Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

171–180 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#171
post #166

Earlier quoted context omitted.

It's not just a corner case. The issue was so prevalent for years that if it was limited to just a few corner cases, the entire protocol must consist of nothing but corner cases. It frequently occurred on the "happy path": on a single server that they control, between identical official clients, in the simplest of situations. There really is no excuse. I'm not saying that building a federated chat network with workin…

> The issue was so prevalent for years that if it was limited to just a few corner cases, the entire protocol must consist of nothing but corner cases. for me it wasn't really; occasionally it would hit me, but mostly it worked, and I have been using it for encrypted communication since 2020. > It frequently occurred on the "happy path": on a single server that they control, between identical official clients, in the…

> for me it wasn't really; occasionally it would hit me, but mostly it worked, and I have been using it for encrypted communication since 2020.

I think the statistic said that around 10% of users receive at least one "unable to decrypt" message on any given day. That's a lot. Perhaps not for devs who are accustomed to technical frustrations, but for non-technical people, that's far too frequent. Other messaging systems worked much better.

> There still can be technical corner cases in the interaction of clients

> a talk for details: https://www.youtube.com/watch?v=ZUSucR2axWI

You linked to a German political talk show. If you wanted to show me the talk in which the guy listed reasons such as "network requests can fail and our retry logic is so buggy that it often breaks" and "the application regularly corrupts its internal state, so we have to recover from that, which is not always easily possible", let's just say I wasn't that impressed.

> well, even if this was true, they still were brave enough to try and eventually pull it off eventually. Perhaps complain to the competent people who haven't even tried.

It isn't a problem that the Matrix team are not federated networking experts. At the time, they had already received millions in investment. That's not FAANG money, but it's still enough to contract the right people to help design everything properly.

I'm not mad at them. Matrix was a bold effort that clearly succeeded in its aims. I'm just disappointed that it was so unreliable for such a long time, and still is to some extent.

Re: Verifying your Matrix devices is becoming mandatory

#172

Earlier quoted context omitted.

For E2EE there is the very old unofficial and only-partially-secure extension of using Blowfish with a static key.

I guess it's not end-to-end, it's decrypted on the server. Presumably if you want to send an encrypted message from one literal endpoint to another, you'd use some other technology. I'm prepared to bet there are enough people doing just that, too.

The extension I just mentioned is E2EE.

Re: Verifying your Matrix devices is becoming mandatory

#173
post #91
post #61

Earlier quoted context omitted.

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

> Let's not forget a team making a great free product.

I am fully appreciative of the work that goes into making a product like this, but I’m also tired of this mentality that nobody is allowed to talk about the problems with the product. Even simple comments from people who tried to use the product but encountered show-stopping issues are getting downvoted into gray text in this thread.

This mentality that we must only speak praise and cannot speak of problems because a product is free is further off putting. I’ve given Matrix/Element an honest try many times because some of the OSS projects I’m involved with use it, but month after month it’s the most troublesome of all of the apps in this space that I use, and it’s not even close. If I’ve gone a month without dealing with Matrix and I have to open it again it feels like there’s a 50:50 chance something is going to either be inexplicably broken or cause problems even though I thought I finally had it all working last time.

The contrast between how hard we’re told that Matrix is the great and superior option and the reality of what it’s like to use it as a casual or occasional user is really wearing me out on the project.

Re: Verifying your Matrix devices is becoming mandatory

#174

As someone whose devices randomly became unverified just a few months ago, signed out, and then tried to use my recovery keys: I was authenticated, but unverified. When attempting to verify iOS, Desktop linux didn’t work. When attempting to verify Desktop Linux, Desktop Windows didn’t work. When verifying Android, iOS didn’t work. Every verified official client for every platform was verified, tried a different verif…

I went through the same frustration recently. I only occasionally use it, but every second or third time I have to open it up to talk in some channel I lose 30 minutes chasing my tail trying to work through the latest set of problems.

I like the idea, but the effort to reward ratio for using the product has not been good. It has caused visible churn and attrition in the few channels I’ve tried to participate in and it’s become a problem for the OSS projects I’m part of that try to use it for their communication. Of course, there are some people who like it that way and think making communication spaces difficult to access is a bonus, but that’s another topic.

Re: Verifying your Matrix devices is becoming mandatory

#175
FYI: here are the videos of the latest matrix conference: [1]. I think there's a lot of interesting stuff going on!

also, instead of hosting your own server or using some (more or less well-financed) public servers, you can simply throw some money at [2] to pay for hosting for your group of friends or family or whatever. (not affiliated, but I like the idea)

[1] https://media.ccc.de/b/conferences/matrix-conf [2] https://etke.cc/

Re: Verifying your Matrix devices is becoming mandatory

#176
post #167

Earlier quoted context omitted.

Wait a minute, doesn't receiving child porn even if unintentionally like the situation above open up the receiver to legal liability? It isn't reasonable to expect users to be 'mentally prepared' to have their devices download child porn because they visited a chat room for support about the chat app they're using.

As someone else have said, then that is an issue with the law. Imagine someone sending you a link that you open and then now you have child porn or whatever else on your hard drive, cached. Quite a shitty situation to be in. Perhaps avoid non-technical rooms or rooms in which you do not trust people.

And then imagine you have windows with recall enabled (that you repeatedly disabled but keeps enabling after updates), and/or cloud backup with automatic CSAM detection. You're screwed

Re: Verifying your Matrix devices is becoming mandatory

#177
post #39

Despite all the gnashing of teeth in this thread, this seems reasonable. This seems to only prevent you from logging into your account, with only a password, NOT verifying it (by dismissing all the prompts asking you to do so), and then sending (and receiving new!) encrypted messages anyway. I've never used an unverified Matrix account in the 6 years that I've been an active user. Verification used to be a bit finick…

> Despite all the gnashing of teeth in this thread, this seems reasonable

I empathize a lot with the negative experiences shared in this thread.

I think the problem is that every little decision in Matrix might be reasonable to the people who have complete context about the decision, but all of the churn and rough edges have added up to a very bumpy ride. Not only that, but it has been a poorly communicated and documented ride as many in this comment section can attest.

I suspect all of these issues and changes feel like no problem to people who are active in Matrix every day and have a support network to chat with where they all get through the issues by sharing tips and info. For the rest of us who are casual users who only occasionally log in it feels like I’m rolling the dice every time I have to use it. Some times it works like it did last time, some times I have to go on a 30 minute adventure with Google and play games across devices to get it back into a working state again.

Re: Verifying your Matrix devices is becoming mandatory

#178
post #20

I tried out an alpha client once & can’t get the stupid pop-up about unverified devices to go away now. Another client didn’t have the verification flow even set up—this will end up being yet another barrier to entry for new clients. With the clients (yes, multiple) crashing often, constantly syncing for ages, & feature sets not on parity + without graceful fallbacks, I do not like the Matrix client space (nor the se…

I like XMPP and I use it with my family (with the Conversation client) but the web interface (converse.js) if pretty rough.

I would like to replace Matrix at work with an XMPP server, but to convince my colleagues I would have to show something better than that :/

Re: Verifying your Matrix devices is becoming mandatory

#179
post #166

Earlier quoted context omitted.

> The issue was so prevalent for years that if it was limited to just a few corner cases, the entire protocol must consist of nothing but corner cases. for me it wasn't really; occasionally it would hit me, but mostly it worked, and I have been using it for encrypted communication since 2020. > It frequently occurred on the "happy path": on a single server that they control, between identical official clients, in the…

> for me it wasn't really; occasionally it would hit me, but mostly it worked, and I have been using it for encrypted communication since 2020. I think the statistic said that around 10% of users receive at least one "unable to decrypt" message on any given day. That's a lot. Perhaps not for devs who are accustomed to technical frustrations, but for non-technical people, that's far too frequent. Other messaging syste…

Correct link: https://www.youtube.com/watch?v=FHzh2Y7BABQ

> I wasn't that impressed.

If you think, I want to impress you, you are wrong.

Re: Verifying your Matrix devices is becoming mandatory

#180

Earlier quoted context omitted.

As someone else have said, then that is an issue with the law. Imagine someone sending you a link that you open and then now you have child porn or whatever else on your hard drive, cached. Quite a shitty situation to be in. Perhaps avoid non-technical rooms or rooms in which you do not trust people.

And then imagine you have windows with recall enabled (that you repeatedly disabled but keeps enabling after updates), and/or cloud backup with automatic CSAM detection. You're screwed

Yes, and we are screwed either way if we use Windows with Recall, or even in general.

I would not consider Windows secure at all, and it seems futile to use a privacy-oriented IM on Windows, it really defeats the purpose.

Imagine using Windows with Recall enabled that takes screenshots of your conversations all the time. You can be using the most effective IM for privacy but it would not help.

So what is the moral of the story? We have shitty laws, and you should not use Windows. :P

Post reply on HN