Matrix hack

>team doesnt identify itself
>unclear about funding
>shit security
>gets hacked
>censors feedback left by anonymous hacker on issue tracker

i'm envisioning a bunch of weak wristed 20-something trannies with blue hair and piercings. am i right?

Attached: file.png (1024x381, 195K)

Other urls found in this thread:

archive.is/3O4QJ
archive.is/RF5OF
github.com/matrix-org/matrix.org/issues/373
archive.is/3O4QJ)...
github.com/matrix-org/matrix.org/issues/371
twitter.com/AnonBabble

At least the protocol itself is good. If this were a """service""" like discord, it would be a much more serious problem. However, this is like IRC or XMPP in the sense that anyone can host an instance.

apparently the messages arent even encrypted from the instance provider. not knowing much about matrix that was rather shocking to me, for something that purports to be so secure

>protocol itself is good
> REST/JSON shit without proper schema
> Only client to server part is stable, server to server is unstable
> Only single implementation by pajeets
> Good

Also
> HTTP polling

So what was the message?

archive.is/3O4QJ < see top links with [SECURITY] in title
archive.is/RF5OF

What's wrong with irc?

antifa cant use it to organize

host your own server then you mong

Matrix seems a bit too zoomery and shady for me. Feels like "privacy", "secure" etc have become kind of a buzzwords for shady shit nowadays.

""""secure""" message hoster gets pwnd as hard as they possibly can and *i'm* the mong

I've read through the Matrix protocol and it's not offering anything useful over XMPP and it's got less chance of replacing IRC.

the CoC people are at it again github.com/matrix-org/matrix.org/issues/373

what chat room do they mean?

it wasn't the matrix protocol or a matrix server or a matrix client that was attacked, retard. fucking xmpp shills

I don't use the matrix.org homeserver so this doesn't affect me.
COPE

uh they had access to the entire matrix.org production infrastructure, to the point where they could have signed malicious client code if they had wanted to
they also had access to unencrypted messages
how much harder do you think its possible to get owned?

shit happens, it's been fixed now

they are demonstrably clueless about security best practices (see archive.is/3O4QJ)... so, the core issue isn't fixed

>not offering anything useful over XMPP
Voice/video calls. XMPP is just glorified and a bit improved email with 0 good clients outside of android.

they got advice on how to fix it and are going to implement the fixes

>censors feedback left by anonymous hacker on issue tracker
That was actually GitHub when they banned that account.

This.

It's really fucking bad as compared to both the XMPP and the Mastodon/ActivityPub ecosystem at every level.

You feel the forwarding delays and terrible clients as user, you suffer bloat or absence of features with servers. you suffer worse than average pajeet code as developer.

I think one of the best summaries is still up:
github.com/matrix-org/matrix.org/issues/371

this is embarrassing, matrix will never recover

Attached: .png (599x592, 311K)

Yeet

Attached: somebody.png (778x640, 69K)

Enforcing E2EE in Matrix requires users to maintain their own encryption keys, which for many is not worth the hassle