Does any data get sent to matrix hq or element?

  • Skull giver@popplesburger.hilciferous.nl
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    5 months ago

    Depends on the services you’re opting into. If you use integration services (sticker packs and such) hosted by the Matrix.org servers then the client will send some data to HQ. Same risk also exists with widgets such as traditional (video) calling which used Jitsi hosted elsewhere. There’s also the optional service that’ll link your phone and email to a Matrix account. All of that can be turned off, but most of it is enabled by default.

    Oh, and if you join any rooms on matrix.org or chat with any :matrix.org users, then that’ll make your server share data, of course.

    • ludicolo@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 months ago

      What do you mean by “traditional video calling”? Are video calls not encrypted? Is traditional meaning out of the box video calling? What is the alternative?

      • Skull giver@popplesburger.hilciferous.nl
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        5 months ago

        Modern Matrix has been moving towards a new video calling platform, but traditionally calls were done by just showing you a web page running Jitsi (by default https://app.element.io/jitsi.html?confId=something). I believe Jitsi gained the ability to encrypt calls, but you’d still be sending metadata (user agent, IP address, etc.) from your Element client to their servers.

        You can prevent this by running your own Jitsi server and configuring your Matrix server/clients to prefer that. matrix-docker-ansible-deploy does this for you, for instance, if you just set jitsi_enabled: true in the config file.

  • ReversalHatchery@beehaw.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    a few years ago there was a scandal about synapse having a lot of defaults that in one way or another resulted in matrix.org receiving a lot of data.

    I think it was cleaned up since then, but it’s always better to audit your configuration along with what are the defaults.

    • ludicolo@lemmy.mlOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      5 months ago

      I had seen a post from the official element account that said something along the lines of “we send encrypted data to the government. If you don’t like that, element isn’t for you.” Not word for word accurate but you get the gist. I didn’t know if that statement only applied to the official matrix.org server or self hosted instances as well.

          • ReversalHatchery@beehaw.org
            link
            fedilink
            English
            arrow-up
            0
            ·
            4 months ago

            I understand that message so that they are providing a messaging service for a fee to police forces. I don’t think they meant that they send encrypted data to them for money.

            • ludicolo@lemmy.mlOP
              link
              fedilink
              English
              arrow-up
              0
              ·
              edit-2
              4 months ago

              “Yes, we fund Matrix dev by selling encrypted messaging to governments, which includes police: if you don’t like that then please feel free to use a different app.”

              Idk that seems pretty clear to me that they are selling encrypted messages to governments and police. Not only that all the comments interpret it the same way.

              EDIT: The more I read it the more I become unsure. Hopefully they elaborate. To me I am confused at the service they are selling. Matrix is open source these organisations could dedicate their own employees to spin it up. Do they have somewhere you can purchase the same service? The phrasing is what gets me. It feels like they are referring to already sent messages and data. If they were referring to a service they provide, that should be clearly stated.

  • fmstrat@lemmy.nowsci.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    5 months ago

    Disclaimer: I am not a synapse dev, but I have run a non-federated server for a long time.

    Assuming you have fully disabled federation and Matrix.org provided services, data should not be leaving your instance. I run mine with bridges for services like Signal, IRC, and Discord, so as expected data goes out through the bridge software (via VPN).

    To be extra safe, you could run it in a Docker container who’s network is limited to local, and an nginx proxy for Element.

  • toastal@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    If you interact with any other server on the network (meaning users on another server), all messages/attachments/metadata will be synced with all other servers by design.

    Given the percentage of users on Matrix.org & servers they provide, some of your data will end up on Matrix HQ servers.