jdev - 2020-07-02

  263. lovetox so we are thinking about impl 0377
  264. lovetox any thoughts?
  273. Zash go for it.
  281. Martin [xep 0377]
  282. Martin [xep-0377]
  283. Martin !xep-0377
  284. Zash No bot here
  285. Martin He, somehow I assumed we are in the prosody muc here. Sorry for the noise.#
  286. Zash It's https://xmpp.org/extensions/xep-0377.html
  287. Martin Thanks, but I already searxed it. :D
  288. Martin lovetox: The prosody community module worked for me with conversations. Don't know if any other client is supporting it already.
  289. lovetox we are in the progress of adding it to gajim
  290. Zash There was that discussion on whether it really should be tied into blocking the way it is. And it doesn't really cover what happens with the reports, but that could be a separate XEP (some day?).
  291. lovetox i think it covers the most usual cases
  292. lovetox so yeah it maybe does not cover some exotic uses of reporting abuse
  293. lovetox but i think most people receive spam and want to block and report
  294. Zash I mean, it doesn't cover handling of abuse reports (by admins)
  295. lovetox why would this be a XEP though?
  296. lovetox i guess admin looks at it, looks at reported account, and decides to ban or warn
  297. Zash Pretty much.
  298. Martin It does expose the message content?
  299. Zash no
  300. Zash An admin might be able to retrieve that from MAM tho
  301. Martin I don't want to dig into users MAM…
  302. Martin Is this even legal?
  303. Zash I think it was suggested last time this came up that it could include an archive id, then the admin can pull only that message and look at it.
  304. Matt it is legal
  305. Zash "Here, look at this spam/abuse" would probably make it legal, but IANAL
  306. Martin Ok, then I have a moral problem with it. :D But if I can get only the reported message via the ID I'd be good with it.
  307. Matt did you know if you ping in a certain state in america its illegal
  308. Matt i think thats so crazy
  309. Martin Zash: Yeah, my concern was seeing other messages as well, while digging through the archive, but with retrieving it by ID that would be no issue anymore.
  310. Zash And that should also cover concerns about forgery that would be possible if you included the whole message when reporting.
  312. Matt but thats what end to end encryptoion is for
  313. lovetox em, if you want to stop spammers you have to look at content
  314. lovetox if you say outright you will never look at user content, then there is really no way for you to stop spammers, and abuse reports could be false
  315. Martin I won't look at _all messages_ because one was reported at spam.
  316. Zash For spam reports admins might only be interested in aggregates for forwarding to the originating server.
  317. Zash 377 data isn't really used today afaik
  318. Zash OTOH, not sure how the XMPP story on handling other kinds of abuse is today.
  323. lovetox Martin, you look at the last 20 messages
  324. lovetox you see with one look if its obviously spam
  325. Guus So, in project management speak, MVP is "minimal viable product" - but what's MLP?
  326. Matt What about fail2ban??
  327. SouL I've never heard of Minimum Lovable Product, Guus :D https://themindstudios.com/blog/mlp-vs-mvp-vs-mmp/
  328. Guus woooow... thanks SouL. I googled, but didn't find that one
  329. SouL Remember to add many heart emojis if you do an MLP
