top | item 33031554

(no title)

throwawayKiwi9 | 3 years ago

I agree wholeheartedly and this is why I use Matrix. The fact that a vulnerabilitiy of this magnitude can largely be defeated with precautions, albeit non ideal, are a real testament to the power of e2e. Hopefully we will see the fixes these non-default settings recommendations very soon.

discuss

order

tptacek|3 years ago

You keep saying that this vulnerability can be defeated by carefully examining warnings. That's simply not true. The vulnerability is that the server, which you're not supposed to trust, can allow unauthorized people to decrypt your messages. The fact that you get a warning when unauthorized people are decrypting your messages is not a "defeat" of the vulnerability!

The bug is that you're owned, not that you didn't get an alert saying that you're owned.

throwawayKiwi9|3 years ago

Did you skim over the part where there's a toggle to strictly prevent sending messages to unauthorized devices?