Live data from Hacker News

Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

element.io

281–290 of 422 posts

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#281
post #233

Earlier quoted context omitted.

>There's no way for me, a hypothetical person who wants to keep my Signal messages 100% encrypted in the Signal ecosystem, to opt out of my contacts using an Element bridge. This sounds like a made-up concern. How do you stop me from screenshotting your convo and posting on twitter, or just copying and pasting from one app to the next?

Those are distinct from my concern. In your scenarios, I have trusted you to keep the conversation secret, and you betrayed that trust. My concern is about giving messages in an automatic fashion to a third party, which I'm completely unaware of and have no way of making an informed decision about. The third party could be breached (they run an online service, which is much, much easier to attack than some dude's iPh…

Just ask your conversation partner?

An Element bridge is just a Signal client hosted on Element's infrastructure. Them using an Element bridge is no different than them using an extra device you didn't know about. That device could've well been insecure, or shared by many people, or hosted in the cloud. If you care about this, you should ask.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#282
post #267

Earlier quoted context omitted.

Doesn't grapheneos allow some type of sandboxing to wall off your true contacts, etc. for exactly this purpose? https://www.reddit.com/r/privacy/comments/nkyzdw/what_is_the...

You know people that have the FB app installed. And all their messages and SMS running through the FB app. And you can't get all of them to stop this madness.

Maybe. I probably don't relate well because I talk to maybe 10ish people regularly.

Everyone else, if they don't migrate to a secure and preferred method, I just use email (with pgp if possible) and call it good.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#283

Earlier quoted context omitted.

I don't follow. What does my hard drive have to do with plaintext messages on Element's servers?

Aj, my bad. I skimmed over the part where it says they are hosting the bridge for you. Since matrix is focused on privacy etc I assumed this is available as a container/VM I can run at home or on a VPS. Indeed then very weird why I should trust them more with my personal data than anybody else.

> Since matrix is focused on privacy etc I assumed this is available as a container/VM I can run at home or on a VPS.

All bridges, and the matrix homeserver itself have been open source and self-hostable for years. I host a homeserver + some bridges myself.

This is just the sugar-coated SaaS for people who dont want to do it themselves.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#284
post #221

Earlier quoted context omitted.

(Element CEO here). Honestly, it depends on your threat profile. Any kind of bridge has to inevitably MITM your conversations in order to work, and we’ve tried to spell that out in all the product info about Element One. If you want to avoid your E2EE conversations on Signal or WhatsApp being relayed via a service like Element One (because you’re an activist or whatever), then your options are to not bridge at all, o…

You misunderstood what he said if that is your TLDR. Furthermore, this is not the first time privacy issues with Matrix have been brought up to you and dismissed without understanding. I am going to begin recommending that people actively avoid adopting Matrix/Element.

Could you expand on the "privacy issues", please? Not sealioning or whatever, I am genuinely interested.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#286
post #266

Earlier quoted context omitted.

This is a very all or nothing mentality. It's also kind of like saying you should put locks on your locks. Signal's core reason for existing is that it puts a focus on privacy. They say this all over their homepage [0]. One of the founders of WhatsApp donated $50M to Signal [1] out of regret for how WhatsApp shifted away from privacy after being acquired by Facebook. The entire project is freely visible to anyone on…

For most people, privacy is a nice-to-have thing. When it's just nice to have, Signal checks that box. If your life depended on it, you would be foolish to depend solely on Signal. How nice it is that encryption has emerged from the dark corners of life and death to become a fashion accessory. But for those that still exist in the world beyond fashion, your criticism seems naive.

[deleted]

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#287

Back in the day before the rise of Facebook, there was an open source service that combined all the popular messaging protocols - MSN, AoL, IRC, etc. It was called Pidgin[0], and it never got particularly big. I see the same thing here. While it's interesting, I'm failing to see what the use case is. What's the niche that needs this solved in a big way? [0] https://www.pidgin.im/

I think Trillian was even older, and I think there were some KDE apps that did it even before that...

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#288

Earlier quoted context omitted.

That has always been the case no? You can't know what the person you are sending the message to is doing with it, the status of their device, or anything else. I fail to see anything that Element is doing "wrong" here, the issues you are describing are issues between you and your conversation partner

That is true, but there is a difference between some messages being screenshotted, and a service that acts as a bridge storing all communication that passes through an account. It's a matter of how likely it is that the assumption "my communication is not going to leak beyond the two participants" is broken. Every step in the wrong direction counts, IMO. Also, AFAIK it wouldn't be trivial to extract all the Signal ch…

It seems like you're trying to hold Element to some kind of impossible standard here. It's not like the tech they used to build the bridge didn't already exist.

The bridge itself serves a specific purpose (opening up Signal to the Matrix API, allowing for the use of a single app), and succeeds at that. Of course there's a trade-off, and the team (at least allegedly) appears to be working on encrypted bridges so that even if the bridge decrypts from Signal, it re-encrypts on the homeserver at rest in a way that only the user (not the bridge) can decrypt in the future.

I think the complaint here is "you advertised a service doing a thing that was already possible, people might use this." I may be mis-characterizing that, but I think it's worth stepping back and thinking a bit more on the actual threat model you face, and how the proposed product (Element One) somehow subverts that. Sure it can do so at scale, but that just means this is one incremental improvement that needs more work, not that the idea needs to be thrown out entirely.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#289
post #97

> It’s also worth noting that end-to-end encryption is necessarily broken as messages to (and from) WhatsApp, Signal and Telegram pass across the bridge(s). The bridge(s) operates in Element’s trusted EMS environment, with no content scanning or datamining, but currently bridged conversations are not stored end-to-end encrypted in Matrix (they will be in the future). As a Signal user, I kind of don't want this to tak…

So then advocate for Signal to fully support third party clients, so that such functionality can be widely supported by multi protocol clients (ala pidgin) rather than needing centralized non-E2E bridges to cope with the administrative overhead of maintaining interoperability.

Re: Element One – All of Matrix, WhatsApp, Signal and Telegram in one place

#290
post #140

Earlier quoted context omitted.

How can I verify you're running unmodified, unhooked source in your server if I'm a user?

You don't, you self-host your own server. My problem with the self-hosted model is that I don't trust myself to get it right and/or keep it updated. My problem with the 3rd-party model is that I don't trust them, either. So, lacking trust in either myself or the third-party, I'm just one of those people you can get only via secure e-mail, clear-text SMS, or whatever well-supported encrypted service happens to be the…

I'm excited about NixOS (/GuixSD) because they would seem to provide a straightforward path to running secure services (self-compiled from publicly reviewable source) while keeping them automatically updated (build rules administered by a third party). I'm not saying this is a good approach for you personally right now, but I can definitely see it becoming popular in several years.
Post reply on HN