Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

221–230 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#221
post #216
post #71

Earlier quoted context omitted.

You did better than I did. I installed the recommended Element app, created an account on matrix.org, tried to send a message to another user, and… gave up. Every try got stuck and eventually created an empty room or whatever they call it. I have literally never succeeded in sending or receiving a single message.

There really is no winning in the org comms/chat apps space when it comes to OSS. Matrix+element, rocket, mattermost, Zulip and so on.. feels like there’s either massive gotchas on free/self hosted or it’s wildly complicated to configure and set up. I’ve been thinking about this a lot. Hosting a private irc server and you lose out on rich embeds and will need your own pastebin-like service to use, video conferencing…

What do you see as the gotchas with Zulip for community use? Zulip is 100% open-source, and we sponsor our hosted services (mobile notifications, etc.) free for OSS projects.

Re: Verifying your Matrix devices is becoming mandatory

#222
post #51

seems like it's just that element (the official, and most popular client) will ignore messages from unverified devices, but since it's part of the spec, other clients that want to be spec-compliant will implement this too. I don't think most other clients follow the spec that closely though. I'm in favor of the change, the only downside I can think of is users with esoteric clients or simple bots that don't support v…

I've had mostly good luck with Matrix too. Been self-hosting since 2022 and while there have been frustrations it has been pretty stable for basic chat.

Re: Verifying your Matrix devices is becoming mandatory

#224
post #91

Earlier quoted context omitted.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

If you make anything public, you will have to deal with it. You should be mentally prepared for that from the start.

in defense of this comment, you do need to do a heck of a lot of preparation (including psychologically) to do anything publicly anymore. wild west days are long gone, at least for US-based servers. I spend a lot of time thinking about how to stop users from interacting too freely, to censor and moderate them so I don't wind up on some news site in 20 years being accused of hosting a site *Widely Used* by pedophilic narcoterror jihadists; I would like to not, but user content (and especially their information) is a huge liability to host... unless you're Equifax or Facebook or Google or some other large corporation -- then you can accidentally dump out everyone's sensitive financial information and only pay them $9 in compensation (or whatever the amount was; I keep throwing the cards they send me in the trash).

(yes I'm salty about that still)

Re: Verifying your Matrix devices is becoming mandatory

#225
post #216

Earlier quoted context omitted.

There really is no winning in the org comms/chat apps space when it comes to OSS. Matrix+element, rocket, mattermost, Zulip and so on.. feels like there’s either massive gotchas on free/self hosted or it’s wildly complicated to configure and set up. I’ve been thinking about this a lot. Hosting a private irc server and you lose out on rich embeds and will need your own pastebin-like service to use, video conferencing…

What do you see as the gotchas with Zulip for community use? Zulip is 100% open-source, and we sponsor our hosted services (mobile notifications, etc.) free for OSS projects.

Hi ! So zulip is actually probably top of this list as the best self managed solution and I’m sorry if I conveyed that it was even near the same ballpark of some of the others. I actually think it’s pretty neat. Interestingly the thing that made us spin down our zulip instance after ten minutes was the “async conversations”. I understand this is a core differentiator for zulip but it immediately felt like the teams channel threading which none of us can stand. The intentions are noble, and the implementation is way better than teams, but it’s interesting to me that solutioning for preventing things from getting buried became the core UX philosophy at play. Really there is something that just works with an absolutely straight forward chronological list of chat messages used in conjunction with a capable search indexer. It’s not that we aren’t willing to try new paradigms, we have tried this paradigm. For a while now. Our topic’d channels are a ghost town these days, our entire org has just moved to making group chats in teams that serve as channels and pinning them because it’s just way easier to work together with regular chat. Ironically we fail to respond to things and struggle more to find things in a topic/threaded paradigm as it seems to go a little too far in isolating “noise”. A lot of serendipitous participation and aha moments and memes come from just glancing a chat discussion that might not immediately involve your attention, and we just operate way better in the open chat space needing only channels/members for the right amount of organization.

Re: Verifying your Matrix devices is becoming mandatory

#226
post #216

Earlier quoted context omitted.

There really is no winning in the org comms/chat apps space when it comes to OSS. Matrix+element, rocket, mattermost, Zulip and so on.. feels like there’s either massive gotchas on free/self hosted or it’s wildly complicated to configure and set up. I’ve been thinking about this a lot. Hosting a private irc server and you lose out on rich embeds and will need your own pastebin-like service to use, video conferencing…

“Compliance” with what ?

Great question! Next question please.

(I have no idea that’s the BS I was told when we left slack for teams)

Re: Verifying your Matrix devices is becoming mandatory

#227
post #58

Earlier quoted context omitted.

I wouldn't characterize Signal as "absolute most possible safety" as you are implicitly doing here. I would probably characterize Signal as "most possible safety for the average nontechnical user" which entails trade-offs against absolute safety for certain UX affordances (and project governance structures that allow for these decisions to be made), because if said affordances are not given, the average nontechnical…

I couldn't be less interested in arguing with you about Signal. My point is that it doesn't make as much sense to compare Signal and Matrix as people think it does. Large-scale group chat is intrinsically less safe than the kind of chats most people use Signal for. You can substitute whichever other secure messenger you prefer. This "average nontechnical user" stuff, though, miss me with. For 2 decades people have be…

> This "average nontechnical user" stuff, though, miss me with. For 2 decades people have been encouraging the "average nontechnical user" to do incredibly unsafe things on the premise that any kind of message encryption is the best alternative to sending plaintext messages. No: telling people not to send those kinds of messages at all, unless you're dead certain the channel they're using is safe, is the only responsible recommendation.

Eh. You misunderstand me. I don't really have too much of a view on this personally. Unless you specifically think that the term "average nontechnical user" is a bad term.

N.B. for other readers of this thread to flesh out my initial point:

Signal specifically didn't do that recommendation until they got sufficient critical mass of users in 2022. In particular Signal gracefully degraded to unencrypted SMS if the other side didn't have Signal.

Likewise Signal required phone numbers until 2024 when it shifted over to usernames, with all the security vulnerabilities that entails.

Signal has repeatedly made trade-offs that prioritize UX over absolute security even in 1-1 chat settings. That's not to criticize those trade-offs, there's a variety of reasons why they make sense or don't. But Signal has consistently demonstrated that it is not willing to make severe compromises to the UX and understandability in the name of absolute security and that it will balance the two.

Re: Verifying your Matrix devices is becoming mandatory

#228
post #33
post #31

Earlier quoted context omitted.

@Arathorn would be an objectively better person to discuss this, but the Redditor isn't completely off the mark: metadata is (currently) not nearly as well-guarded on Matrix compared to Signal. However, work is ongoing to improve the situation; more importantly, Matrix is a different threat model (in my opinion), and allows for different trade-offs. When I use Signal, I have to trust Signal's servers and their admin…

Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.

> Matrix wants to be an encrypted IRC or Slack

matrix's users want it to be a decentralized/encrypted irc/slack, but unfortunately matrix's maintainers believe their mandate is to build a next-gen tcp/ip (or something very close to that)

which dooms the project

Re: Verifying your Matrix devices is becoming mandatory

#229
post #23

I think Matrix as a protocol has been pretty ineffective, as their top priority seems to be keeping data permanent and duplicated. Both performance and privacy are at the bottom of their priority list. The one good thing I can say about it is that encryption of message contents is enabled by default in conversations and available in groups, but that's about it - nothing else is, or can be, encrypted. In other words,…

I wish FOSS communities that want an alternative to Discord or Slack ditched Matrix altogeter. It sucks for that. Better use Zulip or Mattermost, both of which are self-hostable. Edit: I looked up and apparently Mattermost would be out of the question for their feature downgrades in the community version as of late...

Correct me if I'm wrong but I believe Zulip's licensing de facto restrict self-hosting solution for 10 users (others won't see notifications on their mobiles or something like that). This is important for non-commercial communities.

Re: Verifying your Matrix devices is becoming mandatory

#230
post #228
post #33

Earlier quoted context omitted.

Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.

> Matrix wants to be an encrypted IRC or Slack matrix's users want it to be a decentralized/encrypted irc/slack, but unfortunately matrix's maintainers believe their mandate is to build a next-gen tcp/ip (or something very close to that) which dooms the project

Hey, I've been there!

https://web.archive.org/web/19991128144800/http://sonicity.c...

https://web.archive.org/web/20010223171430/http://www.sonici...

Post reply on HN