Skip to content
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

fedi wiki

  1. Home
  2. Technical Discussion
  3. I often see that question about the way I use #E2EE over #ActivityPub.#FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on.

I often see that question about the way I use #E2EE over #ActivityPub.#FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on.

Scheduled Pinned Locked Moved Technical Discussion
e2eeactivitypubfedihoodholossocialmastodon
10 Posts 7 Posters 3 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • apps@toot.fedilab.appA This user is from outside of this forum
    apps@toot.fedilab.appA This user is from outside of this forum
    apps@toot.fedilab.app
    wrote last edited by
    #1

    I often see that question about the way I use #E2EE over #ActivityPub.
    #FediHood and #HolosSocial do not use the end-to-end encryption #Mastodon is working on. They are going for MLS over ActivityPub. I use the Signal Protocol, already working between Holos and FediHood, which I both maintain. Once MLS is available, I'll happily switch.
    But to be clear: it works perfectly with the Signal Protocol. The switch would only be for compatibility.

    1 Reply Last reply
    0
    • analytics@social.vir.groupA analytics@social.vir.group

      @apps I'm curious about your choice of the Signal Protocol. We built our own application that integrates ActivityPub with an E2EE messenger based on the Matrix protocols. It's proven to be very practical – the ActivityPub feed, authorization, and everything else work well – but the Matrix overlay gives us the ability to maintain safe and secure communication.

      apps@toot.fedilab.appA This user is from outside of this forum
      apps@toot.fedilab.appA This user is from outside of this forum
      apps@toot.fedilab.app
      wrote last edited by
      #2

      @analytics
      Honestly, I checked the FEPs before and didn't see one about Matrix, otherwise I would have looked into it more deeply.
      As for my choice, I stayed on the Signal double ratchet mainly for forward secrecy: a compromised key should not open the history.

      wachoperro@rebel.arW 1 Reply Last reply
      0
      • analytics@social.vir.groupA analytics@social.vir.group

        @apps I'm curious about your choice of the Signal Protocol. We built our own application that integrates ActivityPub with an E2EE messenger based on the Matrix protocols. It's proven to be very practical – the ActivityPub feed, authorization, and everything else work well – but the Matrix overlay gives us the ability to maintain safe and secure communication.

        6@possum.city6 This user is from outside of this forum
        6@possum.city6 This user is from outside of this forum
        6@possum.city
        wrote last edited by
        #3

        @analytics@social.vir.group @apps@toot.fedilab.app i wonder if the matrix protocols without using matrix software avoid being completely broken with constant issues all the time, like matrix has
        well, only encryption issues mainly, rest of it tends to work much more reasonably
        matrix encryption is always encryptdon't tho, or should i say
        [failed to decrypt message]

        1 Reply Last reply
        0
        • apps@toot.fedilab.appA apps@toot.fedilab.app

          @analytics
          Honestly, I checked the FEPs before and didn't see one about Matrix, otherwise I would have looked into it more deeply.
          As for my choice, I stayed on the Signal double ratchet mainly for forward secrecy: a compromised key should not open the history.

          wachoperro@rebel.arW This user is from outside of this forum
          wachoperro@rebel.arW This user is from outside of this forum
          wachoperro@rebel.ar
          wrote last edited by
          #4

          @apps @analytics
          I think Matrix shouldn't be a source of trust for anything security related :s
          https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/

          (In the addendum:)

          Matrix dev: meanwhile, it is very unclear that any sidechannel attack on a libolm based client is practical over the network (which is why we didn’t fix this years ago). After all, the limited primitives are commented on in the readme and https://github.com/matrix-org/olm/issues/3 since day 1.

          Soatok: "So the Matrix developers already knew about these vulnerabilities, but deliberately didn’t fix them, for years

          Congratulations, you’ve changed my stance. It used to be “I don’t consider Matrix a Signal alternative and they’ve had some embarrassing and impactful crypto bugs but otherwise I don’t care”. Now it’s a stronger stance:

          Don’t use Matrix.

          I had incorrectly assumed ignorance, when it was in fact negligence.

          There’s no reasonable world in which anyone should trust the developers of cryptographic software (i.e., libolm) that deliberately ships with side-channels for years, knowing they’re present, and never bother to fix them."

          kitkat@climatejustice.socialK ? 2 Replies Last reply
          0
          • wachoperro@rebel.arW wachoperro@rebel.ar

            @apps @analytics
            I think Matrix shouldn't be a source of trust for anything security related :s
            https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/

            (In the addendum:)

            Matrix dev: meanwhile, it is very unclear that any sidechannel attack on a libolm based client is practical over the network (which is why we didn’t fix this years ago). After all, the limited primitives are commented on in the readme and https://github.com/matrix-org/olm/issues/3 since day 1.

            Soatok: "So the Matrix developers already knew about these vulnerabilities, but deliberately didn’t fix them, for years

            Congratulations, you’ve changed my stance. It used to be “I don’t consider Matrix a Signal alternative and they’ve had some embarrassing and impactful crypto bugs but otherwise I don’t care”. Now it’s a stronger stance:

            Don’t use Matrix.

            I had incorrectly assumed ignorance, when it was in fact negligence.

            There’s no reasonable world in which anyone should trust the developers of cryptographic software (i.e., libolm) that deliberately ships with side-channels for years, knowing they’re present, and never bother to fix them."

            kitkat@climatejustice.socialK This user is from outside of this forum
            kitkat@climatejustice.socialK This user is from outside of this forum
            kitkat@climatejustice.social
            wrote last edited by
            #5

            @wachoperro @apps @analytics

            Ever thought about exploitability or vodozemac? No?

            sl007@digitalcourage.socialS wachoperro@rebel.arW 2 Replies Last reply
            0
            • wachoperro@rebel.arW wachoperro@rebel.ar

              @apps @analytics
              I think Matrix shouldn't be a source of trust for anything security related :s
              https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/

              (In the addendum:)

              Matrix dev: meanwhile, it is very unclear that any sidechannel attack on a libolm based client is practical over the network (which is why we didn’t fix this years ago). After all, the limited primitives are commented on in the readme and https://github.com/matrix-org/olm/issues/3 since day 1.

              Soatok: "So the Matrix developers already knew about these vulnerabilities, but deliberately didn’t fix them, for years

              Congratulations, you’ve changed my stance. It used to be “I don’t consider Matrix a Signal alternative and they’ve had some embarrassing and impactful crypto bugs but otherwise I don’t care”. Now it’s a stronger stance:

              Don’t use Matrix.

              I had incorrectly assumed ignorance, when it was in fact negligence.

              There’s no reasonable world in which anyone should trust the developers of cryptographic software (i.e., libolm) that deliberately ships with side-channels for years, knowing they’re present, and never bother to fix them."

              ? Offline
              ? Offline
              Guest
              wrote last edited by
              #6

              @wachoperro @apps @analytics My unofficial risk assessment of Matrix initially was: approaching pre-TLS IRC in its constitution.

              I see I wasn't too far off.

              analytics@social.vir.groupA 1 Reply Last reply
              0
              • kitkat@climatejustice.socialK kitkat@climatejustice.social

                @wachoperro @apps @analytics

                Ever thought about exploitability or vodozemac? No?

                sl007@digitalcourage.socialS This user is from outside of this forum
                sl007@digitalcourage.socialS This user is from outside of this forum
                sl007@digitalcourage.social
                wrote last edited by
                #7

                @kitkat @wachoperro @apps @analytics

                Just btw; there is also this repo
                https://github.com/swicg/activitypub-e2ee/

                1 Reply Last reply
                0
                • kitkat@climatejustice.socialK kitkat@climatejustice.social

                  @wachoperro @apps @analytics

                  Ever thought about exploitability or vodozemac? No?

                  wachoperro@rebel.arW This user is from outside of this forum
                  wachoperro@rebel.arW This user is from outside of this forum
                  wachoperro@rebel.ar
                  wrote last edited by
                  #8

                  @kitkat
                  I will copy it again in case you didn't read it, no?

                  "There’s no reasonable world in which anyone should trust the developers of cryptographic software (i.e., libolm) that deliberately ships with side-channels for years, knowing they’re present, and never bother to fix them."

                  @apps @analytics

                  kitkat@climatejustice.socialK 1 Reply Last reply
                  0
                  • wachoperro@rebel.arW wachoperro@rebel.ar

                    @kitkat
                    I will copy it again in case you didn't read it, no?

                    "There’s no reasonable world in which anyone should trust the developers of cryptographic software (i.e., libolm) that deliberately ships with side-channels for years, knowing they’re present, and never bother to fix them."

                    @apps @analytics

                    kitkat@climatejustice.socialK This user is from outside of this forum
                    kitkat@climatejustice.socialK This user is from outside of this forum
                    kitkat@climatejustice.social
                    wrote last edited by
                    #9

                    @wachoperro @apps @analytics maybe don't always read the same thing and expect to be smarter

                    1 Reply Last reply
                    0
                    • ? Guest

                      @wachoperro @apps @analytics My unofficial risk assessment of Matrix initially was: approaching pre-TLS IRC in its constitution.

                      I see I wasn't too far off.

                      analytics@social.vir.groupA This user is from outside of this forum
                      analytics@social.vir.groupA This user is from outside of this forum
                      analytics@social.vir.group
                      wrote last edited by
                      #10

                      @bms @wachoperro @apps

                      Friends, don't fight. Thank you all for your attention and for sharing your knowledge. I tested Matrix, went through the code, and haven't found any dangerous actions in it so far. I was at a crossroads – Signal or Matrix – but Signal ended up in the spotlight due to a mistake made through FCM push notifications, namely that they were able to extract data via Firebase Cloud Messaging and hand it over to the court. That's why I chose Matrix, but on my end, I also closed those holes so that the notification body isn't transmitted to FCM during push.

                      Of course, the best solution is always the one you develop yourself, but there are plenty of pitfalls there too. For example, today I found 6 vulnerabilities in an app that has been downloaded over 5 million times. I wrote an article about it today without disclosing the app's data to avoid causing harm, and I notified the developers. I'm not falling apart here – I'm just saying that even giant apps often make mistakes, sometimes critical ones – like an exposed API key from a database in decompiled code.

                      Wishing everyone security, success, and peace. And forgive me for writing to you from an account where I have a bot agent running – so if you'd like, we can exchange subscriptions from my active account, where I write personally rather than the OSINT bot. == @newsgroup

                      1 Reply Last reply
                      1
                      0
                      • R relay@relay.fedi.agency shared this topic

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      • First post
                        Last post