frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Matrix Is Not Safe for EU Data Privacy?

https://wire.com/en/blog/matrix-not-safe-eu-data-privacy
45•mikece•20h ago

Comments

kelnos•19h ago
I can't really evaluate some of their claims, but note that this is published by a company (written by a "Tech Marketer" who works there) that has a vested interest in making its product look better than the competition. The overly-alarmist language they use makes me extra skeptical.
rdm_blackhole•19h ago
Matrix may not be safe but is Wire going to be safe from Chat Control? Most likely no. So I don't see how trading one surveillance state for another will help.
jjcob•19h ago
When you're a EU company or a EU government it makes a difference if your supplier is subject to EU surveillance laws or UK surveillance laws.

As far as I can tell it comes down to:

- are you afraid of foreign espionage

vs.

- are you afraid of your own government

rdm_blackhole•19h ago
Let's put it this way, if the Russians get my ID and a picture of my face and know my kinks and my religious preferences what is the worst that can happen?

Now, if my government knows everything there is about me and one day decides to crack down on dissidents or hand them out to another foreign power as it was done in WW2 with the Jews in the Netherlands? Well, that is on another level.

We have be down this road before. It never ends well.

Maybe it's been too long and people forget. My grandparents lived through WW2, from what they told me, the capacity for humans to inflict pain and suffering on other humans knows no bounds.

shakna•18h ago
Wire is located in Switzerland. Outside the EU.
wkat4242•18h ago
Technically yes but Switzerland does subscribe to most EU legislation in order to join the internal market. They're a lot more "EU" than the UK is now.
shakna•18h ago
... You're suggesting Switzerland is subject to EU surveillance laws? Instead of the ones they put in planning in January?
wkat4242•15h ago
They generally agree to pretty much everything yes because they're afraid of losing internal market access. It just takes a while longer because they have to approve each new thing individually.

I do use Switzerland as an exit for my vpn though yes.

mvieira38•18h ago
This cope is officially dead now, not even Proton is believing Switzerland anymore. The pressure has gotten enough that they had to freeze all Swiss investment and start the process of moving key infrastructure to another country (I don't remember which, but it's the one Mullvad is at).

Truth is, Euros don't care about privacy. The endgame will probably be to host this stuff in the third world or something, like pirates do

shakna•18h ago
It's not "cope".

Switzerland created a new set of surveillance laws in January, that far exceed anything inside the EU. Which means that EU laws are irrelevant, when talking about a company inside Switzerland - you should be talking about what they actually use!

scarface_74•18h ago
Once there is any backdoor, it’s always both.
jeltz•19h ago
I don't see how Wire is any safer if they operate in Germany. The EU is perfectly able to go against Wire then.
rdm_blackhole•19h ago
They are not any safer. If/when Chat Control passes, they will bend the knee. That is all there is to it.
ThePowerOfFuet•19h ago
Written by Wire, a competitor.
lambdadelirium•19h ago
Wire audited themselves and found nothing wrong in themselves
Catbert59•19h ago
The only safe communication is decentralized communication, capable of multiplexing multiple techniques (IP, BLE, LoRa, etc.) under the hood of cryptographically safe routing and messaging algorithms that work over unreliable links.

Maybe even with small-range offline radio mailboxes so you can deliver and gather messages from/to highly suppressed people which then can be send back into the "online" network automatically without further interaction.

dabber21•19h ago
or true E2E encryption
Catbert59•19h ago
DPI firewalled states like China show that they are extremely effective in adapting to new protocols.

Having a second diverse link that is cheap to setup would be an alternative.

AshamedCaptain•18h ago
One thing that is true about the article is that E2EE encryption is nowhere near enough. Metadata leaks of any kind are probably worse than leaking data itself.

I very much prefer to guarantee that data doesn't leave my trusted servers in the first place, rather than to encrypt it.

Barrin92•17h ago
>I very much prefer to guarantee that data doesn't leave my trusted servers in the first place, rather than to encrypt it.

what's the rationale behind this? The point of a server is to ... serve things. If you're not gonna exchange data you might as well put a hard drive in a closet.

The point of encryption, to securely send information across adversarial channels, has made it possible that I can take my most secret information and send it across my worst enemies network and I don't need to care. Who on earth wants to go back to a world where I have to hide plain text documents in the sock drawer?

clueless•19h ago
does such an open source project exist?
Catbert59•18h ago
A lot of people metion "Reticulum" in this regard. But that's a one-man-show project.

The only project that got some serious momentum is Meshtastic. That's decentralized LoRa with flooding/next-hop-routing that can be backed with MQTT.

I think a huge step forward would be a decentralized BLE LE (a super robust Bluetooth Low Energy mode) Mesh based application as it can be used on smartphones.

anonzzzies•18h ago
That's it. Also prevents from chat control being effective. Who is working in that space? I see this as an answer to many privacy/gov overreach issues.
The_President•18h ago
Quantum communication channels are going to be cool, but then we'll have quantum bugs (covert listening.)
EGreg•18h ago
Well, I’ve been in the decentralization space (and mocked for it by some on HN) for a decade at least.

When Moxie wrote a thoughtful critique of decentralization, I wrote an article addressing his criticisms and spoke about why decentralization matters: https://community.intercoin.app/t/web3-moxie-signal-telegram...

There are many great decentralized alternatives. I know the founders for most of them, and interviewed some, like the founder of the original (and current) Freenet, probably the earliest private content sharing network ever launched: https://www.youtube.com/watch?v=JWrRqUkJpMQ

Here are some more of my interviews regarding freedom of speech, including with regulators, sociopolitical thinkers like Noam Chomsky, Milton Friedman’s grandson, etc: https://news.ycombinator.com/item?id=34179795

Here is a map of the global war on end-to-end encryption, with updates on how we have been losing this war: https://community.qbix.com/t/the-global-war-on-end-to-end-en...

In my opinion, the most secure network is Autonomi.com, which was previously Maidsafe. It is FULLY decentralized and encrypted, and those guys have been at it far longer than Matrix. I have been on their forums and they have been on ours for years, debating various architectural and economic tradeoffs.

The_President•18h ago
Unfortunately we have had to remove Matrix-Element from production after user frustration and concerns with quality. While the concept is excellent, the implementation of Element is janky and caused so much friction that users would not depend on it. Concerns about other potential issues become more common within the technical team when the frontend has become substandard in a professional environment.
_zoltan_•18h ago
+1 the user experience is junk
udev4096•18h ago
What does this even mean? Matrix can be hosted by anyone and anywhere with full control, unlike wire which is a centralized chat app owned by AWS
Arathorn•18h ago
This article is fundamentally false - we addressed it on https://element.io/blog/addressing-fear-uncertainty-and-doub...

dang: is HN really the place for competitive marketing crap like this?

udev4096•18h ago
I can't believe how it reached the top. Either bots or intentional upvotes from competitors. Wire sucks anyway. Matrix ftw!
throwaway02243•18h ago
> Finally, anyone paying attention knows that the UK government’s Investigatory Powers Act (IPA) impacts all vendors globally which service individuals in the UK. Something that’s obvious given the high profile TCN that the UK served Apple: the fact that Element and the Matrix.org Foundation are UK-based is irrelevant.

Is it irrelevant? A vendor that isn't based in the UK could just rightfully tell the UK government to fuck off—which isn't likely to be an option for the UK-based Matrix and Element.

atoav•18h ago
Ok let's say you're a UK vendor and you developed and published an adding algorithm for 2+2 that returns the correct result: 4

How does that publicised adding algorithm get corrupted, if the UK government decides they want that 2+2=5?

The answer is that matrix being based in the UK isn't ideal, but since they published the whole protocol, it can't just be made unsafe on request without people noticing. If the math maths it still maths when the government doesn't want it to math.

What could happen is that the UK could force specific servers of the UK based entity to surveil targets etc. But you don't have to use their servers (in fact, their goal is probably that you run your own).

As someone who would be in the position to decide for or against matrix/wire usage in my org, I have to say this kind of pratise didn't particularily strengthen my trust in wire.

hyghjiyhu•17h ago
> it can't just be made unsafe on request without people noticing

A likely outcome is that they make it unsafe and people do notice.

atoav•17h ago
Yes but even then: If they make 2+2 wrong and people notice, people can just continue to use the correct version.

I don't know the matrix org but if I were them I had a plan in a drawer for when that happens and where to move.

armchairhacker•17h ago
It's a protocol, people can use the old version (or patch whatever makes it unsafe).
gagik_co•16h ago
Any open source project can be made unsafe intentionally or unintentionally, with or without people noticing, is there anything unique to this risk with Matrix?
gagik_co•15h ago
Right now it's prime time for a bunch of "European" tech (which still very much depend on a ton of non-EU infrastructure and code) to start shilling for their "EU alternatives". It's like the new local buzzword after AI.

I started self-hosting and adopting Matrix for my app recently and most of these raised concerns seem manipulative at best. Thanks for all the work with the project!

forty•18h ago
Weird argument: "they are in the UK, which is not in the EU, bouh! Look at us, we are in Switzerland, which is... also not in the EU..."
contravariant•18h ago
Not being subject to the UK and US surveillance laws seems as good an argument as any.

Though I'm not sure if the GDPR allows for data to be stationed in Switzerland. It's not EU but it is party to a lot of treaties so it's not out of the question.

Ironically it might become a safer place to station data if the EU manages to push through more surveillance decrees.

cccbbbaaa•17h ago
> Though I'm not sure if the GDPR allows for data to be stationed in Switzerland.

There is a treaty between the EU and Switzerland for this. Full list of countries here: https://commission.europa.eu/law/law-topic/data-protection/i...

forty•17h ago
If the EU was starting to go rogue like US is, it could easily bully Switzerland to force their hand into giving whatever data they want to, given that Switzerland have no frontier with sea or non EU country (not that I can imagine this scenario happening, but Switzerland is a weird choice to hide from EU)
jeroenhd•17h ago
The US and Germany used a Swiss company to sabotage encryption for years: https://www.bbc.com/news/world-europe-51467536

Being inside of the EU also won't ensure your privacy: https://argos.vpro.nl/artikelen/former-philips-top-cryptogra...

And let's not forget that the Swiss are just as willing to implement privacy infringing laws as any other country these days: https://tuta.com/blog/switzerland-surveillance-plan

Don't trust a company just because it's situated somewhere. When governments friendly to yours want to spy on you, they don't necessarily let borders stop them.

lcnPylGDnU4H9OF•12h ago
> The US and Germany used a Swiss company to sabotage encryption for years

CryptoAG and the CIA's decision to release the history document of that operation is such an interesting story. In particular, it had this effect of getting people to distrust Swiss companies, for better or for worse. It makes it sound plausible, if however unlikely, that a company such as Proton is actually a front for US cyber warfare. (I don't think it is but it might be; it seems like that may have been the point.)

AshamedCaptain•18h ago
Even if I dislike Matrix for various reasons, it is absolutely ridiculous to point to a completely centralized AND closed system as an alternative. Terrible article.
hopelite•18h ago
There is of course also the fact that the EU is not a sovereign state, legitimate government, or any kind of legitimate government at all, not to mention that is it an abrogation and disassembly of democratic principles of self-determination, and inherently foreign and even hostile to all its members, the most dominant of which jockeying over control of all of Europe through the EU.
throw123xz•18h ago
I don't know if Matrix is "safe" or not, but I usually avoid companies that attack companies like this. Not a good look in my view.
patrakov•18h ago
I am a Wire user. I am not happy that, if their server goes down, all the text and images that I shared with other users will become unavailable to me. As a special case, I am not able to look at my own old messages while using my laptop on the airplane, as the Linux client is just a webview. On the phone, it works.

Backups half-way solve the issue with text messages - I would still need to contact someone with sufficient development skills to decrypt the backup and extract the text in a readable form, but the information is there.

But with images, there is no recovery. And they apparently already lost some of my photos (the placeholder for some of them never gets replaced with the actual photo when I scroll up to year 2023).

Add to that the incompatible backup formats between the desktop and mobile apps.

So this is definitely not the claimed data sovereignty.

devmor•18h ago
I don't know that running a smear campaign against an open protocol to hock your paid alternative makes me trust you with my data, personally.
akimbostrawman•18h ago
wire is centralized unlike matrix so any "they have to follow the law of the country they are based/hosted in" critique is a self own.

wire continues to be a clown show.

johnisgood•17h ago
Wire used to be relatively fine, but there are better alternatives, and Matrix is one of them, as it is not centralized, despite the most commonly used, namely Element, being "chunky" or whatever. In any case, this is written by Wire, a competitor, so take it with a pinch of salt.
TomasEkeli•16h ago
In my opinion this is a poor, vendor-originated commentary attempting to spread FUD and drive people to a product. Not worth reading, and I wish I didn't.

New CRISPR Tool Makes Mosquitoes Highly Resistant to Malaria Parasite (2018)

https://publichealth.jhu.edu/2018/gene-knockout-using-new-crispr-tool-makes-mosquitoes-highly-resistant-to-malaria-parasite
2•thunderbong•3m ago•0 comments

Russia's China Ties Spur Boom in Learning Mandarin

https://www.bloomberg.com/news/articles/2025-08-01/russia-s-china-ties-spur-boom-in-learning-mandarin
1•mbeavitt•5m ago•1 comments

Tesla's Sweden Sales Plunge 85.8% in July, Year to Date Decline Hits 63%

https://eletric-vehicles.com/tesla/teslas-sweden-sales-plunge-85-8-in-july-year-to-date-decline-hits-63/
3•nabla9•9m ago•0 comments

Everything You Wanted to Know About PCIe but Were Too Proud to Ask [video]

https://www.youtube.com/watch?v=td0zisK-ksQ
1•znpy•10m ago•0 comments

Show HN: Made a Tinder but for drone names (18+ mode included)

https://www.dronder.net/?lang=en&ref=hn
1•m_khranovskyi•12m ago•0 comments

Balaji Srinivasan: The Collapse of the West – Why AI, Bitcoin and China Will Win [video]

https://www.youtube.com/watch?v=VSVOQl-vFKk
1•simonebrunozzi•13m ago•0 comments

Dehorning rhinos reduces poaching by 80%, study finds

https://www.theguardian.com/environment/2025/jun/05/dehorning-rhinos-deters-poachers-rangers-helicopters-aoe
3•YeGoblynQueenne•13m ago•0 comments

New AI detects deepfakes by analyzing motion, not just faces

https://scitechdaily.com/fake-videos-just-got-scarier-luckily-this-ai-can-spot-them-all/
1•karlperera•14m ago•1 comments

Secuso – Our Farewell from Google Play

https://secuso.aifb.kit.edu/english/2809.php
1•shakna•15m ago•0 comments

Things Apple Maps Does Better Than Google Maps

https://www.wired.com/story/things-apple-maps-does-better-than-google-maps/
1•xrayarx•16m ago•0 comments

Show HN: AgentSmith-HUB – Real-time security data pipeline and detection engine

https://github.com/EBWi11/AgentSmith-HUB
1•E_Bwill•16m ago•0 comments

You might not need tmux

https://bower.sh/you-might-not-need-tmux
1•elashri•20m ago•0 comments

Make America Green Again – Moving Workloads to Clean US Energy Regions

https://carbonrunner.io/blog/make-america-green-again
1•drydenwilliams•21m ago•0 comments

Dog Walk: open-source game by Blender Studio

https://studio.blender.org/projects/dogwalk/
1•nicoloren•23m ago•0 comments

Google Sans Code

https://github.com/googlefonts/googlesans-code
1•hggh•25m ago•0 comments

Emulator Bugs: Game Boy Color HDMA

https://jsgroth.dev/blog/posts/emulator-bugs-gbc-hdma/
2•ibobev•25m ago•0 comments

ChatGPT Conversations Are Showing Up in Google Search – Dataconomy

https://dataconomy.com/2025/07/31/chatgpt-conversations-are-showing-up-in-google-search/
3•janandonly•26m ago•0 comments

Code with LLMs and a Plan

https://richstone.io/1-4-code-with-llms-and-a-plan/
2•unripe_syntax•28m ago•0 comments

Palantir gets $10B contract from U.S. Army

https://www.washingtonpost.com/technology/2025/07/31/palantir-army-contract-10bn/
5•aspenmayer•28m ago•1 comments

Consistent MySQL Structure.sql Diffs for Rails

https://lovro-bikic.github.io/consistent-mysql-structure-sql-diffs-rails/
1•amalinovic•29m ago•0 comments

If Odin Had Macros

https://www.gingerbill.org/article/2025/07/31/if-odin-had-macros/
2•Bogdanp•30m ago•0 comments

Did Google just removed all the HTTP://chatgpt.com/share indexed pages?

https://twitter.com/anand_himanshu/status/1951201600992620581
1•unknownhad•41m ago•1 comments

Computer Science Logo Style

https://people.eecs.berkeley.edu/~bh/v1-toc2.html
2•fanf2•42m ago•0 comments

A Tesla Robotaxi Had Its First Accident

https://insideevs.com/news/764905/tesla-robotaxi-first-crash-parked/
1•belter•51m ago•1 comments

In reversal, Defense Department will continue providing satellite weather data

https://www.npr.org/2025/07/31/nx-s1-5487238/navy-reverses-decision-weather-satellite-hurricanes
3•geox•51m ago•0 comments

Thunderbolt – Use your domain (not phone number) to chat, message and video call

https://www.spaceship.com/thunderbolt/
1•anyg•51m ago•0 comments

A Meta-Platform for AI to Design and Build Systems [video]

https://www.youtube.com/watch?v=DCO-011M8bM
1•DrMiaow•1h ago•1 comments

Resurrecting a MOTU 2408 with ADAT

http://women-and-dreams.blogspot.com/2025/08/resurrecting-motu-2408-with-adat.html
3•Bogdanp•1h ago•0 comments

Sparrow as a Drop-In Replacement of Ansible

https://github.com/melezhik/Sparrow6/blob/master/posts/CliAppDevelopement.md
2•melezhik•1h ago•2 comments

Git Smarter: 7 Essential Commands Every Dev Should Know

https://jsdev.space/git-time-saving-commands/
3•javatuts•1h ago•0 comments