Ukukhutshwa komthengi weRiot Matrix 1.6 ngoguqulelo oluntsonkothileyo oluya esiphelweni luvuliwe

Abaphuhlisi benkqubo yonxibelelwano yokwabela amagunya eMatrix thaca ukukhutshwa okutsha kwezicelo eziphambili zabaxumi Riot Web 1.6, Riot Desktop 1.6, Riot iOS 0.11.1 kunye neRiotX Android 0.19. Uqhushululu lubhalwa kusetyenziswa itekhnoloji yewebhu kunye nesakhelo seReact (isibophelelo siyasetyenziswa React Matrix SDK). Uguqulelo lweDesktop ndiya e ngokusekelwe kwiqonga Electron. Ikhowudi isasazwa ngu ilayisenisi phantsi kweApache 2.0.

Isitshixo ukuphuculwa kwiinguqulelo ezintsha, i-encryption ekupheleni ukuya ekupheleni (E2EE, i-end-to-end encryption) yenziwe ngokungagqibekanga kuzo zonke iingxoxo zangasese ezintsha, ezingeniswa ngokuthumela izimemo. Uguqulelo olusekugqibeleni luphunyezwa ngokusekwe kwiprothokholi yayo, esebenzisa i-algorithm yotshintshiselwano olungundoqo lokuqala kunye nokugcinwa kwezitshixo zeseshoni. iratchet kabini (inxalenye yeSignal protocol).

Ukuthethathethana nezitshixo kwiingxoxo nabathathi-nxaxheba abaninzi, sebenzisa ulwandiso Megolm, yenzelwe uguqulelo oluntsonkothileyo imiyalezo enenani elikhulu labamkeli kwaye ivumela umyalezo omnye ukuba ucatshulwe ngokuphindaphindiweyo. Umyalezo we-ciphertext ungagcinwa kumncedisi ongathembekanga, kodwa awukwazi ukuguqulelwa ngokuntsonkothileyo ngaphandle kwezitshixo zeseshoni ezigcinwe kwicala lomxhasi (umxhasi ngamnye unesitshixo sakhe seseshoni). Xa uguqulelo oluntsonkothileyo, umyalezo ngamnye uveliswa ngesitshixo sawo ngokusekwe kwiqhosha leseshoni yomxhasi, eliqinisekisa umyalezo ngokunxulumene nombhali. Uthintelo olungundoqo lukuvumela ukuba ulahlekise kuphela imiyalezo esele ithunyelwe, kodwa hayi imiyalezo eza kuthunyelwa kwixesha elizayo. Ukuphunyezwa kweendlela zoguqulelo oluntsonkothileyo kwaphicothwa liQela le-NCC.

Utshintsho lwesibini olubalulekileyo kukusebenza kwenkxaso ye-cross-signing, evumela umsebenzisi ukuba aqinisekise iseshoni entsha kwiseshoni esele iqinisekisiwe. Ngaphambili, xa uqhagamshela kwincoko yomsebenzisi kwisixhobo esitsha, isilumkiso saboniswa kwabanye abathathi-nxaxheba ukuphepha ukuphulaphula ukuba umhlaseli ufikelele kwiakhawunti yexhoba. Ukuqinisekiswa okunqamlezileyo kuvumela umsebenzisi ukuba aqinisekise ezinye izixhobo zabo xa engena kwaye aqinisekise ukuthembela kwi-login entsha okanye ukugqiba ukuba umntu uzame ukudibanisa ngaphandle kolwazi lwabo.

Ukwenza lula ukuseta amagama amatsha, ukukwazi ukusebenzisa iikhowudi zeQR kunikezelwe. Izicelo zokuqinisekisa kunye neziphumo ngoku zigcinwa kwimbali njengemiyalezo ethunyelwe ngokuthe ngqo. Endaweni yencoko yababini ye-pop-up, isiqinisekiso ngoku siyenziwa kwibar esecaleni. Phakathi kwamathuba ahamba kunye, umaleko nawo uqatshelwe ePantalaimon, ekuvumela ukuba uqhagamshelane neengxoxo ezifihliweyo ezivela kubaxhasi abangaxhasi i-E2EE, kwaye isebenza kwakhona kwicala lomxhasi. Isixhobo khangela kunye neefayile zesalathisi kumagumbi encoko afihliweyo.

Ukukhutshwa komthengi weRiot Matrix 1.6 ngoguqulelo oluntsonkothileyo oluya esiphelweni luvuliwe

Masikhumbule ukuba iqonga lokuququzelela unxibelelwano lweMatrix luphuhla njengeprojekthi esebenzisa imigangatho evulekileyo kwaye inika ingqwalasela enkulu ekuqinisekiseni ukhuseleko kunye nobumfihlo babasebenzisi. Uthutho olusetyenzisiweyo yi-HTTPS + JSON kunye nethuba lokusebenzisa iWebSockets okanye iprotocol esekelwe kuyo I-COAP+noise. Inkqubo yenziwe njengoluntu lweeseva ezinokusebenzisana kunye kwaye zidityaniswe kuthungelwano olufanayo olunatyisiweyo. Imiyalezo iphindwaphindwa kuzo zonke iiseva apho abathathi-nxaxheba bomyalezo baqhagamshelwe. Imiyalezo isasazwe ngapha kweeseva ngendlela efanayo ukuba izibonda zisasazwe phakathi kogcino lweGit. Kwimeko yokucima kweseva okwethutyana, imiyalezo ayilahlekanga, kodwa ithunyelwa kubasebenzisi emva kokuba iseva iqalise ukusebenza. Iinketho ezahlukeneyo ze-ID yomsebenzisi ziyaxhaswa, kubandakanya i-imeyile, inombolo yefowuni, iakhawunti ye-Facebook, njl.

Ukukhutshwa komthengi weRiot Matrix 1.6 ngoguqulelo oluntsonkothileyo oluya esiphelweni luvuliwe

Akukho ndawo enye yokusilela okanye ulawulo lomyalezo kuwo wonke umsebenzi womnatha. Zonke iiseva ezigutyungelwe yingxoxo ziyalingana omnye komnye.
Nawuphi na umsebenzisi unokusebenzisa iseva yakhe kwaye ayidibanise kwinethiwekhi eqhelekileyo. Kunokwenzeka ukudala amasango kunxibelelwano lweMatrix kunye neenkqubo ezisekwe kwezinye iiprothokholi, umzekelo, ilungisiwe iinkonzo zeendlela ezimbini zokuthumela imiyalezo kwi-IRC, i-Facebook, iTelegram, i-Skype, i-Hangouts, i-imeyile, i-WhatsApp kunye ne-Slack.

Ukongeza kwimiyalezo ethunyelwa kwangoko kunye neengxoxo, inkqubo inokusetyenziselwa ukuhambisa iifayile, ukuthumela izaziso,
ukuququzelela iikhonferensi zocingo, ukwenza umnxeba welizwi kunye nevidiyo.
I-Matrix ikuvumela ukuba usebenzise ukukhangela kunye nokujonga okungenamkhawulo kwimbali yembalelwano. Ikwaxhasa iimpawu eziphambili ezifana nesaziso sokuchwetheza, ukuvavanywa kobukho bomsebenzisi kwi-intanethi, uqinisekiso lokufunda, izaziso zokutyhala, ukukhangela kwicala leseva, ungqamaniso lwembali kunye nobume bomthengi.

umthombo: opennet.ru

Yongeza izimvo