Conversation
Notices
-
this ad CAN be blocked, bitch (kirby@lab.nyanide.com)'s status on Tuesday, 30-Jul-2024 17:32:01 JST this ad CAN be blocked, bitch i fucking hate xmpp why is it fetching EVERY MESSAGE and all of it is THIS -
† top dog :pedomustdie: (dcc@annihilation.social)'s status on Tuesday, 30-Jul-2024 17:32:00 JST † top dog :pedomustdie: @m0xee @kirby >turned out that it's even worse Basically false. Matrix is even worse because you can't turn it on and off by your self. It also is less secure. -
m0xEE (m0xee@social.librem.one)'s status on Tuesday, 30-Jul-2024 17:32:01 JST m0xEE @kirby
It's a price to pay for proper encryption that works with multiple sessions🤷
XMPP crowd was making fun of Matrix for this, but that is just how Double Ratchet works — now it got implemented in popular XMPP clients and it turned out that it's even worse than it was in Matrix and before that it "just worked" simply because nothing was encrypted. -
m0xEE (m0xee@social.librem.one)'s status on Tuesday, 30-Jul-2024 17:42:10 JST m0xEE @dcc
Of course you can, just create two person room with encryption disabled! If they weren't created with encryption enabled by default, few would be using it and it would defeat the purpose.
And how is it less secure? It's literally the same algorithm.
@kirby -
this ad CAN be blocked, bitch (kirby@lab.nyanide.com)'s status on Tuesday, 30-Jul-2024 17:42:10 JST this ad CAN be blocked, bitch @m0xee @dcc something about metadata † top dog :pedomustdie: likes this. -
† top dog :pedomustdie: (dcc@annihilation.social)'s status on Tuesday, 30-Jul-2024 18:00:56 JST † top dog :pedomustdie: @m0xee @kirby >does he know about the media Matrix as a protocol is just worse than xmpp. -
m0xEE (m0xee@social.librem.one)'s status on Tuesday, 30-Jul-2024 18:00:57 JST m0xEE @kirby
Leaking presence to the servers of participants of a multi-user room that I'm in is the thing I'm the least concerned about TBH, XMPP doesn't do it because the rooms aren't distributed and only exist on the server they were created on. A lot of people do not seem to understand this: XMPP doesn't have a more secure implementation of the feature — it simply doesn't have this feature at all.
@dcc -
m0xEE (m0xee@social.librem.one)'s status on Tuesday, 30-Jul-2024 18:00:57 JST m0xEE @kirby @dcc
And I believe they have even fixed it now, it is possible to prevent interacting with the sessions that you haven't personally authorized, but you have to enable it for each room and for every session of yours individually — far from perfect solution, could've been better, probably this way to prevent breaking compatibility. -
ロミンちゃん (romin@shitposter.world)'s status on Tuesday, 30-Jul-2024 18:27:15 JST ロミンちゃん @m0xee @dcc @kirby
>It's literally the same algorithm
not really, that'd be olm, megolm (the one actually used in e2ee rooms) is double ratchet with extra steps, that may or may not weaken DR security assumptions† top dog :pedomustdie: likes this.
-