Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

201–210 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#201
post #39

Despite all the gnashing of teeth in this thread, this seems reasonable. This seems to only prevent you from logging into your account, with only a password, NOT verifying it (by dismissing all the prompts asking you to do so), and then sending (and receiving new!) encrypted messages anyway. I've never used an unverified Matrix account in the 6 years that I've been an active user. Verification used to be a bit finick…

> Despite all the gnashing of teeth in this thread, this seems reasonable I empathize a lot with the negative experiences shared in this thread. I think the problem is that every little decision in Matrix might be reasonable to the people who have complete context about the decision, but all of the churn and rough edges have added up to a very bumpy ride. Not only that, but it has been a poorly communicated and docum…

> Not only that, but it has been a poorly communicated and documented ride as many in this comment section can attest.

The guides are written for cryptographic infrastructure nerds and not regular normal users that have a habit of forgetting their own passwords after six months. Not to mention the fact that the Element UI tends to churn a lot.

I didn't even know that they deprecated creating new passphrases, and that's what I was telling my users to do!

Re: Verifying your Matrix devices is becoming mandatory

#202
post #61

Earlier quoted context omitted.

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

It’s terrible. I had to leave most channels on the matrix.org namespace because they won’t properly moderate their own server from CSAM. I dropped to 7 day media retention to lower legal liability on my own server, since there’s no way to know when one of my users will be in a channel hit with abuse. At this point the majority use case I have for matrix is to bridge to IRC with heisenbridge and be able to use signal…

I know the matrix honeserver I use has taken our recommendations to NOT cache images from matrix.org due to their non-existent moderation. And the admin put out a bulletin to also recommend disable downloading images as well.

There's also the split room bug (feature?) that allows banned users to still be in rooms where the honeserver doesnt ban them. And then, distributes connection shows ongoing banned content (primarily, you guessed it, CSAM) and the better-moderating admins can't do anything about it.

I'm basically in a few well moderated rooms (Gnuradio, other topics). They do extraordinarily well in not getting many trolls, and for garbage collection.

The only one we're seeing spammed is for some cryptocurrency site Liquid something. But its just commercial spam.

Re: Verifying your Matrix devices is becoming mandatory

#204
post #91

Earlier quoted context omitted.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

> Let's not forget a team making a great free product. I am fully appreciative of the work that goes into making a product like this, but I’m also tired of this mentality that nobody is allowed to talk about the problems with the product. Even simple comments from people who tried to use the product but encountered show-stopping issues are getting downvoted into gray text in this thread. This mentality that we must o…

> I’m also tired of this mentality that nobody is allowed to talk about the problems with the product

I think there's a pretty big difference between constructive criticism vs statements like "The development team seems to not care". To me, it seems pretty clear that the team absolutely cares, but they are also a small and very underfunded team, and things take time. Assuming the worst intentions of a team is the problem and is disappointing to see here.

> I’ve given Matrix/Element an honest try many times because some of the OSS projects I’m involved with use it, but month after month it’s the most troublesome of all of the apps in this space that I use, and it’s not even close.

I don't doubt that, but it does not resonate with me. There have been a few hiccups over the years, eg the database corruption earlier this year (unrelated to the protocol or synapse) resulting in stuck invites, but overall I've had quite a good experience. Far less problems than Teams, and even slack has had issues (mainly, notifications not happening) that I have somehow avoided with Element, although I am aware others have had issues in this area. There are even some things I do with matrix that are simply not possible/practical with the others to begin with.

Re: Verifying your Matrix devices is becoming mandatory

#205
post #186

Earlier quoted context omitted.

"Imagine someone sending you a link that you open and then now you have child porn or whatever else on your hard drive, cached. Quite a shitty situation to be in." I guess the correct legal approach would be to go to police with this. And the correct technical approach to keep online spaces clean, is the ability to kick, mute or ban people who violate the rules. Saying, "just be mentally prepared" sounds to me like a…

I did not use the term "mentally prepared" because I thought it was appropriate, I was just quoting the other guy. I find it silly, too. I will not "accept" child porn or other degeneracies. > Saying, "just be mentally prepared" sounds to me like accepting it. Well, I don't. I go somewhere else. Exactly! You should be going somewhere else. Another Matrix instance, or at the very least another room, and you will be fi…

"You should be going somewhere else. Another Matrix instance, or at the very least another room, and you will be fine."

Well, but I never decided to hang around for longer. Maybe it is because the moderation tools are simply lacking? I would miss the option of not restricting certain users to send pictures in a group.

Re: Verifying your Matrix devices is becoming mandatory

#206
post #205

Earlier quoted context omitted.

I did not use the term "mentally prepared" because I thought it was appropriate, I was just quoting the other guy. I find it silly, too. I will not "accept" child porn or other degeneracies. > Saying, "just be mentally prepared" sounds to me like accepting it. Well, I don't. I go somewhere else. Exactly! You should be going somewhere else. Another Matrix instance, or at the very least another room, and you will be fi…

"You should be going somewhere else. Another Matrix instance, or at the very least another room, and you will be fine." Well, but I never decided to hang around for longer. Maybe it is because the moderation tools are simply lacking? I would miss the option of not restricting certain users to send pictures in a group.

I am not sure if it is currently possible in Matrix, but it is not a bad idea to be able to restrict sending pictures (among other things), I agree.

Re: Verifying your Matrix devices is becoming mandatory

#207
post #73

I use Thunderbird as my main Matrix client since it's already always open on my PC and is Lightweight. Whenever I open Element or any other client (Nheko, etc.) they all complain about each-other being unverified. Clicking verify in any client does nothing. No popups in any other clients - doesn't ever seem to do anything. Sometimes Element will pop up a QR reader but there's no QR presented in the other clients. The…

Not sure how often they update these pages, but Thunderbird is still listed as beta on matrix.org clients page [0], and I remember trying it out some time back and it was indeed very beta (maybe not even beta). It didn't feel like it was getting much maintenance so I stopped using it. I think it's fair to expect bugs in beta releases.

Re: Verifying your Matrix devices is becoming mandatory

#208
post #205

Earlier quoted context omitted.

"You should be going somewhere else. Another Matrix instance, or at the very least another room, and you will be fine." Well, but I never decided to hang around for longer. Maybe it is because the moderation tools are simply lacking? I would miss the option of not restricting certain users to send pictures in a group.

I am not sure if it is currently possible in Matrix, but it is not a bad idea to be able to restrict sending pictures (among other things), I agree.

I just read some complaints with links in sibling comments and sadly no, not possible. Maybe even hard to implement, because of the protocol.

Re: Verifying your Matrix devices is becoming mandatory

#209
post #27

Earlier quoted context omitted.

In this case, it's what you do when signing in from a new device (or browser) to attest that it's yours. It avoids warnings to you and your contacts that a device has gained access to your account without your approval. It involves doing one of these things: - Comparing a short sequence of emoji on each device and confirming that they match. - Using one device to scan a QR code displayed by the other. - Entering a re…

Maybe I’m missing something but why does this service need this process while Discord or whatever don’t?

That's easy, Discord is spyware.

Re: Verifying your Matrix devices is becoming mandatory

#210
post #137
post #27

Earlier quoted context omitted.

In this case, it's what you do when signing in from a new device (or browser) to attest that it's yours. It avoids warnings to you and your contacts that a device has gained access to your account without your approval. It involves doing one of these things: - Comparing a short sequence of emoji on each device and confirming that they match. - Using one device to scan a QR code displayed by the other. - Entering a re…

> The recovery key approach was unfortunately made painful and error-prone in recent Element releases, by disabling the option to choose a passphrase instead, but most people can simply use one of the other two approaches. honestly it's the best thing ever they have done: - I have heard of someone who failed to use Matrix, because he got frustrated of having not a secure enough passphrase - people don't choose secure…

1. Generating a random key by default (but still allowing advanced users to prefer a passphrase) would solve your "secure enough" problem.

2. Better yet, a "secure enough" passphrase could be generated by default, à la Correct Horse Battery Staple. A user wouldn't be forced to choose one.

3. When adding an option, interface complexity can be avoided by simply not showing it by default, or by placing it off to the side in collapsed state where it doesn't draw attention.

4. If you're worried about people writing down a passphrase, you should be even more worried about a string of 50 random characters.

That last one is important. Nobody is going to memorize a random key, which means everyone has to write it to a file (or painstakingly write it on paper) for long term storage. When verifying remote devices, they also have to get the key to the other devices, so they are likely to use copy/paste, which will put it on at least two devices' clipboards, where it will be available for harvesting by nosy apps/websites or accidental pasting to random ones. They also have to figure out a way to transport the key from one device's clipboard to another, which might be email or SMS or some other insecure channel that they're accustomed to using. Or in the unlikely event that they choose paper, they have to painstakingly transcribe it again at the other end.

In other words, forcing the use of a random key does not increase security vs. a well-implemented passphrase system, but instead pushes responsibility for security out of the software and into the hands of people who aren't trained in it. Inviting more big mistakes.

A passphrase would avoid most of those exposure risks by not having to be written down or copy/pasted or sent through insecure channels. And with the right UI, it wouldn't be more complex to use or less secure.

Fortunately, Matrix supports passphrase-derived keys at the protocol level, so client developers who understand how to implement them well for humans can still do so. I hope Element's product managers will come around eventually.

Post reply on HN