Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

151–160 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#151

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

> There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in terms of the UX and it's a crying shame as Matrix/Element had a lot of potential.

It still has.

And with Element X they have greatly improved the UX.

Plus utd errors have been reduced by a lot.

That said, I haven't ever had issues with devices not being correctly verified ( I use that feature since it was released - and can still recover the encrypted messages of that time).

Re: Verifying your Matrix devices is becoming mandatory

#152
post #3

What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.

In my case, it transferred my willingness to self-host a chat server to something else.

Re: Verifying your Matrix devices is becoming mandatory

#153
post #61

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

policy servers show that they indeed do care

Re: Verifying your Matrix devices is becoming mandatory

#154
post #91

Earlier quoted context omitted.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

It is super annoying but you have to be very naive to not understand that anything that can be abused will be abused so you need to bake in countermeasures from day #1 or you might as well not bother with the launch.

with that strategy you won't launch ever if you have limited budget, especially because Matrix isn't exactly a system/protocol off the self

Re: Verifying your Matrix devices is becoming mandatory

#155
post #61

Earlier quoted context omitted.

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

It's kind of wild to me that they haven't prioritized this more. This issue has been open for almost exactly 6 years: https://github.com/matrix-org/matrix-spec/issues/565 . This one even longer: https://github.com/matrix-org/matrix-spec/issues/836 . The Matrix permission system still doesn't even have a way to say "sending images is not allowed" (either per room or per user).

maybe because of limited budget and more urgent issues? who knows

Re: Verifying your Matrix devices is becoming mandatory

#156

As someone whose devices randomly became unverified just a few months ago, signed out, and then tried to use my recovery keys: I was authenticated, but unverified. When attempting to verify iOS, Desktop linux didn’t work. When attempting to verify Desktop Linux, Desktop Windows didn’t work. When verifying Android, iOS didn’t work. Every verified official client for every platform was verified, tried a different verif…

are you using your own server?

I have never heard of such issue and not experienced it despite intensive use, so it's a bit strange that you and people you know have experienced this repeatedly.

Re: Verifying your Matrix devices is becoming mandatory

#157

Earlier quoted context omitted.

> E2EE will never become mainstream iMessage and Whatsapp are both mainstream.

Technically they are, but neither of them fits the strict definition of a E2EE messaging app, while also still hurting the UX. Whatsapp is very insistent about backing up your messages to cloud services without encryption. To use it on desktop, you have to make everything go through your phone. And, afaik, you still can't transfer message backups between Android and iOS. Even disregarding the extreme gatekeeping, iMe…

iMessage has worse UX than signal for key verification, but does support it. https://support.apple.com/en-us/118246

>Both Whatsapp and iMessage are proprietary, so it's also the case of "please trust us that we've implemented it the way we claim we did".

This is simply not true, any serious analysis of Signal would be performed on the binaries and not the source code. Having access to the source code does not make it any easier to discover well-hidden backdoors, but it is possible to exploit e.g. compiler behaviour in a way to create a backdoor that is essentially impossible to detect by reviewing source code.

Access to source code might very well make it easier to discover non-intentional bugs, but does not solve the problem of trust.

Re: Verifying your Matrix devices is becoming mandatory

#158
post #61

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

Considering the thread context I'm curious how would IRC help with that other than people running command line or TUI clients?

Also do you want the development team to moderate self hosted chat servers? How would that work?

Re: Verifying your Matrix devices is becoming mandatory

#159
post #91

Earlier quoted context omitted.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

It is super annoying but you have to be very naive to not understand that anything that can be abused will be abused so you need to bake in countermeasures from day #1 or you might as well not bother with the launch.

Aren't there any moderators in those channels? I have 0 issues in the channels I am in (some podcasting channels, some tech, some FOSDEM.)

I find a lot of value in Element as is, I'm glad they bothered.

Post reply on HN