New signal vulnrubility: in the app, you can read your messages in plaintext!!! Matrix prevents this
@julia just run an aes256 algorithm in your head  /joke

@Jes just imagine keys other person didn't send you, simple as that

@julia

@julia Lol, like 40 years ago I wrote a program that caeser-ciphered your chat messages and got banned from at least one system for it. I called it "Captain Midnight's Secret Encoder Term" which was a huge clue and there were people who didn't bother running it and decoded it in their head.

@julia and to make it extra safe Element X it won’t tell you that it protected your messages and instead just say “Waiting for message”!

@sigmasternchen

@julia [unable to decrypt]
@julia [unable to decrypt message]
@julia a message that you can read is a message someone else can also read under certain circumstances. ;D

@julia

[This Reliquary is Encrypted]

@julia *reverses strings for fun* sick burn, luv
@julia in matrix, no one can read your messages, it’s all encrypted turtles all the way down 🐢
@[email protected] 🔒️ unable to decrypt reply
@julia Matrix is safer because you can't send messages.
@mdhughes @julia yea it forces the user (a potential attacker) to work with ciphertext only, in my experience most symmetric ciphers are a lot less vulnerable when you don't give the attacker known plaintext/ciphertext pairs. So this is clearly a great security feature of Matrix. ooc: (I had all these problems until I migrated away from matrix.org, since then matrix just works, group chats and all)
@julia Do you have a source for this please?
@Ooze source: it's a joke
@julia Ah. Sorry. There was no context.
@Ooze The joke is that of course you can read your own messages in the app

otherwise it'd be useless
@julia Oh gods, of course. I am an idiot.
@Ooze @julia I've managed to avoid using Matrix thus far because I hear it's an absolute ballache to run, but I assume the "Matrix prevents this" is exactly as funny as it sounds.

@woe2you @Ooze @julia

It absolutely is.
So much hassle to persuade it
"I am sending a message to someone, please show it to them"

@Ooze @julia unfortunately, the context could not be decrypted 🔒
@nu @julia @Ooze cross-signing corruption! Megolm session expired! Olm ratchets out of sync! Oops, to-device lost in transit!
@tranquillity @julia @Ooze oh? never seen that before, whats that from?
@nu @julia @Ooze various reasons why Matrix gets UTDs (Unable To Decrypt errors)
@tranquillity @julia @Ooze ahh, ngl act, the only reason ive experienced people being unable to decrypt their stuff was not verifying their devices, or resetting their state because they forget to store the key (also commet ig but that app was in alpha so like, yea, what could i expect)
@nu @julia @Ooze I've seen a bunch lol
Also, not verifying devices is technically bad cross-signing state (okay not necessarily but in practice yes)
@julia holy lol this is so good
@julia still leaks metadata in form of who tried to message you. this needs to be stopped!

@julia Whaaat?! That means it’s open to all sorts of social engineering attacks and people peeking over your shoulder?!

They should be showing messages in a made up language that only the recipient understands. Common industry practice, innit? SMH

@julia thank you for making me choke on my food out of laughter
@julia that punchline is an assassin istg
@julia uhhhhhhhh... Oh, nevermind.

@julia @goldstein Opened the thread to look for people not getting the joke.

Was not disappointed 😹

@julia matrix directly beams the encrypted stream of conversation into your brain. you have to install a homomorphic encryption comprehensor flesh blob into your brain to use it
French govt messaging service breached in account hijacking attack

DINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform.

BleepingComputer