| 11 Aug 2025 |
Charles | wait what | 17:48:45 |
emily | see https://matrix.to/#/!vxTmkuJzhGPsMdkAOc:transformierende-gesellschaft.org/$Gi9Fk9kEfbkUl4wGImJFL-T5EZO0BJ5ePGTrYRzsD9k?via=utzutzutz.net&via=matrix.org&via=tchncs.de, https://matrix.to/#/!ATURSDtpSAgOTfvtbq:lossy.network/$HJYKt60KYvra3DKIjZq88T18DaMFgaf6Y4fk9eJ_pVM?via=nixos.org&via=matrix.org&via=stratum0.org | 17:49:04 |
Charles | rooms i am not in | 17:49:42 |
Charles | https://github.com/element-hq/synapse/releases but yeah i don't see anything here lol | 17:49:50 |
@emma:rory.gay | yeah they botched teh release | 17:50:04 |
emily | fwiw I was pushing for testing out Zulip during the abuse wave and was offered access to the Zulip that was used during the NCA for playing around with it and pulling in whoever on the mod team might be interested in looking at the tooling etc. | 17:50:03 |
emily | I lost the spark for it when the abuse wave died down | 17:50:13 |
emily | but if you are interested in pushing for a move to Zulip I would guess that offer of access still stands | 17:50:24 |
emily | I was discussing it with uep at the time | 17:50:35 |
emily | it's tagged | 17:50:44 |
emily | but it fails many tests | 17:50:47 |
emily | and broke linting CI | 17:50:51 |
Charles | ah lol | 17:50:59 |
emily | so I guess they just did not test it⦠? | 17:51:00 |
Gnuxie ππ | @matthew is this true meow? | 17:51:52 |
@emma:rory.gay | element matthew isnt here... lol | 17:52:15 |
K900 | Well the vuln seems to be "you can force well-behaved servers to roll back to any previous room state" | 17:52:27 |
emily | (it was sil's offer, I think he asked me to open an issue in NixOS/org or something for it?) | 17:52:28 |
K900 | Which isn't quite "arbitrary state overwrite" | 17:52:40 |
Charles | i ended up setting up my own zulip instance that i've primarily been using fwiw | 17:52:44 |
K900 | But it does mean that the create event is now uniquely special | 17:52:47 |
emily | so you're saying even older room versions get to have an omnipotent creator! | 17:53:04 |
ma27 | In reply to @emma:rory.gay element matthew isnt here... lol too busy building a metaverse into matrix I heard | 17:53:16 |
emily | is grapevine still a going concern? | 17:53:44 |
@aloisw:julia0815.de | In reply to @k900:0upti.me Well the vuln seems to be "you can force well-behaved servers to roll back to any previous room state" So their "availability at all costs" approach doesn't even give you availability, great. | 17:54:03 |
Charles | we're working on implementing room v12, it's just slow going | 17:54:08 |
Charles | * we're working on implementing room v12 in grapevine, it's just slow going | 17:54:20 |
Charles | motivation for this is very low as you might imagine | 17:54:31 |
Charles | * motivation for matrix work is very low as you might imagine | 17:54:38 |
emily | indeed | 17:54:42 |