XMPP Service Operators - 2026-05-20


  1. tom

    riseup.net, fix your email server

  2. tom

    Hi! This is the MAILER-DAEMON, please DO NOT REPLY to this email. An error has occurred while attempting to deliver a message for the following list of recipients: [redacted]@riseup.net: 550 5.3.7 Spam is not welcome Below is a copy of the original message:

  3. Guus

    You sending spam again, Tom? ;)

  4. Guus

    (I'm not affiliated to any of this, just making unhelpful comments from the sidelines)

    😆 1
  5. tom

    no, they have their mailserver misconfigured to perm-reject all incoming mail instead of a temporary fail

  6. icebound.dev

    tom, I haven't exactly heard good things from riseup.net tbf

  7. icebound.dev

    besides this is email, I don't think riseup.net has an XMPP server?

  8. Kris

    They used to, but closed it over concerns related to metadata storage on their servers.

  9. Kris

    Which, given their specific threat profile is fair enough 🤷

  10. Kris

    (It was specifically about roster storage and thus a social graph)

  11. jjj333_p [pain.agency]

    it also barely worked. i remember recieving spam but not being able to message back id just get connection errors

  12. jjj333_p [pain.agency]

    so good riddance as far as im concerned

  13. erebion

    > tom, I haven't exactly heard good things from riseup.net tbf Details?

  14. moparisthebest

    update your nginx's again https://xcancel.com/nebusecurity/status/2057071579876753643

  15. moparisthebest

    at this point maybe just run your package manager update command in a while loop...

    🫠 1
  16. MattJ

    moparisthebest, to be clear, afaict there is nothing to update to right now? They announced the vulnerability, but no patch and no release has been made.

  17. moparisthebest

    it seems they reported it and nginx either will shortly or has patched it but I haven't seen anything concrete yet :(

  18. icebound.dev

    > update your nginx's again https://xcancel.com/nebusecurity/status/2057071579876753643 use OpenBSD httpd!!!

  19. moparisthebest

    *sigh* absolutely no reason to believe that has less undiscovered CVEs in it... can we just not here

  20. singpolyma

    it's not a CVE if it's undiscovered 😉

  21. moparisthebest

    I think that's what I said