this post was submitted on 11 Feb 2026
405 points (97.4% liked)

Technology

81078 readers
3885 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

https://commet.chat/

@commetchat@fosstodon.org

you are viewing a single comment's thread
view the rest of the comments
[–] Mio@feddit.nu 4 points 11 hours ago (2 children)

Please explain. They don't have that?

[–] AnyOldName3@lemmy.world 6 points 10 hours ago (1 children)

If it's the problem that I've seen people complain about in the past, it's effectively the same as HTTPS 'not supporting' end to end encryption because it runs over IP and IP packets contain the IP address of where they need to go, so someone can see that two IP addresses are communicating, which is unavoidable as otherwise there's nothing to say where the data needs to go, so no way for it to get there. Someone did a blog post a couple of years ago claiming Matrix was unsecure as encrypted messages had their destination homeserver in plaintext, but that doesn't carry any information that isn't implied by the fact that the message is being sent to that homeserver's IP.

[–] Randelung@lemmy.world 5 points 8 hours ago

But what if the name of my home server is my private key? Mah jong, alchemists!

[–] Shayeta@feddit.org 3 points 8 hours ago (1 children)

Message metadata - such as sender, recipient, device ID, and timestamps - is not encrypted at the transport layer, and in many cases remains visible to the homeserver

https://wire.com/en/blog/matrix-not-safe-eu-data-privacy

[–] Ontimp@feddit.org 6 points 4 hours ago* (last edited 4 hours ago) (1 children)

Wire wrote that article in summer last year to prevent the German IT-Planning Council from adopting Matrix as the communications layer for its consolidated interfederal government-to-citizen messaging infrastructure in the public administration.

So be aware that, to my knowledge, this article is not a good-faith tech blog post but part of public affairs campaign / lobbying attempt.

Would be neat to have meta data encrypted in Matrix, but it's not a deal breaker for most use cases imo.

[–] Shayeta@feddit.org 1 points 1 hour ago (1 children)

Agreed, but metadata not being encrypted remains a fact. Sure, metadata of a single message might not mean much, but when combined with metadata of many messages from many users you can find out a lot about a person and their habits. Especially when cross-referencing with other data sources (social media of other users, phone location, etc.).

https://youtube.com/watch?v=tL8_caB35Pg

[–] Ontimp@feddit.org 1 points 1 hour ago* (last edited 1 hour ago)

Absolutely, it's definitely one of the major areas work on the Matrix standard is needed.

There is an MSC (= a spec change proposal) from September 2025 where the folks at Element proposed a solution for how to do this going forward: https://github.com/matrix-org/matrix-spec-proposals/pull/3414?ref=element.io

This blog article explains it more clearly: https://element.io/blog/hiding-room-metadata-from-servers/