Skip to content
This repository was archived by the owner on Jun 24, 2022. It is now read-only.

πŸ’¬ Discussion | Why is PrivacyTools recommending Riot over Wire when it's less private without a warning on unencrypted metadata?Β #840

Closed
@rawlife56

Description

@rawlife56

Ok! I get it, Riot is federated and their app is a step in the right direction coupled with Matrix protocol but it doesn't come without compromise due to its early beta stage.

privacytools.io mentions 'Wire' stores contact data unencrypted on their servers as their only reason removing it from the top recommendations. Doesn't Riot do the same ? AFAIK, Riot only encrypts the message content as of now if we enable it. Everything from the time stamps to people we have contacted, stickers sent, few attachments, Call duration-recipients and much more except the message content stays unencrypted somewhere in the matrix server. Isn't this situation much worse than Wire ? Yes, we can host our own server unlike any other client but I really doubt that will be more than a small minority of people. Hiding metadata like Signal does isn't their priority either right now looking at their road map.

So the question arises, Shouldn't we mention the large amount of metadata leaks in Riot on the website warning the users beforehand. I'm really in love with Riot for its stability in such an early stage as a user who used wire since a year as my main IM but people should be aware of caveats because they expect the website to mention it because the same website did warn about unencrypted contacts metadata for another chat application. I wouldn't use Riot over Wire or Signal for anything remotely sensitive in its current state.

I may miss something obvious because I'm still an amateur in this stuff. Would love to know if I'm missing anything.

@muppeth summed it up well here. I'm quoting one of his sentence which holds true and explains my concerns in a much easier way 'At this moment I don't see how this(Riot) could be advice as privacy aware service alternative. It's quite possible synapse stores more metadata then whatsapp at this point.'

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions