Matrix Metadata Problem: the server sees everything except your messages

People pick Matrix because of end-to-end encryption. But E2EE only protects message content — everything around it is plaintext.

The server sees:

  • Your ID, IP, client type and version, device you use
  • Your presence, typing status, read receipts
  • Which rooms you join and when you join/leave
  • Who else is in those rooms → your entire social graph
  • Room names, topics, avatars (all plaintext state)
  • For every message: who sent it, which room, a millisecond timestamp, type, size

And federation copies most of that to every other server whose users are in the room. Your "social footprint" isn't one copy — it's as many as there are servers.

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 1 day ago (1 child)

I'm replying to your statement. You proposed Signal as a point of comparison, so those are the apps to compare. They're both less than perfect if your only metric is anonymity, but their shortcomings are very different, and the shortcomings of Signal are fundamentally de-anonymising whereas Matrix is just metadata rich. But you can set your own client string, your username, your avatar, it's all information you inputted (either as a user or app developer). With Signal, the data that's shared is all controlled by Signal.

I'm not defending Matrix. If the design decisions of Matrix aren't what you want, then there's room to ask for or build an alternative. If Matrix or discourse around Matrix is misleading about what is shared then that's a good thing to highlight.

What I meant with my reply was to contrast it with Signal and communicate that Signal isn't a valid alternative. It's not the same class of service. Matrix exists to facilitate chatting with friends and Signal exists to conduct surveillance on you and your friends.

You don't have to choose between these two trade-offs. I'm not saying a third system can't be better. But any third system wasn't being evaluated in the thread I replied to.

  • source
  • parent
  • hideshow 1 child comment