Notes on privacy and data collection of Matrix.org (2019)
gitlab.com
gitlab.com
On the one hand, of course I love that people have the means to audit assumptions.
Both the ability to do so w.r.t the project being transparent and open, but also through time and technical ability.
I am, however, a little upset when people poke at minor issues (that they themselves see as minor) and speak at length about them. *not* because those issues should not be addressed, but because it gives ammunition for people who recommend closed platforms, or more opportunity for people to think of the community as being more divided than it really is.
The more uncertainty a thing is surrounded by: the more people are likely to just say "fuck it" and choose any option as long as it works, and guess what works? Closed platforms, especially those with coherent messaging like facebook or whatsapp.
So, with that in mind: Kudos for such an analysis, but be mindful that such a lengthy document that discusses minor issues can actually harm the matrix project.
And the pathetic thing is, if he had spent more time working on his "Grid protocol" instead of pointless nitpicking, maybe he would have a lot more credibility on the matter.
The parent comment is not using ad hom. They're critiquing the author's work and assessing their credibility based off of that. It's perfectly fine, and a great viewpoint to consider.
And you're mentioning it's outdated, which would be natural given that the last commit was over two years ago.
Under "Purpose and Scope":
> This document is a research paper by Libre Monde ASBL, nonprofit dedicated to protecting people's privacy. We had the need to document privacy points for The Grid Protocol project, fork of the Matrix protocol.
So seems that they probably won't have issues with that it might harm Matrix, as they are a direct competitor. In fact, that might be why they are focusing on the issues they find, minors one included.
I was not aware of the Grid project, but they seem to make good points. Matrix is developed by a restricted group of people with a startup vibe and some cringy/questionable actions:
- spitting on other protocols (or not even acknowledging their existence) without a technical reasoning (Matrix could have been a "simple" decentralized room extension of XMPP or any other established protocol) ; which takes us to the situation where Matrix has the exact same selling points which XMPP had 20 years ago... and keeps on reinventing the wheel
- pushing for a broken state resolution algorithm (decentralized consensus) without a formal analysis, which means it's now reached its 5th or 6th version and Matrix clients are all incompatible with one another (because only Element implements them all) and once they have been upgraded rooms cannot be downgraded so in many places only Element can chat
- requiring a web rendering engine for certain extensions (eg. Video chat) ; HTTP is a decent foundation for a protocol, but why is a Jitsi <iframe> considered a decent extension mechanism? it will just harm security/privacy (through potential XSS) and make it near-impossible for clients to be implemented without a Chrome-based engine, reinforcing Google's monopoly on the web
- putting all of their $$$$ into a single web client with very bad performance, not caring for other platforms; beyond clients, investing in bridging with useless platforms like Microsoft Teams (though i did not find the code for that) while neglecting interop with open protocols like IRC/XMPP (relations with IRC/XMPP people are notoriously not very good though i hope it will improve over time)
All in all, i'm very glad matrix exists because they have popularized bridging and they do care for UX concerns like Spaces. But claiming people who forked the project because of political and technical disagreements are biased because they are a "competitor" is itself a very biased position based on the idea that only one true protocol must remain and others are heretics trying to undermine our technical purity (for their economic gain).
I wish we could have people from different protocols sitting across the table and working on interop so we can stop arguing about which network is best.
The clean rooms approach is a good thing I think. Xmpp is becoming a pileup of different add-ons and suffers from the same issues you mention for matrix (not all features supported by all clients). Probably in a worse way.
I know the reluctance of IRC operators to allow (global) matrix bridges is often a case of different paradigms. On IRC a conversation can only be seen by users who are present at the time. A user joining a bridged matrix room can see the entire history from before they joined. This changes the privacy model a lot (insofar as IRC has any semblance of privacy, but whatever is there is regarded as very important). People running their own Heisenbridge puppeting bridges solves this issue though.
I'm not a matrix dev but I do like it, especially the phenomenon of bridges.
This is not the case, Matrix rooms can be set to allow viewing history only from joining time on. And that is how IRC bridge rooms are mostly configured, indeed based on policies from the bridged IRC networks.
Perhaps this was only introduced later? I'm talking about 3 years ago. But good to see this was fixed.
I don't get it. XMPP had MEGOLM, cross signing, decentralized chat rooms, good iOS support in practice, very simple sync of e2ee chat history, ... 20 years ago?
> spitting on other protocols (or not even acknowledging their existence) without a technical reasoning (Matrix could have been a "simple" decentralized room extension of XMPP or any other established protocol) ;
This simply so wrong: Matrix was created exactly because if the failure of existing protocols [0]. And the mentioned extension was one failure in their mind.
[0]: https://matrix.org/faq/#why-has-no-one-done-this-before%3F
And imho it was the best thing to do. You don't repair a car if repairing costs much more than getting a new one
> pushing for a broken state resolution algorithm (decentralized consensus) without a formal analysis, which means it's now reached its 5th or 6th version and Matrix
In fact there are 9 versions today. Though afaik only one of them was due to a broken consensus algorithm. Others exist for new features. Strangely I can use even the latest ones with alternative clients such as Fluffy Chat - contrary to your claims
> but why is a Jitsi <iframe> considered a decent extension mechanism
It is? Source needed
Native Matrix video chat is being implemented as of now
> putting all of their $$$$ into a single web client with very bad performance, not caring for other platforms
Also wrong: Element has a native Android and a native iOS clie t
This is false. Clients don't do state res, servers do. Clients don't care.
The amount of incorrect info in the GP post is very unfortunate - although I too wish that open standard comms protocols spent more time collaborating than spitting at each other.
hrm, maybe this was true a few years ago?
Element currently develops two web clients. Element Web: https://matrix.org/docs/projects/client/element and Hydrogen: https://matrix.org/docs/projects/client/hydrogen
Element also sponsors development of at least one other community web client that I know of.
Meanwhile, you can find Element's Android client here: https://matrix.org/docs/projects/client/element-android
And the iOS client here: https://matrix.org/docs/projects/client/element-ios
Within Element, new features are developed in cross-functional teams and released in tandem; e.g. Spaces was released on web and mobile at the same time.
On performance - there are definitely some performance issues with matrix clients in general, particularly larger rooms and accounts which are in many rooms. This is an active focus of development, e.g. see work on sync v3, a more efficient matrix sync protocol https://github.com/matrix-org/sync-v3
Disclaimer: I am an Element employee
A lot has happened in and around Matrix since. While this looks like an honest and thorough review, as it’s focusing on defaults and UX/expectations, I’m assuming several things to be outdated. Maybe some of the critique brought up here has even resulted in changes in docs, Element and Synapse already.
Haven’t yet read thoroughly enough to say what, will probably follow up here later.
Note that mxisd (the “only other identity server” referenced), from the paper authors, is now deprecated and part of their “Grid Server”. A community-maintained fork lives on as ma1sd. AFAIK this is the one identity server software to consider for self-hosters.
Also for those new to Matrix, “Riot” referenced is now rebranded as “Element Messenger”.
Crypto that I trust more than Signal
Far more documented and open (even though backend is not)
Supports many clients
https://twitter.com/durov/status/872891017418113024?lang=en
https://telegra.ph/Why-Using-WhatsApp-Is-Dangerous-01-30-4
Besides - Moxie is kind of against decentralization, he thinks that by centralizing trust in a certain entity, things can be better. I am not convinced that such an approach leads to a better model for me to have encrypted communications:
https://news.ycombinator.com/item?id=21904469
I like that Signal started using SGX though. It’s not ideal (now I have to trust Intel instead) but at least if you’re going to be running some code on a centralized service instead of byzantine consensus, let me know you aren’t backdooring it:
https://medium.com/@maniacbolts/signal-increases-their-relia...
Not, it doesn't. You would just need to copy the private key to the other devices.
The content of the message might be encrypted, but metadata can provide valuable intelligence insights.
At least Matrix can be used mostly anonymously through a user-generated identifier, without an email address or phone number, and can be used through Tor.
Matrix OTOH would have a harder time getting adopted: businesses would need to update their websites, facebook pages and flyers to add the matrix contact info. Which they wouldn't do until Matrix is more popular. Which is a chicken and egg problem.
The most common client, Element, will by default ask you for your phone number when registering with the default matrix.org homeserver and the default vector.im identity server will associate your phone number with your matrix user.
So by default (changing servers and/or opting out is easy and encouraged BTW), Matrix already works like you would prefer.
This is BTW a main critique in the OP since it makes vector.im a PII and metadata aggregator.
of course it has, but so has the ability to NOT use a phone number. different use cases
What metadata? Signal doesn't store anything about you aside the date you joined and the time of your last ping.
Last I checked, Signal uses AWS, Azure and GCP. All of those services are completely logged and although "Signal" may not be storing metadata, intelligence services on those networks definitely are.
Signal forces you to use "a" phone number as your identifier. It does not have to be your primary phone number, or home phone number or office phone number. Just a phone number that you have control of.
In most parts of the world, you cannot get "just" a phone number not tied to your real identity.
1. the number everyone you have met since you were 12 has in their contacts.
2. the number a few people have but you also use for you facebook account.
3. the number nobody / no tech has but you have provided your legal id to the network provider.
4. the number nobody / no tech has and you gave the network provider a burner email for.
5. the number nobody / no tech has that you paid for in cash while wearing a wig and glasses half way across town. You put into a new, paid for in cash phone, activated and used briefly while carrying no other electronic devices while disguised and avoiding cctv.
6. the inbound phone number in the lobby of the ritz carlton.
Some of those are better than using 'firstname.lastname' as you identifier. 1&2 are definately public numbers 4&5&6 are not.
#3 in the real world is semi-anonymous - for those with real privacy needs, they should be taking many other precautions and shouldnt be carrying a tracking device or using a single phone number or service irrespective of it being in their name or someone elses or nobody at all. For privacy LARPERS of course it is not at all anonymous.
But some people aren't LARPing, truly need privacy, and compromising their safety to make a point about federation is immoral.
People who truly need privacy in the short term, should consult a professional and not trust random comments from strangers.
Would you like an example that's especially relevant to this thread? Because I can provide you with one.
I never mentioned any particular kind of federation that I prefer. I also never mentioned word "private", which is mostly tangential to federation.
My point is that, in the long run, only federated systems are sustainable, because nobody is able to fund huge servers with millions of users without infinite money. For example, Signal and Telegram are both struggling with that currently; the latter introduced advertisement recently. On the other hand, Mastodon does not seem to have such problem (you could argue that it's too early though).
I do not want to build my own clients, I'm not even a programmer. I want a sustainable network, which could be achieved by a large number of self-hosted instances federated with (possibly) large servers. It has been working fine with email for decades. Also, the competition of various independent clients improves the user experience (like any other healthy competition elsewhere).
"Sustainability" is arbitrary. Everything burns eventually.
I am mostly talking about a use case, where you try to switch all your friends and relatives to a new IM system. If you have to ask them to switch again in a couple of years, you will loose their trust quickly.
That doesn't make Matrix bad. It makes Matrix different. Matrix has different goals than Signal, and those goals simply prioritize security and privacy differently than Signal does.
You're completely right that we have different goals to Signal (openness + freedom rather than privacy-at-all-costs), but I'm not sure that blaming federation is the right answer here. We just prioritised building an open standard over having E2EE from day 1, instead choosing to design things so we could add it later.
Again: I'm not dunking on Matrix. There are things the Matrix approach will do better than Signal can. But protecting individuals is probably never going to be one of them; you're competing with a project that has security and privacy as its overriding goal, and nobody at Signal ever has to ask whether federation --- a protocol complexifier if ever there was one --- merits a security hit.
I don't use Signal for everything (or even most things). I'm completely open to the argument that other messengers are better "overall" than Signal. But on a thread that asks the question of whether Matrix is as secure as Signal (not "secure enough", but rather "at parity with"), there is simply a clear answer.
I'm willing to believe that this is true for Telegram, since they do pretty much everything on the server. With Signal, though, message databases and most business logic are client-side, so the servers are surprisingly dumb and lean. Signal spends way more on salaries and wages than on its servers. In 2019, Signal paid more to Twilio for SMS verification than it did to AWS for hosting: https://projects.propublica.org/nonprofits/organizations/824...
In short? When you look at a room, your client sends a (public) read receipt. So stalkers get near-realtime data on your activity and the simple act of viewing different rooms (and maybe even just focusing the window) to see what's up causes data to be sent to the server. Ugh.
From that angle I like systems like Matrix way more than centralized solutions like Signal, Threema etc., because the whole security and privacy guarantees of the latter can be completely nullified by a single software update. If users don't have full control over the software running on the endpoint then end to end encryption is little more than a marketing gag, IMHO.
But i entirely agree with your point that relying on a single actor for updates/security is really the worst.
Then you can join a room with a disposable account.
Plus, I self host, which, in my opinion, more than makes up for anything else. Hell, I'd take storing my own plain text over E2E on someone else's server even.
Use as much open source applications as possible, And if you want to. Do not force anyone to use them, Just be smart in providing your information.
I use:
Matrix - It's end to end encrypted but some groups i am in, The owners have it disabled for some reason. Keybase - Keybase was sold, But still end to end encrypted. Plus i was using it before they got sold so. Telegram - Telegram is not end to end encrypted by default, Unless you enable secret chats.
More or less how skype used to work, before it got bought by Microsoft and centralized.
I use signal to chat with my cousin who is in another continent, and he is online only when within reach of public wifi when he's outside, which is at night for me. My phone is always connected to 4G, so maybe what you propose could work in this specific case, but in other cases it could be an issue.
If that was the case, you'd use email, not a realtime chat platform.
And keep in mind, it was never an issue with the old, decentralized Skype.