Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

161–170 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#161
I had a more pleasant experience with SchildiChat hosted on a web server than the desktop Element clients.

I don't like the way groups/chatrooms are displayed to be honest. Its confusing. It feels like its trying to get away from the "server room/#somechat" model that works well with IRC and even with trendy current products like Discord.

Re: Verifying your Matrix devices is becoming mandatory

#162
post #133
post #36

Earlier quoted context omitted.

It's pretty accurate. I was a bit shocked when I saw that room names were not encrypted. I thought that was such a basic privacy requirement, and it's not hard to implement when you already have message encryption. Matrix seems to have a lot of these structural flaws. Even the encryption praised in the Reddit post has had problems for years where messages don't decrypt. These issues are patched slowly over time, but…

> These issues are patched slowly over time, but you shouldn't need to show me a graph demonstrating how you have slowly decreased the decryption issues. There shouldn't be any to begin with! If there are, the protocol is fundamentally broken. This is wrong, because afaik these errors happen due to corner cases and I really don't like the attitude here.

It's not just a corner case. The issue was so prevalent for years that if it was limited to just a few corner cases, the entire protocol must consist of nothing but corner cases.

It frequently occurred on the "happy path": on a single server that they control, between identical official clients, in the simplest of situations. There really is no excuse.

I'm not saying that building a federated chat network with working encryption is easy. On the contrary, it is very hard. I'm sure the designers had the best intentions, but they simply lacked the competence to overcome such a challenge and ensure the protocol was mostly functional right from the outset.

Re: Verifying your Matrix devices is becoming mandatory

#163
post #44

Earlier quoted context omitted.

> Despite all the gnashing of teeth in this thread, this seems reasonable I think it's not the requirement itself that's the crucible of discussion but the issues are rather that the blog post should have explicitly defined what verification is in it's second sentence and that matrix/element still is barely useable even for reasonably technical users.

> barely useable even for reasonably technical users My entire family (including my elderly mother) would be very interested to learn how technical they are!

Scale matters. Once you achieve over a hundred of users, you got all the random bugs, and glitches appearing, and you can't guide everyone personally across UX issues. This is when lack of decent documentation, unpolished UI, and even the fact that it uses its own terminology (like "spaces") starts to hurt. I don't mean Synapse/Element combination is bad, but so far it's not great either.

Re: Verifying your Matrix devices is becoming mandatory

#164
post #36

Earlier quoted context omitted.

It's pretty accurate. I was a bit shocked when I saw that room names were not encrypted. I thought that was such a basic privacy requirement, and it's not hard to implement when you already have message encryption. Matrix seems to have a lot of these structural flaws. Even the encryption praised in the Reddit post has had problems for years where messages don't decrypt. These issues are patched slowly over time, but…

The decryption problems I've experienced have a been fixed a while ago. There was a push to fix these last year or the year before that, and at this point I'm pretty sure only some outdated or obscure clients with old encryption liberties still suffer from these problems. The huge amount of unencrypted metadata is pretty hard to avoid with Matrix, though. It's the inevitable result of stuffing encryption into an unen…

Yes, messaging protocols, especially federated ones, are never easy. I just wish we could have skipped the three or four years when Matrix was basically unusable for the average user because end-to-end encryption was switched on by default. Perhaps a clean redesign would have been better. Now they have to change the wheels on a moving car.

Re: Verifying your Matrix devices is becoming mandatory

#165
I've been using Delta Chat with a lot of success. It is easy, it works, bots are easy and the concept is improving. They even plan to have forward secrecy. So, give it a try. If you explored it a long time ago, try again, many things have improved in that ecosystem.

Re: Verifying your Matrix devices is becoming mandatory

#166
post #133

Earlier quoted context omitted.

> These issues are patched slowly over time, but you shouldn't need to show me a graph demonstrating how you have slowly decreased the decryption issues. There shouldn't be any to begin with! If there are, the protocol is fundamentally broken. This is wrong, because afaik these errors happen due to corner cases and I really don't like the attitude here.

It's not just a corner case. The issue was so prevalent for years that if it was limited to just a few corner cases, the entire protocol must consist of nothing but corner cases. It frequently occurred on the "happy path": on a single server that they control, between identical official clients, in the simplest of situations. There really is no excuse. I'm not saying that building a federated chat network with workin…

> The issue was so prevalent for years that if it was limited to just a few corner cases, the entire protocol must consist of nothing but corner cases.

for me it wasn't really; occasionally it would hit me, but mostly it worked, and I have been using it for encrypted communication since 2020.

> It frequently occurred on the "happy path": on a single server that they control, between identical official clients, in the simplest of situations. There really is no excuse.

There still can be technical corner cases in the interaction of clients

a talk for details: https://www.youtube.com/watch?v=ZUSucR2axWI

> I'm sure the designers had the best intentions, but they simply lacked the competence to overcome such a challenge and ensure the protocol was mostly functional right from the outset.

well, even if this was true, they still were brave enough to try and eventually pull it off eventually. Perhaps complain to the competent people who haven't even tried.

Re: Verifying your Matrix devices is becoming mandatory

#167

Earlier quoted context omitted.

If you make anything public, you will have to deal with it. You should be mentally prepared for that from the start.

I mean I could just as easily say you as an user should be mentally prepared. Matrix is developing a privacy IM, you do not really moderate that now, do you? Leave the rooms that raise your cortisol level.

Wait a minute, doesn't receiving child porn even if unintentionally like the situation above open up the receiver to legal liability?

It isn't reasonable to expect users to be 'mentally prepared' to have their devices download child porn because they visited a chat room for support about the chat app they're using.

Re: Verifying your Matrix devices is becoming mandatory

#168
post #167

Earlier quoted context omitted.

I mean I could just as easily say you as an user should be mentally prepared. Matrix is developing a privacy IM, you do not really moderate that now, do you? Leave the rooms that raise your cortisol level.

Wait a minute, doesn't receiving child porn even if unintentionally like the situation above open up the receiver to legal liability? It isn't reasonable to expect users to be 'mentally prepared' to have their devices download child porn because they visited a chat room for support about the chat app they're using.

I'd blame the law if it does.

Re: Verifying your Matrix devices is becoming mandatory

#169
post #167

Earlier quoted context omitted.

I mean I could just as easily say you as an user should be mentally prepared. Matrix is developing a privacy IM, you do not really moderate that now, do you? Leave the rooms that raise your cortisol level.

Wait a minute, doesn't receiving child porn even if unintentionally like the situation above open up the receiver to legal liability? It isn't reasonable to expect users to be 'mentally prepared' to have their devices download child porn because they visited a chat room for support about the chat app they're using.

As someone else have said, then that is an issue with the law.

Imagine someone sending you a link that you open and then now you have child porn or whatever else on your hard drive, cached. Quite a shitty situation to be in.

Perhaps avoid non-technical rooms or rooms in which you do not trust people.

Post reply on HN