> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…
You don't know that when you message someone on Signal it's for their eyes only. What you know is that unless their device is compromised, it is up to them to decide who can read the messages that you send to them. Thus the situation with the bridge is not in reality different from the situation now.
Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
151–160 of 422 posts
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#152> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…
I didn't dive into it, but can you also self-host this? Looking forward to some docker-compose snippets in that case :)
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#153> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…
(Element CEO here). Honestly, it depends on your threat profile. Any kind of bridge has to inevitably MITM your conversations in order to work, and we’ve tried to spell that out in all the product info about Element One. If you want to avoid your E2EE conversations on Signal or WhatsApp being relayed via a service like Element One (because you’re an activist or whatever), then your options are to not bridge at all, o…
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#154> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…
(Element CEO here). Honestly, it depends on your threat profile. Any kind of bridge has to inevitably MITM your conversations in order to work, and we’ve tried to spell that out in all the product info about Element One. If you want to avoid your E2EE conversations on Signal or WhatsApp being relayed via a service like Element One (because you’re an activist or whatever), then your options are to not bridge at all, o…
AFAIU GP’s point was that even if I don’t bridge, the recipient of the message might, thereby diluting the trust all users have in E2E on Signal, since you can’t know who’s bridging and who isn’t.
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#155> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…
You don't know that when you message someone on Signal it's for their eyes only. What you know is that unless their device is compromised, it is up to them to decide who can read the messages that you send to them. Thus the situation with the bridge is not in reality different from the situation now.
Although, to be fair, all of those things are far more difficult than using Element One, so there's an argument to be made about reasonable expectations and the actual likelihood of your messages being private...
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#156Earlier quoted context omitted.
(Element CEO here). Honestly, it depends on your threat profile. Any kind of bridge has to inevitably MITM your conversations in order to work, and we’ve tried to spell that out in all the product info about Element One. If you want to avoid your E2EE conversations on Signal or WhatsApp being relayed via a service like Element One (because you’re an activist or whatever), then your options are to not bridge at all, o…
Sure, but this defeats the entire point of Signal. You don't use it to get the maximum amount of reach to other contacts, you use it because you're confident that what you send ISN'T being MITMed... that's the entire value of the app! So unfortunately if this takes off, you never know if the reason you're even using the application is just being violated. It destroys the entire purpose. That said, I love Matrix more…
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#157Earlier quoted context omitted.
That's all well and good, but I believe the original complaint was more concerning the second party in the conversation. There's no way for me, a hypothetical person who wants to keep my Signal messages 100% encrypted in the Signal ecosystem, to opt out of my contacts using an Element bridge. Sure, I can go around and tell everyone I know that they shouldn't bridge Signal to Element One because , but there's no way f…
> I think it's a great offering, but I share GP's reticence about a system that puts what used to be zero-knowledge conversations in plaintext on a third-party server...all without me realizing. Element CEO here, you must be a tinfoil hat crazy person, everyone should communicate in cleartext, you're not a terrorist are you
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#158Earlier quoted context omitted.
> you pay a monthly fee for someone to man-in-the-middle all your communications. All Matrix homeservers and bridges are open source. I self host some of them myself. Have been doing that long before Element One was a thing.
How can I verify you're running unmodified, unhooked source in your server if I'm a user?
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#159Earlier quoted context omitted.
I don’t run my own service for the same reason I don’t build my own car or I don’t do accounting for my company, I don’t have the time to learn how to do it nor doing it.
No, this is not the same. You want the utmost privacy, yet you still decide to trust someone over it.
Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place
#160Earlier quoted context omitted.
(Element CEO here). Honestly, it depends on your threat profile. Any kind of bridge has to inevitably MITM your conversations in order to work, and we’ve tried to spell that out in all the product info about Element One. If you want to avoid your E2EE conversations on Signal or WhatsApp being relayed via a service like Element One (because you’re an activist or whatever), then your options are to not bridge at all, o…
That's all well and good, but I believe the original complaint was more concerning the second party in the conversation. There's no way for me, a hypothetical person who wants to keep my Signal messages 100% encrypted in the Signal ecosystem, to opt out of my contacts using an Element bridge. Sure, I can go around and tell everyone I know that they shouldn't bridge Signal to Element One because , but there's no way f…