• gianni
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      3 months ago

      How is it a lot harder to track if the FBI can just subpoena the sysadmin for server/room logs?

      With respect, this viewpoint is not defensible from an operational security perspective.

      It’s like saying they should use GMail because they have hundreds of millions of users. When the problem isn’t being a needle in haystack, but rather the fact that Google will gladly look through your private data and happily hand it over to the authorities.

        • gianni
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          What would stop them from subpoenaing all information from your personal server?

          If you’re a drug dealer and the FBI sends you a subpoena—you could simply….not respond.

          There’s no personal information tied to your account.

          There is actually a bunch of metadata tied to your account and your room. That’s partly how they caught that kid with the Pentagon leaks.

          And again, there may be other services between the clients and the matrix server that collect personal data (e.g. reverse proxies, load balancers).

          If you are someone who ostensibly cares about privacy and security (like a drug dealer) why would you rely on the benevolence and security hygiene of a stranger you can’t audit? Instead of using a known good actor, like Signal or SimpleX, or no actor, like Briar.