

E2E encrypted messages in Matrix contain more user metadata than alternatives like SimpleX, nothing scary but a MitM is able to see origin points, destinations, and times of messages. Server to server, if you’re using E2E encryption, it relies on trust that the other server is not compromised.
And it seems Matrix.org is not the best at security disclosures: https://soatok.blog/2026/02/17/cryptographic-issues-in-matrixs-rust-library-vodozemac/#matrix-response






I think it probably doesn’t matter what he wants, it only matters that the data exists at all. If the owner is not giving permission, that’s one thing. But I’m inclined to believe that those American 3-letter agencies aren’t the sort to ask permission.
All it takes is one disgruntled systems engineer who thinks they don’t get paid enough. An agency comes knocking with a sizable offer of cash, and they’ll get the backdoor they want.