 2 users that I played with, exchanging pictures and messages. There were some glitches in the UI that insiste on flagging some sessions as insecure even though I verified every session.

Sometimes it got resolved all on its own, sometimes it stayed like that. No biggie in the end but you can find some bug reports like that on github. Most probably it's getting worked out or was but it definitely happened.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#117
post #103

Earlier quoted context omitted.

I am talking about the insecure session red warnings in the room details and the notices aside messages of untrusted/unverified/forgotten session.

That is only the case when you have verified your friends keys (by qr code or emoji string). When one of your friends account is hijacked and has someone snooping on messages, you'd want to know that. Though I see it might be confusing at first for users to understand that they have to sign their devices. Currently, you have to login with a username/password and afterwards (optionaly) get one of your other devices to…

That and messsages like that when you want to restore your history (but at least you can, big up to matrix for that over Signal):

> Try double checking that you did not mix up your security key, security phrase and login password as explained above.

Re: Element – All-in-one secure chat app for teams, friends and organisations

#119
post #103

Earlier quoted context omitted.

I am talking about the insecure session red warnings in the room details and the notices aside messages of untrusted/unverified/forgotten session.

That is only the case when you have verified your friends keys (by qr code or emoji string). When one of your friends account is hijacked and has someone snooping on messages, you'd want to know that. Though I see it might be confusing at first for users to understand that they have to sign their devices. Currently, you have to login with a username/password and afterwards (optionaly) get one of your other devices to…

I'm using Element very sparsely, but keep getting annoyed by it. I did not care to touch any settings. I have a persistent tab in my browser and it keeps having the notification dot for silly reasons:

- My connection flaked out (duh, I closed the laptop lid).

- Connection for one of my contacts flaked out (?!).

- Something in the signatures changed.

I get how any of that might be a sign of compromise. But I really don't care, I don't use this for anything sensitive. And with only about 20% of notifications being about an actual message, I've developed a blindness towards it.

Edit: having written that, I've noticed it is not doing this right now. Come think of it, it might have stopped a while ago and I simply didn't notice (c.f. developed blindness).

Post reply on HN