Live data from Hacker News

Matrix 2.0: The Future of Matrix

matrix.org

91–100 of 283 posts

Re: Matrix 2.0: The Future of Matrix

#91

Earlier quoted context omitted.

It's one of the most significant open source messaging systems that exist today. Anyone can audit it at any time. What more do you want?

How do you know the matrix.org server or the element.io web client is running the same code as the source posted publicly? How exactly do you, personally, audit a hosted service? The answer to both questions is: you don't.

>How do you know the matrix.org server or the element.io web client is running the same code as the source posted publicly? How exactly do you, personally, audit a hosted service? The answer to both questions is: you don't.

And I don't use them. I grab the posted sources and use them on hardware I physically control. If (I'm not, but I do care about my privacy) I was someone that was being pursued by one or more governments/well-funded private actors, I wouldn't use any communication platforms hosted by others.

As the old saw goes: "Three can keep a secret. If two are dead."

Re: Matrix 2.0: The Future of Matrix

#92

Earlier quoted context omitted.

How do you know the matrix.org server or the element.io web client is running the same code as the source posted publicly? How exactly do you, personally, audit a hosted service? The answer to both questions is: you don't.

So host it yourself. It's literally designed to do that.

Yeah, that's great for me, but doesn't help me when everyone else is using the hosted stuff :)

Re: Matrix 2.0: The Future of Matrix

#93
post #49

Just a question, I haven't been paying attention, but where is Matrix on resolving the Nebuchadnezzar vulnerabilities, and is the project still tracking towards switching to MLS instead of Olm/Megolm?

The main remaining Nebuchadnezzar issue is mitigating server-controlled group membership. The first step has been to kill off the 1st gen E2EE implementations, which were responsible for the implementation vulns found by RHUL - and we should hopefully conclude that next week by moving everything into the matrix-rust-sdk crypto crate implmentation: https://github.com/vector-im/element-web/issues/21972#issuec... is the tracker.

Then, we can address the harder server-controlled group membership issue in one place. First step will be to improve device verification & trust so that trust is the default, not the exception, to make it easier to spot and warn about unexpected devices in the room. The full solution is then either MSC3917 (https://github.com/matrix-org/matrix-spec-proposals/blob/fay...) - or potentially to switch everything to MLS.

We're working on MLS anyway in parallel to RHUL mitigation work; you can see the progress at https://arewemlsyet.com, and it's looking good.

I'm guessing you're not interested in doing a podcast on "yay we converged our crypto implementations on a single robust Rust implementation so we can fix the remaining bugs in one place", but as soon as the server-controlled group membership thing is solved we'll be in touch. Work has also gone much slower than hoped on this, thanks to the joys of funding open source.

Re: Matrix 2.0: The Future of Matrix

#94
post #80

Matrix is great but when is the tech industry going to deal with the fact that many, if not all, bridges are against the respective services' ToS and subsequently put the developers of those bridges under legal risk? Whatsapp has already sent legal threats to multiple bridge-component level project maintainers without any recourse.

The EU just designated Whatsapp as a gatekeeper under the Digital Markets Act: https://ec.europa.eu/commission/presscorner/detail/en/ip_23_... following the "full list of do's and don'ts" link on that page:

> Gatekeeper platforms will have to:

> - allow third parties to inter-operate with the gatekeeper’s own services in certain specific situations

> - allow their business users to access the data that they generate in their use of the gatekeeper’s platform

Re: Matrix 2.0: The Future of Matrix

#95
post #80

Matrix is great but when is the tech industry going to deal with the fact that many, if not all, bridges are against the respective services' ToS and subsequently put the developers of those bridges under legal risk? Whatsapp has already sent legal threats to multiple bridge-component level project maintainers without any recourse.

The EU interoperability mandate for messaging services will surely improve this situation.

Re: Matrix 2.0: The Future of Matrix

#96
post #55

Do they also plan to ditch the desktop Electron version for the users to enjoy similar performance improvements?

Element X actually runs really well on macOS already on Apple Silicon; I regularly use it as my desktop app whenever Element Web is having... issues. It would be amazing to plonk matrix-rust-sdk into Element Web and switch Electron for Tauri or something... but one thing at a time.

Re: Matrix 2.0: The Future of Matrix

#97
post #90

Earlier quoted context omitted.

I didn't claim/assert anything other than what I linked to already in my original post. You don't have to care, and like I said, I don't care if you care or not. I'm just making people aware, because some people _do_ care. It's nice that you personally use matrix on hardware under your physical control. That's rare. The vast vast majority of matrix users have their account on matrix.org and are using Element. I'm gla…

When someone asks "why should I care," the implication is that they want to know why you care. Dodging the question here is an interesting way to respond

People who want to work closely with authorities probably shouldn't be trusted to provide your secure communication software.

Re: Matrix 2.0: The Future of Matrix

#98
post #94
post #80

Matrix is great but when is the tech industry going to deal with the fact that many, if not all, bridges are against the respective services' ToS and subsequently put the developers of those bridges under legal risk? Whatsapp has already sent legal threats to multiple bridge-component level project maintainers without any recourse.

The EU just designated Whatsapp as a gatekeeper under the Digital Markets Act: https://ec.europa.eu/commission/presscorner/detail/en/ip_23_... following the "full list of do's and don'ts" link on that page: > Gatekeeper platforms will have to: > - allow third parties to inter-operate with the gatekeeper’s own services in certain specific situations > - allow their business users to access the data that they generate…

This is likely also the sole reason[1] that Meta is considering connecting Threads to the fediverse.

[1] https://yiffit.net/comment/498225

Re: Matrix 2.0: The Future of Matrix

#99
post #94
post #80

Matrix is great but when is the tech industry going to deal with the fact that many, if not all, bridges are against the respective services' ToS and subsequently put the developers of those bridges under legal risk? Whatsapp has already sent legal threats to multiple bridge-component level project maintainers without any recourse.

The EU just designated Whatsapp as a gatekeeper under the Digital Markets Act: https://ec.europa.eu/commission/presscorner/detail/en/ip_23_... following the "full list of do's and don'ts" link on that page: > Gatekeeper platforms will have to: > - allow third parties to inter-operate with the gatekeeper’s own services in certain specific situations > - allow their business users to access the data that they generate…

There's a fair amount of silly legislation that gets passed in the EU, but forward-thinking (or maybe just here-thinking?) laws like these (and the GDPR!) make me glad I live here.

Re: Matrix 2.0: The Future of Matrix

#100

Earlier quoted context omitted.

>Regular reminder Matrix/Element work closely with law-enforcement to provide encrypted comms for them. Thank you for the reminder. Based on that, are you claiming that Matrix servers/clients are insecure or have government back doors? If so, what evidence do you have that supports such a claim? If not, why should I care? I'm not a fan of many organizations/individuals. Should I survey them all to create a database o…

I didn't claim/assert anything other than what I linked to already in my original post. You don't have to care, and like I said, I don't care if you care or not. I'm just making people aware, because some people _do_ care. It's nice that you personally use matrix on hardware under your physical control. That's rare. The vast vast majority of matrix users have their account on matrix.org and are using Element. I'm gla…

Since you didn't actually answer the question "why should I care?", perhaps you might deign to answer these instead:

>>I'm not a fan of many organizations/individuals. Should I survey them all to create a database of software those folks use and refuse to use any software they use? What value would I derive from such actions?

Why are those useful questions? Pick some software -- any software in wide use -- and you'll find that someone you find objectionable is using such software.

That includes OS's, browsers, databases, web/application servers, BIOS firmware, chat clients/servers, etc., etc., etc.

If using software that's also used by someone whose actions and/or rhetoric are objectionable to you is "capitulation" to those with whom you oppose/disagree, then you should power off all your electronic devices, smash them into little pieces and never look back.

But (IMHO, at least) taking such a position takes "guilt by association" to ridiculous extremes, especially when talking about open source software that can be audited and modified to suit your purposes.

Don't want your sensitive information shared? Don't share it on platforms not under your control. Full stop.

I'll say it again[0], "three can keep a secret. If two are dead." Food for thought, no?

[0] https://news.ycombinator.com/item?id=37602606

Post reply on HN