Conversation

Replying to and
It has a lot of issues. It uses long-term identity keys without automatic authorized key rotations, and even worse, it doesn't use session keys so there is no forward secrecy. It has a lot of bad cryptography including current generation keys still having SHA-1 fingerprints, etc.
1
Replying to and
Shouldn't use those CLI tools for secure messaging which should have properties like forward secrecy and properly designed session verification. Matrix E2EE is quite good for message data but metadata isn't encrypted and it's federated not P2P with most using enormous servers.
1
Show replies