Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

61–70 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#61

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

Re: Verifying your Matrix devices is becoming mandatory

#62
post #44

Earlier quoted context omitted.

> Despite all the gnashing of teeth in this thread, this seems reasonable I think it's not the requirement itself that's the crucible of discussion but the issues are rather that the blog post should have explicitly defined what verification is in it's second sentence and that matrix/element still is barely useable even for reasonably technical users.

> barely useable even for reasonably technical users My entire family (including my elderly mother) would be very interested to learn how technical they are!

Argue with the people in this thread that made this argument.

Re: Verifying your Matrix devices is becoming mandatory

#63
post #39

Despite all the gnashing of teeth in this thread, this seems reasonable. This seems to only prevent you from logging into your account, with only a password, NOT verifying it (by dismissing all the prompts asking you to do so), and then sending (and receiving new!) encrypted messages anyway. I've never used an unverified Matrix account in the 6 years that I've been an active user. Verification used to be a bit finick…

Doesn’t verification also exchange encryption keys, letting you decrypt messages from before you logged in? I remember that being a huge issue where you would see unable to decrypt messages.

Probably just bad UX to let people skip the verification step.

Re: Verifying your Matrix devices is becoming mandatory

#64
post #39

Despite all the gnashing of teeth in this thread, this seems reasonable. This seems to only prevent you from logging into your account, with only a password, NOT verifying it (by dismissing all the prompts asking you to do so), and then sending (and receiving new!) encrypted messages anyway. I've never used an unverified Matrix account in the 6 years that I've been an active user. Verification used to be a bit finick…

Doesn’t verification also exchange encryption keys, letting you decrypt messages from before you logged in? I remember that being a huge issue where you would see unable to decrypt messages. Probably just bad UX to let people skip the verification step.

Yes. If you don’t verify, every conversation is empty.

Re: Verifying your Matrix devices is becoming mandatory

#65
post #3

What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.

I was afraid of that as well given the wording but, no, it's nothing to do with third parties at all. Just when you log into a new device, you confirm it on your old device so it knows it can transfer encryption keys for old messages to the new device

This has been in Element/Matrix since forever and I found it the easiest verification mechanism of all the encrypted messengers I've tried. I'm not surprised they're making this part of the standard process, but the wording in 2025 is... unfortunate. Or perhaps that adjective should be applied to the rest of the world since it's not the Matrix Foundation which changed. For the reader to decide ^^

Re: Verifying your Matrix devices is becoming mandatory

#66

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

I feel they underestimated what the MVP really is and started touting Matrix as great before it was really there, which has backfired and led to disappointment. They also went a bit too overboard on the overgeneralized idea of it being "a decentralized eventually consistent JSON database", which led to a lack of focus on its concrete usability as a chat system. I still use it and it's not bad in some respects, but it's a long, long way away from being able to attract a mass of ordinary users.

Re: Verifying your Matrix devices is becoming mandatory

#68
post #17

I don’t use Matrix, but if it’s E2EE, then how is it possible in the current design for an unverified device to even exist? It has the keys, or it doesn’t, right?

You don't have to use E2EE if you don't want to. I personally don't because I don't care about it, and it adds extra difficulties to the experience.

Re: Verifying your Matrix devices is becoming mandatory

#69
post #41
post #33

Earlier quoted context omitted.

Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.

I trust my life to the server I host in my own closet. People can lecture me all day long about the superiority of Signal's encryption, and I'll just slowly rotate my chair to point my index finger at the Dell OptiPlex behind me.

I obviously can't speak for you, but there's not a freaking chance I'd trust my life to the servers I run.

To go maybe too literal: when I'm working on machines that could physically eat me, I don't trust myself with just one off switch -- I want redundancy. And since computers are horrible piles of ridiculous complexity, the closest I can get (and not really get close) is trusting some of the top minds to overthink the crap out of it in a way that I can't do with the systems I manage.

But again, YMMV.

Re: Verifying your Matrix devices is becoming mandatory

#70
post #52
post #27

Earlier quoted context omitted.

In this case, it's what you do when signing in from a new device (or browser) to attest that it's yours. It avoids warnings to you and your contacts that a device has gained access to your account without your approval. It involves doing one of these things: - Comparing a short sequence of emoji on each device and confirming that they match. - Using one device to scan a QR code displayed by the other. - Entering a re…

> Pretty quick and easy in most cases The experiences reported here seem to say otherwise... As others, anyhow, I haven't tried again recently > (Gripe: The recovery key approach was unfortunately made painful and error-prone in recent Element releases, by disabling the option to choose a passphrase instead, but most people can simply use one of the other two approaches.) I last tried Element about six months ago, bu…

I think current Element versions accept either a recovery key or recovery passphrase in the same input field, so there's no getting it wrong. Since you seem focused on UI, it's worth noting that Element X (their beta mobile app) has a greatly simplified interface; their team clearly has been working to make it easier.

Also, other clients exist.

For whatever it's worth, I've been using Matrix for about five years, including some of its roughest times. I seldom see errors these days, but I can understand how folks who were frustrated with earlier iterations would still be soured to it. Such is the nature of an ambitious work in progress, I suppose.

I use it because there is nothing else with the combination of features that are most important to me, and because (despite my gripes) I can see slow and steady improvement. I think it's moving in the right direction overall. I could picture introducing family members to it once Matrix 2.0 is released and the implementations shake out any early problems.

Post reply on HN