Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don’t use Matrix, but if it’s E2EE, then how is it possible in the current design for an unverified device to even exist?

It has the keys, or it doesn’t, right?



Matrix has E2EE support and many clients are pushing it as the default. But it also supports rooms that are only encrypted in transit.


That's correct, but E2EE also allows for unverified devices[0]. Key distribution and device verification are separate issues, and the former doesn't enforce the latter until April 2026 as they've announced in the HN article.

[0] https://matrix.org/docs/matrix-concepts/end-to-end-encryptio...


You don't have to use E2EE if you don't want to. I personally don't because I don't care about it, and it adds extra difficulties to the experience.


If you don't need e2ee, are there features that make matrix better than xmpp?


Both XMPP (via OMEMO) & Matrix use libsignal for double-rachet encryption—so they have the same encryption properties. The biggest practical differences for the average user in my opinion is XMPP has a separate concept for DMs (not a 2-user room with encryption like Matrix), XMPP allows encryption to be both enabled then later disabled, & Matrix offers better resilience as messages & attachments get synced to all servers a room (which has a massive downside of resources, storage sizes, & moderation; if a server goes offline, you still have a history of the chat but if someone shares something explicit, such as CP, it will propagate thru the network & there is no way to delete it across nodes).

One of the better comparisons out there: https://www.freie-messenger.de/en/systemvergleich/xmpp-matri...


Lots of open source projects have matrix servers and not XMPP servers. Some bridges don't have XMPP equivalents (and some bridges don't have Matrix equivalents either).

XMPP also does E2EE of course, though I've found it to be a worse experience on most clients compared to Matrix.


decentralized rooms, built in video conferencing, consistent chat history storage




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: