Search

Items tagged with: matrix

DashEquals
1 week ago
Times #Discord has tried to track me in the past day: 500+

Times #Reddit has tried to track me in the past day: 1000+

Times #Google has tried to track me in the past day: 2000+

Times #Mastodon has tried to track me in the past day: 0

Times #Funkwhale has tried to track me in the past day: 0

Times #Matrix has tried to track me in the past day: 0

This is why we need to leave proprietary network services. They will *always* track you. #privacy #selfhosted
Lohan G
4 days ago
Sri Lankan government might block Facebook and WhatsApp today in the guise of combating "fake news". In that case, I highly recommend using #Matrix (riot.im in most app stores. https://riot.im ). It is a decentralized platform that cannot be blocked this way #lka #SriLanka
Derek Caelin
5 days ago
Matrix.org #hack forces servers offline, encrypted chat history lost | ZDNet

Matrix.org suffered a cyberattack which forced the group to boot all of their users out of the system.

https://www.zdnet.com/article/matrix-hack-forces-servers-offline-user-credentials-leaked/

#matrix #encryption
Image/photo
Hubert Chathi
7 days ago
#matrix

It's btw great to be a part of a team that takes this kind of an attack and as a team uses it to only come back stronger <3
Un joli nom de domaine, pour la messagerie sécurisée du gouvernement https://botsin.space/@DNSresolver/101946113561070147 #DNS #Matrix #Riot
Nobody [LinuxWalt (@lnxw48a1)]
7 days ago from Shoyu
Someone copies the output from installing #Steam on #Nix into a #Matrix room.

I’m glad I still have “mark all as read” ... this would be a lot to scroll through. That’s why they created pastebins.
Robert
2 weeks ago
Der Hack auf die Instanz matrix.org macht wieder das Chatssystem wieder zumindest hier publik.

Ich frage mich, ob #matrix heutzutage noch vertretbar ist. Die Ressourcenhungrigkeit ist in heutigen Zeiten (Klimawandel...) ein Horror. Viel CPU-Nutzung und hoher Speicherbedarf kostet elektrisch Energie. Und ich meine nicht im Kleinen, sondern betrachtet auf das große Ganze.

Sicherlich ist Matrix technisch gut. Aber die Klimaschädlichkeit sollte zu einem Redesign führen oder zu einem Einstampfen.
Sheogorath
2 weeks ago
After Matrix has restored its major services, they noticed that the GPG keys used for signing packages where compromised.

The key IDs are:

AD0592FE47F0DF61 (synapse)
E019645248E8F4A1 (Riot/Web)

Please make sure to no longer use those keys.

#matrix #Riot #infosec #security
Sheogorath
2 weeks ago
Too early to be happy, seems like the attacker found their way in and is still around on Matrix's infrastructure.

The attack has proven themselves to have shell access on their synapse instance, which is definitely bad. It means that all user accounts are compromised and have to be reset.

https://twitter.com/matrixdotorg/status/1116593380102852608

There will go a lot of efforts into figuring out the details and fixing the vulnerability.

Meanwhile, send some love to the people behind matrix!

#matrix #matrixDown #riot
Sheogorath
2 weeks ago
The homeservers are back up 🎉

It seems like they are missing some pictures right now, I guess those will come back later.

Make sure you change your password (and NickServ passwords) and happy chatting!

See you around 👋

#matrix #matrixDown #matrixBackUp #Riot
Sheogorath
2 weeks ago
Matrix is coming back up! One of the first things happening was writing a new blog post about the incident which you can find here:

https://matrix.org/blog/2019/04/11/security-incident/

TL;DR: Some outdated software was discovered and cracked by an attack which then had access to various data points.

Important: Change your password ASAP (including NickServ when you used the IRC bridges)

Hint: The homeserver is not back up yet.

#matrix #matrixDown #Riot
rubenwardy
2 weeks ago
Lol! #matrix has been banned from #Freenode for now due to their security breach, kinda hilarious

Source: https://twitter.com/freenodestaff/status/1116618703179616256
Jason Robinson
2 weeks ago
It does prove the usefulness of #federation that through all the #Matrix outage, my account was not affected at all. Most of the people I chat to are on other servers than the one affected.

Federate <3
Hubert Chathi
2 weeks ago

We have discovered and addressed a security breach - Matrix


https://matrix.org/blog/2019/04/11/security-incident/

If you have ever had an account on the matrix.org server, please reset the password and also any other sites passwords if you used the same password elsewhere.

More details by the team to follow.

#security #infosec #matrix
Que Shu
silverwizard
2 weeks ago from ZoobopDeDoDop!
'if you're a matrix.org user you should change your password now.'

It's running again, but:
'The hacker exploited a vulnerability in our production infrastructure'

https://matrix.org/blog/2019/04/11/security-incident/

#infosec #matrix
/dev/urandom
2 weeks ago
so, for me as someone who uses #matrix, but on the cybre.space server -- should i change my password? @chr
Nobody [LinuxWalt (@lnxw48a1)]
2 weeks ago from web
@pskoskinski@mstdn.io @kaikatsu Yep. Some public homeservers have shut down over the amount of maintenance needed and the resource consumption. That's why I can't tell any specific person they should self-host #Synapse, but the #Matrix network does need more servers and to have the network's users dispersed more widely among those servers.
Nobody [LinuxWalt (@lnxw48a1)]
2 weeks ago from Shoyu
@kaikatsu The list I saw was pretty short. https://www.hello-matrix.net/public_servers.php

I think the best thing for the #Matrix network is for more people to #self-host. I’m not saying you or any specific person should do so, because even I don’t currently host #Synapse.
Hong Kong or Sweden
Claes Wallin (隤)
2 weeks ago
https://todon.nl/@paulfree14/101909957892477960

'if you're a matrix.org user you should change your password now.'

It's running again, but:
'The hacker exploited a vulnerability in our production infrastructure'

https://matrix.org/blog/2019/04/11/security-incident/

#infosec #matrix
'if you're a matrix.org user you should change your password now.'

It's running again, but:
'The hacker exploited a vulnerability in our production infrastructure'

https://matrix.org/blog/2019/04/11/security-incident/

#infosec #matrix
Sheogorath
2 weeks ago
@matrix Turns out that there was a successful compromise of the Matrix infrastructure happening.

Details from Matrix on Twitter: https://twitter.com/matrixdotorg/status/1116388572922302466

You may ask how that could happen, but more important: It didn't stay unnoticed and that's a good sign.

#Matrix #Riot #matrixDown #infosec
Sheogorath
2 weeks ago
For those who run on Matrix.org and wonder why there is no connection:

Matrix announced an emergency maintenance… on Twitter:

https://twitter.com/matrixdotorg/status/1116304867683905537

Sadly @matrix didn't receive the love it deserves and informs the Fediverse.

Anyway, that's why we have a community. We compensate short coming of each other and together make sure the world becomes a better place!

#Matrix #matrixDown #riot
Nobody [LinuxWalt (@lnxw48a1)]
2 weeks ago from web
#Matrix.org and #Riot.im are down for emergency maintenance on their server infrastructure. There are other #Matrix homeservers, and this is a perfect time to disperse.
Tursiops
3 weeks ago
Nuaḡe Libre lance son serveur de communication Matrix ouvert à tous gratuitement !

Matrix est un protocole de communication ouvert, décentralisé et fédéré qui permet de se passer de bon nombre de logiciels privateurs tels que #microsft #skype , #facebook #messenger ou #discord et dont les fonctions de base peuvent être étendues par des "passerelles" et des "intégrations" afin de le rendre inter-opérant avec un maximum d'applications.
Parmis les fonctions disponibles :
- Conversations sécurisées, chiffrage de bout-en-bout optionnel
- Vidéoconférence à plusieurs avec partage d'écran
- Intégrations de base dont #jitsi #etherpad #youtube #google-docs #google-calendar #irc #tradingview #spotify #slack
- Bots #github #giphy #google-image #wikipedia #rss

Cerise sur le gâteau, le chat Nuaḡe Libre s'intègre totalement dans l'environnement #nextcloud disponible en #monnaie-libre :)

Créez votre compte et connectez vous avec le client Riot disponible sur chat.nuagelibre.fr

Présentation de Riot sur Nextinpact

https://www.nuagelibre.fr
https://matrix.nuagelibre.fr
https://matrix.org

#nuagelibre #matrix #riot #décentralisation #gafam
Nua廎〔 Libre
3 weeks ago
Nuaḡe Libre lance son serveur de communication Matrix ouvert à tous gratuitement !

Matrix est un protocole de communication ouvert, décentralisé et fédéré qui permet de se passer de bon nombre de logiciels privateurs tels que #microsft #skype , #facebook #messenger ou #discord et dont les fonctions de base peuvent être étendues par des "passerelles" et des "intégrations" afin de le rendre inter-opérant avec un maximum d'applications.
Parmis les fonctions disponibles :
- Conversations sécurisées, chiffrage de bout-en-bout optionnel
- Vidéoconférence à plusieurs avec partage d'écran
- Intégrations de base dont #jitsi #etherpad #youtube #google-docs #google-calendar #irc #tradingview #spotify #slack
- Bots #github #giphy #google-image #wikipedia #rss

Cerise sur le gâteau, le chat Nuaḡe Libre s'intègre totalement dans l'environnement #nextcloud disponible en #monnaie-libre :)

Créez votre compte et connectez vous avec le client Riot disponible sur chat.nuagelibre.fr

Présentation de Riot sur Nextinpact

https://www.nuagelibre.fr
https://matrix.nuagelibre.fr
https://matrix.org

#nuagelibre #matrix #riot #décentralisation #gafam
Nobody [LinuxWalt (@lnxw48a1)]
4 weeks ago from web
@moonman @clacke I liked #Mattermost in the very limited place I tried it out. It was just the lack of active users that caused me to close the account.

#Riot (or perhaps #Synapse; somewhere in the #Matrix ecosystem) is still too alpha to be recommendable. It is obvious that both of them are inspired by something else that I have not seen or used ( Possibly #Slack? ) which probably does all the same things.

"Use X; it is the same thing but slightly different" doesn't seem to work very well as a way of persuading people.
Don di Dislessia
1 month ago
Ich hatte gerade eine Diskussion zu #Signal und habe deshalb jetzt eine Frage dazu. Mir wurde gesagt, dass der #Server bei Signal nur die Verbindung aufbaut und absolut nichts speichert, stimmt das?

Wenn das stimmt, warum macht #Matrix das dann nicht auch so, beziehungsweise was genau wird eigentlich alles auf dem Matrix Server gespeichert?
Nobody [LinuxWalt (@lnxw48a1)]
1 month ago from AndStatus
@litnyykid Are you the person from the #Matrix #Python room?
Manfred Kutschera
1 month ago
'Er' kommt, sobald er das #MatrixBootcamp richtig umgesetzt hat. Dann aus der #Matrix mittenrein in den vorgewärmten Pool :)
balouqlc
2 months ago
So, #Matrix hab ich jetzt auch. Werde das auch auf dem Iphone lassen. Es braucht ja auch nicht zu funktionieren, da ich dort offensichtlich nur ein einziges Kontaktchen hab und mir dort daher niemand schreiben wird. 😂😂
Nobody [LinuxWalt (@lnxw48a1)]
2 months ago from Shoyu
Hmm. No one in the #Matrix room is posting the latest 16 bit dad links. https://www.16bitdad.com/ is a blog and blatant money-making scheme where one can tell what companies sponsored each post by the topics and embedded links, but no sponsors are ever openly identified.

It is funny to read with ad-blocking turned all the way up.
Eugen
2 months ago
#Matrix question: How do I turn a local user into an admin on my own server? Is /usr/bin/register_new_matrix_user the only way?
Array
2 months ago
@piecritic @jhaye they are quite arrogant, that's why my involvement ended with #matrix-hq getting demolished.
Array
2 months ago
@succfemboi @jhaye

one would have thought the active exploitation of a 0day (representative of an entire class of design flaws in the matrix protocol) that made #matrix-hq completely unusable would have been enough. unfortunately it wasn't.

i have more vulns though. not bothering to report them since they won't do a proper audit of the protocol.
Jonathan S.
2 months ago
To elaborate on this, here's an algorithm how to DDoS someone and break the Matrix network at the same time:

* Get a domain
* Get a wildcard certificate
* Spawn a stripped down instance with $randomname.yourdomain.org that can only talk to matrix.org.
* Send a join to #matrix:matrix.org
* Redirect $randomname.yourdomain.org to your target you want to DDoS
* Kill the instance, repeat with another $randomname

Now 2000 - 5000 servers will constantly hammer your target with TLS handshakes.
Jonathan S.
2 months ago
I tried hard to use #Matrix. After wasting a week on it, I just had to give up. The protocol is just too bad, and the federation design is broken. It's impossible for me to run a server due to this. The Matrix protocol *by design* is the largest DDoS amplification attack vector I have ever seen. Until they fix that, I cannot use it. And it doesn't seem to be a priority to fix it, it's just "Would be nice if we would fix it some day".
phranck
2 months ago
TIL: Da gibt es einen dezentralen #Messanger namens #Riot auf Basis der #Matrix. 👍🏻

https://kabi.tk/matrix-schnellstart-deutsch.pdf
Hubert Chathi
2 months ago
Did you know that #FreedomBox offers a one-click install of @matrix?

#Matrix is software for messaging and VoIP. #FreedomBox installs #Matrix for you and helps you configure it.

#Matrix hosts your chat rooms, which support conference calls and video calls! Just connect with the #Riot chat app. Riot has a beautiful UI!

Do you want to use #Matrix on your #FreedomBox? What better way to connect with friends than #Riot?

Let us know what you think!


Image/photo


Jonathan S.
2 months ago
To add the insult to injury, Synapse, the reference server implementation, can only use a single CPU (I would have 12 cores I could spare entirely for #Matrix).

Serious, non-rant question: How do other people manage to run #Synapse?
Jonathan S.
2 months ago
Running a #Matrix server is extremely painful. The client side looked nice, but federation seems entirely broken. The protocol is so inefficient that joining a single larger room resulted in my server being unavailable and at 100% CPU for hours now. The logs indicate just how inefficient the protocol is: We’re talking many, many QPS over 10 hours, while the server remains unusable.

Federation was the big selling point, but unfortunately, this is where it utterly fails. (1/2)
switching.social
2 months ago
Added an "alternatives to slack" page with Matrix / Riot on it, hope this is ok:

https://switching.social/ethical-alternatives-to-slack/

Any corrections/suggestions?

#Matrix #Riot #Slack
Nobody [LinuxWalt (@lnxw48a1)]
2 months ago from web
@bob #Tox was one of four things (Tox, #Ring, #Matrix, #Wire) I tried to get family members to try out a couple of years back. None of them ever did, so I cannot say whether Tox is useful (being that I have never actually used it).
MacLemon
2 months ago
🍌🐧🔑🤖🙂🚂🙂 is the new “Correct Horse Battery Staple”. #Matrix #RiotChat
61
2 months ago
@bumi

Whatever you do, stay well clear of #disqus !

https://opkode.com/blog/disabling-disqus/

Some people use #email, others #matrix, the author of #conversejs has an idea to use #XMPP chatrooms for this, others have even used github issues! And others do not bother with comments at all.

If I had to, I'd probably look into a #conversejs widget giving you access to a chatroom or matrix, though I'm not too familiar with it.

@fribbledom
vt
3 months ago
СЯУ, что оказывается в протоколе Matrix официальный Riot-клиент долбит сервер GET-запросами по 10 раз в секунду. Действительно, чего это у них сервер плохо работает? Совершенно непонятно!

#matrix#красноглазые протоколы
Yerevan
hoergen
3 months ago from fediverseration
Statt Whatsapp: Frankreich wandert in die Matrix

Die Behörden und Ministerien der französischen Regierung beginnen damit, ihre eigene Whatsapp-Alternative auf Basis der freien Chat-Software Matrix auszurollen.
https://www.golem.de/news/statt-whatsapp-frankreich-wandert-in-die-matrix-1902-139167.html
#DecentraliceIT #Riot #Matrix #Federation
Later posts Earlier posts