|
|
|
|
|
by notyourday
1934 days ago
|
|
> You can just enjoy the fact you know you chose someone you trust (us!) with your data. Yeah, no. Blast from the past: https://news.ycombinator.com/item?id=19642554 This is the entity/company who decided to revoke clients keys because not because the users messed up but because they messed up and therefore destroying access to the users messages and defended that as the approach! |
|
>You might have lost access to your encrypted messages.
>As we had to log out all users from matrix.org, if you do not have backups of your encryption keys you will not be able to read your encrypted conversation history. However, if you use server-side encryption key backup (the default in Riot these days) or take manual key backups, you’ll be okay.
>This was a difficult choice to make. We weighed the risk of some users losing access to encrypted messages against that of all users' accounts being vulnerable to hijack via the compromised access tokens. We hope you can see why we made the decision to prioritise account integrity over access to encrypted messages, but we're sorry for the inconvenience this may have caused. [1]
I think this shows they simply revoked keys to avoid the hacker accessing messages. Had messages been breached, that would have been significantly worse for an E2EE federated messaging platform.
[1]: https://matrix.org/blog/2019/04/11/we-have-discovered-and-ad...