Matrix: An open network for secure, decentralized communication
matrix.org
matrix.org
I’m no stranger to self‐hosting, and I personally run my own email server (with MTA‐STS, DANE, and mandatory TLS for outgoing mail) and Mumble for voice chat, and even Pleroma. These have all been very reliable, enough that I regularly communicate with friends this way. In contrast, my Matrix experience makes me reluctant to suggest it to anyone I know, because it’s hard enough to get anyone onto something user‐friendly like Signal.
I want to love Matrix. The idea is really cool, there is obviously a lot of work behind it, and I appreciate having something federated to compete with Signal’s model. But it just hasn’t worked for me. I hope the self‐hosted situation will improve.
Synapse on the other hand is mature and solid (if still a bit resource heavy).
Sorry that you got bitten by this :(
Matrix – An open network for secure, decentralized communication https://news.ycombinator.com/item?id=24239564
Matrix 1.0 and the Matrix.org Foundation https://news.ycombinator.com/item?id=20157809
Matrix 1.0 – Are We Ready Yet? https://news.ycombinator.com/item?id=19416678
Synchronous Messaging at Mozilla: The Decision https://news.ycombinator.com/item?id=21835749
Automattic invests in Matrix https://news.ycombinator.com/item?id=23256050
Cross-signing and end-to-end encryption by default https://news.ycombinator.com/item?id=23107564
Running your own secure communication service with Matrix and Jitsi https://news.ycombinator.com/item?id=22802645
We’ve decided to rename Riot https://news.ycombinator.com/item?id=23611863
You have everything from Drone C2, to chat, to networked photoframes.
It definitely has a lot of growing and a chunk of bugs to get ironed out but I truly believe that a federated open source chat protocol is the only option for the open future of IM, and Matrix is the best we have in that space.
Matrix has e2ee but the overall UX of Matrix is still not really there, and the encryption can have issues where messages are not able to be decrypted. It has been audited and is open source. With Matrix you have more freedom because you can run your own server, but personally I would pick Signal since there is less chance of messing things up, for example accidentally having an un-encrypted chat.
Telegram does not do encrypted chats by default and has a history of implementing their own poor encryption. The Telegram server is closed source.
WhatsApp has good encryption, the same as Signal, enabled for all chats. But it is closed source.
Matrix is the only one where you can be sure that the source code matches what you are running on both the client and (your) server.
All of them use broadly similar E2EE protocols from the same cryptographic lineage (except possibly Telegram who have a history of making false claims about their encryption protocols). The Signal/WhatsApp implementation feels a bit more mature than Matrix's.
I don't feel super great about any of them, but I'd absolutely pick Matrix over any of the others.
If it’s privacy from the platform operators, then Telegram loses because it stores all normal chats in plain text on its servers (though that makes searching a great experience). Signal, to a great extent, and WhatsApp to a lesser extent, try to avoid storing information about your use of the platform. But they do maintain some metadata until the time you delete your account.
All the above fail on the phone number requirement to sign up. They’re also centralized platforms depending on the benevolence of one team or company.
Matrix is a mix here. It allows you to sign up without revealing your phone number. If you choose to use end-to-end encryption, then all your chats would be encrypted (like in Signal or WhatsApp, where this is the default). But Matrix also stores metadata about you and your presence.
My recommendation would be Matrix because you’re not tied to one provider (you can self host it and connect with other Matrix instances, if you wish). The client UI and UX are lacking, but I believe this has a better future on privacy than Signal (with the addition of non-chat features like Mobilecoin).
Short version:
- If you absolutely need your messages to be private, use Signal.
- If you're looking for a more flexible/future-proof chat app that doesn't have some of Signal's downsides, use Element, but be cautious because it's had some issues in the past.
- Use the others if someone forces you to, I guess.
Longer version:
----
Signal has been around for a while and is highly vetted by the security industry, and most security professionals I see online swear by it. Signal does a lot of stuff very right and for the most part does an extremely good job of not leaking extra data.
Signal has several glaring downsides that do not affect its overall security, but that might be dealbreakers for some people:
- it requires a phone number to sign up
- very glaringly, it leaks to other contacts on your phone who are already using Signal that you've joined (they'll get a notification in Signal that you installed the app).
- it's extremely centralized, which Moxie (the creator) lists as an upside because it allows faster iteration and simplifies some problems like key sharing, but which many people see as a downside for a lot of reasons, including that it makes it harder to fix problems that Moxie isn't interested in prioritizing (such as requiring phone numbers or leaking that you've joined to contacts).
Signal is a narrow application trying to solve a narrow problem, secure text messages. It is highly secure for that use case, and difficult to use outside of that use-case. It also has some questionable choices about privacy in regards to user identity around signup, and questionable choices around things like alias accounts. But again, Signal isn't really trying to solve those problems.
----
Element/Matrix is trying to solve those problems.
In theory, Element/Matrix is a better choice than Signal; but theory isn't the same as practice. In practice, Element is trying to do something much harder than Signal is doing, (decentralized end-to-end encryption), and Element is a much newer app undergoing a lot more active development, which makes it harder to trust. Element has had issues in the past with leaking data and vulnerabilities. Unlike with Signal, it is possible to make unencrypted rooms in Element (Signal makes this a bit harder unless one of your contacts is using SMS text messaging). Signal tends to be really obsessive about not leaking any contextual information around things like stickers, basically no HTTP requests to anyone other than Signal's servers, and a lot of those HTTP requests get masked and obfuscated in really smart ways. Element sometimes messes up in this area.
Element is also just flat-out bigger than Signal in terms of what functionality it's trying to achieve, which makes it more complicated. All of that makes it harder to trust Element for really, really important communication at this time.
On the other hand, Element is decentralized and is working on some privacy tools including P2P communication that Signal is kind of ignoring because Moxie likes his server. Element might occasionally leak information in a bad request, but it doesn't require users to give their phone number to join. It is attempting to solve problems around private communication that Signal is not interested in solving and that likely will not be interested in solving for some time if ever. Certainly if you are looking for a chat app in the neighborhood of Discord, or you care about having multiple identities online, or if you care about self-hosting, Signal is not going to work for you, it cannot handle those use cases -- it's not designed to do so.
Element has the downside of being a bigger application, but it also has the upside of being a bigger application, meaning that it's a good way of unifying a lot of different chat needs into a single interface with pretty consistent security guarantees across all of them. And that turns out to be really good for adoption. There is a strong benefit to keeping apps small, but as Moxie himself would say, UX also matters with getting people to use encrypted apps -- and being able to seamlessly jump between public chat rooms and private end-to-end encrypted rooms is a big usability win.
----
My take: I use Element whenever possible for chats that I would like to be private but where it wouldn't be the end of the world if they leaked, and for default chats that I don't particularly care about. I am slowly looking to turn it into a Discord replacement for closed communities including family chats; this is something that frankly isn't possible on Signal.
However, for a nontrivial amount of one-on-one communication, and on any topic where I desperately needed privacy, I would rely on Signal. It's easier for people to use because it's a much simpler, smaller product, and frankly I trust Signal's reliability and security more than I trust Element's. It's also easier to onboard friends and family members who are texting with me over the phone and who already know my number onto Signal because it's a drop-in replacement for their SMS. I don't have to stop using Signal just because someone in my family is on SMS (although note that in that case Signal offers very little to any encryption benefits for those conversations at all).
My long-term hope is to move to Element for everything, and I think Element will likely get to the point where I can confidently do that. I don't think that Signal is the future of encryption, I just think it's the best tool on the market right now. I also don't think Element is necessarily insecure right now, I just don't know for certain that it is secure and I'm waiting to see its security validated more. At least, I'm not as confident about it as I am about Signal, and I find that Signal is a particularly good SMS replacement at this point in time.
My feeling is that between Element and Signal, most chat needs should be covered including stuff like video calls, screen-shares, etc... so outside of existing user pressure, I really don't see the need to even look at or evaluate the other ones beyond "they're like Element but less flexible/future-proof/decentralized" or "they're like Signal but less trustworthy."
I would also include stuff like email in that assessment. I use email because of network effects but I'm slowly moving away from it for everything else. Realistically if the network effects didn't exist there would be no reason to ever try to send secure information over email, and there's little to no need to try and build encryption on top of it (insert many links to why PGP encrypted emails are foot guns), because outside of network effects almost anything you can do with email you can also do with either Signal or Element. Signal has obviously better privacy and (frankly) Element has better decentralization given the current spam situation and the industry consolidation that email has seen over time.
So my advice is use Signal/Element and ignore the rest unless you have friends/family/industry pressures to use the others. Balance between Signal/Element based on what your specific priorities are and how much the limitations of each bother you.
matrix, well you are the owner of the server if you choose so you get to decide.
signal calls itself "open source" but its not really "free software". the same "open source vs free software" comes up. what i think signal is "source open" and not much. you can't set up your own server, your own client, they are selling centralization as a feature which its not. email has proved otherwise for decades. matrix is what is email.
IMO that's an acceptable tradeoff for achieving decentralization without making the protocol overly complex (AIUI something like Signal's "sealed sender" system doesn't work in a decentralized environment)...but it still feels like a nagging threat that needs a proper solution eventually.
Practicality and function are always a tradeoff for privacy, though.
Also remember that privacy and security are never a silver bullet, and anyone claiming that something is, is probably not being genuine about their intentions. Privacy and security are about making things harder, not impossible - how difficult is entirely based on what you're trying to protect, and from who or whom you're trying to protect it. There are no perfect systems or completely safe platforms/locations/etc.
Right, with that out of the way.
In this case, tapping is less of a concern with anything E2EE encrypted and using proper cryptography suites - which is usually a given these days with most privacy-focused applications. Signal, Matrix, and Briar come to mind. But "censorship resistance" being the key term here, means that the infrastructure used to actually send the messages cannot be tampered with or otherwise taken offline.
You want to make sure that automatic updates can't be pushed to the app by a third party. App signing helps but making sure that automatic updates are off and that you update frequently enough and ensuring that each release is properly released by the author is important. There are other modes where this still isn't bulletproof (system OTA update with a backdoor, app author is compromised, etc.) but these are typically not within your model.
Open source projects tend to be the defacto if you really care about good intentions since it allows everyone (including you, but more importantly, independent auditors and people who are experts at looking at this stuff) to look at the code and assess that it works as described.
Telegram is not censorship resistant[0], and while it's E2EE in secret chats, it's not E2EE by default. This is a common misconception by a lot of people.
Signal by design isn't censorship resistant but they do a lot of work to make it effectively so (e.g. [1]) - when they're not fighting amongst themselves[2]. Signal is also quite aggressive when it comes to antiestablishment sentiments historically, which depending on where you are can work against you or be in conflict with your goals[3].
Matrix is a decent enough protocol at a higher level, though admittedly I'm not super acquainted with its internals. I do use it quite a bit, however, and generally like it, but it's very unapproachable to all but the savvier tech enthusiasts, and has a pretty young ecosystem when it comes to clients, phones, etc. It's also wildly underused compared to other platforms. I myself am a long time IRC user and get very confused with Matrix at times.
Finally there's Briar[4], which I've not used but it was mentioned not too long ago here on HN. It can use other means of communication on phones to send messages securely.
As always, Tor can be a great way to obfuscate your internet usage and in some cases even bypass state-enacted blockages of certain sites, but it's not foolproof and can actually make things worse[5] if you don't understand how it works and when not to use it. Make sure to research first.
By the way, threat modeling[6] can be fun and is applicable to a lot of situations, including your own personal safety. The five functions[7] are a fun place to start. Read up on it if you want!
Hope this is a decent enough overview!
[0] https://en.wikipedia.org/wiki/Government_censorship_of_Teleg...
[1] https://reclaimthenet.org/signal-offers-workarounds-for-iran...
[2] https://github.com/net4people/bbs/issues/63
[3] https://cyberlaw.stanford.edu/blog/2021/05/i-have-lot-say-ab...
[4] https://briarproject.org/how-it-works/
[5] https://support.torproject.org/faq/staying-anonymous/
[6] https://en.wikipedia.org/wiki/Threat_model
[7] https://www.nist.gov/cyberframework/online-learning/five-fun...
Signal is also end-to-end encrypted, but suffers from a lack of users and their apps don't have a great UI. Sync is also not that great, and backups are terrible.
Telegram is the best app feature-wise (stickers, multi-device, bots, instant sync, unlimited storage) but chats are not end to end encrypted by default. Their apps are native on all platforms, and are very smooth.
Element (a matrix client) has e2ee chats, but the UI is not that great, and the number of users seem to be lower than Signal.
FYI, WhatsApp has added Reactions. It is in beta for some users.
https://wabetainfo.com/whatsapp-beta-for-android-2-21-25-11-...
I.e. it's not like a protocol usable by system competing with discord, slack, teams etc.
If you ignore matrix in this comparison and only look at phone messaging signal wins by far.
If it's about non-phone specific messaging matrix wins by default as the other don't even really compete there.
The official web client is sluggish. I still can't jump back and forwards to notifications. It's very cpu-intensive for me.
This never happened to me with email, even when encrypted (as long as I have the privates keys). All MUAs offer search capabilities, and/or exports so I have access to existing information.
Not to say it's flawless to retrieve information (and personally I would like to see an archival-type client / tempted to make one), but it would be wrong to say it doesn't exist! :)
The Mac client has a search button and it asks me for a search term. When I enter a string (which I know to appear in the room I selected) the search reports ""No results" ... I'm not sure if I'd call this an "existing search capability" either ;-0
OK, I have to admit that the latest Mac client now (finally) has an export feature, as I just checked. So it seems usability improvements happen, albeit slowly and unevenly deployed.
With irssi (IRC in general), you grep a logfile. Since I don’t log, I only /lastlog on what’s still in my buffers.