Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

111–120 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#111
post #36
post #23

I think Matrix as a protocol has been pretty ineffective, as their top priority seems to be keeping data permanent and duplicated. Both performance and privacy are at the bottom of their priority list. The one good thing I can say about it is that encryption of message contents is enabled by default in conversations and available in groups, but that's about it - nothing else is, or can be, encrypted. In other words,…

It's pretty accurate. I was a bit shocked when I saw that room names were not encrypted. I thought that was such a basic privacy requirement, and it's not hard to implement when you already have message encryption. Matrix seems to have a lot of these structural flaws. Even the encryption praised in the Reddit post has had problems for years where messages don't decrypt. These issues are patched slowly over time, but…

The decryption problems I've experienced have a been fixed a while ago. There was a push to fix these last year or the year before that, and at this point I'm pretty sure only some outdated or obscure clients with old encryption liberties still suffer from these problems.

The huge amount of unencrypted metadata is pretty hard to avoid with Matrix, though. It's the inevitable result of stuffing encryption into an unencrypted protocol later, rather than designing the protocol to be encrypted from the start.

I've had similar issues with other protocols too, though. XMPP wouldn't decrypt my messages (because apparently I used the wrong encryption for one of the clients), and Signal got into some funky state where I needed to re-setup and delete all of my old messages before I could use it again. Maintained XMPP clients (both of them) seem to have fixed their encryption support and Signal now has backups so none of these problems should happen again, but this stuff is never easy.

Re: Verifying your Matrix devices is becoming mandatory

#112
post #64

Earlier quoted context omitted.

Yes. If you don’t verify, every conversation is empty.

But it also asks for recovery key and complains about it being out of sync until entered even if you do the verification step! Entirely possible to only get a partial recovery of messages until this is entered.

That's not normal. It doesn't happen on any of my accounts or clients. Verification takes a moment if you're in a lot of rooms, but it exchanges all keys.

Re: Verifying your Matrix devices is becoming mandatory

#113
post #17

I don’t use Matrix, but if it’s E2EE, then how is it possible in the current design for an unverified device to even exist? It has the keys, or it doesn’t, right?

You don't have to use E2EE if you don't want to. I personally don't because I don't care about it, and it adds extra difficulties to the experience.

If you don't need e2ee, are there features that make matrix better than xmpp?

Re: Verifying your Matrix devices is becoming mandatory

#114
post #22

I have a private matrix server for a few friends. Whenever someone logs on with a new device or client it lists them as being unverified. Eventually it goes away. I really have no idea at what point verification occurs.

They verify their device. Usually means opening Matrix on a other device, clicking the pop-up, and scanning a QR code or matching emoji. One device signs proof of verification of the other and exchanges encryption keys so the new device can read encrypted conversations.

Unverified devices are indistinguishable from a hacker logging in through credential stuffing/password leaks until verification is done.

It's a process similar to adding devices to Signal or WhatsApp, except with Matrix you can still log in without having physical access to another device. Useful if you only ever visit unencrypted rooms perhaps.

Re: Verifying your Matrix devices is becoming mandatory

#115
post #41

Earlier quoted context omitted.

I trust my life to the server I host in my own closet. People can lecture me all day long about the superiority of Signal's encryption, and I'll just slowly rotate my chair to point my index finger at the Dell OptiPlex behind me.

I obviously can't speak for you, but there's not a freaking chance I'd trust my life to the servers I run. To go maybe too literal: when I'm working on machines that could physically eat me, I don't trust myself with just one off switch -- I want redundancy. And since computers are horrible piles of ridiculous complexity, the closest I can get (and not really get close) is trusting some of the top minds to overthink…

Well, when US-EAST-1 went down, my family was still chatting. Same with Cloudflare. Even if I lose internet, we can all chat so long as we’re on the network.

That said, the uptime is still probably worse than Signal. I didn’t mean trust the reliability. I meant the security.

Re: Verifying your Matrix devices is becoming mandatory

#116

Earlier quoted context omitted.

You don't have to use E2EE if you don't want to. I personally don't because I don't care about it, and it adds extra difficulties to the experience.

If you don't need e2ee, are there features that make matrix better than xmpp?

Lots of open source projects have matrix servers and not XMPP servers. Some bridges don't have XMPP equivalents (and some bridges don't have Matrix equivalents either).

XMPP also does E2EE of course, though I've found it to be a worse experience on most clients compared to Matrix.

Re: Verifying your Matrix devices is becoming mandatory

#117

Earlier quoted context omitted.

I mean we’re there for Signal. The parts that suck still are regarding access/retention of old messages which is an area Matrix is ironically slightly better about. But Signal we don’t need to think about verification, at worst it says this asshole has a new identity and then I have to tell them I’ve reset my iPhone for the 4th time this week… Normal users do find retention important even if privacy/security minded u…

Can you use Signal across multiple devices?

You can use Molly to put Signal on multiple devices or you can bridge it into Matrix or XMPP, but you'll always need to run on one "main" device.

Re: Verifying your Matrix devices is becoming mandatory

#118

What exactly does this entail? I'm willing to be charitable in assuming that their use of "verify" isn't the modern usage of "give us your ID!" but I'm not enmeshed enough in the ecosystem anymore to know.

If you don't mind reading an essay, here is mine from the same discussion: https://news.ycombinator.com/item?id=45989744

Re: Verifying your Matrix devices is becoming mandatory

#119

Earlier quoted context omitted.

Officially it supports linking other devices like their desktop app as a secondary. I currently use this to link into signal-mautrix on my matrix homeserver. This way I can access signal from multiple phones and multiple computers using a matrix client instead.

But you still need one "primary" device and it has to be a phone, right? That's different from Matrix where you can have arbitrary devices that are all on an equal footing.

Yes. And, annoyingly, when you only use Signal occasionally, these desktop sessions expire. And you have to link again. And when you do, you end up with a gap in your conversation history because "security".
Post reply on HN