-
moparisthebest
imagine "permanently bricking your rooms" being a thing that exists in a protocol lol https://grapheneos.social/@GrapheneOS/111123792907620861
-
moparisthebest
good to know we are ahead of the curve on moderation tooling too, and sadly not the only one that needs it
-
meson
moparisthebest: there's actually a good blog posts which summarizes the flaws in the matrix protocol, like the one mentioned in the toot, in a bit more detail: https://telegra.ph/why-not-matrix-08-07✎ -
meson
moparisthebest: there's actually a good blog post which summarizes the flaws in the matrix protocol, like the one mentioned in the toot, in a bit more detail: https://telegra.ph/why-not-matrix-08-07 ✏
-
deuton
> another fun way to attack a room is just to join hundreds or thousands of bots to the room ... > the only way to discard all of this spam complexity is to recreate the room. Sounds like effectively a way to brick rooms.
-
lovetox
What xmpp Server would prevent 100.000 Bots Form joining a mich?✎ -
lovetox
What xmpp Server would prevent 100.000 Bots Form joining a muc? ✏
-
lovetox
Of course one could think of measures, but i doubt any Server has them now
-
Ge0rG
most servers will probably just collapse ;)
-
jonas’
lovetox, but it won't render the room useless forever
-
jonas’
and countermeasures like not broadcasting presence do exist
-
jonas’
(in some implementations anyway)
-
lovetox
True we don't need to destroy a room to get rid of the problem
-
lovetox
What I wanted to say is ddos measures could be better on most servers
-
jonas’
sure
-
jonas’
there is always room for improvement
-
Link Mauve
lovetox, Prosody comes with mod_limits built-in, which would effectively prevent such an attack.
-
jonas’
mod_limits prevents joins?
-
Link Mauve
It prevents 100k joins at the same time, by preventing that s2s from delivering such traffic.
-
jonas’
assuming they're all from the same domain
-
jonas’
Link Mauve, actually, mod_limits may make things much worse in reality
-
jonas’
a join request is just a few dozen bytes. the response to a join fans out to multiple s2s links typically, and typically more than once on each s2s link. mod_limits will thus cause a massive backlog of outbound stanzas eventually (assuming other servers also use mod_limits)
-
Zash
Application aware multipliers for response size?
-
moparisthebest
> lovetox, but it won't render the room useless forever This is the point ↺
-
MSavoritias (fae,ve)
Plus no json and split brain problems. Matrix has said: > In future we can and will switch to a canonical binary format (eg the MIMI IETF work is rather quaintly fixated on using TLS Presentation Layer as a binary format).
-
MSavoritias (fae,ve)
Which mimi btw seems to adopt. Matrix is out of the picture it seems
-
singpolyma
good. let's create yet another standard. what could go wrong
-
moparisthebest
Obligatory https://xkcd.com/927/
-
Zash
What.
-
lissine
> Obligatory https://xkcd.com/927/ xmpp is the universal messaging standard, with it's focus on gateways