Earlier quoted context omitted.
You did better than I did. I installed the recommended Element app, created an account on matrix.org, tried to send a message to another user, and… gave up. Every try got stuck and eventually created an empty room or whatever they call it. I have literally never succeeded in sending or receiving a single message.
There really is no winning in the org comms/chat apps space when it comes to OSS. Matrix+element, rocket, mattermost, Zulip and so on.. feels like there’s either massive gotchas on free/self hosted or it’s wildly complicated to configure and set up. I’ve been thinking about this a lot. Hosting a private irc server and you lose out on rich embeds and will need your own pastebin-like service to use, video conferencing…
Verifying your Matrix devices is becoming mandatory
221–230 of 251 posts
Re: Verifying your Matrix devices is becoming mandatory
#222seems like it's just that element (the official, and most popular client) will ignore messages from unverified devices, but since it's part of the spec, other clients that want to be spec-compliant will implement this too. I don't think most other clients follow the spec that closely though. I'm in favor of the change, the only downside I can think of is users with esoteric clients or simple bots that don't support v…
Re: Verifying your Matrix devices is becoming mandatory
#223Does anyone have any experience with Keet as an alternative? https://keet.io/
Re: Verifying your Matrix devices is becoming mandatory
#224Earlier quoted context omitted.
Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.
If you make anything public, you will have to deal with it. You should be mentally prepared for that from the start.
(yes I'm salty about that still)
Re: Verifying your Matrix devices is becoming mandatory
#225Earlier quoted context omitted.
There really is no winning in the org comms/chat apps space when it comes to OSS. Matrix+element, rocket, mattermost, Zulip and so on.. feels like there’s either massive gotchas on free/self hosted or it’s wildly complicated to configure and set up. I’ve been thinking about this a lot. Hosting a private irc server and you lose out on rich embeds and will need your own pastebin-like service to use, video conferencing…
What do you see as the gotchas with Zulip for community use? Zulip is 100% open-source, and we sponsor our hosted services (mobile notifications, etc.) free for OSS projects.
Re: Verifying your Matrix devices is becoming mandatory
#226Earlier quoted context omitted.
There really is no winning in the org comms/chat apps space when it comes to OSS. Matrix+element, rocket, mattermost, Zulip and so on.. feels like there’s either massive gotchas on free/self hosted or it’s wildly complicated to configure and set up. I’ve been thinking about this a lot. Hosting a private irc server and you lose out on rich embeds and will need your own pastebin-like service to use, video conferencing…
“Compliance” with what ?
(I have no idea that’s the BS I was told when we left slack for teams)
Re: Verifying your Matrix devices is becoming mandatory
#227Earlier quoted context omitted.
I wouldn't characterize Signal as "absolute most possible safety" as you are implicitly doing here. I would probably characterize Signal as "most possible safety for the average nontechnical user" which entails trade-offs against absolute safety for certain UX affordances (and project governance structures that allow for these decisions to be made), because if said affordances are not given, the average nontechnical…
I couldn't be less interested in arguing with you about Signal. My point is that it doesn't make as much sense to compare Signal and Matrix as people think it does. Large-scale group chat is intrinsically less safe than the kind of chats most people use Signal for. You can substitute whichever other secure messenger you prefer. This "average nontechnical user" stuff, though, miss me with. For 2 decades people have be…
Eh. You misunderstand me. I don't really have too much of a view on this personally. Unless you specifically think that the term "average nontechnical user" is a bad term.
N.B. for other readers of this thread to flesh out my initial point:
Signal specifically didn't do that recommendation until they got sufficient critical mass of users in 2022. In particular Signal gracefully degraded to unencrypted SMS if the other side didn't have Signal.
Likewise Signal required phone numbers until 2024 when it shifted over to usernames, with all the security vulnerabilities that entails.
Signal has repeatedly made trade-offs that prioritize UX over absolute security even in 1-1 chat settings. That's not to criticize those trade-offs, there's a variety of reasons why they make sense or don't. But Signal has consistently demonstrated that it is not willing to make severe compromises to the UX and understandability in the name of absolute security and that it will balance the two.
Re: Verifying your Matrix devices is becoming mandatory
#228Earlier quoted context omitted.
@Arathorn would be an objectively better person to discuss this, but the Redditor isn't completely off the mark: metadata is (currently) not nearly as well-guarded on Matrix compared to Signal. However, work is ongoing to improve the situation; more importantly, Matrix is a different threat model (in my opinion), and allows for different trade-offs. When I use Signal, I have to trust Signal's servers and their admin…
Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.
matrix's users want it to be a decentralized/encrypted irc/slack, but unfortunately matrix's maintainers believe their mandate is to build a next-gen tcp/ip (or something very close to that)
which dooms the project
Re: Verifying your Matrix devices is becoming mandatory
#229I think Matrix as a protocol has been pretty ineffective, as their top priority seems to be keeping data permanent and duplicated. Both performance and privacy are at the bottom of their priority list. The one good thing I can say about it is that encryption of message contents is enabled by default in conversations and available in groups, but that's about it - nothing else is, or can be, encrypted. In other words,…
I wish FOSS communities that want an alternative to Discord or Slack ditched Matrix altogeter. It sucks for that. Better use Zulip or Mattermost, both of which are self-hostable. Edit: I looked up and apparently Mattermost would be out of the question for their feature downgrades in the community version as of late...
Re: Verifying your Matrix devices is becoming mandatory
#230Earlier quoted context omitted.
Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.
> Matrix wants to be an encrypted IRC or Slack matrix's users want it to be a decentralized/encrypted irc/slack, but unfortunately matrix's maintainers believe their mandate is to build a next-gen tcp/ip (or something very close to that) which dooms the project