Earlier quoted context omitted.
Have they done anything to mitigate this? Like client side filters or message scanning for new direct messages?
The main things are https://matrix.org/blog/2025/04/introducing-policy-servers/ (for flexible serverside moderation) and the rest of the stuff in https://matrix.org/blog/2025/02/building-a-safer-matrix/ . Clientside filters already existed, but given they only apply per client and there are a lot of different clients, we focused on serverside filtering.
Verifying your Matrix devices is becoming mandatory
241–250 of 251 posts
Re: Verifying your Matrix devices is becoming mandatory
#242From an outsider's point of view, what is this "verifying"? Because it sounds like "we'll put them in a database so we can sell it" to me...
cryptographic process to poof that the devices you use in fact belong to you (as cryptographic identity)
Where is that data stored?
What happens if I'm on holiday in Paris and drop my phone, which is the only device I have with me, in the Seine?
Sounds like more passkeys security theater/inconvenience to me.
Re: Verifying your Matrix devices is becoming mandatory
#243Earlier quoted context omitted.
cryptographic process to poof that the devices you use in fact belong to you (as cryptographic identity)
To poof to who? Where is that data stored? What happens if I'm on holiday in Paris and drop my phone, which is the only device I have with me, in the Seine? Sounds like more passkeys security theater/inconvenience to me.
> What happens if I'm on holiday in Paris and drop my phone, which is the only device I have with me, in the Seine?
1) use your recovery key (to recover your identity (prooven by private keys) from the server) - I believe it only works if you enabled server side key storage
Or
2) create a new identity (contacts will be notified)
Or
3) wait until you have access to another device again
Source of truth: https://spec.matrix.org/v1.16/client-server-api/#cross-signi...
Re: Verifying your Matrix devices is becoming mandatory
#244I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy. I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in…
Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.
Re: Verifying your Matrix devices is becoming mandatory
#245Earlier quoted context omitted.
What do you see as the gotchas with Zulip for community use? Zulip is 100% open-source, and we sponsor our hosted services (mobile notifications, etc.) free for OSS projects.
Hi ! So zulip is actually probably top of this list as the best self managed solution and I’m sorry if I conveyed that it was even near the same ballpark of some of the others. I actually think it’s pretty neat. Interestingly the thing that made us spin down our zulip instance after ten minutes was the “async conversations”. I understand this is a core differentiator for zulip but it immediately felt like the teams c…
But Zulip’s default view is a list of all messages in all threads in all channels which has no context for the individual messages, like
Re: Verifying your Matrix devices is becoming mandatory
#246Earlier quoted context omitted.
Hi ! So zulip is actually probably top of this list as the best self managed solution and I’m sorry if I conveyed that it was even near the same ballpark of some of the others. I actually think it’s pretty neat. Interestingly the thing that made us spin down our zulip instance after ten minutes was the “async conversations”. I understand this is a core differentiator for zulip but it immediately felt like the teams c…
I also found the Zulip UX to be really confusing at first. The issue is messages show up in multiple places which is unintuitive for someone with a spacial brain like me. What I do (because I use Zulip every day) is read messages only in their threads. I click on one thread in the sidebar, get caught up, then move to the next thread. (This is also how I use Discord and Slack.) So I treat it as if channels contain thr…
The combined feed is helpful for some (e.g., in lower-traffic organizations, or if you like to see messages as they come in), and was the default home view many years ago.
Re: Verifying your Matrix devices is becoming mandatory
#247Earlier quoted context omitted.
Wait a minute, doesn't receiving child porn even if unintentionally like the situation above open up the receiver to legal liability? It isn't reasonable to expect users to be 'mentally prepared' to have their devices download child porn because they visited a chat room for support about the chat app they're using.
As someone else have said, then that is an issue with the law. Imagine someone sending you a link that you open and then now you have child porn or whatever else on your hard drive, cached. Quite a shitty situation to be in. Perhaps avoid non-technical rooms or rooms in which you do not trust people.
This is unacceptable.
Re: Verifying your Matrix devices is becoming mandatory
#248Earlier quoted context omitted.
I think current Element versions accept either a recovery key or recovery passphrase in the same input field, so there's no getting it wrong. Since you seem focused on UI, it's worth noting that Element X (their beta mobile app) has a greatly simplified interface; their team clearly has been working to make it easier. Also, other clients exist. For whatever it's worth, I've been using Matrix for about five years, inc…
I tried the current Element and Element X. In short, the passphrase works with both and the recovery key with neither, specifically: Element classic has two separate fields; if I input the recovery key (in the correct field), I get told "Backup could not be decrypted with this PASSPHRASE: please verify that you entered the correct recovery passphrase." That's how it was the last time I used it, and if I'm not mistake…
However, a couple of things occur to me:
- No Matrix client that I know of supports setting both a randomly generated recovery key and recovery passphrase on the same account. So in order to test both, you would have to use a separate account for each. If you tried to test both on the same account, it's expected that one of the two would be rejected.
- You didn't specify a platform, but since you wrote "Element classic", I guess you must mean Android or iOS. I used Element Desktop / Web to set up my accounts, which could explain why I saw different prompts.
I hope you reported the error message referring to a passphrase when a key had been entered. I imagine that could leave the user wondering whether they had made a typo or the app had misinterpreted what they typed, which would not inspire confidence in it.
Re: Verifying your Matrix devices is becoming mandatory
#249Earlier quoted context omitted.
Let's not forget the shock image spam issue. Public Matrix channels are plagued with horrendous shock images (including CSAM). The development team seems to not care, they have a proposal for "policy servers" which is still incomplete and not supported by all server implementations.
Considering the thread context I'm curious how would IRC help with that other than people running command line or TUI clients? Also do you want the development team to moderate self hosted chat servers? How would that work?
Re: Verifying your Matrix devices is becoming mandatory
#250Earlier quoted context omitted.
It is super annoying but you have to be very naive to not understand that anything that can be abused will be abused so you need to bake in countermeasures from day #1 or you might as well not bother with the launch.
Aren't there any moderators in those channels? I have 0 issues in the channels I am in (some podcasting channels, some tech, some FOSDEM.) I find a lot of value in Element as is, I'm glad they bothered.
Their server clearly doesnt care that a single federated server was sending out thousands of invites, and there's no way to avoid the spam.
In general using matrix was always a pain in the rear for one reason or another.