8 ms·
Cool! I’ve recently consolidated all of my Google Chat and WhatsApp friends onto Matrix (via Element) because it’s E2EE. Gchat isn’t and I assume that Meta has
by jckahn 2y ago
Cool! I’ve recently consolidated all of my Google Chat and WhatsApp friends onto Matrix (via Element) because it’s E2EE. Gchat isn’t and I assume that Meta has a backdoor into WhatsApp conversations. So, those platforms can’t be trusted. Signal doesn’t have a web interface, so that’s a no-go for me. lol Telegram.
Matrix has been great for me and I recommend that everyone else use it!
- Steltek 2y agoSelf-hosted Matrix with all the bridges is awesome and brings back that Pidgin/Adium life of one chat app for all of my friends. Too bad Apple has an uncanny ability to avoid consequences with iMessage.
- nisa 2y agoIt's wonderful that it seems work well for you but my experience in bridging group chats with XMPP or IRC was terrible. Lost messages, bridge crashes, puppet accounts getting randomly broken/duplicated with discarded messages. From the bridges I've run, only the Telegram bridge is somewhat stable for me but it also has it's warts. Might be different if you run a strictly personal server for 1:1 conversations but I'd say from an ux perspective the bridges idea largely failed IMHO. I don't think it's the fault of element/matrix it's a difficult problem and I guess with limited resources they made a lot of progress and made things possible that weren't before but it's not plug and play, at least it wasn't for me. In general I've found it's also difficult to communicate in group chats if there are two worlds with a slightly different view (missing reactions, some elements of the messenger are not supported like captions, polls and so on...)
- VladVladikoff 2y ago>lol Telegram Did I miss something? what's wrong with telegram?
- celsoazevedo 2y agoI assume it's the lack of end-to-end encryption by default on basic features. Good service btw, but not the best from a privacy point of view.
- jckahn 2y agoThis is exactly it.
- SahAssar 2y agoBesides that there it's also them choosing to roll their own crypto instead of using established cyphers and protocols.
- emptysongglass 2y agoAnd every time someone makes this comment. MTProto 2 uses standard crypto primitives. Besides this, do you know who else rolled their own crypto? Moxie. You don't get to roll your own crypto first and then weaponize this against your opponents but that's exactly what he did along with abusing words like "plaintext" to describe any encryption not E2EE.
- deleted 2y ago[deleted]
- maqp 2y agoAES-IGE is not best practice. Neither is this https://words.filippo.io/dispatches/telegram-ecdh/ https://words.filippo.io/dispatches/telegram-ecdh/ The difference is Moxie isn't an amateur when it comes to cryptographic design. Wikipedia actually lists him as a cryptographer. The company has also employed an actual mathematician/cryptographer, Trevor Perrin. Meanwhile, Telegram employed the CEO's brother who's a geometrician, which is not the same. You wouldn't hire a dentist to perform brain surgery even though both studied medicine. Signal protocol's double ratchet is considered best practice by pretty much every competent cryptographer. MTProto's main issues are not the teething issues of the yester-years. It's the fact every chat is sent to the server that can then read the messages. Telegram only has E2EE in internet debates about it's non-existent E2EE in practice.
- 9283409232 2y agoWasn't there a big falling out between the Matrix team and Element or am I misremembering what happened?
- Arathorn 2y agoElement is the company formed by the team who created Matrix to work on Matrix, almost all of whom are still there; there is no falling out :) The Matrix Foundation is the non-profit set up by the Matrix team in 2018 to keep Matrix itself independent of Element and other Matrix vendors - to act as a steward of the protocol and a standards body. Originally Element donated almost all of its code on Matrix to the Foundation (e.g. Synapse, the original Matrix server) as permissive Apache-licensed FOSS, assuming that if Matrix was successful, folks would want to fund it. In practice, by 2023, Matrix was very successful... but it transpired that the vast majority of folks commercially building on the Foundation's Apache licensed code failed to route any funding back to the Foundation (as the hosting body) or to Element (as the primary code contributor), despite many polite requests. As a result, there wasn't enough $ to pay folks at Element to keep working on the core Matrix projects as their day job. So, to keep the lights on, Element stopped donating their work to the Foundation, and changed license to non-permissive AGPLv3 in order to sell AGPL-exceptions to the folks commercialising it. This has helped the situation somewhat (although Element isn't at breakeven yet). Meanwhile, it's left the Foundation focused on governance, the Matrix standards process, trust & safety and hosting core libraries like E2EE and matrix-rust-sdk. There's no beef between the Foundation and Element over this. In a utopia the projects would certainly have stayed as Apache licensed code in the Foundation - but then again, other standards bodies like W3C or XSF don't publish code these days: it's a phase that a given protocol grows out of once third party organisations get busy building implementations. Disclaimer: i'm conflicted on this, being project lead/co-founder for Matrix, and then CEO/CTO at Element.
- ants_everywhere 2y agoI say this all the time, but the point of the permissive licenses is you're making a donation to private industry. There are reasons to do this, for example if you believe that private industry adopting some technology is good and you want to make that happen. But people keep seeming surprised by the fact that these donations aren't reciprocated (or at least people don't seem to plan for them to never be reciprocated). It sounds to me like the AGPL license was more consistent with their goals.
- deleted 2y ago[deleted]
- jcul 2y agoSignal doesn't have a web interface, but being able to use a desktop app is OK for me. The big downside for me is not being able to use it on two devices. All the other services, privacy concerns or not can now do this. It's one reason why I stopped donating to / advocating for signal.
- nothrabannosir 2y agoSettings -> linked devices? https://support.signal.org/hc/en-us/articles/360007320551-Linked-Devices https://support.signal.org/hc/en-us/articles/360007320551-Li...
- jcul 2y agoThis lets you use the desktop application and a phone at the same time, which I use. It doesn't allow you to use multiple phones at the same time.
- kaiken1987 2y agoIt's something I've just recently run into trying to set it up on an Android tablet. The funny thing is they allow it on an iPad. It'd be great if they allowed just any phone or tablet to link to the primary device. I'd complain but it's been deaf ears for the last 4 years to get them to put gifs back into the desktop app.
- nothrabannosir 2y agoThanks I didn't know that
- foresto 2y ago> I assume that Meta has a backdoor into WhatsApp conversations They don't need a back door when they control the front door: the app. End-to-end encryption doesn't protect the endpoints. (In other words, your concern is warranted.)
- ranger_danger 2y agoAnd the default/largest homeserver, matrix.org, uses cloudflare, so all your data belongs to them as well.
- foresto 2y agoIt is disappointing that they use Cloudflare, especially since most Matrix metadata hasn't yet been moved to the end-to-end encrypted channel. (Arathorn: is e2ee metadata still on the roadmap?) But no, not all your data is exposed. The e2ee parts, like message content in encrypted rooms, are opaque to Cloudflare.
- Arathorn 2y agoyup, encrypted metadata is very much on the roadmap. https://github.com/matrix-org/matrix-spec-proposals/pull/4256 https://github.com/matrix-org/matrix-spec-proposals/pull/425... is one of the more recent proposals for it.
- pentagrama 2y agoYou're absolutely right. End-to-end encryption protects message content, but WhatsApp still collects metadata, which is incredibly valuable. Even though they can't read your messages, they know who you talk to, how often, when, and for how long. They also track your device info, IP address (which can reveal your location), network details, and app usage patterns. And this data isn’t just sitting there—Meta uses it. For example, if you chat with a business on WhatsApp, you might start seeing ads for that business on Instagram or Facebook. They don’t need to read your messages when they can infer so much just from how you use the app. Disclaimer: Comment translated from Spanish and corrected by Chat GPT.
- ranger_danger 2y agoThere are ways to get web interfaces for Signal. But I think the bigger issue is that any platform that controls the javascript sent to you from a web page, can also backdoor/MITM/inject malicious code at any time without you knowing.
- crossroadsguy 2y agoYou mean you access all these on Matrix/Element via the bridge? Or you actually mean you convinced all of them to ditch their chat apps and migrate to Matrix, or at least install Element as well in addition to the other ones? It’s a feat if it’s the latter without or without ditching. Is this a very privacy conscious demographic?
- jckahn 2y agoI got my friends to install Element and use that to message me instead of Gchat/WhatsApp. They’re all quite tech savvy and have varying degrees of privacy consciousness. I also got my partner to switch to it. She’s not a super nerd like me but she was able to figure it out easily enough.
- anotherpaul 2y agoFor me the issue was contact names tbh. Is that solved? It used to be that the contact name was set by the contact and not by me/my address book.
- methuselah_in 2y agoYou should not use it ! Xmpp is the answer with its few issues and matrix requires hell of system resources as well.
- spintin 2y ago[dead]
- spintin 2y ago[dead]