Earlier quoted context omitted.
Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…
Here's a screen recording of me trying to log in to app.element.io [0]. 0:10 - Stuck on "Verify this login" despite cancelling 1:00 - Same as above. The security phrase I have saved seems to be invalid. 1:38 - Can't drag or expand the left panel. Went away when I made the window wider after I stopped recording. 1:52 - After clicking "Verify" again, the session immediately verifies? I didn't enter any passphrase or do…
We can do better than Signal
211–220 of 290 posts
Re: We can do better than Signal
#212Earlier quoted context omitted.
The solution is simple. Make the decentralized systems social, with reputation.
And that then is extremely easy to abuse as soon as you have enough people with high rank enough deciding to start to misbehave.
Re: We can do better than Signal
#213Earlier quoted context omitted.
I can't see how this is a problem on its own. If they were eschewing some better option than "don't trust the server", that would be a problem, but is there a better option?
Yes, the solution is … allow the protocol to let people run their own servers?
It's kind of fascinating, they have done a pretty good job of laying out their goals, easy contact discovery, forced protocol upgrades, etc, and people come up with all these improvements they could make by just setting aside those goals.
Re: We can do better than Signal
#214Earlier quoted context omitted.
Yep, there should be a crash or bug report form within the app itself, and an email for bugs at something like support@element.io
There is one in Element Android. When the phone is shaken, a dialogue pops up "It seems you're shaking your phone in frustration, file a bug report". It has in-app bug reporting.
Re: We can do better than Signal
#215Earlier quoted context omitted.
Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…
I don't actually think anything is awful, but my main complaint about Element as a GUI app, is that aside from opening the chromium developer console and watching what it does, it has very few options to diagnose client-server connectivity or TLS crypto key handshake issues. I wish it wasn't an Electron app built on Chromium which makes it a huge resource hog. There's lots of underlying dependency and reliance on wha…
Re: We can do better than Signal
#216Earlier quoted context omitted.
Here's a screen recording of me trying to log in to app.element.io [0]. 0:10 - Stuck on "Verify this login" despite cancelling 1:00 - Same as above. The security phrase I have saved seems to be invalid. 1:38 - Can't drag or expand the left panel. Went away when I made the window wider after I stopped recording. 1:52 - After clicking "Verify" again, the session immediately verifies? I didn't enter any passphrase or do…
Firefox 68? I'm running Firefox 84.0.2 on Pop_OS 20.04. I can empathize with the project maintainer for not prioritizing a browser ~20 versions behind latest.
Re: We can do better than Signal
#217Earlier quoted context omitted.
By punishing their connections when they misbehave. Or at least, that's how you make it not matter. If spam-bot hands out reputation to spim-bot and then you get a bunch of garbage from spim-bot, derate everything coming from anyone that has given either of them reputation (and perhaps ignore their attestations also).
Now what happens when spam is done through a compromised user, or when the user acts human and has real interactions before spamming?
But fundamentally, it isn't particularly harmful to just burn a user that starts spamming. If a compromised account is recovered, it's fine if they have to restore communication out of band, if it isn't recovered it's fine that it is burned.
Re: We can do better than Signal
#218Earlier quoted context omitted.
I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…
Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…
In my case, my issues came down to mostly your last point:
> Verifying yourself when you log in on a new device has confusing UX, and there's a known bug that can stop keys being synced to the new login even once verified.
If I installed a desktop client on two different mac computers, I would have issues with messages not decrypting properly until I do a re-verification, and figuring that out took some Googling and trial-and-error.
Re: We can do better than Signal
#219Earlier quoted context omitted.
Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…
Here's a screen recording of me trying to log in to app.element.io [0]. 0:10 - Stuck on "Verify this login" despite cancelling 1:00 - Same as above. The security phrase I have saved seems to be invalid. 1:38 - Can't drag or expand the left panel. Went away when I made the window wider after I stopped recording. 1:52 - After clicking "Verify" again, the session immediately verifies? I didn't enter any passphrase or do…
Re: We can do better than Signal
#220Earlier quoted context omitted.
Simple Groups and painless multimedia was what gave WhatsApp the edge in the early days
Liked "Simple Groups and painless multimedia was what gave WhatsApp the edge in the early days" ------- ^ That's and ultra low res photo sharing what you get when you group SMS/MMS with folks in the Apple ecosystem. You don't get it in WhatsApp, etc.