Live data from Hacker News

Verifying your Matrix devices is becoming mandatory

element.io

231–240 of 251 posts

Re: Verifying your Matrix devices is becoming mandatory

#231
post #58

Earlier quoted context omitted.

I couldn't be less interested in arguing with you about Signal. My point is that it doesn't make as much sense to compare Signal and Matrix as people think it does. Large-scale group chat is intrinsically less safe than the kind of chats most people use Signal for. You can substitute whichever other secure messenger you prefer. This "average nontechnical user" stuff, though, miss me with. For 2 decades people have be…

> This "average nontechnical user" stuff, though, miss me with. For 2 decades people have been encouraging the "average nontechnical user" to do incredibly unsafe things on the premise that any kind of message encryption is the best alternative to sending plaintext messages. No: telling people not to send those kinds of messages at all, unless you're dead certain the channel they're using is safe, is the only respons…

I disagree with basically all of this but none of it is on topic for this thread and none of it has anything to do with the point I was making.

Re: Verifying your Matrix devices is becoming mandatory

#232

Earlier quoted context omitted.

I wish FOSS communities that want an alternative to Discord or Slack ditched Matrix altogeter. It sucks for that. Better use Zulip or Mattermost, both of which are self-hostable. Edit: I looked up and apparently Mattermost would be out of the question for their feature downgrades in the community version as of late...

Correct me if I'm wrong but I believe Zulip's licensing de facto restrict self-hosting solution for 10 users (others won't see notifications on their mobiles or something like that). This is important for non-commercial communities.

No. See the "Sponsorship and discounts" section on the pricing page, which makes clear the 10 users limit for free usage of the mobile notifications service is for workplace use, not communities.

Re: Verifying your Matrix devices is becoming mandatory

#234
post #228
post #33

Earlier quoted context omitted.

Matrix and Signal have very different objectives. Matrix wants to be an encrypted IRC or Slack. Signal wants to be a secure messenger you can entrust your life to. They are both worthy projects; there's not as much overlap as people think.

> Matrix wants to be an encrypted IRC or Slack matrix's users want it to be a decentralized/encrypted irc/slack, but unfortunately matrix's maintainers believe their mandate is to build a next-gen tcp/ip (or something very close to that) which dooms the project

speaking as Matrix’s lead maintainer: we are focused on it powering decentralised and encrypted whatsapp (or teams) alternatives.

unsure what makes you think we want to build a next-gen tcp/ip, but can I have some?

Re: Verifying your Matrix devices is becoming mandatory

#235
post #3

What is verification? What does it involve doing? A lot of information on why it's useful, but how is it implemented? I hope it's not something like the Play Integrity API, but with no information to go on, I can't say either way.

[dead]

Re: Verifying your Matrix devices is becoming mandatory

#236

Earlier quoted context omitted.

And what could be more urgent than this?

building a more flexible solution for blocking content, rather than hardcoded rules like "no images": https://matrix.org/blog/2025/04/introducing-policy-servers/

Is there something fundamental to the matrix architecture and permissions system that makes it impossible or difficult to allow room/server operators the ability to limit certain users from posting multimedia content?

Re: Verifying your Matrix devices is becoming mandatory

#237
post #91
post #61

Earlier quoted context omitted.

Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.

Let's not forget a team making a great free product. Yeah we can complain about filthy materials but imagine you working hard to build something as nice as Matrix/Element only for these low-lifes to do these horrible things to it. How annoying it must be to have to spend time battling such things.

It's not just their servers, it's the architecture, the difficulties in self hosting, the meh origins of protocol, the resource hogging official clients, multiple implementations with differing protocol support. It's just a mess and I've given up on it this year.

Re: Verifying your Matrix devices is becoming mandatory

#238
post #167

Earlier quoted context omitted.

Wait a minute, doesn't receiving child porn even if unintentionally like the situation above open up the receiver to legal liability? It isn't reasonable to expect users to be 'mentally prepared' to have their devices download child porn because they visited a chat room for support about the chat app they're using.

As someone else have said, then that is an issue with the law. Imagine someone sending you a link that you open and then now you have child porn or whatever else on your hard drive, cached. Quite a shitty situation to be in. Perhaps avoid non-technical rooms or rooms in which you do not trust people.

I don't know. I've read of this alleged nightmare scenario in hundreds of forum posts, mailing lists and threads and it's not something that's actually being followed up on in any capacity. The opposite is the case in that law enforcement doesn't have the resources to get as many perpetrators as they would like to. They're not going to raid your home because you idled in a channel that got spammed or because you received and email or because some service you hosted briefly cached a csam jpg on disk. If you've made political enemies and are under observation already than perhaps this might work as a way in but even then it would be easier to just do something illegal and construct the evidence to point to another cause.

I mean, when does this actually end up with consequences for anyone? Even on managed and surveilled company devices I'm not expecting this to cause any harm to anyone involved. IT staff at previous employers and clients had other things to worry about.

Maybe I'm just not familiar with some legal jurisdictions or cases where this was a cause of concern. Let me know.

Re: Verifying your Matrix devices is becoming mandatory

#239
post #165

I've been using Delta Chat with a lot of success. It is easy, it works, bots are easy and the concept is improving. They even plan to have forward secrecy. So, give it a try. If you explored it a long time ago, try again, many things have improved in that ecosystem.

Yeah it's a lot more "just works" than Matrix, still some limitations but improving quickly.

Re: Verifying your Matrix devices is becoming mandatory

#240

Earlier quoted context omitted.

> This "average nontechnical user" stuff, though, miss me with. For 2 decades people have been encouraging the "average nontechnical user" to do incredibly unsafe things on the premise that any kind of message encryption is the best alternative to sending plaintext messages. No: telling people not to send those kinds of messages at all, unless you're dead certain the channel they're using is safe, is the only respons…

I disagree with basically all of this but none of it is on topic for this thread and none of it has anything to do with the point I was making.

The point of HN comments are for tangents, so I'm happy to hear why you as a domain expert disagree with any of what I raised there.

Also to your point

> For 2 decades people have been encouraging the "average nontechnical user" to do incredibly unsafe things on the premise

Sure I can agree with that. But that wasn't my point either? Unless again you specifically object to the term "average nontechnical user."

Post reply on HN