Earlier quoted context omitted.
Maybe I'm not clear -- destroying any user's data without user's explicit authorization is unacceptable for any non-joke of a system. If users' keys are linked to the session key then the system has to be designed in a way that the centralized session key store is protected like a pot of gold. That's a design constraint and dictates operational constraints. > Matrix doesn't store messages locally long-term and all yo…
If Riot kept around your session keys even if you were logged out I guarantee that a similar complaint would be made about it being insecure since it leaks keys. I would also like to point out that e2e is still not enabled by default because of issues like this. If you enable it you should know to enable key backups. Riot has supported automatic key backups for the past few months, and if you'd used that you wouldn't…
Encrypt the bloody backup keys with a key derived from a passphrase selected by a user.
> I think in many respects, the people working on Matrix are going to get criticised like this no matter what they do. I note you haven't actually suggested a specific proposal for how to fix this -- you're just going on about design cinstraints and how Matrix is therefore a joke system. To me that seems to be more snark than useful advice.
The snark would be to say "Use Matrix. Who cares about the system not being built to deal with the design constraints"
No one should defend Matrix after this. It was not a mess up. It was an Equifax level fuckup that was totally preventable.