Earlier quoted context omitted.
Gematik co-funded the most recent Matrix audit of vodozemac[1], and is poised to fund 3 more (of matrix-rust-sdk-crypto, matrix-rust-sdk and the whole stack end-to-end) to ensure the E2EE is where it needs to be. So I'd say that the German government definitely cares about E2EE for its civil servants, and we're very grateful for them funding security research. Meanwhile, BWI is helping fund the work needed to address…
Cool, thanks! That's interesting to know. Do you know how they deal with FOI and auditable communications in this case? PS: I talked about the seemingly unexploitable IND-CCA vulnerability because it means Matrix can't give you some security guarantees : It should be fine - we don't have an exploit, only a vulnerability - but it is not clear how to reason to arrive at "there cannot be an exploit". If you care about s…
Fair enough on IND-CCA; as you know, we are fixing it anyway.