Live data from Hacker News

Notes on privacy and data collection of Matrix.org (2019)

gitlab.com

11–20 of 102 posts

Re: Notes on privacy and data collection of Matrix.org (2019)

#11
post #9

Earlier quoted context omitted.

I've never heard of Tox, but it doesn't even have an iOS client. That's a good reason to ignore it.

That's such a silly statement when you're a slave to Apple, which is closed source. You could be using an open source, non-googled, android OS with an open source Tox or Briar client.

Sure, you could. How many people do? I don't. I could. But that doesn't solve my problem with Tox.

I use IM apps to keep in touch with people in my social circle. I've been coercing a lot of my close friends to switch to Matrix (I use the word "element" because they're not tech savy and I don't want them to be too off-put), and some of them actually do.

If Tox does not have an app on iOS store, that, as of now, makes it impossible for me to suggest it to approx. 60% of my friends, folks I exchange instant messages with, on a daily basis. Due to this, I'm sure you could see why this limitation makes this platform/service absolutely useless for me.

Re: Notes on privacy and data collection of Matrix.org (2019)

#12
IMHO, aspects like metadata and application security are often much more important than the cryptographic protocol when assessing the security of a system like a messenger. People e.g. love to celebrate the Signal protocol because of its double-ratchet key rotation scheme, which is of course great and provides a little bit of additional security, but the other technical and organizational aspects of the system are just as important to assure privacy and security.

From that angle I like systems like Matrix way more than centralized solutions like Signal, Threema etc., because the whole security and privacy guarantees of the latter can be completely nullified by a single software update. If users don't have full control over the software running on the endpoint then end to end encryption is little more than a marketing gag, IMHO.

Re: Notes on privacy and data collection of Matrix.org (2019)

#13
post #9

Earlier quoted context omitted.

That's such a silly statement when you're a slave to Apple, which is closed source. You could be using an open source, non-googled, android OS with an open source Tox or Briar client.

Sure, you could. How many people do? I don't. I could. But that doesn't solve my problem with Tox. I use IM apps to keep in touch with people in my social circle. I've been coercing a lot of my close friends to switch to Matrix (I use the word "element" because they're not tech savy and I don't want them to be too off-put), and some of them actually do. If Tox does not have an app on iOS store, that, as of now, makes…

from a certain pragmatic sense, I agree with you. a messenger app that wants wide adoption needs to have clients for the devices the userbase uses. adding device switching costs on top of app switching costs is not something i'm after.

granted my goal is simply to have just a bit more privacy than the plaintext bulk scanning that messenger does, so i use centralized signal rather than something 'purer' like running my own matrix. (though i do run my own zulip)

matrix p2p at general availability will be my next move after signal once signal has its next big outage

Re: Notes on privacy and data collection of Matrix.org (2019)

#14
post #3

I'm of two minds when it comes to reports like this. On the one hand, of course I love that people have the means to audit assumptions. Both the ability to do so w.r.t the project being transparent and open, but also through time and technical ability. I am, however, a little upset when people poke at minor issues (that they themselves see as minor) and speak at length about them. *not* because those issues should no…

> So, with that in mind: Kudos for such an analysis, but be mindful that such a lengthy document that discusses minor issues can actually harm the matrix project.

Under "Purpose and Scope":

> This document is a research paper by Libre Monde ASBL, nonprofit dedicated to protecting people's privacy. We had the need to document privacy points for The Grid Protocol project, fork of the Matrix protocol.

So seems that they probably won't have issues with that it might harm Matrix, as they are a direct competitor. In fact, that might be why they are focusing on the issues they find, minors one included.

Re: Notes on privacy and data collection of Matrix.org (2019)

#15
post #9

Earlier quoted context omitted.

That's such a silly statement when you're a slave to Apple, which is closed source. You could be using an open source, non-googled, android OS with an open source Tox or Briar client.

Sure, you could. How many people do? I don't. I could. But that doesn't solve my problem with Tox. I use IM apps to keep in touch with people in my social circle. I've been coercing a lot of my close friends to switch to Matrix (I use the word "element" because they're not tech savy and I don't want them to be too off-put), and some of them actually do. If Tox does not have an app on iOS store, that, as of now, makes…

> If Tox does not have an app on iOS store, that, as of now, makes it impossible for me to suggest it to approx. 60% of my friends

If iOS does not allow 3rd party programs on "their" phones (or GPL'ed software on their "store"), that, as of now, makes it impossible for me to suggest it to 100% of my friends. It's easy to shift the blame on volunteer developers when you have a multi-billion corporation making their lives miserable (see also the background notification issue on iOS).

Also, mostly rich people use iPhones. The rest of us use cheap Android devices or dumb phones... iPhones are non-existent in my social circles, except for the odd second-hand-with-broken-screen iPhone someone got for free.

Re: Notes on privacy and data collection of Matrix.org (2019)

#17

IMHO, aspects like metadata and application security are often much more important than the cryptographic protocol when assessing the security of a system like a messenger. People e.g. love to celebrate the Signal protocol because of its double-ratchet key rotation scheme, which is of course great and provides a little bit of additional security, but the other technical and organizational aspects of the system are ju…

Unless something has changed in the past years, Signal and Matrix have this in common that any room you join displays your identifier for every one to see (phone number / MXID) publicly, leading to problems of harassment/spam.

But i entirely agree with your point that relying on a single actor for updates/security is really the worst.

Re: Notes on privacy and data collection of Matrix.org (2019)

#18
post #8
post #3

I'm of two minds when it comes to reports like this. On the one hand, of course I love that people have the means to audit assumptions. Both the ability to do so w.r.t the project being transparent and open, but also through time and technical ability. I am, however, a little upset when people poke at minor issues (that they themselves see as minor) and speak at length about them. *not* because those issues should no…

I know it is going to sound like an ad-hominem, but once I realized that this is from the same person behind the "Grid protocol", I immediately closed the tab. This guy seems to be on a quixotic vendetta against msxid. It is the third or fourth persona (first it was from a personal account, then from his company, now he has even a non-profit advocating for privacy) that he created to re-hash the same old, outdated an…

It is ad-hominem and bias

Re: Notes on privacy and data collection of Matrix.org (2019)

#19
post #3

I'm of two minds when it comes to reports like this. On the one hand, of course I love that people have the means to audit assumptions. Both the ability to do so w.r.t the project being transparent and open, but also through time and technical ability. I am, however, a little upset when people poke at minor issues (that they themselves see as minor) and speak at length about them. *not* because those issues should no…

> So, with that in mind: Kudos for such an analysis, but be mindful that such a lengthy document that discusses minor issues can actually harm the matrix project. Under "Purpose and Scope": > This document is a research paper by Libre Monde ASBL, nonprofit dedicated to protecting people's privacy. We had the need to document privacy points for The Grid Protocol project, fork of the Matrix protocol. So seems that they…

> So seems that they probably won't have issues with that it might harm Matrix, as they are a direct competitor.

I was not aware of the Grid project, but they seem to make good points. Matrix is developed by a restricted group of people with a startup vibe and some cringy/questionable actions:

- spitting on other protocols (or not even acknowledging their existence) without a technical reasoning (Matrix could have been a "simple" decentralized room extension of XMPP or any other established protocol) ; which takes us to the situation where Matrix has the exact same selling points which XMPP had 20 years ago... and keeps on reinventing the wheel

- pushing for a broken state resolution algorithm (decentralized consensus) without a formal analysis, which means it's now reached its 5th or 6th version and Matrix clients are all incompatible with one another (because only Element implements them all) and once they have been upgraded rooms cannot be downgraded so in many places only Element can chat

- requiring a web rendering engine for certain extensions (eg. Video chat) ; HTTP is a decent foundation for a protocol, but why is a Jitsi considered a decent extension mechanism? it will just harm security/privacy (through potential XSS) and make it near-impossible for clients to be implemented without a Chrome-based engine, reinforcing Google's monopoly on the web

- putting all of their $$$$ into a single web client with very bad performance, not caring for other platforms; beyond clients, investing in bridging with useless platforms like Microsoft Teams (though i did not find the code for that) while neglecting interop with open protocols like IRC/XMPP (relations with IRC/XMPP people are notoriously not very good though i hope it will improve over time)

All in all, i'm very glad matrix exists because they have popularized bridging and they do care for UX concerns like Spaces. But claiming people who forked the project because of political and technical disagreements are biased because they are a "competitor" is itself a very biased position based on the idea that only one true protocol must remain and others are heretics trying to undermine our technical purity (for their economic gain).

I wish we could have people from different protocols sitting across the table and working on interop so we can stop arguing about which network is best.

Re: Notes on privacy and data collection of Matrix.org (2019)

#20

IMHO, aspects like metadata and application security are often much more important than the cryptographic protocol when assessing the security of a system like a messenger. People e.g. love to celebrate the Signal protocol because of its double-ratchet key rotation scheme, which is of course great and provides a little bit of additional security, but the other technical and organizational aspects of the system are ju…

Unless something has changed in the past years, Signal and Matrix have this in common that any room you join displays your identifier for every one to see (phone number / MXID) publicly, leading to problems of harassment/spam. But i entirely agree with your point that relying on a single actor for updates/security is really the worst.

I'd say that revealing a phone number is probably worse than a matrix ID. But indeed, it would be nice if miatrix clients from element would support multiple identities.

Then you can join a room with a disposable account.

Post reply on HN