Live data from Hacker News

Element Matrix Services Announces Element Home

element.io

101–110 of 169 posts

Re: Element Matrix Services Announces Element Home

#101

Earlier quoted context omitted.

Hi - Yep, we totally get that this won't be for everyone. We're currently looking for ways to be able to increase the efficiency of these smaller servers and to be able to pass those cost reductions on to customers. We've also got some projects in the works aimed at being able to offer single account / single user "homeservers" and obviously the pricing for these would be much lower, but we're not quite there yet. Mo…

What hosting provider are you using? AWS, GCP, and Azure are several times more expensive with the same performance as smaller providers, of which DigitalOcean provides the worst performance. (50% less) https://vpsbenchmarks.com

Currently we're using AWS (but we're hoping to become more cloud agnostic in the future).

(I head up Element Matrix Services)

Re: Element Matrix Services Announces Element Home

#102
post #99
post #98

I find the chart presented to be very deceptive with regards to "Own your data" and Signal. It implies that the Signal servers store your messages and other data which they do not.

AFAIK they do, just not in a way that anyone but the sender and receiver(s) can read.

Encrypted messages are stored on their servers only until they are delivered, and then deleted.

From their privacy policy:

    Messages. Signal cannot decrypt or otherwise access the content of your messages or calls. Signal queues end-to-end encrypted messages on its servers for delivery to devices that are temporarily offline (e.g. a phone whose battery has died). Your message history is stored on your own devices.

    Additional technical information is stored on our servers, including randomly generated authentication tokens, keys, push tokens, and other material that is necessary to establish calls and transmit messages. Signal limits this additional technical information to the minimum required to operate the Services.

Re: Element Matrix Services Announces Element Home

#103
post #17

This is probably a stab at BeeperHQ, judging by the price.

I chat with Arathorn pretty regularly and I'm quite sure that we're not competitors, at least not yet . Beeper is focused in hosting and maintaining bridges between Matrix and other networks. EMS is vanilla Matrix hosting.

Re: Element Matrix Services Announces Element Home

#104
post #99

Earlier quoted context omitted.

AFAIK they do, just not in a way that anyone but the sender and receiver(s) can read.

Encrypted messages are stored on their servers only until they are delivered, and then deleted. From their privacy policy: Messages. Signal cannot decrypt or otherwise access the content of your messages or calls. Signal queues end-to-end encrypted messages on its servers for delivery to devices that are temporarily offline (e.g. a phone whose battery has died). Your message history is stored on your own devices. Add…

[deleted]

Re: Element Matrix Services Announces Element Home

#105

Earlier quoted context omitted.

You definitely can make it work with Let's Encrypt, that shouldn't disturb anything. Setting up STUN and TURN is a real pain, though, if you run into any issues.

Interesting! Were you able to set up a fully encrypted TURN server to use with Matrix? Any tips? I wasn't able to succesfully.

Tip: read the "Be precise and informative about your problem" section [0] of the infamous "How To Ask Questions The Smart Way".

Actually, I'd suggest reading the entire document when you have time. For now, though, at least have a read of that section (it's short and sweet).

[0]: http://www.catb.org/~esr/faqs/smart-questions.html#beprecise

Re: Element Matrix Services Announces Element Home

#106
post #49

This seems like a great move forward for Element, looks like this is angling to replace the New Vector offering they had a while back? The pricing is certainly odd, though. For 5 bucks a month I run my own server with almost a dozen folks on it, which requires basically zero maintenance (I can count the number of times I've had to go in and restart it over the past two years on one hand). Double that for a limit of 5…

> You can just enjoy the fact you know you chose someone you trust (us!) with your data. That stood out to me as poorly phrased, as well. They're assuming I trust them. Even if I do/would have, it's a turn-off.

I agree completely. I thought the point of element and matrix was that I don't trust anyone, and that the messages are e2e encrypted. I guess maybe metadata is still accessible by Element?

Re: Element Matrix Services Announces Element Home

#107
post #44

The terms of service are interesting: > This agreement does not apply to Matrix servers run by anyone else - Matrix is an open network like the Web and this agreement only applies to the server provisioned by the Customer and provided by Element. What do other Matrix servers matter to my hypothetical Element Home server or my selfhosted matrix-synapse server? >The Customer must ensure that all Authorised Users are at…

> What do other Matrix servers matter to my hypothetical Element Home server or my selfhosted matrix-synapse server?

Matrix is federated, like email. Once you send a message to someone on another server, what happens to it is out of your / your server's control.

(E.g., Google's Terms of Service apply to Gmail, but you can use Gmail to send mail to someone at Yahoo... at which point it's beyond Google's reach.)

Re: Element Matrix Services Announces Element Home

#108

Earlier quoted context omitted.

> Keep in mind that this was a bad hack and IMO they made the right decision to revoke keys (alternative is possible leak of every message, ever sent on their platform) but I don't like that it came to that. Do you think they should not have revoked keys, and if so why? That is not a decision for them to make, rather that is a decision for their users to make. Their inability to understand that the mantra of a compan…

>That is not a decision for them to make, rather that is a decision for their users to make. At which point the data could be taken and leaked. That would end the company, protocol, and platform forever. >Their inability to understand that the mantra of a company that happen to carry user data is "Shall not lose user's data" means the are not tall enough to take the ride. I think having lost data is better than havin…

> At which point the data could be taken and leaked. That would end the company, protocol, and platform forever.

First of all, Could and is are two different things. Second of all, if the protocol and company are so badly designed that "could" is equal to "leaked" then it should be the end of the the protocol and the company.

> I think having lost data is better than having it stolen and lost...

Not "stolen" vs. "lost" but "possibly stolen" vs. "definitely lost". It is up to a user to establish if they think that "possibly stolen" is worse than "definitely lost"

> But saying "the users should have the choice" simply would have opened up the risk of a more serious attack at the whim of whoever was doing the attack...

Absolutely not. That's the trade off that one makes when deciding to handle user data. Encryption and backup strategies come into play there. The company in question had not bothered to think about it.

Re: Element Matrix Services Announces Element Home

#109

Earlier quoted context omitted.

Their quote related to the incident and deleting keys (GPG release signing keys on prod machines, no locked down servers, etc leading to the hack): >You might have lost access to your encrypted messages. >As we had to log out all users from matrix.org, if you do not have backups of your encryption keys you will not be able to read your encrypted conversation history. However, if you use server-side encryption key bac…

They revoked keys of users without giving users a choice, ability to save, backup user messages etc. It is a company with operations, engineering and business ran by amateurs that do not understand the foundation of any user facing business - when you have a choice between not destroying user data and devising a method to handle a situation even if it costs you and losing user data, you do the first. Every single per…

No keys were revoked (nor does Element have the power to do so). What happened was that existing user login sessions were destroyed and users had to log in again.

If you had either backed up your keys locally or had an encrypted copy of your keys stored on the server-side as a backup, no access was lost.

Re: Element Matrix Services Announces Element Home

#110
post #88

Earlier quoted context omitted.

Fewer ways for it to be misconfigured? In Matrix you've got to remember to turn on the encryption, and verify each of your clients. At least that's my understanding, maybe that is out of date.

Encryption is on by default. In both cases you should verify.

It's also worth noting that verification is much easier these days given that cross-signing has been implemented.

Before you had to verify each pair of (sender, recipient) devices. This meant N*M verifications.

Now you only need to verify a new device when you are setting it up and each new recipient when you start talking to them for the first time. So it's N+M verifications.

Post reply on HN