security
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| security [2026/03/26 06:10] – admin | security [2026/03/30 02:34] (current) – admin | ||
|---|---|---|---|
| Line 13: | Line 13: | ||
| * Matrix | * Matrix | ||
| - | | + | * Configuration Steps: |
| - | * Homeserver owners can join encrypted chats and impersonate users by adding their own device key to the target users account. | + | |
| - | * A stolen domain for homeserver can gain rights as any user that has joined the room from the homeserver, This is due to Matrix stores permissions as user@homeserverDomain.com for rooms. | + | * Enable End To End Encryption (E2EE) for sensitive rooms. |
| - | * Fluffychat client is recommended, | + | * Security And Privacy Notes: |
| + | * While messages are encrypted in E2EE rooms, privacy leaks are possible. Metadata is not encrypted and currently not supported by the protocol, although it' being worked on.This includes usernames of who are in encrypted chat rooms, who created the room, and the title of the room. | ||
| + | | ||
| + | * A stolen domain for homeserver can gain rights as any user that has joined the room from the homeserver, This is due to Matrix stores permissions as user@homeserverDomain.com for rooms. | ||
| + | * Fluffychat client is recommended, | ||
| + | * Users joining E2EE encrypted rooms can not see past messages. This is being worked on currently (https:// | ||
security.1774505420.txt.gz · Last modified: 2026/03/26 06:10 by admin
