Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

81–90 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#81

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

If IRC suffices for your purposes, then Matrix, with its encryption and all, is apparently overkill.

If I were to upgrade an IRC-based community to something newer and richer, I'd go with Jabber, well-known, well-established, with a ton of various clients and several servers. Yes, it's not ideal, but it's still a massive upgrade compared to IRC, if your server supports a good list XEPs and your community members agree to use non-esoteric clients that also support them.

Re: Verifying your Matrix devices is becoming mandatory

#82
post #3

What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.

I’m a server admin and I still couldn’t tell you why when I sign new endpoints in and verify for cross-signing it still also asks me for a recovery key.

For encrypted search on desktop it has to fetch batches of messages and this is configurable in settings. It just had a number? what is that? how large the batch is, how many ms? no clue! good thing we can’t do encrypted search on mobile/web.

Re: Verifying your Matrix devices is becoming mandatory

#83
post #64

Earlier quoted context omitted.

Doesn’t verification also exchange encryption keys, letting you decrypt messages from before you logged in? I remember that being a huge issue where you would see unable to decrypt messages. Probably just bad UX to let people skip the verification step.

Yes. If you don’t verify, every conversation is empty.

But it also asks for recovery key and complains about it being out of sync until entered even if you do the verification step! Entirely possible to only get a partial recovery of messages until this is entered.

Re: Verifying your Matrix devices is becoming mandatory

#84
post #72

"Now the end-to-end encryption will leak into the UX even more and you better like it" I'll say it again: E2EE will never become mainstream unless someone somehow manages to implement it such that it's completely transparent to the user while keeping all the features that people have come to expect from IM apps, like server-stored conversation history or support for multiple devices. By "completely transparent" I mea…

I mean we’re there for Signal. The parts that suck still are regarding access/retention of old messages which is an area Matrix is ironically slightly better about. But Signal we don’t need to think about verification, at worst it says this asshole has a new identity and then I have to tell them I’ve reset my iPhone for the 4th time this week…

Normal users do find retention important even if privacy/security minded users find value in ephemerality.

Re: Verifying your Matrix devices is becoming mandatory

#85
post #33
post #31

Earlier quoted context omitted.

@Arathorn would be an objectively better person to discuss this, but the Redditor isn't completely off the mark: metadata is (currently) not nearly as well-guarded on Matrix compared to Signal. However, work is ongoing to improve the situation; more importantly, Matrix is a different threat model (in my opinion), and allows for different trade-offs. When I use Signal, I have to trust Signal's servers and their admin…

Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.

When you leak that much metadata, it's disenginious to call it encrypted.

Re: Verifying your Matrix devices is becoming mandatory

#86
post #3

What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.

Thankfully, no, it's not anything evil like Play Integrity is. The simple explanation is that the first time you log in to an existing account from a new device, you need to go on one of your old devices and confirm that the new one is yours.

Re: Verifying your Matrix devices is becoming mandatory

#89
post #72

"Now the end-to-end encryption will leak into the UX even more and you better like it" I'll say it again: E2EE will never become mainstream unless someone somehow manages to implement it such that it's completely transparent to the user while keeping all the features that people have come to expect from IM apps, like server-stored conversation history or support for multiple devices. By "completely transparent" I mea…

If that's true, then E2EE will never become mainstream. Consider this scenario: "My phone got lost/stolen/broken, so I just got a new one. I haven't logged in to this app since I got my last phone, so I forget my credentials for it. I'll reset them through my email. What do you mean my conversation history is gone?"

That's not really far-fetched. If you can get your conversation history back in that scenario, then so can the server operator so it's not real E2EE, and if you can't, then by your statement it won't become mainstream.

Re: Verifying your Matrix devices is becoming mandatory

#90

What exactly does this entail? I'm willing to be charitable in assuming that their use of "verify" isn't the modern usage of "give us your ID!" but I'm not enmeshed enough in the ecosystem anymore to know.

Yeah, IMO "verify" was a poor choice of wording for what this is. It has nothing to do with remote attestation or any other form of Treacherous Computing, and it has nothing to do with your real-life identity. It's just "go on your old device and confirm that the new device is really yours."
Post reply on HN