Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How come https://riot.im (Matrix) manages to sync between devices AND have E2E, while also being federated?

That's not what you get when you have a secure system, that's what you get when you design a system that can collect (and possibly monetize) the data of millions of users.



I believe that making sync work with E2E bring either security issues or more burden on the user; I would like them in telegram, but I also like the "if you send this message you exactly the device it go to, not an old laptop i forgot in the office, just my phone". it is meant to be secure on a device level.


Yeah, you'd have to manually put your private keys onto your computer from your phone.


Or you do what Matrix does, and given every device its own keypair, and let users track whether they are talking to a trusted decice or not.


That's not what I meant. Yes you can have sync and E2E. With different trade-offs.

Telegram is secure from device to device, not from account to account. If I send you a secure message from my iPad I don't have to worry about the web session I opened a week ago on someone else laptop.


People down voting this comment, care to explain what's wrong with it?




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: