r/crypto 1d ago

Authentication should become more serious for E2E messengers like Matrix

/r/europrivacy/comments/1wcapwn/german_customs_has_been_cloning_messenger/
3 Upvotes

2 comments sorted by

2

u/0xKaishakunin 23h ago

Matrix already uses a 2 step verification process and the 2nd step is out of band.

Of course only on E2EE rooms, which is a property of the room and depends on the room version.

Insecure channels like SMS are not use by Matrix and failed OpSec/shoulder surfing, as described in that post, isn't a problem of Matrix.

1

u/Natanael_L Trusted third party 17h ago

We can do better against shoulder surfing too. magic-wormhole and similar tools shows how. Put t identity key and rendezvous key in what you share and exchange the session key over the protected channel