Matrix Metadata Problem: the server sees everything except your messages

People pick Matrix because of end-to-end encryption. But E2EE only protects message content — everything around it is plaintext.

The server sees:

  • Your ID, IP, client type and version, device you use
  • Your presence, typing status, read receipts
  • Which rooms you join and when you join/leave
  • Who else is in those rooms → your entire social graph
  • Room names, topics, avatars (all plaintext state)
  • For every message: who sent it, which room, a millisecond timestamp, type, size

And federation copies all of that to every other server whose users are in the room. Your “social footprint” isn’t one copy — it’s as many as there are servers.

  • illusionist@lemmy.zip
    link
    fedilink
    arrow-up
    1
    ·
    13 hours ago

    It depends on your threat profile. I’m fine with that data being public on matrix - which I use for communities.

    The less data is known, the better

    • verifytheposter@leminal.spaceOP
      link
      fedilink
      arrow-up
      1
      ·
      3 hours ago

      These aren’t mutually exclusive trade-offs: Matrix could support communities while minimizing or encrypting metadata by default. There should be a protocol that doesn’t require device details and profile data to be exposed just to participate.