!GsmxjHfeAYLsTEQmjS:nixos.org

Matrix Meta (Nix)

630 Members
Discuss your proposals for the Matrix space here, before suggesting them in #matrix-suggestions:nixos.org179 Servers

Load older messages


SenderMessageTime
15 May 2025
@f0x:pixie.townf0x
In reply to @dgrig:erethon.com
(This is a bit pedantic, but it's good that people are informed. Leaving rooms in matrix isn't enough from a moderation perspective. Because if they ever rejoin they'll have the power level they had when they left unless they were demoted. And if the domain ever expires, anyone can take over the domain and recreate any users.)
no? federation relies on request signatures, and someone taking over the domain won't have access to your homeserver's key
17:59:08
@saiko:knifepoint.net@saiko:knifepoint.net
In reply to @f0x:pixie.town
no? federation relies on request signatures, and someone taking over the domain won't have access to your homeserver's key
what happens if the key for a homeserver changes, for example in this case?
18:03:22
@emma:rory.gay@emma:rory.gayover time homeservers will accept the new key18:04:33
@emma:rory.gay@emma:rory.gayat most in 90 days18:04:43
@dgrig:erethon.comdgrig

When my homeserver died I was back and federating within 12 hours or so. It would have been the same case if the domain was taken over.

The spec mentions this https://spec.matrix.org/v1.14/server-server-api/#security-considerations

18:05:46
@saiko:knifepoint.net@saiko:knifepoint.netah cool, good to know!18:05:53
@saiko:knifepoint.net@saiko:knifepoint.netso the domain isn’t “bricked” if you lose the key, that would suck18:06:22
@dgrig:erethon.comdgrigMy understanding is that keys are trusted immediately on Synapse18:10:45
@f0x:pixie.townf0xhuh.. that seems.. bad18:23:22
@dgrig:erethon.comdgrigGiven the various issues with dnssec or hpkp, it's somewhat reasonable that we're at this state currently. It's not ideal though indeed18:34:43
16 May 2025
@aloisw:julia0815.de@aloisw:julia0815.deDNSSEC will also not help you for the "domain takeover" case at all.07:08:36
@dgrig:erethon.comdgrigMy comment about dnssec and hpkp was an example on how losing keys can have serious impact on a service that we've seen people aren't prepared for in the real world.07:15:21
@aloisw:julia0815.de@aloisw:julia0815.deKey pinning for sure, but I somehow fail to see what the failure mode for DNSSEC here should be. You can just publish new keys and things should work again at most a TTL later.07:24:25
@aloisw:julia0815.de@aloisw:julia0815.deOn the other hand of course there is always going to be a trade-off between not being vulnerable to domain takeover and allowing recovery for lost keys.07:28:21
@aloisw:julia0815.de@aloisw:julia0815.de(Or, for that matter, to allow a legitimate new owner of the domain to use it for their purposes.)07:29:06
@dgrig:erethon.comdgrigack, dnssec might have not been the best example, but I think it still illustrates the point that systems that require key management are more complex. I don't have numbers for this, but I would love knowing how many homeservers would have issues federating if keys took longer to be trusted again (i.e. how many people recreate their HS without a backup of the keys).07:39:41
@mk360:matrix.orgmk360 joined the room.12:14:00
@mk360:matrix.orgmk360how do i enable chaotic-nyx flake in nixos12:14:59
@mk360:matrix.orgmk360i need the cachyos kernel in my system12:15:11
@k900:0upti.meK900This is the wrong room for this 12:15:41
@k900:0upti.meK900Also please don't use riced kernels, they don't actually help 12:15:48
@mk360:matrix.orgmk360how so12:15:58
@mk360:matrix.orgmk360this one has lto optimization12:16:03
@mk360:matrix.orgmk360i need that12:16:05
@k900:0upti.meK900Can you explain to me, in three sentences or less, what "lto optimization" is and why it matters to you? 12:16:41
@k900:0upti.meK900Except "the internet said it makes more fast" 12:16:49
@mk360:matrix.orgmk360i guess so whatever12:17:41
@mk360:matrix.orgmk360anyways how do i get nvidia drivers unstable in nixos14:04:08
@k900:0upti.meK900This is the wrong room for this14:12:44
@k900:0upti.meK900 You want #Nix / NixOS 14:12:47

Show newer messages


Back to Room ListRoom Version: 6