I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…
Verifying your Matrix devices is becoming mandatory
71–80 of 251 posts
Re: Verifying your Matrix devices is becoming mandatory
#72I'll say it again: E2EE will never become mainstream unless someone somehow manages to implement it such that it's completely transparent to the user while keeping all the features that people have come to expect from IM apps, like server-stored conversation history or support for multiple devices. By "completely transparent" I mean that the user doesn't have to do any extra actions whatsoever to make it work.
Re: Verifying your Matrix devices is becoming mandatory
#73Clicking verify in any client does nothing. No popups in any other clients - doesn't ever seem to do anything. Sometimes Element will pop up a QR reader but there's no QR presented in the other clients. The UX around Matrix is a nightmare.
Re: Verifying your Matrix devices is becoming mandatory
#74I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…
Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.
At this point the majority use case I have for matrix is to bridge to IRC with heisenbridge and be able to use signal on my laptop through mautrix-signal and nheko. The number of native channels I’m in continues to shrink.
Re: Verifying your Matrix devices is becoming mandatory
#75Re: Verifying your Matrix devices is becoming mandatory
#76What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.
In this case, it's what you do when signing in from a new device (or browser) to attest that it's yours. It avoids warnings to you and your contacts that a device has gained access to your account without your approval. It involves doing one of these things: - Comparing a short sequence of emoji on each device and confirming that they match. - Using one device to scan a QR code displayed by the other. - Entering a re…
Re: Verifying your Matrix devices is becoming mandatory
#77Earlier quoted context omitted.
So is this like the Signal PIN which is required when installing on a new device? If you forget, the cryptography changes and old contacts are warned that signatures are rotated, right?
Yes, the purpose is the same but the UX is a bit different.
Re: Verifying your Matrix devices is becoming mandatory
#78Re: Verifying your Matrix devices is becoming mandatory
#79I use Thunderbird as my main Matrix client since it's already always open on my PC and is Lightweight. Whenever I open Element or any other client (Nheko, etc.) they all complain about each-other being unverified. Clicking verify in any client does nothing. No popups in any other clients - doesn't ever seem to do anything. Sometimes Element will pop up a QR reader but there's no QR presented in the other clients. The…
Re: Verifying your Matrix devices is becoming mandatory
#80seems like it's just that element (the official, and most popular client) will ignore messages from unverified devices, but since it's part of the spec, other clients that want to be spec-compliant will implement this too. I don't think most other clients follow the spec that closely though. I'm in favor of the change, the only downside I can think of is users with esoteric clients or simple bots that don't support v…
Self hosting the call/video feature became a lot more complicated though (and it's incompatible with the old system).