|
|
|
|
|
by notyourday
2621 days ago
|
|
Matrix operational security is a joke and developers understanding of security is a joke. This is 2019, not 1992. Infrastructure with ssh access without hole punching for currently active authorized connections only? Decrypted signing keys accessible over the network? CI servers and developers having root access? Though the "we had to revoke all the keys so you lost access to your encrypted messages unless you backed them up" takes the cake. |
|
This is just how it works. It's been well documented and mobile clients got updates that backs up the keys automatically. It's also effectively the same as WhatsApp and some other IMs (they just don't even save your encrypted messages). Either way - backup, or lose your history.