Among other features, it has end-to-end encryption, federation, comprehensive support for multiple devices and doesn't require a phone number. Basically, as far as I'm concerned, it has all of Signal's security but none of its flaws.
For the Android folks, it's available on F-Droid as well as the Play Store.
Surprisingly, despite the features and security, it's approachable enough that my mostly tech illiterate wife is able to handle it without issues.
[0]: https://matrix.org/
[1]: https://element.io/
What about metadata protection? Whenever I hear people talk about how unsupportive Signal / Moxie is of federation and how federation would be better for everyone's privacy, my question is this: In case of Signal you only need to trust one provider (Signal) with your metadata (who's talking to whom) whereas with a federated network you have to trust your provider and all providers your friends use.
On top of that Signal has a track record of standing in for their users' privacy[0]. That probably can't be said about the administrator of some random Matrix server.
[0]: https://signal.org/bigbrother/eastern-virginia-grand-jury/
Currently, yes, you're right. However Matrix is actively working on eliminating this problem in various ways. The most recent reference I know of is [0].
However I don't think the state of things today leaves a clear winner. Right now it's a tradeoff. You can either trust Signal and put all of your communications in the hands of a single third-party (so single point of failure) or you can use Matrix and deal with the levels of trust you're happy to place in your friends' homeservers (but gain multiple points of failure).
I think the OWS/Moxie hate is misplaced. They’re competing with iMessage and WhatsApp and Instagram and Facebook, and Signal is a much better option than all of those.
Let’s be honest: the alternative is that Facebook gets all of our chats in cleartext.
> Off the bat, let me explain that I expect a tool which claims to be secure to actually be secure. I don’t view “but that makes it harder for the average person” as an acceptable excuse. If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries....it’s your responsibility to clearly explain the drawbacks and advantages of the tradeoffs you make. If you make broad and inaccurate statements about your communications product being “secure”, then when the political prisoners who believed you are being tortured and hanged, it’s on you.
B) Matrix has always been very easy to set up E2E
C) Matrix is now E2E by default, at least with the client non-technical users will be using. I think it is for the other clients as well, but I do not know for sure.
Matrix was years from being E2E by default when this post, and that recommendation, was written.
It was still removed. Would it have been better to leave a note saying it had been? Yes. Nobody is perfect however.
> Matrix was years from being E2E by default when this post, and that recommendation, was written.
See point B from my other comment.
Edit: Add Would ... however.
Is it E2E for their other rooms? No.
Is it E2E for any usage of matrix they were going to be doing? Yes.
I also told them to be sure to hit that button if they did start any other rooms. None of them ever did, but they knew that they should if they cared about being secure.
Riot.im also did a good job of letting you know that it was unencrypted unless you hit that button.
Edit: What it boils down to, is that Matrix has been easy to set up E2E for as long as I can remember. It is also trivial to create a matrix account with no tie to your IRL self.
You seem really hung up on that. A transient recommendation has very little to do with stated expectation that "a tool which claims to be secure [should] actually be secure".
(Matrix is very cool and I think it has a bright future as an IRC replacement and ultimately, perhaps, a Slack competitor --- something that provides opsec suitable for a commercial setting. I always come across as a Matrix hater in these threads, and I do not hate Matrix, and wish the project well.)
To me, messaging is a mess at the moment, somewhat like IoT because of lack of solid widely adopted standards (either de facto or de jure).
It's extremely difficult to get friends and family to use something. Most decisions are driven by secondary considerations, like it comes with an OS, or as part of an email or office system, or a gaming system. In some cases it's because "it's what everyone is using".
This shifts the threshold a bit in terms of concerns. What I mean by that is given the inertia involved in moving people to use a messaging system, the bar gets raised in terms of moving people off because of network effects. It's hard enough to get any friends or family to use Signal as an alternative to other things; convincing them to switch again introduces other problems.
I'd prefer something that can be used in more decentralized way, but that has its own issues in terms of syncing and always-on problems. And as security increases, more and more inconveniences are introduced -- it might be worth it, but the case still has to be made implicitly or explicitly to friends and family.
Again, not saying these kinds of discussions shouldn't happen, but they often seem kind of theoretical to me or like they're missing the point because of bigger issues with the messaging ecosystem in general. If you're not going to be able to use Signal anyway because everyone you know is using Whatsapp or iMessaging, or feel like messenger use is driven by "whatever is most popular" it feels like it's difficult to weigh things like "won't put on fdroid". I'd love to see it on fdroid but where does that rank?
It is on us with tech skills to help others to get out of any centralized alternative. Ease of use will come with the less technical user base.
If we keep expecting underfunded and under-resourced parties to come up with software ready and with absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams, we are never going to make a dent on mindshare of the general public.
If on the other hand are diligent in refusing for centralized alternatives while willing to learn and emulate what they do right, then we will at the very least be in a state of steady progress. Matrix and Synapse from two years ago where way worse than they are today. I am confident that in two years from now it will be even better and easier than it is today. Facebook/Google Meet/MS Teams/Skype from two years ago was centralized and closed, just as I expect them to be closed two years from now.
Signal started as any other startup. And yet ;)
> while willing to learn and emulate what they do right, then we will at the very least be in a state of steady progress
In total agreement with you
Not sure what you mean here. To me Signal is just another startup that wants to keep control over the market and uses excuses such as "federation leads to fragmentation and bad UX" in order to put its own interests ahead of the users. To me they are no different than FB or Google.
My counterpoint is: Signal started as any startup. Now it basically defines e2e encryption. Why can't other "underfunded and under-resourced parties" do similar things?