Discussion
Loading...

Post

Log in
  • Sign up
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Daniel Gultsch
Daniel Gultsch
@daniel@gultsch.social  ·  activity timestamp 4 days ago
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer  ·  activity timestamp 5 days ago

https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/

#Matrix #infosec #vulnerabiltiy #cryptography #privacy

RE: https://furry.engineer/@soatok/116088639302283341

I’m not qualified to comment on the alleged security vulnerability in #Matrix, but 'the entire Matrix community sucks because one user once disagreed with me on the Internet' is such a wild take.

  • Copy link
  • Flag this post
  • Block
Wladimir Palant
Wladimir Palant
@WPalant@infosec.exchange replied  ·  activity timestamp 4 days ago

@daniel I haven’t seen any comments about the Matrix community, only about the project’s vulnerability response. Even if it’s one user, it’s the user handling security reports. If they reject legitimate vulnerabilities as “not relevant in practice” – that is very concerning. If Matrix is supposed to be considered secure, they need working processes for handling vulnerability reports. If on the other hand they have a hobbyist approach to security then their product cannot be considered secure.

Note: It may in fact be “not relevant in practice” yet. Still, an important building block of the protocol is compromised. It needs to be fixed, preferably before somebody figures out how to make this issue relevant in practice. Because somebody inevitably will.

  • Copy link
  • Flag this comment
  • Block
inso
inso
@inso@framapiaf.org replied  ·  activity timestamp 4 days ago

@WPalant @daniel but they did not reject it, even if there's no vuln they accepted that it would be good in terns of defense in depth.
https://matrix.org/blog/2026/02/analysis-of-reported-issues-in-vodozemac/

Analysis of reported issues in vodozemac

Matrix, the open protocol for secure decentralised communications
  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 3 days ago

@inso @WPalant @daniel [very loud incorrect buzzer]

https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/#matrix-response

Dhole Moments

Cryptographic Issues in Matrix’s Rust Library Vodozemac

Two years ago, I glanced at Matrix’s Olm library and immediately found several side-channel vulnerabilities. After dragging their feet for 90 days, they ended up not bothering to fix any of i…
  • Copy link
  • Flag this comment
  • Block
inso
inso
@inso@framapiaf.org replied  ·  activity timestamp 3 days ago

@soatok @WPalant @daniel i don't see how your addemdum adds anything, if a group participant is malicious, they already are getting the keys and can decrypt everything.

They said they'd add the check but clearly there's no pressure to do it in any kind of urgency as there's no vuln. There's no need to start an inflamatory post based on this either.

I mean even Signal added the check only last week (do you have something to do with it? 😝)

  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 3 days ago

@inso @WPalant @daniel You're either on the Matrix team and trying to deflect or astroturf, or suck at reading English. I laid everything out once, I'm not going to do it again.

  • Copy link
  • Flag this comment
  • Block
inso
inso
@inso@framapiaf.org replied  ·  activity timestamp 3 days ago

@soatok @WPalant @daniel well let's agree to disagree on your reading on this then. Happy not to waste to much life time on this social media drama.

  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 4 days ago

@daniel ...one? lol, lmao

  • Copy link
  • Flag this comment
  • Block

Bonfire social

This is a bonfire demo instance for testing purposes

Bonfire social: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in Create account
  • Explore
  • About
  • Members
  • Code of Conduct