Live data from Hacker News

Notes on privacy and data collection of Matrix.org (2019)

gitlab.com

91–100 of 102 posts

Re: Notes on privacy and data collection of Matrix.org (2019)

#91
post #78

Earlier quoted context omitted.

I don’t need it encrypted BY DEFAULT. If I want to encrypt something, I can. It also means the chats aren’t available on other devices and you lose other capabilities

> It also means the chats aren’t available on other devices Not, it doesn't. You would just need to copy the private key to the other devices.

How to do it?

Re: Notes on privacy and data collection of Matrix.org (2019)

#92
post #89

Earlier quoted context omitted.

Yeah. How'd that work out for Matrix? Here's a hint: find out when the project was started, and when the network first required end-to-end encryption. Warning: the answer to that entirely vindicates Signal's position on federation; you may not like it. That doesn't make Matrix bad. It makes Matrix different . Matrix has different goals than Signal, and those goals simply prioritize security and privacy differently th…

I'll bite: we first created Matrix in 2014; we started implementing E2EE in 2016 and we turned it on by default in 2020. The reason it took so long was because we focused first on getting decentralisation (not federation) correct, and then the protocol started to get prematurely successful and we got sucked into ensuring the implementations (and spec) scaled and the governance was correct... even before E2EE was stab…

As I recall, you had false starts getting E2E enabled by default (6 years after the project started)... because popular client software didn't have it working. That's not a problem Signal has or ever will have: when they want to roll out new privacy features (like they just did days ago!), they roll the clients.

Again: I'm not dunking on Matrix. There are things the Matrix approach will do better than Signal can. But protecting individuals is probably never going to be one of them; you're competing with a project that has security and privacy as its overriding goal, and nobody at Signal ever has to ask whether federation --- a protocol complexifier if ever there was one --- merits a security hit.

I don't use Signal for everything (or even most things). I'm completely open to the argument that other messengers are better "overall" than Signal. But on a thread that asks the question of whether Matrix is as secure as Signal (not "secure enough", but rather "at parity with"), there is simply a clear answer.

Re: Notes on privacy and data collection of Matrix.org (2019)

#93
post #92

Earlier quoted context omitted.

I'll bite: we first created Matrix in 2014; we started implementing E2EE in 2016 and we turned it on by default in 2020. The reason it took so long was because we focused first on getting decentralisation (not federation) correct, and then the protocol started to get prematurely successful and we got sucked into ensuring the implementations (and spec) scaled and the governance was correct... even before E2EE was stab…

As I recall, you had false starts getting E2E enabled by default (6 years after the project started)... because popular client software didn't have it working. That's not a problem Signal has or ever will have: when they want to roll out new privacy features (like they just did days ago!), they roll the clients. Again: I'm not dunking on Matrix. There are things the Matrix approach will do better than Signal can. But…

I don’t think we had any false starts on e2ee by default? We wrote pantalaimon as a local shim to let any unencrypted matrix client do e2ee, and then (eventually) flipped the switch. The thing that stopped us doing so earlier is that we wanted to have optional online keybackup and cross signing and better key verification UX before we forced everyone into it.

Re: Notes on privacy and data collection of Matrix.org (2019)

#94
post #88

Earlier quoted context omitted.

> "the only way things can actually be secure in the long run is for them to be federated the way I want them to be" I never mentioned any particular kind of federation that I prefer. I also never mentioned word "private", which is mostly tangential to federation. My point is that, in the long run, only federated systems are sustainable, because nobody is able to fund huge servers with millions of users without infin…

Dismissing a platform that's solving real problems for real people right now because it might not exist in 5 years is a pretty weird thing to do. "Sustainability" is arbitrary. Everything burns eventually.

The problem is that such security is unstable due to unstable funding and the single target. You never know when it stops being secure (without a warning) or even available.

I am mostly talking about a use case, where you try to switch all your friends and relatives to a new IM system. If you have to ask them to switch again in a couple of years, you will loose their trust quickly.

Re: Notes on privacy and data collection of Matrix.org (2019)

#95
post #91

Earlier quoted context omitted.

> It also means the chats aren’t available on other devices Not, it doesn't. You would just need to copy the private key to the other devices.

How to do it?

This is currently only a hypothetical possibility AFAIK.

Re: Notes on privacy and data collection of Matrix.org (2019)

#96

Earlier quoted context omitted.

> And Signal forces you to use your phone number as your identifier Signal forces you to use "a" phone number as your identifier. It does not have to be your primary phone number, or home phone number or office phone number. Just a phone number that you have control of.

> Just a phone number that you have control of. In most parts of the world, you cannot get "just" a phone number not tied to your real identity.

[deleted]

Re: Notes on privacy and data collection of Matrix.org (2019)

#97
post #86

Earlier quoted context omitted.

Prepaid cellular phones and Google Voice aren't available in most parts of the world with a little effort?

I was speaking about the prepaid cellular phones. Again, in most parts of the world, you cannot get an anonymous sim-card. AFAIK you also cannot create a Google account without a phone number.

Everyone loves to say depends on your threat model so lets define "tied to your real identity".

1. the number everyone you have met since you were 12 has in their contacts.

2. the number a few people have but you also use for you facebook account.

3. the number nobody / no tech has but you have provided your legal id to the network provider.

4. the number nobody / no tech has and you gave the network provider a burner email for.

5. the number nobody / no tech has that you paid for in cash while wearing a wig and glasses half way across town. You put into a new, paid for in cash phone, activated and used briefly while carrying no other electronic devices while disguised and avoiding cctv.

6. the inbound phone number in the lobby of the ritz carlton.

Some of those are better than using 'firstname.lastname' as you identifier. 1&2 are definately public numbers 4&5&6 are not.

#3 in the real world is semi-anonymous - for those with real privacy needs, they should be taking many other precautions and shouldnt be carrying a tracking device or using a single phone number or service irrespective of it being in their name or someone elses or nobody at all. For privacy LARPERS of course it is not at all anonymous.

Re: Notes on privacy and data collection of Matrix.org (2019)

#98
post #9

Earlier quoted context omitted.

That's such a silly statement when you're a slave to Apple, which is closed source. You could be using an open source, non-googled, android OS with an open source Tox or Briar client.

Sure, you could. How many people do? I don't. I could. But that doesn't solve my problem with Tox. I use IM apps to keep in touch with people in my social circle. I've been coercing a lot of my close friends to switch to Matrix (I use the word "element" because they're not tech savy and I don't want them to be too off-put), and some of them actually do. If Tox does not have an app on iOS store, that, as of now, makes…

There are two main categories of privacy protecting software. Ones for the masses, and ones for the power users.

Those don't mix well, unfortunately.

I also use Signal to stay in touch with the friends who aren't power users.

Re: Notes on privacy and data collection of Matrix.org (2019)

#99
post #84

Earlier quoted context omitted.

None of what you've said to support that argument sounded persuasive to me. I think it's a pretty transparent rhetorical sleight of hand to say "the only way things can actually be secure in the long run is for them to be federated the way I want them to be". I get it, you want to run federated systems that you can build your own clients for. The evidence for those kinds of systems being the most private runs strongl…

> "the only way things can actually be secure in the long run is for them to be federated the way I want them to be" I never mentioned any particular kind of federation that I prefer. I also never mentioned word "private", which is mostly tangential to federation. My point is that, in the long run, only federated systems are sustainable, because nobody is able to fund huge servers with millions of users without infin…

> nobody is able to fund huge servers with millions of users without infinite money. For example, Signal and Telegram are both struggling with that currently

I'm willing to believe that this is true for Telegram, since they do pretty much everything on the server. With Signal, though, message databases and most business logic are client-side, so the servers are surprisingly dumb and lean. Signal spends way more on salaries and wages than on its servers. In 2019, Signal paid more to Twilio for SMS verification than it did to AWS for hosting: https://projects.propublica.org/nonprofits/organizations/824...

Re: Notes on privacy and data collection of Matrix.org (2019)

#100
post #88

Earlier quoted context omitted.

Dismissing a platform that's solving real problems for real people right now because it might not exist in 5 years is a pretty weird thing to do. "Sustainability" is arbitrary. Everything burns eventually.

The problem is that such security is unstable due to unstable funding and the single target. You never know when it stops being secure (without a warning) or even available. I am mostly talking about a use case, where you try to switch all your friends and relatives to a new IM system. If you have to ask them to switch again in a couple of years, you will loose their trust quickly.

You keep alluding to the "instability" of Signal's security, but your argument for that is a non sequitur. Repeating it doesn't make it more compelling.
Post reply on HN