Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

131–140 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#131
post #91

Earlier quoted context omitted.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

If you make anything public, you will have to deal with it. You should be mentally prepared for that from the start.

I mean I could just as easily say you as an user should be mentally prepared.

Matrix is developing a privacy IM, you do not really moderate that now, do you? Leave the rooms that raise your cortisol level.

Re: Verifying your Matrix devices is becoming mandatory

#132
post #72

"Now the end-to-end encryption will leak into the UX even more and you better like it" I'll say it again: E2EE will never become mainstream unless someone somehow manages to implement it such that it's completely transparent to the user while keeping all the features that people have come to expect from IM apps, like server-stored conversation history or support for multiple devices. By "completely transparent" I mea…

> E2EE will never become mainstream

iMessage and Whatsapp are both mainstream.

Re: Verifying your Matrix devices is becoming mandatory

#133
post #36
post #23

I think Matrix as a protocol has been pretty ineffective, as their top priority seems to be keeping data permanent and duplicated. Both performance and privacy are at the bottom of their priority list. The one good thing I can say about it is that encryption of message contents is enabled by default in conversations and available in groups, but that's about it - nothing else is, or can be, encrypted. In other words,…

It's pretty accurate. I was a bit shocked when I saw that room names were not encrypted. I thought that was such a basic privacy requirement, and it's not hard to implement when you already have message encryption. Matrix seems to have a lot of these structural flaws. Even the encryption praised in the Reddit post has had problems for years where messages don't decrypt. These issues are patched slowly over time, but…

> These issues are patched slowly over time, but you shouldn't need to show me a graph demonstrating how you have slowly decreased the decryption issues. There shouldn't be any to begin with! If there are, the protocol is fundamentally broken.

This is wrong, because afaik these errors happen due to corner cases and I really don't like the attitude here.

Re: Verifying your Matrix devices is becoming mandatory

#134
post #21

Earlier quoted context omitted.

Yes, the purpose is the same but the UX is a bit different.

Quite. I have yet to manage a verification between clients. I have had all variations of clients ignoring requests, reporting requests only for the requesting client to ignore the response. Both ends quitting declaring that the other end cancelled, asking for the other end to input a code while the other end shows no interface for doing so. It marked the end of me using Matrix as a platform. I'd go back to the old IR…

I have never failed at that. Worst case I type my recovery key and done.

I still have my encrypted messages available from 2020

Re: Verifying your Matrix devices is becoming mandatory

#135

Earlier quoted context omitted.

But it also asks for recovery key and complains about it being out of sync until entered even if you do the verification step! Entirely possible to only get a partial recovery of messages until this is entered.

That's not normal. It doesn't happen on any of my accounts or clients. Verification takes a moment if you're in a lot of rooms, but it exchanges all keys.

been a pretty reliable issue when I've set up a new device. Whatever keys the client is getting, they're apparently not useful.

(This general flakiness of features just sometimes not working as they should is probably the main reason I haven't tried to recommend friends to switch to element)

Re: Verifying your Matrix devices is becoming mandatory

#136
post #77

Earlier quoted context omitted.

Yes, the purpose is the same but the UX is a bit different.

If by bit different you mean absolute nightmare then yes

imho it's the best out there

- no unnecessary coupling to a phone client

- no coupling to any other client - I can just put my recovery key in and be verified without having to deal with other apps.

Re: Verifying your Matrix devices is becoming mandatory

#137
post #27
post #3

What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.

In this case, it's what you do when signing in from a new device (or browser) to attest that it's yours. It avoids warnings to you and your contacts that a device has gained access to your account without your approval. It involves doing one of these things: - Comparing a short sequence of emoji on each device and confirming that they match. - Using one device to scan a QR code displayed by the other. - Entering a re…

> The recovery key approach was unfortunately made painful and error-prone in recent Element releases, by disabling the option to choose a passphrase instead, but most people can simply use one of the other two approaches.

honestly it's the best thing ever they have done:

- I have heard of someone who failed to use Matrix, because he got frustrated of having not a secure enough passphrase

- people don't choose secure passphrases

- it provides options making things more complex (especially when guiding others)

- you know you won't memorize it, so you are more likely to put it down

Re: Verifying your Matrix devices is becoming mandatory

#138
post #107
post #70

Earlier quoted context omitted.

I think current Element versions accept either a recovery key or recovery passphrase in the same input field, so there's no getting it wrong. Since you seem focused on UI, it's worth noting that Element X (their beta mobile app) has a greatly simplified interface; their team clearly has been working to make it easier. Also, other clients exist. For whatever it's worth, I've been using Matrix for about five years, inc…

I tried the current Element and Element X. In short, the passphrase works with both and the recovery key with neither, specifically: Element classic has two separate fields; if I input the recovery key (in the correct field), I get told "Backup could not be decrypted with this PASSPHRASE: please verify that you entered the correct recovery passphrase." That's how it was the last time I used it, and if I'm not mistake…

> Element X has a single field, that supposedly takes both passphrases and recovery keys, but if I enter the recovery key I'm directed to a "Verify with another verified device" screen, even if I had logged out from all other sessions.

I have just tried this on Android.

I am directed to

1) "Device verified - Now you can read or send messages securely, and ... - [Continue]"

2) "Help improve Element X ... [OK] [Not now]"

3) list of chats

Element X Android fyi. No problems logging in using Firefox.

Re: Verifying your Matrix devices is becoming mandatory

#139
post #81

Earlier quoted context omitted.

If IRC suffices for your purposes, then Matrix, with its encryption and all, is apparently overkill. If I were to upgrade an IRC-based community to something newer and richer, I'd go with Jabber, well-known, well-established, with a ton of various clients and several servers. Yes, it's not ideal, but it's still a massive upgrade compared to IRC, if your server supports a good list XEPs and your community members agre…

> If IRC suffices for your purposes, then Matrix, with its encryption and all, is apparently overkill. IRC has encryption too. You run it over TLS.

For E2EE there is the very old unofficial and only-partially-secure extension of using Blowfish with a static key.

Re: Verifying your Matrix devices is becoming mandatory

#140
post #39

Despite all the gnashing of teeth in this thread, this seems reasonable. This seems to only prevent you from logging into your account, with only a password, NOT verifying it (by dismissing all the prompts asking you to do so), and then sending (and receiving new!) encrypted messages anyway. I've never used an unverified Matrix account in the 6 years that I've been an active user. Verification used to be a bit finick…

Doesn’t verification also exchange encryption keys, letting you decrypt messages from before you logged in? I remember that being a huge issue where you would see unable to decrypt messages. Probably just bad UX to let people skip the verification step.

> Doesn’t verification also exchange encryption keys, letting you decrypt messages from before you logged in?

if you use key backup

Post reply on HN