Encryption in the Context of Matrix

How to Keep Your Account Secure

How to Keep Your Friends Safe

Device Verification

With Matrix, whenever you sign-in to a new device, you need to "verify" that device. What this is, essentially, is confirming that it was indeed you that signed-in to the new device, and not someone who has managed to get your password. Like with Signal, your homeserver doesn't have an (unencrypted) copy of your messages. This is more secure, but if you lose access to all your devices you will lose your messages. Keep this in mind.

In order to do verification, you need two devices/clients, the new one which you just signed into, and one which you previously verified. The first device you ever sign-in on (probably the one you made your account with) is automatically considered verified.

When you get to the app home screen after logging-in on the new device, you will likely be shown a message letting you know you need to verify that device. Click on that to start.

Step-by-Step guide

When you first sign-in to Element Web on a device, you should be presented with this screen requesting verification:

Screenshot of Element Web, text says 'Verify this device', 'verify your identity to access encrypted messages and prove your identity to others.' Button labelled 'Verify with another device' present

Click "Verify with another device". It'll take you to the home screen with this over the screen:

Screenshot of something on Element Web, text says 'Verify other device, to proceed, plese accept the verification request on your other device

As it says, open up any other device which is already verified. You should get a "verification request" you can select on the other device. Accept it. How the next part proceeds depends on the other device. If it is a device known to have a camera, like a smartphone, the new device will show a QR code, like this:

Screenshot of Element Web, shown is the text 'verify other device', with two options, a QR code to scan, or the text 'compare unique emoji' with a button labelled 'start'

If you get that option, either scan the QR code, at which point verification is basically done, or continue on to try the emoji method.

If neither of the devices are smartphones, you will only be presented with one option to verify by checking for matching emoji, as below:

Select that single choice, at which point you will be presented with this screen on both devices:

Check if the set of emojis shown on the screens match, and if so, click the button saying they match. If they don't match, there is likely something going wrong, so contact the admin of the AACK homeserver for assistance.
And that's it! You've now verified the device. You should see this screen confirming verification was successful:

Screenshot of Element, there is a big green shield with a tick in it, with the text 'you've successfully verified Element Android'