We analyse mSyphrus: a government communicator based on the Matrix protocol

kontrabanda.net 1 month ago

The Ministry of Digital Affairs launched the mSzyfr communicator in April 2026, which is announced to supply “full digital sovereignty”.

This service is mainly intended for state authorities, but access to the platform – with the approval of the ministry – can besides be granted to "other entities".

Audits outside the scope of the public

According to the papers obtained by the editorial board "Contrabands" in the mode of access to public information, so far over PLN 1.2 million has been spent on maintaining the mSzyfr communicator.

Until 30 March 2026, the agreement concerning the communicator Threem, the full cost of which was PLN 21.8 million. The Ministry of Digital Affairs decided not to extend this agreement without giving a circumstantial reason.

According to public information sent on 15 June 2026, work for maintaining mSzyfr lies with NASK-PIB, a state body supervised by the Ministry of Digital Affairs.

The Ministry, asked by the "Contrabands" for safety audits concerning mSzyfr, refused to make them available, citing Article 37 of the National Cybersecurity strategy Act. According to this article, it is impossible to get specified audits through a request for public information.

What is the mSyphrus based on?

Minister of State, Paweł Olszewski, stressed on 1 of the parliamentary committeesthat mSzyfr is based on “Polish solutions, Polish infrastructure, Polish code”, and that “there are no external components”.

However, on the government website it is stated that mSzyfr is based on Element Server Suite Pro – commercial version of the communicator component that uses the open Matrix protocol.

Both projects – component (communicator) and Matrix (protocol) – were created by British company component Creations Limited, which until 2025 was called fresh Vector Limited. The second has been managed for a long time by Matrix Foundation.

In the authoritative FAQ document prepared by NASK, mSzyfr described as an open origin solution.

This is partially actual – the code of the client application on which mSzyfr was based (Element X) is available under a free licence (GNU AGPLv3). However, component Server Suite Pro – the software underlying mSzyfru – is commercial productwhose origin code is not publically available.

The "Contrabanda" Editorial Office requested further public information. We besides asked for a comment from the Ministry of Digital Affairs on the message by Paweł Olszewski, which we did not receive until the publication.

How do we know that the mSzyfr application is based on the component X application?

NASK on your website published ZIP files with the origin code of mSzyfr applications, resulting from the licensing conditions (GNU AGPLv3 requires the modified origin code to be public in its entirety). For archiving (and allowing to view changes made in time) we published a copy of it in the version for Android and for iOS on Codeberg.

There are many references to the home application in the mSzyfr code – both for 1 platform and the other. The Android version was based on component X in version 26.03.4 (newest at the time of publication: 26.06.4) and on iOS – 25.12.1 (newest at the time of publication: 26.06.1).

Examples in the Android app may be the README.md file, which explicitly mentions that it concerns the component X application:

... the LearnMoreConfig.kt file, from which references to the element.io page have not been deleted:

...until yet after the CHANGES.md file, describing any change that has been implemented in component X application.

Since the mSzyfru code was only published in the form of ZIP files, it was the only mention point, how up-to-date the code of the government communication application was.

Element X version for Android from March 2026 and safety patches

If we consider that the mSzyfr version of Android is actually further based on the same version of component X, then at least 2 crucial safety amendments may be applicable in the absence of sync of mSyphrus code to the parent project. At this point, we're talking about numbers. CVE-2026-45056 and CVE-2026-45057which in the root application component X on Android were patched in version 26.05.1.

We are not able to independently confirm whether any action has been taken in this substance due to the form of publication of the code utilized by NASK. We've reported the case to CERT and we're waiting for them to respond.

Sources

The title photograph was taken by hand and is available on Wikimedia Commons CC BY-SA 4.0 International. The text of the article is based on the following external text and/or audiovisual sources:

    Read Entire Article