The developers of the decentralized messaging system Matrix announced that they are disabling the servers Matrix.org and Riot.im due to a breach of their infrastructure. It turned out that the servers were compromised twice, and hackers posted full information about the server configuration on the project's homepage. They also clarified that they copied the database containing hashed passwords of nearly five and a half million users of Matrix. As proof, they published the hash of the Matrix project leader.

According to the developers, the issue was caused by an unupdated Jenkins continuous integration system. There was a vulnerability that allowed the attackers to infiltrate the system. Currently, all users are advised to change their passwords. However, during the password change process in the main Riot client, a problem was discovered where files containing backup keys for decrypting messages disappeared.
The Matrix project is positioned as a secure decentralized solution with end-to-end encryption. It promises a high level of security and user privacy, as well as open standards. One of the arguments is the use of the Signal algorithm. The system also supports searching and unlimited viewing of chat history, file transfers, voice, and video communications. Additionally, there are features like typing notifications, read confirmations, push notifications, and side search. server.
On the server side, it supports synchronization of client history and states, various identifier options, and so on. However, it has not yet been clarified when the service will be fully restarted.
Source: 3dnews.ru
