Skip to content

The strategy of `Harvest now, decrypt later' seems like a HUGE problem for matrix's privacy and encryption.Β #1868

@Kreyren

Description

@Kreyren

Disclaimer: I am making this as #975 doesn't seem to addressed with the needed urgency to verify whether is this actually a problem as assumed and if so to be actionable on the approach and urgency to manage this as e.g. crypto is not the full solution as e.g. routing might also need to be reconsidered.

It seems to me that Harvest now, decrypt later (https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later) a strategy where a threat actor collects and stores encrypted data to be decrypted in the future once a method that can decrypt these messages at a reasonable time and efficiency is discovered (e.g. Quantum Computers) poses a HUGE problem for all matrix users and their privacy as any threat actor can just spin up a home server (or home servers as the way matrix relays the messages seems to make it very efficient to do so) and start collecting these encrypted events (encrypted messages, images, etc..) to be able to decrypt them in the future, but please correct me if i am wrong as where i stand now it seems sane to consider matrix as compromised and consider this a Shit Hit The Fan issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions