Update Blog “2026-10-05-matrix-is-a-pain”

This commit is contained in:
2026-10-07 08:04:46 +00:00
parent 69bc62c695
commit 15d60daf6d

View File

@@ -59,6 +59,24 @@ Important also to note that a generic cloudflare origin cert (like the default `
Matrix is a protocol, not a product. That means anyone can make a new way of interfacing with the protocol, ie a client, and use that to communicate with any other client. It's as simple as that. Matrix is a protocol, not a product. That means anyone can make a new way of interfacing with the protocol, ie a client, and use that to communicate with any other client. It's as simple as that.
Synapse is just the server, it provides the protocol endpoints needed to use matrix, but no actual user-facing interface. To actually message people, you need a client. Once again, the most popular is whatever matrix.org reccomends, and that happens to be element. Element is shit, imo. It looks bad, it's bloated, and the desktop version is just a glorified webapp. It also requires either hosting a really heavy service yourself, or relying on someone else's server to stay up. Both pointless options if you want to be decentralised. Synapse is just the server, it provides the protocol endpoints needed to use matrix, but no actual user-facing interface. To actually message people, you need a client. Once again, the most popular is whatever matrix.org recommends, and that happens to be element. Element is shit, imo. It looks bad, it's bloated, and the desktop version is just a glorified webapp. It also requires either hosting a really heavy service yourself, or relying on someone else's server to stay up. Both pointless options if you want to be decentralised.
The best clients are fully local, and the most minimal is iamb. Vim bindings, The best clients are fully local, and the most minimal is iamb. Vim bindings, fully tui, no mouse support whatsoever. It's what I choose to use in my config, so I have to glaze it. Then there are more esoteric options, like commet, which has a great mobile client, mirroring that of old school discord, but uses literally the same ui on desktop for some reason. It also does some funky shit when it comes to authentication and cross signing, and has very nearly deleted all my devices' authentication a few times. I should probably explain cross signing now, huh?
#### Cross signing is also a pain
I didn't know about cross signing when I first use matrix, because there was literally nothing saying you had to be careful about it. As I said, matrix supports end to end encryption (e2ee from here), which means that you need some way to encrypt the messages end to end. Take whatsapp as an example, your signing keys are held permanently on the mobile app, and when you link a device, that device gets access to your keys, so you can read your messages. These keys are also the reason that it's a pain in the ass to move whatsapp to a new device, no matter how many wizards they present you with, and also why you can't log into whatsapp on multiple phones at once. I'm safe in assuming that whatsapp rotates the keys regularly, on a local timer, and then presents whoever you're messaging with the public key, and, to prevent sending the pubkey with every message, gives the pubkey an expiry matching up with when the next key swap is. This is what's known in the DNS world as a TTL, or time to live. If another device logged in as the same user was using an old key, no messages sent from that device would be able to be decrypted by the recipient, and no sent messages would be able to be read either.
You can think of the primary logged in device as the "root device", acting as the source of truth for all other logged in devices. When you first log in, most clients will ask you to verify. You put in a passkey and out comes a shiny recovery key that you will almost certainly lose or forget about. If you've ever used a crypto wallet, it's the same concept. If you forget your password, you have an absolute way to get all your money back, just that instead of money it's messages. The difference here is that only the session that gave you the recovery key, or any sessions verified against it, will accept that recovery key. If you log out of your root session without verifying any other devices, all the encrypted messages sent from that client basically just vanish.
You verify all other devices through the root device, and if you log out of the root device, you can choose another root device by putting the recovery key into another device that was previously verified. Simple, right? This song and dance of root devices and ssl is how matrix manages to keep authenticity, unlike irc which was almost completely anonymous, while also not needing a user to hand over their email to some big company if they don't want to. Just don't log out of your root device, or at the very least, remember which device that even is. (I dont remember mine)
The only downside of this mutual verification nonsense is that the keys can't be rotated nearly as easily. Of course, modern SSL kind of removes the need for that, but if you wanted to rotate your keys, it would take far more effort than literally any other chat platform.
## Decentralised Moral of the story
Matrix is a pain in the ass, but if you aren't hosting it yourself, it's a great way to talk to other people that also don't like big evil companies.
I don't like big evil companies!! Text me at @admin:voidarc.co.uk
Also join the voidarc official matrix server at #space:voidarc.co.uk. You know how it works, you deserve it. If you join through this, tell me so that I know people actually read this blog lol. Byee