RE: https://furry.engineer/@soatok/116088639302283341
So, Matrix responded with a blog post.
I added an addendum to mine to rebut theirs: https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/#matrix-response
RE: https://furry.engineer/@soatok/116088639302283341
So, Matrix responded with a blog post.
I added an addendum to mine to rebut theirs: https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/#matrix-response
@vavsvirtual hey you you wanted to read this article right? well now there's more
@soatok im still a little confused how the identity element is a problem
let’s say i have a group chat with friends:
- one friend uses a client that sets identity element to 0 (whether purposefully setting it or downloading a malicious client unaware it’s disguised as an encrypted client)
- anyone sniffing the traffic between us can trivially decrypt the messages?
do i have that right?
@Logical_Error Yes, assuming they can observe the ciphertext.
If Matrix is deployed with well-configured TLS, this means probably only the homeserver is in a position to do this. If Matrix isn't, it's free real estate for QUANTUMINSERT and other attacks.
You and your friends will be "using" encryption, believing that your messages are private, while not having any real confidentiality.
This is a cryptographic protocol failure that results in silently losing confidentiality without warning. In the context of cryptographic attacks, the severity is pretty high.
Could the users also just give their private key to an adversary? Yes, but that requires an out-of-band signal. This compromises privacy without any external leak.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.