4 ms·
Interesting take. Do you have any reference to back these allegations up? (Honestly interested)
by yuchi 5y ago
Interesting take. Do you have any reference to back these allegations up? (Honestly interested)
- callahad 5y agoI work at Element. At first blush, https://serpentsec.1337.cx/matrix https://serpentsec.1337.cx/matrix seems like a fair writeup of Matrix protocol metadata, with examples, by a third party.
- easygenes 5y agoWhat's your take on this analysis? https://lukesmith.xyz/articles/matrix-vs-xmpp https://lukesmith.xyz/articles/matrix-vs-xmpp It seems like the connection to Amdocs and their interest in collecting metadata for surveillance is a stain on the privacy-focused image.
- olah_1 5y agoIt is interesting that the funding from them happened very early on, at the same time as the design of the protocol itself. Now it is too late to rethink the design to be less of a honeypot. So the only solution is P2P matrix. But even P2P matrix will need some way to back up the metadata so it’s saved between sessions. So again the honeypot seems unavoidable.
- Arathorn 5y agothat analysis seems to be a hatchet job in favour of XMPP, complete with a deeply unpleasant undertone of antisemitism...
- easygenes 5y agoThe author admits to using Matrix personally and concedes that it’s better than basically everything but XMPP. It seems his progress was from Matrix to XMPP after personal experience. The tone of the part about connections to Israeli intelligence doesn’t read as “anti-Semitic” to me, as it’s pointed at motivations of the government spy apparatus and doesn’t make generalizations about Israeli or Jewish people. Though the tongue-in-cheek sarcasm is hard to untangle. The overall tone is sadly that of someone who has spent too much time making internet memes, but I believe the author is a trained linguist with a sardonic sense of humor.
- kevincox 5y agoMy main problem is that many new features seem to leak more and more data. Encryption support is always "will be added later". For example if you want to send a sticker or any inline image you need to upload it to the server in plaintext. Topics and profiles are unencrypted even in "encrypted rooms". Matrix is a pain-text protocol with a couple of encrypted extensions on top. Even worse is that most clients will happily let you use these leaky features in encrypted rooms with no warnings. I love Matrix, it is actually my primary chat network. But the way these features are getting added makes me really disappointed. You don't make a secure protocol by stuffing as many features as you can then adding encryption later. You build a secure protocol by making sure that every feature added is secure from the start, otherwise it is rejected or needs to explicitly justify why it can't or shouldn't be made secure.
- Arathorn 5y agoMatrix's architecture today means that the servers can see who their users are talking to, and when - but not what (assuming it's end-to-end encrypted). Just like a PGP mail service like Protonmail. Because Matrix stores conversation history on the server (unlike Signal) so you can get at it when from multiple logins, you end up with that metadata stored on the server. We're fixing this by working on P2P Matrix (as per the blog post - it's one of the main initiatives that the funding is going towards). https://matrix.org/blog/2020/06/02/introducing-p-2-p-matrix https://matrix.org/blog/2020/06/02/introducing-p-2-p-matrix explains how P2P addresses the metadata problem. The whole "heavily sponsored by the intelligence community" thing is a conspiracy theory. It's true that Matrix is popular with government and national security folks and Element gets money from them... but it's because they want the E2EE and data sovereignty for themselves, rather than because they are trying to torment their citizens(!!)
- logikblok 5y agoCongratulations on the raise and keep up the good work!
- goodpoint 5y agoIt's a simple fact: a distributed/p2p application that cannot be monetized does not generate revenue.