frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Matrix messaging gaining ground in government IT

https://www.theregister.com/2026/02/09/matrix_element_secure_chat/
68•rbanffy•1h ago

Comments

bsaul•1h ago
I wonder why matrix isn't more widerspread at this point. It's open, it's e2ee, it works, it has client lib for integration with any tool..

What makes it not more popular ? Is it the federated approach ? The client applications that don't look really fancy ?

bratwurst3000•1h ago
mostly the federate aproach. Most people dont want to think about anything network related.

Element is ok as an app imho

coolius•1h ago
For me the issue that prevented me from really using matrix is that none of the big clients support multiple servers. As a non enterprise user, this has prevented me from seriously adopting it several times.
Arathorn•1h ago
Element X finally has this on Android (in Labs) now. Web & iOS will follow.
tionis•1h ago
Fluffychat does and I would argue is one of the big ones. Its however quite mobile optimized (basically more like WhatsApp, less like slack).
nkmnz•1h ago
Search is essentially broken and completely useless. If I’m mistaken, maybe someone might chime in and explain how I can make it work. But right now, the only way to search for messages is to export them and search in the text file.
j1elo•58m ago
If that's true, it sounds terrible, and a reason enough to not consider it at all. So much of the work in bug organizations is about just searching for past conversations when a similar issue had been discussed... Search must be flawless.
olafmol•51m ago
It’s open source right? You know what to do ;)
rolymath•43m ago
This is the fastest way to get people to say "I hate proprietary solutions but at least they work"
throwaway150•25m ago
Then you should use proprietary solutions. Open source solutions are written by developers for themselves. They are not writing it for you. They have no reason to write them for you. You are not paying them. It is a labor of love they are doing for themselves.

Yet as a bonus they are offering it to you for free as a gift with the hope that if it doesn't work for you, you can improve it or hire someone you can.

If you only care about consuming open source but not contributing, by all means you should buy proprietary solutions.

karel-3d•27m ago
Get into an online argument with the developers about what is the right approach and which dependency is to blame?
throwaway150•17m ago
There is no need to get into an online argument with the developers. The open source software is still offered to you as a gift. You can modify it however you need and keep it for yourself.

The developers developed the open source software for themselves. Doesn't work for you? Too bad. But they are not going to develop it for you. Definitely not, when you are not paying them.

If it doesn't work for you, you shouldn't think, "Oh, I need to get into an online argument with the developers." Here's what you do.

1. Develop the fix/feature you need for yourself. If you cannot do it yourself, hire someone you can.

2. Send a pull request to the developers. They have no obligation to merge it. Remember they developed their stuff for themselves. You developed your stuff for yourself. If they merge, great. If they don't merge, you've still got your stuff for yourself.

3. If they don't merge your stuff, you could maintain a fork. Yes, it's a pain to keep your fork updated but you need to do your own work. Nobody else will do your work for you.

If all this is too difficult for you, why even consider open source? Just use proprietary software.

I truly don't understand the self-entitled HN comments that think for some strange reason that someone else should give you a software for free and then do all the work for you.

andylynch•1h ago
I think it’s a few things

- lots of places kind of Teams by default - or Slack or discord m, even WhatsApp - or in intensive cases, things like Refinitiv, Bloomberg, and, Symphony , which is kind of federated, but adds all the automation and also governance stuff needed for 100MM trades via IM and the like.

blitzar•57m ago
> governance stuff needed for 100MM trades via IM

We have come a long way from Yahoo messenger days.

https://www.reuters.com/article/technology/oil-traders-prepa...

tapoxi•59m ago
Enterprises get Teams for free with O365, or use Slack if they really care about the experience.

Most individuals don't care and use iMessage/WhatsApp. Those that do use Signal since it's dramatically easier.

rolymath•45m ago
Teams has not been free with O365 for years now.
galbar•55m ago
I am a daily user, family and friends chatting on Matrix.

My take is that there are two layers of friction:

a) people that care about chat encryption and would be willing to change, already did, to Telegram and/or Signal. "I'm not going to install yet another chat app" is a real answer by a friend of mine

b) no one wants to either host their own server, nor pay someone to host it for them. If it wasn't for me and a one of my friends, none of the people I chat with daily would be on Matrix.

And yes, there is the matrix.org server. Out of the ~13 people I chat frequently with, 1 is on matrix.org. "What's the point of changing apps if I'm still going to be using the centralized server" is another answer I've gotten.

I don't know what the solution to this dynamic is other than us, the power users, setting it up and paying for the group of people around us.

INTPenis•36m ago
What about maintaining encryption for an entire room of clients? I heard it's very difficult and prone to errors. Do you enforce it?
Arnt•3m ago
I use matrix. Every chat room I use is unencrypted and all have at least one matrix.org user. I assume it can be encrypted but the usability is such that in practice it's cleartext.
Valodim•33m ago
> a) people that care about chat encryption and would be willing to change, already did, to Telegram and/or Signal.

It continues to baffle me that the "telegram is encrypted" spin is still widely believed, even on a forum like this. Telegram is for 99.9% of intents and purposes not encrypted.

Anonyneko•27m ago
And even when you do enable encryption of the chat contents, the unencrypted metadata is often enough for security services to make a suspect out of you. Granted, this is mostly a concern for Russian and Belarusian users.
BLKNSLVR•54m ago
I ran a server for a while a couple (maybe a couple of couples) of years ago, and client devices periodically disconnected and had to be re-setup / re-authenticated from scratch, losing the chat history and being a general hassle. It happened often enough that I got jack of it.

I like the idea, a lot, but the implementation at the time annoyed me away from it. I just don't have time / motivation at the moment to have another go. We ended up on Discord for family communication and it works well. I know Discord is on the lower end of 'one of the bad guys', but for the same reason I don't re-setup Matrix I don't move off Discord. At least it's not WhatsApp...

I did try to get them onto Signal, but I don't think Signal did group chat back then - which means it must have been before 2020.

megous•44m ago
Bloated server implementation with lack of alternatives and a complicated protocol.
jasonfrost•41m ago
I don't remember why but I had to download a separate notification app that pushed notis
munin•40m ago
Matrix is an unserious project and the client ecosystem is a train wreck. The server ecosystem is not much better. The Element people, who are kind of the default Matrix people because as far as I can tell are the only people getting paid, will tell you that this is because a bunch of IT integrator companies unjustly profit off of the open source work by selling services to European companies but contributing none back to either Element or other open source Matrix projects.

The first issue I'd like to address is that one: as a small business, I tried to purchase software from Element and was told that I was not large enough to justify their time. Fair enough, I only wanted a 200 seat license and I was willing to pay per seat, but I guess they really want the high value contracts if they have a limited sales team. However, it is a bit much to go from that experience to their justification about the structure of their project. Maybe they should think about taking some sales opportunities that present themselves?

Then there are branding and release decisions around the clients that Element makes. There are two projects in the client space from Element: a client called Element, and a client called Element X. Element X is the newer one. Element (do you see how this is getting confusing yet) is simultaneously at different times an Electron desktop app, a mobile app, and a web app. Element X is becoming all of those things but the feature parity is not even between them. Element supports "legacy" Jitsi for voice and video calling while Element X supports newer Element call - which is different from legacy Element, Element call is a webRTC implementation native to the Matrix ecosystem while the "legacy" Jitsi is a way to send clients a URL for Jitsi calls and have them shell out to another app to actually implement the call. Fair enough. However, the desktop Element X client does not yet support new Element call but the "old" Element client does support both "legacy" Jitsi and new Element call. And the Element X mobile app cannot call the old Element mobile app - but I think the other way around can. Even getting your head around this as an IT person is confusing.

To add insult to injury the new Element X app on mobile is in some ways a downgrade because they integrated the cloud vendor push notification services into the app, so even though you have "sovereign" and "self-hosted" infrastructure you're still, on a good day, leaking meta-data about your chats back through to the people you were trying to decouple yourself from anyway. You can run your own push notification services for this mostly if you want and all your mobile clients are Android but like, why.

Then, there's desktop client usability. During account setup, Element/Matrix makes a big ceremony out of establishing your cryptographic identity. Perfect. And as part of that you write down a 10-ish something word passphrase that is a recovery sequence for said identity. Perfect. Then some network hiccup happens that disturbs the Element client like some kind of prey animal and it spontaneously logs you out. You log back in, but there are no fields or options visible to use that recovery passphrase to restore your cryptographic identity. Your only option is to reset your identity, which makes all prior chats you have had unreadable. That part at least makes sense but why have this recovery story if it is not tested or usable in the app? This is probably an Element thing but in my research I have not found a client that people say is more robust, though at this point I'm open to trying.

It's also possible that the way most people use this is as a web app, which is to be fair more robust. It does seem worse from a security point of view to have one central web server dealing in most of your users plain text, though. At that point, why not use Mattermost? I guess they're even more hostile to their users/customers, for some reason.

Finally, there's the server ecosystem. The thing that is frustrating to me here is the interplay between Synapse, Matrix Authentication Service (MAS), and OIDC. This, as far as I can tell, is all intentionally hostile to drive you into Element's commercial product offering. Which I find especially galling because they won't sell your their commercial offering anyway, so you're going to have to figure it out for yourself. Synapse has some legacy support for OIDC which you are going to need to enable for backwards compatibility. However, for forwards compatibility with Element X, you are going to need MAS. Synapse is a large, mature Python project. MAS is a single Rust binary which is simultaneously a server and CLI to do user management. You'll need both configured against your OIDC provider. Why didn't the new OIDC features just get integrated into Synapse?

I think that a lot of this is an outcome of the fact that Element is very literally in a "the old world is dying and the new world struggles to be born" situation at this time. I do have a lot of sympathy for being in the position of having huge companies - especially companies as annoying as IT outsourcing and integration - make a line of business out of configuring and installing your open source software. However, I have to say, having spent some of my professional life now also configuring and installing this open source software, I understand why those IT outsourcing companies have a moat. If the open source software was easier to install and use, perhaps those companies would have less of a moat. It seems to me that at least some of the story from Element is that if they make the ecosystem harder to use and understand, then people will take their money and the business will survive. However, in my experience, they won't take your money anyway.

TavsiE9s•29m ago
Thank you, I was about to post a response similar to yours sans the "trying to buy licenses" part.
nickslaughter02•34m ago
The UK is the number one enemy of security and encryption. Did you read and compile all of the libraries and clients yourself?
LeelaAI•32m ago
I enjoy self hosting stuff with Docker. Matrix/synapse is one of the more difficult / PitA projects I’ve ever gotten up and running.
snorremd•26m ago
When me and a bunch of friends and acquaintances switched away from Slack a little under a year ago (I think) we looked into Matrix. One of the primary requirements was that even our non-technical friends should be able to use it.

At the time Matrix/Element had recently launched their Matrix 2.0 efforts and I tried setting up the whole stack without resorting to their all in one shell-script meant for non-production use. I did not mind hosting four different servers (Synapse, Matrix Auth Service (MAS), Call, etc), but did find the integration and config job a bit tedious. The main blocker though was the lack of an invite-system in the new Matrix Auth Server. Also the fact that the Element X app uses a new Livekit based call server while other clients/apps use a different approach is also something not great.

We ended up going for Mattermost. One service easily hosted with Docker. One app, and easy invites. While I think federation would be cool, right now Mattermost was a bit simpler to get up and running.

Element seems more focused on enterprise and government contracts than self-hosters. I think this is fine, they need to pay their bills. But Matrix 2.0 for self-hosters might need a better story right now.

netdevphoenix•24m ago
Consensus. People like to follow what the majority does even if it's suboptimal.
Anonyneko•19m ago
Compared to Telegram, it feels like using a laggy MSN Messenger. The experience, both client and server-wise, just feels very unpolished. It's no single big thing, it's more like death by a thousand cuts.

I was bullish on Matrix because it's so extensible, but in the end I realized that only the default client experience matters as that's the one everyone will be using. And it just isn't there yet. In the end, all the group chats I was in migrated to Discord or Telegram, so I had no more reason to use it...

guerrilla•17m ago
The UIs are terrible. I've tried it a few different times with friends and we gave up each time.
dotdi•1h ago
I was on a team that evaluated moving a significant portion of a product that should be used for government/healthcare onto Matrix. There were several drawbacks that made us NOT go this route:

- Olm/Megolm does not offer forward secrecy for group messaging

- Olm/Megolm does ensure end-to-end encryption for message data, but not for metadata.

- Federation makes it challenging to be GDPR compliant

- Synapse is very heavy, other implementations are less production ready

- For better or worse, the matrix foundation is under UK jurisdiction.

I'm sure I forget some of the nuance, but these were some of the major points. However, there are several government entities in Germany, France, Poland, etc, that can live with the limitations and DO self-host Matrix servers.

I won't go into the pair of high-severity vulns in 2025 (and the somewhat difficult mitigation) because that could hit anyone.

Buxato•1h ago
Thanks for the info, what do you think about Delta chat?
dotdi•43m ago
The cryptography is sound, however, it's also frequently changing, in addition to straying from standards more or less. This makes it difficult to give a firm answer.

This ETH (i.e. Zurich) paper[0] identified several exploitable vulnerabilities (bad), which were quickly addressed by delta chat (good).

So overall, I'd see it as a good messenger, but with downsides.

[0]: https://www.usenix.org/system/files/usenixsecurity24-song-yu...

Arathorn•56m ago
> Olm/Megolm does not offer forward secrecy for group messaging

Megolm does provide forward secrecy - just in blocks of messages. If a message key gets stolen, an attacker could decrypt subsequent messages from that sending device until the next session begins: by default this happens either after 100 msgs have been sent, a week has elapsed, or if the room membership changes. Most folks consider this to be adequate perfect secrecy.

In terms of the Matrix Fdn being incorporated in the UK… I guess that means one shouldn’t use the Internet, given IETF is US incorporated? :)

dotdi•47m ago
> In terms of the Matrix Fdn being incorporated in the UK… I guess that means one shouldn’t use the Internet, given IETF is US incorporated? :)

The outputs of the IETF are RFCs. The Matrix foundation does more directly oversee the "de-facto" Matrix, so has more influence, could bow to government pressure or changing laws, etc. etc.

danjones-crypto•17m ago
Re. security of old keys/sessions/messages after compromise of some current state (i.e. notions like forward security):

Do Matrix clients still keep the oldest version of the Megolm ratchet they have ever received? When I last looked (around 2024), the libraries maintained by the Matrix.org core team did.

This means that, while Megolm has a ratchet that can be used to provide forward security, no Matrix implementation that I am aware of does this. This seems to me to be because other features of the Matrix specification rely on continued access to these old keys (like Megolm key backups and history sharing).

Re. security of new keys/sessions/messages after compromise of some current state (i.e. notions like post-compromise security, future secrecy):

My understanding is that, while a _sender_ will rotate Megolm sessions every 100 or so messages, recipients tend not to: clients will accept ciphertexts sent from those old sessions for an indefinite period of time. Again, I haven't been following developments in the Matrix world for a little while, so please correct me if I'm wrong.

This seems (to me) to be for similar reasons to the above: recipients keep around the recipient sessions so they can be backed up and shared with new devices (for history sharing). But (!) Matrix could get way better authentication guarantees if they just _disabled accepting messages_ from these old sessions at the same schedule as the sender stops using them.

--

These are not a unreasonable compromises (there aren't too many attempts to square this circle, and most that I'm aware of are quite academic) but it's worth making clear that just because Olm/Megolm/the Matrix spec have particular features, it doesn't mean they are used properly to give the security guarantees we would naively expect from their composition. At least, this is the case for almost all Matrix clients that I'm aware of.

user32489318•41m ago
Which tool did you guys end up using?
Buxato•1h ago
I deleted my matrix account after I receive some very nasty spam in form of Element Android notification. I think it wasn't Matrix direct fault, but as I used some Matrix chat groups and the list of member was public .. But I got really alarmed and angry when I receive so disgusting spam.
ticulatedspline•5m ago
Never heard of Matrix before (as a protocol) what's it's advantage over XMPP?

Rethinking the Linux Desktop: Base OS and AppImages

https://world.hey.com/fredrik.sundqvist/rethinking-the-linux-desktop-base-os-and-appimages-53f4f1b8
1•madspindel•10s ago•0 comments

OSS Claude for Excel

https://github.com/hewliyang/open-excel
1•hewliyang•28s ago•0 comments

Show HN: Self-healing data pipeline for F1 telemetry (Python and Type Inference)

1•tarekclarke•52s ago•0 comments

Three Cache Layers Between Select and Disk

https://frn.sh/iops/
1•dlt•1m ago•0 comments

Clawrun – One-click deployment for OpenClaw

https://clawrun.dev/
1•augustopinheir•1m ago•1 comments

Show HN: Pentests cost $10K, I built an open-source one for $0.12

https://github.com/FrancescoStabile/numasec
1•francesco_sta•2m ago•0 comments

SpaceX shifts focus to building a self-growing city on the Moon

https://twitter.com/elonmusk/status/2020640004628742577
1•simonebrunozzi•3m ago•0 comments

Sound and Practical Points-To Analysis for Incomplete C Programs [pdf]

https://www.sjalander.com/research/pdf/sjalander-cgo2026-pip.pdf
1•st_•3m ago•0 comments

Chaquopy: The Python SDK for Android

https://github.com/chaquo/chaquopy
1•gitprolinux•4m ago•0 comments

The Homunculus

https://explodi.tubatuba.net/2026/02/09/the-homunculus
1•phaser•6m ago•0 comments

Ask HN: Help me find an old Atari 800/800XL program – "Tortoise and the Hare"

1•itay-maman•6m ago•0 comments

Agentic coding improves ARC AGI 2 performance across models

https://pivotools.github.io/pivotools-quarto-blog/posts/agentic_coding_arc_agi/
1•steinsgate•7m ago•1 comments

What They Copied

https://www.prndlcars.com/p/what-they-copied-ferrari-luce-jony-ive
1•ilamont•7m ago•0 comments

Invisible Bunnies and World of Warcraft

https://warcraft.wiki.gg/wiki/Invisible_bunny
1•speckx•8m ago•0 comments

Disappointing Phones

https://cadence.moe/blog/2026-02-08-disappointing-phones
1•mewmewblobcat•10m ago•0 comments

Brussels Admits: Substantial EU Funds Have Gone to Spyware Manufacturers (2025)

https://www.heise.de/en/news/Brussels-Admits-Substantial-EU-Funds-Have-Gone-to-Spyware-Manufactur...
2•nickslaughter02•10m ago•0 comments

Yo Shell

https://github.com/pizlonator/yosh
1•handfuloflight•11m ago•0 comments

Open source real-time screen analysis tool powered by Screenpipe and local LLM

https://github.com/cyrus-cai/livepipe
1•kii9999•12m ago•0 comments

Memory Devices (Bell System Film, 1959) [video]

https://www.youtube.com/watch?v=Px9ZfLyeAWU
1•fortran77•13m ago•0 comments

Ultrasync

https://github.com/darvid/ultrasync
1•handfuloflight•14m ago•0 comments

A raycasting engine in 7 easy steps

https://austinhenley.com/blog/raycasting.html
1•ibobev•21m ago•0 comments

Constraint Propagation for Fun

https://eli.li/constraint-propagation-for-fun
1•ibobev•21m ago•0 comments

Python Syntax compiles to Java source code – meet Java++

https://github.com/CrimsonDemon567PC/JavaPP
1•CrimsonDemon567•21m ago•0 comments

Jony Ive Designed Ferrari Luce EV Interior

https://www.topgear.com/car-news/electric/official-ferraris-first-ev-called-luce-interior-apples-...
3•elxr•21m ago•4 comments

OCapN and Structural Authority in Agentic AI

https://serefayar.substack.com/p/ocapn-and-structural-authority-in-agentic-ai
2•serefayar•22m ago•0 comments

Added OTEL Observability to OpenClaw agents full GenAI spec support

https://github.com/openclaw/openclaw/pull/11100
3•draismaa•24m ago•2 comments

Learn Weird Programming Languages

https://okienko.day/posts/2026-02-06-weird-languages.html
2•hubertmalkowski•25m ago•0 comments

Japan LLC has been trading its way out of a fiscal hole

https://www.ft.com/content/f7d3f20c-b303-4f6c-b4a0-8ee8906ae155
2•throwaway2037•25m ago•1 comments

Vending-Bench 2

https://andonlabs.com/evals/vending-bench-2
2•samdung•26m ago•0 comments

Danish Red Street Lighting Solves a Problem Every City Has

https://www.newsweek.com/denmark-red-street-lighting-gladsaxe-11488484
2•sohkamyung•26m ago•0 comments