A frog who wants the objective truth about anything and everything.

Alt of [email protected]

  • 2 Posts
  • 21 Comments
Joined 1 year ago
cake
Cake day: November 11th, 2024

help-circle





  • Matrix is so laggy and clunky and slow and annoying. XMPP was just perfect. And the “Conversations” client, for XMPP, is so fucking fast.

    I’ve noticed that as well, XMPP has never been laggy in my experience, it’s very snappy. Matrix is hit or miss, sometimes fine, sometimes a bit slow, especially in larger rooms.

    How does XMPP’s E2EE compare to matrix’?

    As far as I know, XMPP’s OMEMO encryption is modeled off of Signal’s encryption, but modified to function without a centralized server. It’s generally regarded as a very solid, strong encryption, even better than openPGP.

    Matrix’s encryption uses Megolm or olm, which I believe is also regarded well as far as the encryption itself. The issue is that Matrix’s inherent design means it’s spreading copies of the metadata of those messages (though the contents of the message itself is encrypted) far and wide to many servers unnessesarily. Seeing as a lot can still be gleaned from metadata (when a message was sent, to who it was sent to), it’s a concerning model considering how big the main Matrix server is, which means that it usually always receives a copy of all metadata activity on the protocol, unless a self-hosted server completely kills federation (which defeats the point of it).

    A good comment from an older reddit thread summed it up well:

    matrix.org is unique because it hosts so many user accounts. As a result, it becomes a metadata honeypot for the entire matrix network. It’s kind of a design flaw in my eyes. Matrix is great. But it would be even better if it didn’t have this issue.

    Xmpp is federated, but you have the option of not sharing chat metadata with other servers on the network. Matrix doesn’t give that option. matrix.org is effectively a central server due to the fact that a majority of accounts are hosted there, AND all metadata associated with those accounts, which includes metadata from other servers they communicate with, accumulates on matrix.org. I would suspect a very high percentage of matrix metadata, ends up on a single server. Xmpp just does not have this problem.






  • I don’t know how, but ultimately this is on us all to fix

    There are concrete steps we can take toward resisting this takeover, eventually culminating in in the deployment of one of our most powerful weapons: a proper, long-term, nation wide General Strike.

    The country would be brought to its knees if suddenly deprived of profit and labor. That tactic was extremely effective in Chile in 2019, and had they not fallen for the trick of liberal reform, they would’ve had a successful revolution on their hands with virtually no bloodshed.

    But getting to the point where we can enact a general strike requires we do some groundwork in other ways, which will both make it more effective, and more bearable for us all to weather. Here’s what we need to do (the titles below expand if you click them):

    Learn First Aid! ⛑️

    As we’re seeing, deadly violence is being used against us and it will only continue. It extremely important to have the skills to be able to keep yourself and others alive if they get hurt.

    Tacticool Girlfriend provides a great introduction to building a personal first aid kit, called an IFAK, which can deal with things like bullet wounds and other serious bleeding wounds. I also want to emphasize her recommendation of only buying medical gear from reputable sources (not Amazon!), such as North American Rescue to avoid fakes that could cost you your life.

    But you’ll need to learn how to use that equipment, too. The best resource for that is to take a local Stop The Bleed class, which are pretty widely available in most places. They may cost a small fee, but can also sometimes be free. Alternatively, if you cannot access a local class, this video by PrepMedic will give you a solid understanding of how to use Tourniquets and Gauze for wound packing.

    Injuries are less harmful if they are tended to early. Learning first aid can help conserve resources when healthcare becomes unaffordable. Having several medics in case of harm by police is an extremely powerful morale booster during a protest that may become a police riot. When you become comfortable with the basics of first aid, riot medicine is the next suggested step.

    Establish or join local Mutual Aid networks ✊

    If you haven’t already, get to know your neighbors. Mutual aid is a willingness to support and grow your community. This can include informal networks through friends, tenant/renter organizations, solidarity groups, and industrial unions.

    These are groups using direct action to solve each other’s problems. Building strong communities makes it difficult for fascism to take root. The actions of the government are going to hit every community hard, and the ones who build trust in each other and work together are most likely to survive. We’ve been building a list of resources in [email protected] to help you on your way. Also check out this handy guide to find existing groups in your area.

    This isn’t only for your own community protection. Your ability to organize today will change the political landscape tomorrow. When revolution occurs, the social organizations that show the greatest resilience through the regime are the ones typically calling the shots when the dust settles. When it comes to elections, get out the vote drives are useless if most of the voters are fascists. At some point, you have to do grassroots political education if you don’t want fascist candidates winning elections. Mutual aid networks are excellent forums not only for teaching each other good political ideas, but demonstrating them in practice.

    Join a Union and Prepare 💪

    If you aren’t in a union (or even if you are, it’s worth dual-carding), consider joining the IWW to or contacting EWOC to unionize your workplace (bonus: you’ll get higher wages, better benefits, and more time off if you succeed!) to strengthen a general strike if we manage to enact one, as most unions have a strike fund that can supplement your income during a general strike to make it more financially bearable (you should also save as much money as you can reasonably do, so it can also be used to keep yourself afloat during a strike). A General Strike is officially planned by the UAW for May 1st 2028, but it was planned before Trump was elected, and by then may be too late, so prepare now for one that may start sooner.

    And for our international friends, you should join one as well, as fascism is gaining momentum globally. If your country isn’t listed below, just contact the IWW directly in the link above, and they’ll help you set up a new local branch.

    • 🇦🇷 Argentina: FORA
    • 🇦🇺 Australia: ASF-IWA
    • 🇧🇷 Brazil: FOB
    • 🇧🇬 Bulgaria: ARS, CITUB
    • 🇩🇪 Germany: FAU
    • 🇬🇷 Greece: ESE
    • 🇮🇹 Italy: USI
    • 🇮🇪 Ireland: IWW Ireland
    • 🇳🇱 🇧🇪 Netherlands & Belgium: Vriji Bond
    • 🇪🇸 Spain: CNT
    • 🇸🇪 Sweden: SAC
    • 🇬🇧 United Kingdom: UVW
    Adopt Security Culture and Digital Camouflage 🛡️

    Sometimes benign seeming efforts can turn into unexpected personal data collecting traps. Like an obscure website for exchanging contact info with other students turning into a global ad-tech surveillance network (Facebook), or innocent seeming online personality tests being use to harvest character profiles. Even Etsy, Reddit, Tinder, and Duolingo are feeding information to US Government Agencies like ICE.

    Security culture is commonly used to describe the general awareness of such potential traps and how it can affect groups or entire communities. This goes beyond mere individual privacy efforts, as without joint efforts these often fail to work.

    Especially in activist circles, security culture is paramount. For opsec reasons not everyone in the group might be aware of what clandestine efforts others are involved in, but with a general security culture many potential data leaks can be avoided.

    Movements are made by the volume of their participants, and the easier and less dangerous it is to participate, the more people will get involved. As more people get involved, individual involvement becomes even less dangerous, creating a virtuous cycle.

    We’ll start it off with some General Advice:

    • Mentally wall off personal uniquely identifying info from your online presence, actively build a habit of opsec so that withholding information is your default mental state
    • Be careful about who you meet online
    • Use different, unrelated usernames, passwords & emails for every account. And try not to connect to those accounts with your real IP address (use Tor or a VPN)
    • Be mindful that anything done online leaves a trail
    • agents provocateurs may seek to find patsies willing to perform an ill-advised illegal activity in order to legitimize police repression. If someone is trying to pressure you, especially if you don’t have a long and proven history with them, be extremely wary.

    For a full guide on what encrypted communications platforms to use, and how to stay off the radar, read the Digital Camouflage section within the Monthly Meta post here (you’ll need to scroll down. I’d add it here, but it won’t fit in this comment).

    I’d also highly recommend Full Spectrum Resistance to anyone who wants further info on how to resist (audiobook version here).






  • EDIT 2: The Fluxer dev agreed to remove the CLA!

    EDIT: Just a heads up to anyone interested in Fluxer: I was just informed today of a huge red flag for Fluxer; it has a contributor CLA that could allow it to change to a non-FLOSS license in the future. I was hopeful for it previously, but that kills it for me.

    Of all the discord clones, this one does look promising I must admit, especially since the dev has mentioned they’d be open to incorporating federation and some encryption abilities down the road. The GPL license is a good mark, and the dev seems pretty chill. Downside is that’s it’s still very rough and in more of a visually polished alpha state. The dev mentioned they’re about to release a major refactor of the codebase, which they hope will fix the sluggishness the server is experiencing after an influx of new users from the Discord dumpster fire.

    Personally, I’d still suggest Movim over Fluxer at the moment.

    Movim already has a proven, scalable back-end (XMPP), it’s already federated, already provides good encryption, has 90% feature parity with Discord such as Chats, group video calls, screen-sharing with audio (requires chromium browser to share audio for now), its made in the EU, and it’s ready right now, not some time in the future (if Discord users fleeing discord try Fluxer, they’d be likely to bail on it due to the current bugs and just go back to discord). The Movim developer is also currently working on adding in discord-like channels and rooms.

    But that’s just my 2 cents. Fluxer is one to keep an eye on for the future, though.






  • Hm, perhaps your instance needs to update to a newer version? I notice that it’s on 1.4.6, while Piefed.social is currently running version 1.5.3

    EDIT: Ah, nevermind, 1.4.6 is only a couple weeks old! I was thinking of the gap in those releases in relation to Lemmy’s, where that would be a massive difference.

    Is voyager updated to the latest release?