this post was submitted on 02 Oct 2026
1464 points (99.5% liked)
Programmer Humor
33451 readers
1590 users here now
Welcome to Programmer Humor!
This is a place where you can post jokes, memes, humor, etc. related to programming!
For sharing awful code theres also Programming Horror.
Rules
- Keep content in english
- No advertisements
- Posts must be related to programming or programmer topics
- If the mod doesn't find it funny, you're banned. Ha-ha!... For real: do not use the community for "statements". There are other places for such content. Keep it chill and funny.
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Most accurate description of Element I've ever heard to be honest. It's literally just Discord, with all of it's bloat, but with a protocol that wants to have "security" bolted on. And all of the security related dialogs have race conditions in them. Actually, not just in Element, all clients, even nheko and fluffychat, have race conditions in the fucking security dialogs. All of my devices are just unverified now, I just gave up.
XMPP at least functions reliably, if you ignore all of the protocol extensions and use it like IRC with images of course.

Tox supermacy! Though the main and only good Android client got archived. But like, whatever. Fuck phones anyway.
what security dialogs? and what race conditions? do you know what that means, or are you just throwing around words?
if you mean the "verify your new device" dialog, yeah, it has a problem. it won't appear most of the time on clients that were not open when you sent the verification request from the new device. I don't know why, and this is not comfortable, but then I can start verification from a device I already have, and it will work. or I can also just fill in the password from my password manager, which you surely have too.
but I haven't seen other problems with it recently.
which does not even have a bolted on security that way.
calling element classic good is a bit of a stretch. it was very slow.
That series of dialogs and pretty much everything else, including "verified devices" menu. Also, apart from race conditions it's often just desync. Like, right now for me, nheko and Element say everything is unverified but fluffychat says everything including itself is verified.
Not Element Classic, I meant aTox (Tox for Android). It still functions, though.
its not desynced, it is just not presented well. I think when it shows whether another device was verified, it actually does not show if you have completed verification of that device on your account, but instead whether that device is trusted by the current one (for purposes of sharing keys and whatever). in short, it's not "the user account trusts the device", but "this device trusts that device".
when you verify device A with device B, they will mutually trust each other. if device B already trusted devices C and D, device A will immediately start trusting them too.
if you then log in on device E and you don't verify it with any of the others, it will basically form a distinct "trust group".
in your case it seems there are also cases when device A says it trusts B, but B says it does not trust A. how long ago did you verify your nheko, element and fluffychat devices? it looks like their verification could not complete, maybe one of them had a bug at the time or crashed before properly saving its database.
both issues won't solve themselves automatically, you will have to verify the unverified device again. or if it does not work, report the problem with logs with the function in the app, on both sides.
I see. tox seems to be faring worse in security. in matrix, encryption is optional in the protocol, but it's built on well studied cryptosystem. so far when it fails, it's people not being able to read messages they should, not unexpected people being able to read messages. and that's because of flaws in key distribution.
in tox, it seems encryption is mandatory, but they roll their own cryptosystem. and their cryptosystem has flaws that nonexperts commonly run into
Jason Donenfeld, wireguard creator to expert:
https://github.com/TokTok/c-toxcore/issues/426
downvote was not me.
Ah, verification and trust are separate. Cool.
Well, it was like 2 years ago? I had a different Element session than now (new one now for testing), nheko and fluffychat, and I pressed every possible button and nothing happened. When I open nheko, a dialog box says "Activate encryption"; "to make this device trusted {blah blah blah}" with a big "Verify" button. Pressing it does the same as closing the dialog, so a whole lot of nothing. Same right now. I did try logging out and back in on different devices, back then only though.
Because that's how it's routed, yes. Peer to peer with fewer points of centralization (still there for node discovery and TCP<>UDP tunnels and shit). The message encryption and the transport encryption are the same.
I stopped reading there. I mean, good thing to know that it's possible (especially for potential punks using it and whatnot), but I feel like opsec is fucked regardless in this case.
I don't use nheko, I think it should have shown a menu saying something like "waiting to accept verification request". thats what other clients do.
did you have any other client opened on another device when you pressed verify?
Tox did their own insecure crypto and got roasted by the Wireguard dev, now they are apparently rewriting it.
I agree that Matrix is complex but personally never had issues with key verification. Just try to restart it, maybe on the other device?
Everyone does crypto in their own way and roasts each other. On a quantum physical mathematical psychological level unidentified flying object Yugoslavia something something. I only really believe stuff in relation to exploits when there's a demo.
Yeah I gave up on Element/Matrix too, for other reasons.
First of all the clients don't work for shit and every update breaks something IME, got tired of that. Also for all of my normie friends and family it was "too hard" to use, I disagree, but regardless what good is a chat app if I have nobody to use it with? Further, the one friend I did convince to join also joined the public Ras Pi room, and some dickhead posted CP in it, he saw, and then I had to explain "no, this isn't a 'pedo app,' that is spam and they get banned," and I'm gonna be real I don't want to have to do that again and I can't in good faith recommend my mother use a goddamn app that very possibly could spam her with CP.
So, I moved to Delta Chat. Fixes all those problems, no complaints. Easy to use, easy onboarding, no discoverability, just chats.
Yeah but XMPP sounds so techy you know... /s
I bet that if someone scraped together the bare minimum and found a catchy name it'd be the winner easily.
Et-tu-Brutus would slay IMO.
https://astrachat.com/ paid XMPP. It claims the US army, apart from a few other government entities around the world, use it. I find this funny because this implies someone integrated Grok into XMPP.
Also, the old name for XMPP is Jabber. That sounds less techy, you know.
Jabber, now that's a name I haven't heard in a long time...
the trick is to not mention XMPP to the end users. if they dig deep in the app settings they can find it out, but otherwise all that end users need to know is just, download the app named conversations, and use this domain and username. the domain could likely be hidden from them by deep linking, and sending the link in a company email. then they just need to log in as anywhere else.
Snikket.org
element is much lighter weight, my god wgat fuck are you even dreaming up about, discord is fucking unresponsive and horrible to use, I do agree that the device verificstion still barely works sometimes, and you can also just use a different a client, as far as web clients go cinny is really good honestly, cinny is fast and responsive it even feels almost native, which compared to garbagecord is a night and day difference in usability beyond DOING ALL OF THIS WHILE USING LESS RESOURCES, for android Schildichat Next is my choice
Here, the webapps are measured via the very scientific method of Firefox about:processes, doesn't even account Firefox itself which is like 760 megs (decimal MB or MiB? I am not sure) if I were to believe it.
On amd64, loonix with glibc and all that crap, zero memory pressure (assuming I am reading "shared" correctly in htop which I assume to be libraries like glibc and glib):
lmao