I've had a few people ask why I didn't post the full Matrix email on my Fedi thread. There are two reasons:

  • It wouldn't fit in 1k characters.
  • Listen carefully:
  • Y'know how "just getting caught cheating on your monogamous partner" isn't the right time to discuss exploring ethical nonmonogamy?

    In a similar vein, asking for information while dismissing a report as "no practical security impact" is still dismissing the goddamn report.

    I excerpted the part of their email where they dismissed my report. That was the part that initiated the immediate disclosure. The inciting turn of phrase.

    It doesn't matter how much you piss on my leg, I'm not going to believe it's raining.

    Matrix has many incentives to lie or mislead. Their leadership includes the CEO of a company whose product is a Matrix client. There's active political talks about the EU investing heavily in Matrix. He's got a vested interest in looking good, even at the expense of doing or even being good.

    On the other hand, I have nothing to gain. If everyone switches to Matrix tomorrow, nothing in my life changes. If Matrix self-implodes and everyone goes back to XMPP tomorrow, nothing in my lfie changes.

    The only things I want are:

  • End-to-end encryption to be better.
  • End-to-end encryption to become ubiquitous for communication protocols and apps.
  • The large tech companies whose business models involve privacy violations and stealing from artists and other creative workers to burn down so gloriously that society forgets the word "billionaire" in twenty years.
  • But what about "don't make perfect the enemy of good"?

    If your cryptography isn't damn near-perfect, it's shit. There aren't many cryptographic solutions that get a C+ in the world. It's either an A, A-, or an F.

    @soatok what do you think about autocrypt v2

    https://autocrypt2.org/#/

    https://fosdem.org/2026/schedule/event/TV7GCC-autocrypt_2_post-quantum-cryptography_and_reliable_deletion_forward-secrecy/

    Btw if I bother please feel free to ignore. I don't want no smoke πŸ™

    Autocrypt v2 - Post-Quantum and Reliable Deletion

    Modern OpenPGP v6 certificate with post-quantum cryptography, reliable deletion, and transport-agnostic messaging for decentralized systems.

    @nemo It's built on OpenPGP, so I immediately bail out

    @soatok OK :) Thanks πŸ™

    Last question: if something should happen to Signal/Molly, I've read that some folks proposed a cross-platform contingency plan. Do you have two cents on that if the worst-case should happen and Signal shouldn't be available for a prolonged time due to deliberate problems?

    @nemo If that happens, use whatever apps you can but assume they're all compromised.

    https://grugq.github.io/blog/2013/06/13/ignorance-is-strength/

    ignorance is strength - Hacker OPSEC

    Seven, this rule is so underratedKeep your family and business completely separatedBiggie Smalls Counterintelligence Theory and Practice for Crack …

    @soatok I hope that this will not happen…

    Thank you very much for your time and your work appreciate it a lot πŸ’š πŸ™