Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

141–150 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#141
post #64

Earlier quoted context omitted.

Yes. If you don’t verify, every conversation is empty.

But it also asks for recovery key and complains about it being out of sync until entered even if you do the verification step! Entirely possible to only get a partial recovery of messages until this is entered.

cannot confirm this either

one method of verification suffices (be it recovery key or using a different device)

Re: Verifying your Matrix devices is becoming mandatory

#142
post #20

I tried out an alpha client once & can’t get the stupid pop-up about unverified devices to go away now. Another client didn’t have the verification flow even set up—this will end up being yet another barrier to entry for new clients. With the clients (yes, multiple) crashing often, constantly syncing for ages, & feature sets not on parity + without graceful fallbacks, I do not like the Matrix client space (nor the se…

> I tried out an alpha client once & can’t get the stupid pop-up about unverified devices to go away now.

Open app with device management (e.g. Element Desktop) and remove the unverified devices you don't intend to verify.

Regarding XMPP: With the lack of Cross Signing, key backup and consistent storage of messages, it can't be expected to provide the convenience Matrix does for the foreseeable future - just my personal opinion. The matrix-rust-sdk should it also make easy to get started with a client.

Re: Verifying your Matrix devices is becoming mandatory

#143
post #91
post #61

Earlier quoted context omitted.

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

It is super annoying but you have to be very naive to not understand that anything that can be abused will be abused so you need to bake in countermeasures from day #1 or you might as well not bother with the launch.

Re: Verifying your Matrix devices is becoming mandatory

#144

Earlier quoted context omitted.

If you make anything public, you will have to deal with it. You should be mentally prepared for that from the start.

I mean I could just as easily say you as an user should be mentally prepared. Matrix is developing a privacy IM, you do not really moderate that now, do you? Leave the rooms that raise your cortisol level.

> I mean I could just as easily say you as an user should be mentally prepared.

Users tend to be less aware of these things than the operators of such servers (or at least, that's how it should be).

> Matrix is developing a privacy IM, you do not really moderate that now, do you?

No, but you can create mechanisms for the users to flag problematic accounts.

> Leave the rooms that raise your cortisol level.

The filth will follow the users. That's the whole game plan here: to cause grief.

Re: Verifying your Matrix devices is becoming mandatory

#145
post #72

"Now the end-to-end encryption will leak into the UX even more and you better like it" I'll say it again: E2EE will never become mainstream unless someone somehow manages to implement it such that it's completely transparent to the user while keeping all the features that people have come to expect from IM apps, like server-stored conversation history or support for multiple devices. By "completely transparent" I mea…

> E2EE will never become mainstream iMessage and Whatsapp are both mainstream.

Technically they are, but neither of them fits the strict definition of a E2EE messaging app, while also still hurting the UX.

Whatsapp is very insistent about backing up your messages to cloud services without encryption. To use it on desktop, you have to make everything go through your phone. And, afaik, you still can't transfer message backups between Android and iOS.

Even disregarding the extreme gatekeeping, iMessage relies on Apple managing your encryption keys so there are no confidentiality guarantees. Apple can, at any moment, give themselves a key to decrypt your messages.

Both Whatsapp and iMessage are proprietary, so it's also the case of "please trust us that we've implemented it the way we claim we did".

Re: Verifying your Matrix devices is becoming mandatory

#146

I am not sure the founder is reading this. I tried googling but couldn't find it - I recall the hn handle being something like Atheon. Not that hn sends mention notifications. Matrix is something that had my eyes lit after years or being burnt/disappointed by communication apps (Signal included). I had converted/migrated a lot of people to it (I mean of course they didn't "convert" but they had it and were replying t…

> Matrix, Vector, Riot, Element – things just kept happening. App was never an end user app and it became very clear that it was not the intention either.

Element X definitely is.

Re: Verifying your Matrix devices is becoming mandatory

#147

Earlier quoted context omitted.

You don't have to use E2EE if you don't want to. I personally don't because I don't care about it, and it adds extra difficulties to the experience.

If you don't need e2ee, are there features that make matrix better than xmpp?

decentralized rooms, built in video conferencing, consistent chat history storage

Re: Verifying your Matrix devices is becoming mandatory

#148
post #51

seems like it's just that element (the official, and most popular client) will ignore messages from unverified devices, but since it's part of the spec, other clients that want to be spec-compliant will implement this too. I don't think most other clients follow the spec that closely though. I'm in favor of the change, the only downside I can think of is users with esoteric clients or simple bots that don't support v…

no, you are not alone, though I don't host

Re: Verifying your Matrix devices is becoming mandatory

#149

Earlier quoted context omitted.

I mean I could just as easily say you as an user should be mentally prepared. Matrix is developing a privacy IM, you do not really moderate that now, do you? Leave the rooms that raise your cortisol level.

> I mean I could just as easily say you as an user should be mentally prepared. Users tend to be less aware of these things than the operators of such servers (or at least, that's how it should be). > Matrix is developing a privacy IM, you do not really moderate that now, do you? No, but you can create mechanisms for the users to flag problematic accounts. > Leave the rooms that raise your cortisol level. The filth w…

I have been in many rooms that are completely fine; technical rooms.

As for flagging problematic accounts: how would that work in a decentralized E2EE system, and do you think it cannot be abused? What would you want them to do if I flag your account a million times? Keep in mind they probably may not be able to keep up with it, nor do I expect them to. Additionally, you still should be able to use the service due to its decentralized, privacy-preserving nature, so the worst thing that may happen is getting banned from a Matrix instance, or a room.

Re: Verifying your Matrix devices is becoming mandatory

#150

Earlier quoted context omitted.

> If IRC suffices for your purposes, then Matrix, with its encryption and all, is apparently overkill. IRC has encryption too. You run it over TLS.

For E2EE there is the very old unofficial and only-partially-secure extension of using Blowfish with a static key.

I guess it's not end-to-end, it's decrypted on the server.

Presumably if you want to send an encrypted message from one literal endpoint to another, you'd use some other technology. I'm prepared to bet there are enough people doing just that, too.

Post reply on HN