6 ms·
E2EE vulnerabilities in matrix-js-sdk, matrix-ios-sdk and matrix-android-sdk2
- martinralbrecht 4y agoWrite-up of the vulnerabilities and attacks by research team who reported them: https://nebuchadnezzar-megolm.github.io/ https://nebuchadnezzar-megolm.github.io/
- jeroenhd 4y agoQuite bad vulnerabilities in some cases, but the fact none of these bugs were on the protocol level is a good look for the ecosystem as a whole.
- martinralbrecht 4y agoSeveral of these bugs were indeed on the protocol level: https://nebuchadnezzar-megolm.github.io/ https://nebuchadnezzar-megolm.github.io/
- Syonyk 4y ago> In summary, we found that Matrix and its flagship client Element as deployed provided neither authentication nor confidentiality against homeservers that actively attack the protocol, i.e. its end-to-end encryption fell short of the security guarantees expected from it. While... frustrating to see that these vulnerabilities exist, I'm happy to see that at least the bulk of them require a malicious homeserver. And Matrix makes it easy(ish... if you're a sysadmin type...) to run your own homeserver. I've generally assumed in the past couple years of running Matrix that if someone else controlled my homeserver, they could probably do something malicious, which is why I run my own, on hardware I control. Perfect? No, but it's a sure bit better than running on some major tech company's chat infrastructure. The main problem is I don't know of anything better, short of just giving up and going back to IRC - which, even with znc, isn't nearly as nice as Matrix/Element/etc, though it's far lighter to run at all ends. And IRC is mostly just plaintext (yes, there are some plugins that help, no, they don't really work reliably in my experience with them). I'm open to being convinced otherwise, but even with this bit of a charlie foxtrot going on, I still think Matrix is probably the least-awful of modern chat options, if you can run your own homeserver.
- omegacharlie 4y agoIs Synapse not infamous for its memory consumption and losing sync with other homeserver(s)?
- IceWreck 4y agoWell dendrite is beta software. Ive been running it for almost two years now and its close to synapse in functionality now while being super lightweight compared to it. And then there is Conduit which is written in Rust
- Syonyk 4y agoIt's far heavier than I'd prefer, yes. However, I've got my own box colo'd, so I can give plenty of resources to the VM it runs in, and it seems to hold up just fine in operation. Realistically, the bulk of my traffic is to other users on the same homeserver, so I'm less likely to notice sync/federation issues. A few people do talk across different servers, though, and would bug me if something was broken. It seems to be fine, just very CPU and RAM heavy for what a chat server ought to be using in my view of things. I won't claim it's perfect, but it does provide for a robust and modern-ish chat service that's not reliant on the good will and data monetization of major tech companies.
- neiljohnson 4y agoSynapse has come a long way in the past few years both in terms of reliability and resource usage. The following give some details: * https://matrix.org/blog/2020/11/03/how-we-fixed-synapses-scalability https://matrix.org/blog/2020/11/03/how-we-fixed-synapses-sca... * https://twitter.com/matrixdotorg/status/1434912387933560837 https://twitter.com/matrixdotorg/status/1434912387933560837 What's more the Synapse team recently announced support for Rust meaning that various performance critical sub-components can be ported over from Python. * https://matrix.org/blog/2022/09/09/this-week-in-matrix-2022-09-09#synapse-website https://matrix.org/blog/2022/09/09/this-week-in-matrix-2022-... As mentioned elsewhere Dendrite (Go) and Conduit (Rust) are both entirely useable albeit beta implementations.
- palata 4y ago
- omegacharlie 4y agoCertainly glad these vulnerabilities were disclosed and patched without exploitation by malicious entities. However. Does anyone else feel uneasy about Matrix end-to-end encryption and how some people justify its provenance by asserting it is the same encryption as Signal despite the homebrew implementation by Matrix having obvious differences to attempt to accommodate multi-device support among other features?
- lmm 4y ago> However. Does anyone else feel uneasy about Matrix end-to-end encryption and how some people justify its provenance by asserting it is the same encryption as Signal despite the homebrew implementation by Matrix having obvious differences to attempt to accommodate multi-device support among other features? Signal's implementation (assuming it's what they say it is) is equally "homebrew"; it was derived from OTR but it's not the same protocol, and things like the server-assisted initial key exchange are both bolted-on and often omitted from security analysis in a way that I find very dubious. (Frankly the only crypto protocols mature enough that I really trust them are PGP, TLS, and maybe SSH, but I don't think any of them are suitable for a use case where you want to avoid non-repudiable signatures)
- palata 4y ago> and things like the server-assisted initial key exchange are both bolted-on and often omitted from security analysis in a way that I find very dubious. You mean the Extended Triple Diffie-Hellman? What do you mean by "bolted-on"? Would you consider it "bolted-on" too, if it was just a normal Diffie-Hellman (hence not asynchronous)?
- jimlongton 4y ago
- jimmygrapes 4y agoOne of my biggest pain points in setting up an unfederated homeserver for my friend group was trying to figure out how to not have so much access as the server admin. I am nowhere near an expert at cybersecurity or cryptography or sysadmin things, but I had a strong sense of "I shouldn't be allowed to do this" - for example, when users had difficulty verifying their sessions, I was able to simply click a link in Element to "manually verify" the user on behalf of the entire encrypted group. This was several years ago and the verification flow seems to have improved since then, but that gave me some misgivings.
- cpach 4y agoSome more comments over here: https://news.ycombinator.com/item?id=33009721 https://news.ycombinator.com/item?id=33009721