Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does matrix even support end-to-end encryption? Last I checked it didn't have /any/, except maybe server-to-server and even that wasn't enabled.

I also seem to remember going over their homebrewed cryptographic rachet and it didn't properly HMAC.

EDIT: Apparently riot.im supports E2E, but it's not a part of the Matrix protocol and it's not encrypted by default. The Olm rachet was also audited by NCC, so that's nice.



E2E /is/ part of the Matrix protocol - it's just still in beta. The spec PRs haven't landed yet (http://matrix.org/speculator/spec/drafts%252Fe2e/client_serv...). Once out of beta it'll be turned on everywhere by default.


They have e2e on all devices now.


But still no way to enforce or enable as default.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: