Live data from Hacker News

Notes on privacy and data collection of Matrix.org (2019)

gitlab.com

71–80 of 102 posts

Re: Notes on privacy and data collection of Matrix.org (2019)

#71
post #66

Earlier quoted context omitted.

This isn't responsive to the previous comment. Either the messenger meets or exceeds the privacy and security of Signal or it doesn't. If it doesn't, that's material regardless of what you believe about the aesthetics of Signal or their communitarian spirit. Most people who use secure messengers are LARPing (often in a good-willed performative way, as a way of supporting the privacy of others who truly need it). But…

Security is not everything there is to want from a messenger. Due to its centralized approach, Signal is having a problem with financing and I doubt it can be easily solved. It had a large downtime recently. Also, it becomes an easy target for all kinds of bad actors, since it's the single server. I trust it less for those reasons, even if it's "secure" by your standards. I just don't see it being secure long-term, n…

I agree that security isn't everything there is to want from a messenger. But when the question being asked is "which messengers are secure", it is the only question that matters.

Re: Notes on privacy and data collection of Matrix.org (2019)

#72
post #50

Earlier quoted context omitted.

With grease around that. Clients will buffer offline messages, and send them when the other end is online. More or less how skype used to work, before it got bought by Microsoft and centralized.

That doesn't work if you are never (or not often) online at the same time as the other. I use signal to chat with my cousin who is in another continent, and he is online only when within reach of public wifi when he's outside, which is at night for me. My phone is always connected to 4G, so maybe what you propose could work in this specific case, but in other cases it could be an issue.

>That doesn't work if you are never (or not often) online at the same time as the other.

If that was the case, you'd use email, not a realtime chat platform.

And keep in mind, it was never an issue with the old, decentralized Skype.

Re: Notes on privacy and data collection of Matrix.org (2019)

#73
post #44

Earlier quoted context omitted.

The Jitsi thing is going away, matrix already has its own video chat for 1:1 chats, and it's coming for rooms soon too. The Jitsi option was a temporary setup. The clean rooms approach is a good thing I think. Xmpp is becoming a pileup of different add-ons and suffers from the same issues you mention for matrix (not all features supported by all clients). Probably in a worse way. I know the reluctance of IRC operator…

> A user joining a bridged matrix room can see the entire history from before they joined. This is not the case, Matrix rooms can be set to allow viewing history only from joining time on. And that is how IRC bridge rooms are mostly configured, indeed based on policies from the bridged IRC networks.

Ah ok I remember this was a problem that was mentioned by the hackint network when people wanted to add a bridge there. We moved our community to OFTC as a result.

Perhaps this was only introduced later? I'm talking about 3 years ago. But good to see this was fixed.

Re: Notes on privacy and data collection of Matrix.org (2019)

#74
post #59

Earlier quoted context omitted.

I don't get this kind of thinking? How does the why of what he's saying influence the what ? Or even worse, disqualify it? If it's factually correct then the reason behind writing it seems quite irrelevant, to me at least. And you're mentioning it's outdated, which would be natural given that the last commit was over two years ago.

It was outdated two years ago already, people already back then assuming good intent and pointed out that the "issues" he complained about were being worked on, yet he adamantly continued to ignore it and claim that everyone using Matrix was being duped and that his implementation of the id server was the only way to go. That is why .

Oh ok, I stand corrected. Wasn't clear to me from your original post, but it actually makes sense now that I re-read it.

Re: Notes on privacy and data collection of Matrix.org (2019)

#75
post #71

Earlier quoted context omitted.

Security is not everything there is to want from a messenger. Due to its centralized approach, Signal is having a problem with financing and I doubt it can be easily solved. It had a large downtime recently. Also, it becomes an easy target for all kinds of bad actors, since it's the single server. I trust it less for those reasons, even if it's "secure" by your standards. I just don't see it being secure long-term, n…

I agree that security isn't everything there is to want from a messenger. But when the question being asked is "which messengers are secure", it is the only question that matters .

No, there is also a question "how long can this messenger stay secure?" In case of Signal, IMHO, the answer is "not very long".

Re: Notes on privacy and data collection of Matrix.org (2019)

#76
post #59
post #8

Earlier quoted context omitted.

I know it is going to sound like an ad-hominem, but once I realized that this is from the same person behind the "Grid protocol", I immediately closed the tab. This guy seems to be on a quixotic vendetta against msxid. It is the third or fourth persona (first it was from a personal account, then from his company, now he has even a non-profit advocating for privacy) that he created to re-hash the same old, outdated an…

I don't get this kind of thinking? How does the why of what he's saying influence the what ? Or even worse, disqualify it? If it's factually correct then the reason behind writing it seems quite irrelevant, to me at least. And you're mentioning it's outdated, which would be natural given that the last commit was over two years ago.

It doesn't, but you can spend less effort engaging with someone acting in bad faith.

Re: Notes on privacy and data collection of Matrix.org (2019)

#77
post #35
post #27

Earlier quoted context omitted.

In terms of closed centralized services, I’d say Telegram is my top pick, followed by Signal. But I would take open source decentralized networks over them anyday, and my favorite is Freenet, or the much newer network, MaidSAFE because it is the most secure thing I have ever seen (but that’s not mainstream yet).

I don't see the allure of Telegram over anything; can you elaborate?

More user friendly

Crypto that I trust more than Signal

Far more documented and open (even though backend is not)

Supports many clients

Re: Notes on privacy and data collection of Matrix.org (2019)

#78
post #41
post #27

Earlier quoted context omitted.

In terms of closed centralized services, I’d say Telegram is my top pick, followed by Signal. But I would take open source decentralized networks over them anyday, and my favorite is Freenet, or the much newer network, MaidSAFE because it is the most secure thing I have ever seen (but that’s not mainstream yet).

Telegram is not encrypted E2E by default at all.

I don’t need it encrypted BY DEFAULT. If I want to encrypt something, I can. It also means the chats aren’t available on other devices and you lose other capabilities

Re: Notes on privacy and data collection of Matrix.org (2019)

#79
post #41

Earlier quoted context omitted.

Telegram is not encrypted E2E by default at all.

And the encryption they are offering is custom, which is always at least suspect.

I actually trust it more to not have backdoors. Signal is written by the same guys who sold to Facebook, and although both Moxie and Pavel are anarchists, I trust the guys who were actually ousted from their own country and yes, rolled their own encryption (with bounties to break it) rather than use an officially approved one

https://twitter.com/durov/status/872891017418113024?lang=en

https://telegra.ph/Why-Using-WhatsApp-Is-Dangerous-01-30-4

Besides - Moxie is kind of against decentralization, he thinks that by centralizing trust in a certain entity, things can be better. I am not convinced that such an approach leads to a better model for me to have encrypted communications:

https://news.ycombinator.com/item?id=21904469

I like that Signal started using SGX though. It’s not ideal (now I have to trust Intel instead) but at least if you’re going to be running some code on a centralized service instead of byzantine consensus, let me know you aren’t backdooring it:

https://medium.com/@maniacbolts/signal-increases-their-relia...

Post reply on HN