| 23 May 2025 |
emily | the invite spam is quite a bit less bad than that was frankly | 08:07:32 |
Zhaofeng Li | In reply to @emilazy:matrix.org (and even when they do, homeservers and clients don't purge media from caches by default on deletion, so it's too late to prevent illegal material propagating to the storage of hundreds of machines) on that note, what's the solution now? I think a few years back we were sharing media IDs to be deleted manually | 08:09:38 |
uep | for the most part it's just "delete remote images" from the cache.. and hope the spammers aren't your own users | 08:11:16 |
uep | which of course has other impact on genuine users and content, so the spammers win regardless | 08:11:51 |
Zhaofeng Li | ok, good to know | 08:12:09 |
emily | for deletion, yeah I think it's basically complete purges. for what you are legally required to do per jurisdiction – I wouldn't want to comment honestly | 08:12:44 |
emily | my impression is that for CSAM the legal requirements are sufficiently strict that "there was this spam wave and Matrix makes it really hard to purge this stuff" is not going to mean anything. OTOH I also hear that in some jurisdictions deleting isn't enough, you have to proactively report it. which seems completely untenable in this case | 08:13:26 |
uep | (and whatever each client uses for clear cache, too) | 08:13:36 |
emily | so, uh, I guess the safe advice is stop running a homeserver? | 08:13:39 |
emily | …or a client? | 08:13:44 |
| Suwon Park joined the room. | 08:17:13 |
Zhaofeng Li | In reply to @emilazy:matrix.org so, uh, I guess the safe advice is stop running a homeserver? Is there a way to disable media "processing" on one's homeserver? I know there may not be a clean way to do this, but I guess even nginx block rules may be better than nothing | 08:19:23 |
dgrig | What I do is have remote media have a very small TTL, so they're deleted within the day automatically and at the same time have enabled authenticated media, so a non user of my HS can't access media stored in my server. | 08:19:28 |
Zhaofeng Li | People were talking about blocking invites on nginx, and I suppose media is another thing people would want to block 🤷♂️ | 08:20:17 |
Suwon Park | Hello~ Can I get an invitation to the new NixOS room? | 08:20:31 |
Zhaofeng Li | also how did this message get through in the old #users room?
https://matrix.to/#/!RRerllqmbATpmbJgCn:nixos.org/$o6fZtlcepowuBtqDA5rLijG3DmfO3kTqNQhI5bJUpCU?via=lossy.network&via=matrix.org&via=tchncs.de
| 08:27:47 |
KFears (burnt out) | In reply to @emilazy:matrix.org a thing Matrix famously has a track record for completing on time and without issues? Yeah, that's why I insist that viability of Matrix long-term should be questioned | 08:28:39 |
emily | I think you can. iirc someone in here (magic_rb?) mentioned disabling media stuff | 08:29:03 |
emily | you can also block the invite endpoint | 08:29:08 |
emily | I think nobody thinks Matrix is good at this point, there's just lack of agreement about whether a viable alternative exists. | 08:29:27 |
emily | I'd still prefer Zulip out of all the options, I think. | 08:29:37 |
KFears (burnt out) | In reply to @emilazy:matrix.org I think nobody thinks Matrix is good at this point, there's just lack of agreement about whether a viable alternative exists. Yeah, and a lack of agreement if sticking to the horrors of Matrix wins over the costs of migrating to (theoretical) alternative | 08:33:49 |
KFears (burnt out) | The lack of agreements are certainly a pattern in a meta way, too... | 08:34:49 |
KFears (burnt out) | * The lack of agreements is certainly a pattern in a meta way, too... | 08:35:02 |
Zhaofeng Li | honestly I shouldn't have bothered to look, but if power levels are just a suggestion then maybe matrix moderation just doesn't work | 08:38:15 |
K900 | Power levels are not a suggestion | 08:38:36 |
K900 | It's just an old message | 08:38:40 |
K900 | That has not federated previously | 08:38:44 |
Zhaofeng Li | it was way after the power level restrictions were changed (actually rechanged) | 08:39:43 |
uep | and the room state is rather messed up and probably out of sync, which is why it was re-made already | 08:39:43 |