7 ms·
Matrix Is Not Safe for EU Data Privacy?
- kelnos 1y agoI can't really evaluate some of their claims, but note that this is published by a company (written by a "Tech Marketer" who works there) that has a vested interest in making its product look better than the competition. The overly-alarmist language they use makes me extra skeptical.
- rdm_blackhole 1y agoMatrix may not be safe but is Wire going to be safe from Chat Control? Most likely no. So I don't see how trading one surveillance state for another will help.
- jjcob 1y agoWhen you're a EU company or a EU government it makes a difference if your supplier is subject to EU surveillance laws or UK surveillance laws. As far as I can tell it comes down to: - are you afraid of foreign espionage vs. - are you afraid of your own government
- shakna 1y agoWire is located in Switzerland. Outside the EU.
- wkat4242 1y agoTechnically yes but Switzerland does subscribe to most EU legislation in order to join the internal market. They're a lot more "EU" than the UK is now.
- shakna 1y ago... You're suggesting Switzerland is subject to EU surveillance laws? Instead of the ones they put in planning in January?
- wkat4242 1y agoThey generally agree to pretty much everything yes because they're afraid of losing internal market access. It just takes a while longer because they have to approve each new thing individually. I do use Switzerland as an exit for my vpn though yes.
- mvieira38 1y agoThis cope is officially dead now, not even Proton is believing Switzerland anymore. The pressure has gotten enough that they had to freeze all Swiss investment and start the process of moving key infrastructure to another country (I don't remember which, but it's the one Mullvad is at). Truth is, Euros don't care about privacy. The endgame will probably be to host this stuff in the third world or something, like pirates do
- shakna 1y agoIt's not "cope". Switzerland created a new set of surveillance laws in January, that far exceed anything inside the EU. Which means that EU laws are irrelevant, when talking about a company inside Switzerland - you should be talking about what they actually use!
- rdm_blackhole 1y agoLet's put it this way, if the Russians get my ID and a picture of my face and know my kinks and my religious preferences what is the worst that can happen? Now, if my government knows everything there is about me and one day decides to crack down on dissidents or hand them out to another foreign power as it was done in WW2 with the Jews in the Netherlands? Well, that is on another level. We have be down this road before. It never ends well. Maybe it's been too long and people forget. My grandparents lived through WW2, from what they told me, the capacity for humans to inflict pain and suffering on other humans knows no bounds.
- pixxel 1y ago[dead]
- scarface_74 1y agoOnce there is any backdoor, it’s always both.
- jeltz 1y agoI don't see how Wire is any safer if they operate in Germany. The EU is perfectly able to go against Wire then.
- rdm_blackhole 1y agoThey are not any safer. If/when Chat Control passes, they will bend the knee. That is all there is to it.
- ThePowerOfFuet 1y agoWritten by Wire, a competitor.
- lambdadelirium 1y agoWire audited themselves and found nothing wrong in themselves
- Catbert59 1y agoThe only safe communication is decentralized communication, capable of multiplexing multiple techniques (IP, BLE, LoRa, etc.) under the hood of cryptographically safe routing and messaging algorithms that work over unreliable links. Maybe even with small-range offline radio mailboxes so you can deliver and gather messages from/to highly suppressed people which then can be send back into the "online" network automatically without further interaction.
- dabber21 1y agoor true E2E encryption
- Catbert59 1y agoDPI firewalled states like China show that they are extremely effective in adapting to new protocols. Having a second diverse link that is cheap to setup would be an alternative.
- AshamedCaptain 1y agoOne thing that is true about the article is that E2EE encryption is nowhere near enough. Metadata leaks of any kind are probably worse than leaking data itself. I very much prefer to guarantee that data doesn't leave my trusted servers in the first place, rather than to encrypt it.
- Barrin92 1y ago>I very much prefer to guarantee that data doesn't leave my trusted servers in the first place, rather than to encrypt it. what's the rationale behind this? The point of a server is to ... serve things. If you're not gonna exchange data you might as well put a hard drive in a closet. The point of encryption, to securely send information across adversarial channels, has made it possible that I can take my most secret information and send it across my worst enemies network and I don't need to care. Who on earth wants to go back to a world where I have to hide plain text documents in the sock drawer?
- 1y ago
- The_President 1y agoUnfortunately we have had to remove Matrix-Element from production after user frustration and concerns with quality. While the concept is excellent, the implementation of Element is janky and caused so much friction that users would not depend on it. Concerns about other potential issues become more common within the technical team when the frontend has become substandard in a professional environment.
- _zoltan_ 1y ago+1 the user experience is junk
- udev4096 1y agoWhat does this even mean? Matrix can be hosted by anyone and anywhere with full control, unlike wire which is a centralized chat app owned by AWS
- AshamedCaptain 1y agoEven if I dislike Matrix for various reasons, it is absolutely ridiculous to point to a completely centralized AND closed system as an alternative. Terrible article.
- Arathorn 1y agoThis article is fundamentally false - we addressed it on https://element.io/blog/addressing-fear-uncertainty-and-doubt-thrown-at-element-and-matrix/ https://element.io/blog/addressing-fear-uncertainty-and-doub... dang: is HN really the place for competitive marketing crap like this?
- udev4096 1y agoI can't believe how it reached the top. Either bots or intentional upvotes from competitors. Wire sucks anyway. Matrix ftw!
- throwaway02243 1y ago> Finally, anyone paying attention knows that the UK government’s Investigatory Powers Act (IPA) impacts all vendors globally which service individuals in the UK. Something that’s obvious given the high profile TCN that the UK served Apple: the fact that Element and the Matrix.org Foundation are UK-based is irrelevant. Is it irrelevant? A vendor that isn't based in the UK could just rightfully tell the UK government to fuck off—which isn't likely to be an option for the UK-based Matrix and Element.
- atoav 1y agoOk let's say you're a UK vendor and you developed and published an adding algorithm for 2+2 that returns the correct result: 4 How does that publicised adding algorithm get corrupted, if the UK government decides they want that 2+2=5? The answer is that matrix being based in the UK isn't ideal, but since they published the whole protocol, it can't just be made unsafe on request without people noticing. If the math maths it still maths when the government doesn't want it to math. What could happen is that the UK could force specific servers of the UK based entity to surveil targets etc. But you don't have to use their servers (in fact, their goal is probably that you run your own). As someone who would be in the position to decide for or against matrix/wire usage in my org, I have to say this kind of pratise didn't particularily strengthen my trust in wire.
- hyghjiyhu 1y ago
- forty 1y agoWeird argument: "they are in the UK, which is not in the EU, bouh! Look at us, we are in Switzerland, which is... also not in the EU..."
- contravariant 1y agoNot being subject to the UK and US surveillance laws seems as good an argument as any. Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. It's not EU but it is party to a lot of treaties so it's not out of the question. Ironically it might become a safer place to station data if the EU manages to push through more surveillance decrees.
- cccbbbaaa 1y ago> Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. There is a treaty between the EU and Switzerland for this. Full list of countries here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en https://commission.europa.eu/law/law-topic/data-protection/i...
- forty 1y agoIf the EU was starting to go rogue like US is, it could easily bully Switzerland to force their hand into giving whatever data they want to, given that Switzerland have no frontier with sea or non EU country (not that I can imagine this scenario happening, but Switzerland is a weird choice to hide from EU)
- jeroenhd 1y agoThe US and Germany used a Swiss company to sabotage encryption for years: https://www.bbc.com/news/world-europe-51467536 https://www.bbc.com/news/world-europe-51467536 Being inside of the EU also won't ensure your privacy: https://argos.vpro.nl/artikelen/former-philips-top-cryptographer-admits-to-compromising-encryption-devices- https://argos.vpro.nl/artikelen/former-philips-top-cryptogra... And let's not forget that the Swiss are just as willing to implement privacy infringing laws as any other country these days: https://tuta.com/blog/switzerland-surveillance-plan https://tuta.com/blog/switzerland-surveillance-plan Don't trust a company just because it's situated somewhere. When governments friendly to yours want to spy on you, they don't necessarily let borders stop them.
- hopelite 1y agoThere is of course also the fact that the EU is not a sovereign state, legitimate government, or any kind of legitimate government at all, not to mention that is it an abrogation and disassembly of democratic principles of self-determination, and inherently foreign and even hostile to all its members, the most dominant of which jockeying over control of all of Europe through the EU.
- throw123xz 1y agoI don't know if Matrix is "safe" or not, but I usually avoid companies that attack companies like this. Not a good look in my view.
- patrakov 1y agoI am a Wire user. I am not happy that, if their server goes down, all the text and images that I shared with other users will become unavailable to me. As a special case, I am not able to look at my own old messages while using my laptop on the airplane, as the Linux client is just a webview. On the phone, it works. Backups half-way solve the issue with text messages - I would still need to contact someone with sufficient development skills to decrypt the backup and extract the text in a readable form, but the information is there. But with images, there is no recovery. And they apparently already lost some of my photos (the placeholder for some of them never gets replaced with the actual photo when I scroll up to year 2023). Add to that the incompatible backup formats between the desktop and mobile apps. So this is definitely not the claimed data sovereignty.
- devmor 1y agoI don't know that running a smear campaign against an open protocol to hock your paid alternative makes me trust you with my data, personally.
- akimbostrawman 1y agowire is centralized unlike matrix so any "they have to follow the law of the country they are based/hosted in" critique is a self own. wire continues to be a clown show.
- johnisgood 1y agoWire used to be relatively fine, but there are better alternatives, and Matrix is one of them, as it is not centralized, despite the most commonly used, namely Element, being "chunky" or whatever. In any case, this is written by Wire, a competitor, so take it with a pinch of salt.
- TomasEkeli 1y agoIn my opinion this is a poor, vendor-originated commentary attempting to spread FUD and drive people to a product. Not worth reading, and I wish I didn't.