I like and use Element but it definitely isn't ahead in usability. Getting e2e set up for "average" people isn't trivial. Especially if they have multiple devices.
That being said it is the the best long term option in my opinion and I am donating to the organization. Hopefully they can work on polishing the e2e UX.
Do you mean about accessing an encrypted chat from multiple devices?
If yes, I was playing with that just this weekend and I did not understand at all how to trust the other devices by using "text" (which "text"? I didn't get anything to type/check/approve anywhere); on the other hand by using the option to use emoji (compare a series of emoji between devices and then confirm) was very simple.
As well finding the link to a group-chat that I just created was not simple (or at least the place where to find it was not obvious).
> That being said it is the the best long term option in my opinion and I am donating to the organization. Hopefully they can work on polishing the e2e UX.
Same here & I agree.
I'm also confused why each device is handled separately. I would rather I just share a key around (and ideally it rotates occasionally) and not share what and how many devices I have and what one I am using at the moment.
Aha, didn't notice that, thx!
> I'm also confused why each device is handled separately.
Well, I can understand it more or less (I guess kind of similar to confirming in Whatsapp your multiple open sessions on different devices, to ensure that nobody is using something that you forgot/left behind?), but doing it this way is quite hardcore - on the other hand it could be that the whole thing is deeply embedded in the software's encryption principles/guidelines => it would probably still be ok, but it needs to be explained better, be more clearly accessible.
I guess that having a rotating key (with the software asking from time to time "do you want to accept key jf8k4d9k?") would probably be confusing for non-technical users and would probably generate uncertainty/anxiety/etc... ?
For the rotating key it would be automatically signed by the previous key or master key so no user-visible change would be shown.
So you don't think that if I cross-sign devices A and B, and then I would cross-sign devices B and C, if I would revoke B then C would automatically become invalid as well?
Kind of similar question about "key backups" (to which keys would device C have access to?).
(I honestly did not ever look into all these details - I was hoping that this would be covered by more clever people)
Maybe the best solution would be revocation after a date. So you can say "don't trust anything after {time-i-lost-the-device}" or "don't trust anything after {now}" and it does the right thing. However that could be complex to implement correctly in software. Lots of bookkeeping.
I set up my own server using Synapse, and invited about half a dozen other IRL techie friends to join me in there to continue chatting during Covid times.
Considering we've all worked in tech for decades and run our own servers/services, none of us can really work out how the hell it's supposed to work. I mean, after lots of time consuming verifying of devices it kind of works. Except recently, all of a sudden, one of the people in our main chat room can not see the messages I sent from one of my devices. It tells him to get my keys from another session, he has only every used a single device/session. There is no UI that either of us can find to help fix it. We can chat fine in a different encrypted room, or if I use a different device.
I'm not pulling anyone else into the Matrix ecosystem until encryption stops being just so god damn awful.
Verify this, is this you that.
I think partly its because i am not always on latest version of Synapse so the self-updating clients expect slightly different backends but uff.
It feels like Moxie is right with his anti federation argument. Call me stupid but i am really trying to keep it together but i still cant tell why some of the popups show up or why some sessions of my friends wont decrypt and they show gibberish.
This is the problem with matrix et al. They have to offer something that is leagues ahead of the current baseline, which I'm not convinced they are.
I've been running my own email server for going on 20 years now.
[edit] To add to the above, I use the same Matrix server to chat in various Matrix, IRC and Gitter rooms, and also to host a couple of self-written bots which I use to control a few aspects of my life. Email isn't really a replacement for the things I use Matrix for.
Although I do praise it for not requiring and collecting my phone number and being a bit more future-proof and decentralised, unlike Signal and Telegram.
But in terms of getting my friends grandmother over it, it completely loses on usability and its name is so confusing to them you just had to also mention the Matrix protocol, when it is just Element. which even that by itself is very ambiguous.
If only it could be present-ready.
No, I am kidding :).
The way I see it Matrix and Signal have different short term and long term goals, some overlapping. And both could do way better in term of usability.
Also you can use alternative clients, which (I think) is against Signal's TOS, and is at least discouraged.