Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

191–200 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#191
post #155

Earlier quoted context omitted.

It's kind of wild to me that they haven't prioritized this more. This issue has been open for almost exactly 6 years: https://github.com/matrix-org/matrix-spec/issues/565 . This one even longer: https://github.com/matrix-org/matrix-spec/issues/836 . The Matrix permission system still doesn't even have a way to say "sending images is not allowed" (either per room or per user).

maybe because of limited budget and more urgent issues? who knows

And what could be more urgent than this?

Re: Verifying your Matrix devices is becoming mandatory

#193
post #61

Earlier quoted context omitted.

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

Considering the thread context I'm curious how would IRC help with that other than people running command line or TUI clients? Also do you want the development team to moderate self hosted chat servers? How would that work?

Must irc clients do not automatically download or show images which means joining a room and spamming a bunch of them is less impactful on recipients and so less appealing to trolls, so it doesn’t happen.

Re: Verifying your Matrix devices is becoming mandatory

#194
post #23

I think Matrix as a protocol has been pretty ineffective, as their top priority seems to be keeping data permanent and duplicated. Both performance and privacy are at the bottom of their priority list. The one good thing I can say about it is that encryption of message contents is enabled by default in conversations and available in groups, but that's about it - nothing else is, or can be, encrypted. In other words,…

I wish FOSS communities that want an alternative to Discord or Slack ditched Matrix altogeter. It sucks for that. Better use Zulip or Mattermost, both of which are self-hostable.

Edit: I looked up and apparently Mattermost would be out of the question for their feature downgrades in the community version as of late...

Re: Verifying your Matrix devices is becoming mandatory

#195

I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…

When I looked into it the complexity of standing up and admin'ing a Matrix server was clearly either a massive "architecture smell" so bad the project was likely long-term doomed, or a deliberate choice to make it terrible to get people to pay for managed hosting.

In either case, that's a no for me dawg.

Re: Verifying your Matrix devices is becoming mandatory

#196

Earlier quoted context omitted.

> E2EE will never become mainstream iMessage and Whatsapp are both mainstream.

Technically they are, but neither of them fits the strict definition of a E2EE messaging app, while also still hurting the UX. Whatsapp is very insistent about backing up your messages to cloud services without encryption. To use it on desktop, you have to make everything go through your phone. And, afaik, you still can't transfer message backups between Android and iOS. Even disregarding the extreme gatekeeping, iMe…

> iMessage relies on Apple managing your encryption keys so there are no confidentiality guarantees. Apple can, at any moment, give themselves a key to decrypt your messages.

It relies on Apple device managing your encryption keys, no? Which, yes, Apple can still access if it really wanted to simply by virtue of being able to push an iOS update that does that. But the same exact vulnerability applies to any app running on your iPhone.

Re: Verifying your Matrix devices is becoming mandatory

#197

Earlier quoted context omitted.

Officially it supports linking other devices like their desktop app as a secondary. I currently use this to link into signal-mautrix on my matrix homeserver. This way I can access signal from multiple phones and multiple computers using a matrix client instead.

But you still need one "primary" device and it has to be a phone, right? That's different from Matrix where you can have arbitrary devices that are all on an equal footing.

Yes, and there's also a limit of max 5 linked devices.

Re: Verifying your Matrix devices is becoming mandatory

#198

As someone whose devices randomly became unverified just a few months ago, signed out, and then tried to use my recovery keys: I was authenticated, but unverified. When attempting to verify iOS, Desktop linux didn’t work. When attempting to verify Desktop Linux, Desktop Windows didn’t work. When verifying Android, iOS didn’t work. Every verified official client for every platform was verified, tried a different verif…

I've had constant problems with the verification ever since it was introduced. As far as I can tell it hasn't improved at all. Sometimes it works, sometimes it repeatedly kicks me out moments after succeeding, and it's still prompting me to verify some old devices that I removed Element from years ago and I can't find any way to make the constant pop-ups go away (when they feel like appearing again - sometimes they go away for a couple months).

All this will do is make me lose EVERY profile.

Re: Verifying your Matrix devices is becoming mandatory

#199
post #155

Earlier quoted context omitted.

maybe because of limited budget and more urgent issues? who knows

And what could be more urgent than this?

building a more flexible solution for blocking content, rather than hardcoded rules like "no images": https://matrix.org/blog/2025/04/introducing-policy-servers/

Re: Verifying your Matrix devices is becoming mandatory

#200
post #23

I think Matrix as a protocol has been pretty ineffective, as their top priority seems to be keeping data permanent and duplicated. Both performance and privacy are at the bottom of their priority list. The one good thing I can say about it is that encryption of message contents is enabled by default in conversations and available in groups, but that's about it - nothing else is, or can be, encrypted. In other words,…

Okay so -- this and Bluesky.

REALLY feels like no one talks about how "permanent and duplicated" is very much an anti-feature if autonomy and safety and freedom is your goal?

Like, no actually - automatically saving everything all the time is bad. I thought we sort of already knew that.

Post reply on HN