30 ms·
> How is this worse than any system that depends on a server that routes messages? Like almost all of them... Not in the same way that email does. Email metada
by dngray 4y ago
> How is this worse than any system that depends on a server that routes messages? Like almost all of them...
Not in the same way that email does. Email metadata is much more extensive than that of say Matrix.
If we look at metadata, often the subject isn't encrypted and ugly UX hacks then are made like https://tools.ietf.org/html/draft-autocrypt-lamps-protected-headers-02 https://tools.ietf.org/html/draft-autocrypt-lamps-protected-...
This replaces the subject with "...", however if I send that email to someone who doesn't support that every email I send is going to have the same subject, making it difficult for them to easily find the "correct" email from a group. Protonmail for example doesn't support encrypted subjects.
With Matrix for example the only real metadata is room id, and flow of events (what Matrix ID is in what room). You can have rooms which are centralized to a specific server and then that's not an issue.
It will be interesting to see where P2P functionality leads in the future. https://matrix.org/blog/2021/05/06/introducing-the-pinecone-overlay-network https://matrix.org/blog/2021/05/06/introducing-the-pinecone-... I think with any long-term identity, it's going to be trackable to some extent, so that is up to specific threat model, whether you get worried about that.
With Signal and Sealed Sender https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/ even less metadata is available, although this centralized model is not without downsides such as being operated by a single entity.
We discuss in quite some depth https://www.privacyguides.org/real-time-communication/ https://www.privacyguides.org/real-time-communication/
> Yeah, the world definitely needs more "purpose built" protocols...
With protocols like olm, you also have concept of different devices, device keys, which can be revoked, and shifted without having to ditch all your keys at once. Cross signing means new devices can be "trusted".