!GsmxjHfeAYLsTEQmjS:nixos.org

Matrix Meta (Nix)

617 Members
Discuss your proposals for the Matrix space here, before suggesting them in #matrix-suggestions:nixos.org173 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
23 May 2025
@emilazy:matrix.orgemilythe first phase was joining the rooms directly and spamming CSAM/gore08:05:22
@emilazy:matrix.orgemilycoupled with DoS targeting federation so that deletion events for the messages didn't get propagated quickly08:05:38
@emilazy:matrix.orgemily(and even when they do, homeservers and clients don't purge media from caches by default on deletion, so it's too late to prevent illegal material propagating to the storage of hundreds of machines)08:06:11
@emilazy:matrix.orgemilythat's why we went invite only08:06:17
@emilazy:matrix.orgemilythe invite spam is quite a bit less bad than that was frankly08:07:32
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @emilazy:matrix.org
(and even when they do, homeservers and clients don't purge media from caches by default on deletion, so it's too late to prevent illegal material propagating to the storage of hundreds of machines)
on that note, what's the solution now? I think a few years back we were sharing media IDs to be deleted manually
08:09:38
@uep:matrix.orguepfor the most part it's just "delete remote images" from the cache.. and hope the spammers aren't your own users08:11:16
@uep:matrix.orguepwhich of course has other impact on genuine users and content, so the spammers win regardless08:11:51
@zhaofeng:zhaofeng.liZhaofeng Liok, good to know08:12:09
@emilazy:matrix.orgemilyfor deletion, yeah I think it's basically complete purges. for what you are legally required to do per jurisdiction – I wouldn't want to comment honestly08:12:44
@emilazy:matrix.orgemilymy impression is that for CSAM the legal requirements are sufficiently strict that "there was this spam wave and Matrix makes it really hard to purge this stuff" is not going to mean anything. OTOH I also hear that in some jurisdictions deleting isn't enough, you have to proactively report it. which seems completely untenable in this case08:13:26
@uep:matrix.orguep(and whatever each client uses for clear cache, too)08:13:36
@emilazy:matrix.orgemilyso, uh, I guess the safe advice is stop running a homeserver?08:13:39
@emilazy:matrix.orgemily…or a client?08:13:44
@sepiabrown:matrix.orgSuwon Park joined the room.08:17:13
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @emilazy:matrix.org
so, uh, I guess the safe advice is stop running a homeserver?
Is there a way to disable media "processing" on one's homeserver? I know there may not be a clean way to do this, but I guess even nginx block rules may be better than nothing
08:19:23
@dgrig:erethon.comdgrigWhat I do is have remote media have a very small TTL, so they're deleted within the day automatically and at the same time have enabled authenticated media, so a non user of my HS can't access media stored in my server.08:19:28
@zhaofeng:zhaofeng.liZhaofeng LiPeople were talking about blocking invites on nginx, and I suppose media is another thing people would want to block 🤷‍♂️08:20:17
@sepiabrown:matrix.orgSuwon ParkHello~ Can I get an invitation to the new NixOS room?08:20:31
@zhaofeng:zhaofeng.liZhaofeng Li

also how did this message get through in the old #users room?

https://matrix.to/#/!RRerllqmbATpmbJgCn:nixos.org/$o6fZtlcepowuBtqDA5rLijG3DmfO3kTqNQhI5bJUpCU?via=lossy.network&via=matrix.org&via=tchncs.de

08:27:47
@kfears:matrix.orgKFears (burnt out)
In reply to @emilazy:matrix.org
a thing Matrix famously has a track record for completing on time and without issues?
Yeah, that's why I insist that viability of Matrix long-term should be questioned
08:28:39
@emilazy:matrix.orgemily I think you can. iirc someone in here (magic_rb?) mentioned disabling media stuff 08:29:03
@emilazy:matrix.orgemilyyou can also block the invite endpoint08:29:08
@emilazy:matrix.orgemilyI think nobody thinks Matrix is good at this point, there's just lack of agreement about whether a viable alternative exists.08:29:27
@emilazy:matrix.orgemilyI'd still prefer Zulip out of all the options, I think.08:29:37

Show newer messages


Back to Room ListRoom Version: 6