THE CHAT PROTOCOL OF THE FUTURE
-
THE CHAT PROTOCOL OF THE FUTURE

-
THE CHAT PROTOCOL OF THE FUTURE

like with all things there is a solution: using terraform to manage the channels in the space
-
like with all things there is a solution: using terraform to manage the channels in the space
the terraform provider creates and owns the channel. it is the only user with the right to turn on encryption for said channels. voila. this is a perfectly reasonable solution.
-
the terraform provider creates and owns the channel. it is the only user with the right to turn on encryption for said channels. voila. this is a perfectly reasonable solution.
matrix E2EE channels are fucking stupid because they leak all sorts of metadata
for example, the topic is unencrypted
reactions are unencrypted
replies reference unencrypted MXIDs so you can tell what is being replied to even if the payload itself is encrypted
do not use them. do not waste your time on them. it is not worth it.
-
matrix E2EE channels are fucking stupid because they leak all sorts of metadata
for example, the topic is unencrypted
reactions are unencrypted
replies reference unencrypted MXIDs so you can tell what is being replied to even if the payload itself is encrypted
do not use them. do not waste your time on them. it is not worth it.
or as I put it in the Bundernet #known-issues room which is acting as an FAQ

-
R relay@relay.an.exchange shared this topic
-
I incentive moved this topic from Uncategorized
-
or as I put it in the Bundernet #known-issues room which is acting as an FAQ

@ariadne Matrix also allows unencrypted messages in encrypted rooms, and the information that a room is encrypted may not reach a client. I reported this to both clients and the matrix spec, but was told that this was expected behaviour both times ("because we want to allow bots"). Dumbest E2E impl out there.
-
R relay@relay.infosec.exchange shared this topic
-
matrix E2EE channels are fucking stupid because they leak all sorts of metadata
for example, the topic is unencrypted
reactions are unencrypted
replies reference unencrypted MXIDs so you can tell what is being replied to even if the payload itself is encrypted
do not use them. do not waste your time on them. it is not worth it.
@ariadne is this something that could be fixed or is it too fundamental to how Matrix works?
-
THE CHAT PROTOCOL OF THE FUTURE

@ariadne Are there any good, federated and E2EE IMs? Signal has good E2EE but not federation, XMPP has better federation but no E2EE out of the box.
IMHO, Matrix is currently the best of what we got, in terms of both decentralisation and privacy. -
@ariadne Are there any good, federated and E2EE IMs? Signal has good E2EE but not federation, XMPP has better federation but no E2EE out of the box.
IMHO, Matrix is currently the best of what we got, in terms of both decentralisation and privacy.@tapafon when it comes to E2EE federation is not a priority for me, safety is the priority.
-
@tapafon when it comes to E2EE federation is not a priority for me, safety is the priority.
-
-
@tapafon @ariadne The whole "Metadata" discussion is for the most part FUD by Signal fans.
OFC this doesn't mean I deny the problem.
- But if you are concerned about said issue then you'd already only communicate with you own private self-hosted servers that are only reachable with a VPN over Tor.
The truth is that as of now there are no good options out there, unless you consider sending #PGP-encypted messages to a self-hosted, hidden ntfy.sh server to each other.
-
@tapafon @ariadne The whole "Metadata" discussion is for the most part FUD by Signal fans.
OFC this doesn't mean I deny the problem.
- But if you are concerned about said issue then you'd already only communicate with you own private self-hosted servers that are only reachable with a VPN over Tor.
The truth is that as of now there are no good options out there, unless you consider sending #PGP-encypted messages to a self-hosted, hidden ntfy.sh server to each other.
-
-
But if you are concerned about said issue then you'd already only communicate with you own private self-hosted servers that are only reachable with a VPN over Tor.
Again: Layering & Defining your Scope is critical.
If we expect "#TechIlliterate #Nirmies" to "migrate to #Tails & #GrapheneOS or die" they'll give us all the finger and most likely add a restraint order on top of it.
- OFC we need to work on this scope, but I'd rather offer the "best possible" than being complicit in the Starus Quo.
Feel free to name alternatives that actually work and have actual support…
-
@tapafon @ariadne that won't hapoen because #Signal are so fucking criminally incompetent that they are hard locked-in on #aws on their inrastructure.
- It would likely be easier and cheaper in terms of personnel hours needed to just make better, hardened clients for existing protocols rather than "unfuck" the mess that is @signalapp, which at best is just a big-ass #Honeypot!