6 ms·
For anyone wondering how it compares to Signal privacy wise: Signal works with a contact list, for private 1 to 1 and private groups. You need a phone number t
by antpls 6y ago
For anyone wondering how it compares to Signal privacy wise:
Signal works with a contact list, for private 1 to 1 and private groups. You need a phone number to use it, and they claim to encrypt almost all metadata, such as message senders. Signal claims they cannot read the content nor the history of users actions (but you have to trust them on that, they claim to use SGX enclave stuff, but can anyone technically verify that they do what they say they are doing?)
Element works with rooms, there is no contact list. A 1 to 1 conversation is a room with 2 people. The homeserver Matrix.org stores all metadata and they are readable (metadata are not private/not encrypted) by Matrix for some features to work. You only need a nickname to use it (at least for now). The content of conversations are e2e encrypted. In theory, i understand it would be possible for a matrix server to delete any metadata/messages once messages are delivered, but some features would not work, and you would also have to trust the server to actually delete the metadata.
Would be happy to read anyone who could correct or complete me.
- arghwhat 6y agoMatrix: Every home server involved in the chat stores the message, and messages on matrix are therefore most considered permanent. As matrix is federated, every user can be on their own homeserver, which will be storing a copy of all messages seen by that user. E2E is more recent and optional. Most rooms are not E2E, and have browsable history. Signal: Only E2E, with clients themselves storing the only copy of messages. You can only see messages that a device has received. Any app you did not write/review and compile requires trusting the author, so this is not a signal specific concern. A crypto app can always store and send keys to a server if it wanted. However, unlike WhatsApp, these apps are open source and can be reviewed and compiled if you so desire.
- kitkat_new 6y agoI doubt that most rooms are not E2EE. People usually have more private conversations than public ones. Private rooms are the default and they default to E2EE.
- oehtXRwMkIs 6y agoE2EE by default is a recent change so I doubt it.
- snvzz 6y ago>E2E is more recent and optional. Most rooms are not E2E, and have browsable history. E2E is actually turned on by default, as of about one year ago.
- eredengrin 6y ago> Most rooms are not E2E, and have browsable history. Not sure how this is meaningful especially without further context. A large number of rooms on matrix are public channels to begin with (eg bridged rooms from irc, open source collaboration channels, etc), so they have no need for e2e encryption. All this is really saying is that E2EE is optional, which you already said (and which I'd also argue is probably irrelevant, especially given that E2EE is on by default).
- redsolver 6y agoThe main difference is that you can choose your own homeserver and communicate with users on other homeservers which makes the Matrix protocol decentralized or at least distributed. So when I'm @redsolver:matrix.org, I can still chat with @bob:example.com just like with other distributed systems like email.
- jszymborski 6y agoWould anyone be familiar as to how to regularly purge metadata (or even message history) from homeservers? I run my own server and don't need my message history to live forever there.
- gary-kim 6y agoSet the retention policy setting on your homeserver (I'm assuming you're using Synapse): https://github.com/matrix-org/synapse/blob/bce0c91d9a89097c94d687aadfed9b4ebbdcc75d/docs/sample_config.yaml#L410-L425 https://github.com/matrix-org/synapse/blob/bce0c91d9a89097c9... I also have mine set up though without a default_policy so I can have the server forget stuff in my bot control rooms cause they get cluttered with useless stuff pretty fast.
- jszymborski 6y agoThanks so much! I’m also running a lot of bots so this’ll be particularly useful.
- suyash 6y agoElement looks like more of a hassle specially for non tech savvy users in my family circle, I'm trying to get them to move to Signal from WhatsApp / FB Messenger.
- kitkat_new 6y agohow so?
- suyash 6y agolook at the setup steps and compare that with installing Signal app
- kitkat_new 6y agoset username & pw? people get that done - look at Instagram which grew despite having to do the exact same
- m-p-3 6y agoSure, Signal is simpler, but Matrix isn't harder than configuring a new email account on an free provider, and you still get the option of setting up your own if you want to use your own domain name. And I hate that Signal's identity is linked to a phone number.
- dunefox 6y ago> Matrix isn't harder than configuring a new email account on an free provider You say that, but for a number of my contacts this is a significant hurdle... especially relatives.
- sundarurfriend 6y agoOut of curiosity, why Signal and not Telegram? I don't know details about either, just that Telegram seems more popular with reportedly a better UI for non-technical people.
- busrf 6y agoHave you read this very extensive blog post on how the SGX enclave is used for Signal’s contact discovery? https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/