I haven't had much luck finding tropical fish related communities on Matrix, so I decided to create a room based on the "if you build it, they will come" principle.
implicitly trusted shared state means a hostile peer can alter the shared state by providing different data. this was used to break #matrix-hq last year (and is why it's difficult to replay the log past May 2018)
AP implementations should not disclose objects they don't own when fetched. Indeed, this is a glaring omission from AP. Indeed, AP is a pile of garbage.
You're preaching to the choir here, I'm just trying to solve real pain points so that we can buy some time.
Matrix has other security problems. Yeah, they have multi-party device encryption ala MegOLM, but Matrix Protocol itself implicitly trusts shared state data when resolving DAG updates, as they are trying to have their cake and eat it to regarding the CAP theorem. See also the depth_counter attack JZK perfected and demonstrated in #matrix-hq last year.
Entre maston y matrix se encuentra practicamente el 90% de las instancias. ¿Que demuestra esto?
Una cosa es segura, que junto a ser las redes favoritas, la desproporcion tan gigante que existe me indica que la "deiversificacion" no es tan grande como se piensa...
@kaitatsu There shouldn't even be a main server. That's part of the problem. But, yes, #Synapse's resource consumption is unduly constraining the number of public #Matrix homeservers.
Hopefully, the E2EE experience has improved now that they can store keys server-side (which could have its own negatives). *All* my former person-to-person #Matrix contacts abandoned it because of "cannot decrypt this message" warnings seen in various #Riot.im clients when reading our conversations, so I would hesitate to recommend it until I know that's fixed.
@xj9 #Riot is inconsistent, slow, constantly buggy. If they released a better replacement for #Synapse tomorrow, Riot would still constrain most #Matrix use to a certain subset of techpeeps.
Social media, including WhatsApp are blocked in Sri Lanka at the moment. My friends and colleagues are looking for alternative platforms to communicate. I've been able to get some of them on #Matrix and XMPP. #Telegram seems to have gained some popularity in this context. Telegram claims to be a "distributed" platform because their "servers are spread worldwide for security and speed".
Well, if that qualifies as "distributed", then Facebook, WhatsApp and Twitter too are distributed. Am I wrong?
It does prove the usefulness of #federation that through all the #Matrix outage, my account was not affected at all. Most of the people I chat to are on other servers than the one affected.