1. What measurements will be taken to mitigate identification through typing rhythm/pattern by an adversary
2. Why is this chosen for the GSoC instead of a adding an additional option for e2e encryption by default? (or something similar that supports e2e encryption that is not accidentally turned off)
RTT can be encrypted using omemo:1 (and should be if you want to protect against malicious servers).
RTT instructions are batched into messages of fixed intervals (something like 1s), making it impossible for servers to see any pattern (other than ongoing communication between the two users).
If you don't want to leak that you are currently typing to a user, you need to turn off RTT. Dino allows you to turn off the "is typing"-notification for the same reason.
Ok. That was the part I was hoping for.
Even so I wished the resources would be used for something that is improving Dino's security, that feature doesn't seem to be as bad as I feared in the beginning.
thank you for your explanation.
2. GSoC is for students that are new to open-source contributions and work on a project for 3 months straight. Students propose their project, with some suggestions provided by the project maintainers (which act as mentors throughout the summer).
Depending on what you include in the goal of enabling e2ee by default, it's either far less than 3 months of work or requires deep understanding of crypto which you can hardly expect from most students.
A instance dedicated - but not limited - to people with an interest in the GNU+Linux ecosystem and/or general tech. Sysadmins to enthusiasts, creators to movielovers - Welcome!