People are migrating en masse from WhatsApp to Signal and Telegram. I am pretty sure it's ruffling some feathers considering the vocal people defending and promoting Matrix and federation in every Signal thread and considering this informal poll: https://news.ycombinator.com/item?id=25669864
Telegram
806 points
Zom
3 points
Viber
15 points
Threema
69 points
Signal
1699 points
Discord
102 points
Matrix (added after 25 mins)
374 points
Last I read speculations were that Signal had something like 10 millions users/downloads and Matrix 25 millions users (take that with a boulder of salt).
Cool. Now get 5 friends of yours to join you in a crypted room with each using a phone and then a browser, wait two days, get back to it and manage all the insecure session notices.
Beware, they removed the warning from the android client though. It confused people.
That is only the case when you have verified your friends keys (by qr code or emoji string).
When one of your friends account is hijacked and has someone snooping on messages, you'd want to know that.
Though I see it might be confusing at first for users to understand that they have to sign their devices. Currently, you have to login with a username/password and afterwards (optionaly) get one of your other devices to sign your new device. Which the UI does clearly ask you to do though.
I'm using Element very sparsely, but keep getting annoyed by it. I did not care to touch any settings. I have a persistent tab in my browser and it keeps having the notification dot for silly reasons:
- My connection flaked out (duh, I closed the laptop lid).
- Connection for one of my contacts flaked out (?!).
- Something in the signatures changed.
I get how any of that might be a sign of compromise. But I really don't care, I don't use this for anything sensitive. And with only about 20% of notifications being about an actual message, I've developed a blindness towards it.
Edit: having written that, I've noticed it is not doing this right now. Come think of it, it might have stopped a while ago and I simply didn't notice (c.f. developed blindness).
No, no, no. I have been toying my own Matrix instance and I registered 2 users that I played with, exchanging pictures and messages. There were some glitches in the UI that insiste on flagging some sessions as insecure even though I verified every session.
Sometimes it got resolved all on its own, sometimes it stayed like that. No biggie in the end but you can find some bug reports like that on github. Most probably it's getting worked out or was but it definitely happened.
Downloaded client on Windows. Fine. Installed fine.
Hit the button to make an account, everything went fine. It sent a verification email. I clicked the link. It said "something" was wrong with my setup. I JUST installed it, with the default options.
On a hunch, I went back to the client, and was able to log in. The failure message was entirely spurious. If I hadn't been tech savvy I likely would have been scared off and not bothered, assuming it was just broken.
Telegram 806 points
Zom 3 points
Viber 15 points
Threema 69 points
Signal 1699 points
Discord 102 points
Matrix (added after 25 mins) 374 points
Last I read speculations were that Signal had something like 10 millions users/downloads and Matrix 25 millions users (take that with a boulder of salt).