Live data from Hacker News

Matrix Is Not Safe for EU Data Privacy?

wire.com

41–50 of 56 posts

Re: Matrix Is Not Safe for EU Data Privacy?

#41
post #19

Weird argument: "they are in the UK, which is not in the EU, bouh! Look at us, we are in Switzerland, which is... also not in the EU..."

Not being subject to the UK and US surveillance laws seems as good an argument as any. Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. It's not EU but it is party to a lot of treaties so it's not out of the question. Ironically it might become a safer place to station data if the EU manages to push through more surveillance decrees.

> Though I'm not sure if the GDPR allows for data to be stationed in Switzerland.

There is a treaty between the EU and Switzerland for this. Full list of countries here: https://commission.europa.eu/law/law-topic/data-protection/i...

Re: Matrix Is Not Safe for EU Data Privacy?

#42
post #8

Earlier quoted context omitted.

When you're a EU company or a EU government it makes a difference if your supplier is subject to EU surveillance laws or UK surveillance laws. As far as I can tell it comes down to: - are you afraid of foreign espionage vs. - are you afraid of your own government

Let's put it this way, if the Russians get my ID and a picture of my face and know my kinks and my religious preferences what is the worst that can happen? Now, if my government knows everything there is about me and one day decides to crack down on dissidents or hand them out to another foreign power as it was done in WW2 with the Jews in the Netherlands? Well, that is on another level. We have be down this road bef…

[dead]

Re: Matrix Is Not Safe for EU Data Privacy?

#43
post #19

Weird argument: "they are in the UK, which is not in the EU, bouh! Look at us, we are in Switzerland, which is... also not in the EU..."

Not being subject to the UK and US surveillance laws seems as good an argument as any. Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. It's not EU but it is party to a lot of treaties so it's not out of the question. Ironically it might become a safer place to station data if the EU manages to push through more surveillance decrees.

If the EU was starting to go rogue like US is, it could easily bully Switzerland to force their hand into giving whatever data they want to, given that Switzerland have no frontier with sea or non EU country (not that I can imagine this scenario happening, but Switzerland is a weird choice to hide from EU)

Re: Matrix Is Not Safe for EU Data Privacy?

#44
post #19

Weird argument: "they are in the UK, which is not in the EU, bouh! Look at us, we are in Switzerland, which is... also not in the EU..."

Not being subject to the UK and US surveillance laws seems as good an argument as any. Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. It's not EU but it is party to a lot of treaties so it's not out of the question. Ironically it might become a safer place to station data if the EU manages to push through more surveillance decrees.

The US and Germany used a Swiss company to sabotage encryption for years: https://www.bbc.com/news/world-europe-51467536

Being inside of the EU also won't ensure your privacy: https://argos.vpro.nl/artikelen/former-philips-top-cryptogra...

And let's not forget that the Swiss are just as willing to implement privacy infringing laws as any other country these days: https://tuta.com/blog/switzerland-surveillance-plan

Don't trust a company just because it's situated somewhere. When governments friendly to yours want to spy on you, they don't necessarily let borders stop them.

Re: Matrix Is Not Safe for EU Data Privacy?

#45
Wire used to be relatively fine, but there are better alternatives, and Matrix is one of them, as it is not centralized, despite the most commonly used, namely Element, being "chunky" or whatever. In any case, this is written by Wire, a competitor, so take it with a pinch of salt.

Re: Matrix Is Not Safe for EU Data Privacy?

#46
post #32

Earlier quoted context omitted.

Ok let's say you're a UK vendor and you developed and published an adding algorithm for 2+2 that returns the correct result: 4 How does that publicised adding algorithm get corrupted, if the UK government decides they want that 2+2=5? The answer is that matrix being based in the UK isn't ideal, but since they published the whole protocol, it can't just be made unsafe on request without people noticing. If the math ma…

> it can't just be made unsafe on request without people noticing A likely outcome is that they make it unsafe and people do notice.

Yes but even then: If they make 2+2 wrong and people notice, people can just continue to use the correct version.

I don't know the matrix org but if I were them I had a plan in a drawer for when that happens and where to move.

Re: Matrix Is Not Safe for EU Data Privacy?

#47
post #32

Earlier quoted context omitted.

Ok let's say you're a UK vendor and you developed and published an adding algorithm for 2+2 that returns the correct result: 4 How does that publicised adding algorithm get corrupted, if the UK government decides they want that 2+2=5? The answer is that matrix being based in the UK isn't ideal, but since they published the whole protocol, it can't just be made unsafe on request without people noticing. If the math ma…

> it can't just be made unsafe on request without people noticing A likely outcome is that they make it unsafe and people do notice.

It's a protocol, people can use the old version (or patch whatever makes it unsafe).

Re: Matrix Is Not Safe for EU Data Privacy?

#48
post #9

Earlier quoted context omitted.

or true E2E encryption

One thing that is true about the article is that E2EE encryption is nowhere near enough. Metadata leaks of any kind are probably worse than leaking data itself. I very much prefer to guarantee that data doesn't leave my trusted servers in the first place, rather than to encrypt it.

>I very much prefer to guarantee that data doesn't leave my trusted servers in the first place, rather than to encrypt it.

what's the rationale behind this? The point of a server is to ... serve things. If you're not gonna exchange data you might as well put a hard drive in a closet.

The point of encryption, to securely send information across adversarial channels, has made it possible that I can take my most secret information and send it across my worst enemies network and I don't need to care. Who on earth wants to go back to a world where I have to hide plain text documents in the sock drawer?

Re: Matrix Is Not Safe for EU Data Privacy?

#50
post #32

Earlier quoted context omitted.

Ok let's say you're a UK vendor and you developed and published an adding algorithm for 2+2 that returns the correct result: 4 How does that publicised adding algorithm get corrupted, if the UK government decides they want that 2+2=5? The answer is that matrix being based in the UK isn't ideal, but since they published the whole protocol, it can't just be made unsafe on request without people noticing. If the math ma…

> it can't just be made unsafe on request without people noticing A likely outcome is that they make it unsafe and people do notice.

Any open source project can be made unsafe intentionally or unintentionally, with or without people noticing, is there anything unique to this risk with Matrix?
Post reply on HN