I wanna know if MATRIX recipients know my IP, and more globally what the recipients know about me (how the matrix protocol works). THX

  • GravitySpoiled@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    8 months ago

    It’s not a disaster. That’s overstating it. It just leaks some metadata to the server. Nothing that’s inherently wrong with it and which won’t be solved over time.

    Some may don’t like that everything is stored on the server compared to signal where it only transits the server. But for companies or gov that should be/is mandatory. And it makes handling cross client and updating devices a lot easier for normal consumers.

    • poVoq@slrpnk.net
      link
      fedilink
      arrow-up
      2
      ·
      8 months ago

      You seem to be unaware of how Matrix works. It is inherent to the protocol that room metadata is shared with other servers. It is not fixable as it is working as intended. This feature is nice for censorship resistance, but it is pretty much a nightmare for metadata privacy.

        • poVoq@slrpnk.net
          link
          fedilink
          arrow-up
          2
          ·
          8 months ago

          Like all of it. It is not a “leak” if it is working as intended.

          Anyone can spin up a Matrix server, join a room with it and the Matrix network will happily push a complete copy of the room metadata (all the way back to the point the room was first created) to that new homeserver.

            • poVoq@slrpnk.net
              link
              fedilink
              arrow-up
              2
              ·
              8 months ago

              Yes it is a problem for both public and private rooms as this info is stored and shared retroactively. Lets say one of the participants of a private room gets compromised or you invite someone that has their account on a compromised homeserver. This then results in the entire room meta-data history (since the room was created) being shared with that compromised homeserver which can then easily analyse it in detail.

              • GravitySpoiled@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                8 months ago

                That doesn’t sound realisticly threatening to me. Besides, if I want the highest security and privacy I use onion routing.

                • poVoq@slrpnk.net
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  edit-2
                  8 months ago

                  lol, why are you even posting on a privacy community then? And using Tor doesn’t help at all in that case.