Skip Navigation
81 comments
  • Then, it would be called matrix? 🤔

    • Only if the signal crew collectively fell down, hit their heads and forgot about their whole mission of protecting metadata privacy. Matrix is a privacy nightmare (compared to signal). It offers optional encryption for the actual text of the messages sent, but everything else from room membership lists to reactions are unencrypted and stored forever by the server. The end to end encrypted message feature was bolted on after the rest of the thing was built, and it shows.

      We’ve seen https://signal.org/bigbrother/ where signal proudly shows that they don’t have any metadata about their users to turn over. There’s a reason we don’t see anything like this for matrix.

      Matrix is good at federating, but fucking horrible at keeping your information safe.

      • I don't think you understand why current servers operate the way they do.

        Matrix server implementations function on the idea that your data lives in the server, so of course it needs that information (who is here, who is talking to whom) - or else, as an example, if you lost your devices you wouldn't be able to recover your info (like on Signal).

        I don't want Signal's Peer-to-Peer solution. I own my server, so I'm okay with keeping my own metadata. I want my communications with others to be encrypted, but recoverable if I lose access to my devices.

        I think what you want is a Peer to Peer encrypted solution, which Matrix is working on, but isn't available yet.

        Follow this site for info on Matrix's progress in that space: https://arewep2pyet.com/ What you're looking for is info on Pinecone.

        TLDR: poop wants a peer-to-peer encrypted network, Matrix is not that (yet).


        Further reading:

        Matrix's architecture today means that the servers can see who their users are talking to, and when - but not what (assuming it's end-to-end encrypted). Just like a PGP mail service like Protonmail. Because Matrix stores conversation history on the server (unlike Signal) so you can get at it when from multiple logins, you end up with that metadata stored on the server.

        We're fixing this by working on P2P Matrix (as per the blog post - it's one of the main initiatives that the funding is going towards). https://matrix.org/blog/2020/06/02/introducing-p-2-p-matrix explains how P2P addresses the metadata problem.

        (...)

      • Genuine question: where are you guys on Beeper, privacy-wise?

    • I'm not super familiar with matrix, is it end to end encrypted likesignall?

  • Do you mean decentralized or federated? I don't really see how Signal would work with something like ActivityPub where so much information is meant for public viewing.

    There's also Matrix if you're looking for just decentralized and federated.

  • Thank you, I'll probably keep Signal away from it, but WhatsApp and SMS hoover up my metadata anyway, so nothing to lose there.

81 comments