Implementing End-To-End Encryption in Matrix Clients
matrix.org
matrix.org
The details for these for those interested can be found at:
https://github.com/matrix-org/matrix-doc/pull/1703
https://github.com/matrix-org/matrix-doc/issues/1267
https://github.com/matrix-org/matrix-doc/pull/1544
and
Keep up the good work! (…but do remember to get some bloody sleep every once in a while)
There is obviously a reason why you can't disable encryption once enabled, but it does suck that fields within m.room.encryption which are entirely advisory (since as far as I know the current implementation doesn't block messages that use old sessions) can't be changed.
It's good to see that the session is being rolled somewhat frequently though. This does explain some of my questions about why the old-school key backups kept getting larger even though I haven't joined any new chats.
[1]: https://github.com/matrix-org/matrix-js-sdk/blob/03a54353be9...
Last time I checked there was the Matrix reference implementation and Riot. Today, there's a bunch of gorgeous Matrix clients that I can see people actually use. Alternative clients like Fractal and Nheko can make or break the ecosystem and I'm glad to see continuous improvement in that area.
It's especially nice to see the cross-signing proposal approved, as trying out just a few Matrix clients over time has added 9 separate keys I need to approve to my account already. Stuff like this will make it easy to switch phones/desktops/apps and will be wonderful for public uptake.
It's possible libpurple's security has improved since then, but I wouldn't count on it.
There's a list here: https://matrix.org/docs/projects/bridges
I can't stop suggesting Matrix to people!
As it is you list stuff like Nheko which claims to E2E encrypt messages but not attachments.
nheko lost its maintainer for a few months hence stuff like the missing e2e attachments, but they are trivial to add; hopefully someone will contribute them soon.
[0] https://github.com/matrix-hacks/matrix-puppet-signal [1] https://datatracker.ietf.org/wg/mls/about/
https://github.com/vector-im/riot-web/issues/6779 is the issue tracking turning it on by default.
apps like riot make it pretty clear when you are in an unencrypted convo (typically the composer says “Send a message (unencrypted)”.