Join Nostr
2026-02-18 15:10:51 UTC
in reply to

Wladimir Palant on Nostr: I haven’t seen any comments about the Matrix community, only about the project’s ...

I haven’t seen any comments about the Matrix community, only about the project’s vulnerability response. Even if it’s one user, it’s the user handling security reports. If they reject legitimate vulnerabilities as “not relevant in practice” – that is very concerning. If Matrix is supposed to be considered secure, they need working processes for handling vulnerability reports. If on the other hand they have a hobbyist approach to security then their product cannot be considered secure.

Note: It may in fact be “not relevant in practice” *yet*. Still, an important building block of the protocol is compromised. It needs to be fixed, preferably *before* somebody figures out how to make this issue relevant in practice. Because somebody inevitably will.