this post was submitted on 23 Sep 2024
340 points (98.9% liked)

Technology

59381 readers
3715 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] crimsoncobalt@lemmy.world 46 points 1 month ago (38 children)

I wish Telegram would just enable default E2EE. Oh well, time to switch to Signal!

[–] melroy@kbin.melroy.org 3 points 1 month ago (31 children)

I also don't trust Signal.. And I won't gonna switch a 4th time. I might as well switch to Matrix chat now.

[–] stefenauris@pawb.social 16 points 1 month ago (2 children)

I'm not sure how much we can trust matrix either to be honest. There's some cryptographic flaws in their Olm Library. https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/

As it turns out being both secure and convenient is very difficult

[–] kevincox@lemmy.ml 9 points 1 month ago

That is a pretty weak argument. The issues are minor and in a library that people are moving off of to a better build and stronger validated library. Yes, it should have been like that in the first place, but the problem is minor and being addressed.

I would look more to the various features of Matrix that aren't encrypted like room names, topics, reactions, ... and not to mention the oodles of unencrypted metadata. I really wouldn't call Matrix a high-privacy system.

I like Matrix and use it regularly, but it definitely doesn't have a privacy-first mindset like Signal does. I'm hoping that this improves over time, but without a strong privacy first leadership it seems unlikely to happen.

[–] melroy@kbin.melroy.org 5 points 1 month ago (2 children)

Olm is now deprecated and all development is now focused into Vodozemac: https://github.com/matrix-org/vodozemac. That being said, is there no proven Olm Protocol alternative implementation for e2e encryption (proven technology) instead of reinventing the wheel.

[–] melroy@kbin.melroy.org 4 points 1 month ago (1 children)

ow interesting. TIL.... Olm Protocol is a clone of Signal’s Double Ratchet.

[–] progandy@feddit.org 1 points 1 month ago

vodozemac might become that proven implementation. Without reinventing the wheel there will never be an alternative, because everyone just reuses the one existing library.

load more comments (28 replies)
load more comments (34 replies)