XSF Discussion - 2018-04-09

  229. edhelas


  230. edhelas

    > I think the solution is a set of improvements. RSS as a protocol needs to be expanded so that it can offer more data around prioritization as well as other signals critical to making the technology more effective at the reader layer. This isn’t just about updating the protocol, but also about updating all of the content management systems that publish an RSS feed to take advantage of those features.

  231. edhelas

    Pubsub :-° ?

  232. marmistrz has joined

  233. Ge0rG has joined

  234. Steve Kille has joined

  235. Andrew Nenakhov

    I've read that article in my RSS reader. To me, RSS is pretty much alive.

  236. edhelas

    Andrew Nenakhov don't wanna use Pubsub :D Movim is my news reader B-)

  237. Guus has left

  238. Martin has joined

  239. SaltyBones has left

  240. rtq3 has left

  241. remko has joined

  242. edhelas


  243. Valerian has left

  244. Valerian has joined

  245. goffi has joined

  246. Andrew Nenakhov has left

  247. Andrew Nenakhov has joined

  248. Andrew Nenakhov has left

  249. Andrew Nenakhov has joined

  250. Valerian has left

  251. ludo has left

  252. ludo has joined

  253. efrit has joined

  254. Valerian has joined

  255. ralphm has joined

  256. jonasw

    GDPR meeting in 5

  257. jonasw

    according to my clock and calendar at least

  258. winfried

    jonasw: according to mine too ;-)

  259. jonasw


  260. jonasw

    pep., Ge0rG, you there?

  261. Ge0rG

    jonasw: kind of

  262. Ge0rG

    I fixed my poezio, but this is still the worst monday I've had this year

  263. jonasw


  264. Ge0rG


  265. jonasw

    Ge0rG, set up a disk quota for your borg things so that they can’t eat all the disk space.

  266. jonasw

    disk quotas aren’t deep magic

  267. Ge0rG

    jonasw: good point. But then I couldn't prune the old backups any more because pruning would exceed the quota

  268. jonasw

    also allows you to disable/unset the quota while pruning when you need that

  269. jonasw

    it’s all a matter of invoking edquota and increasing the limit temporarily :)

  270. Ge0rG

    I didn't even anticipate the backups to grow that large.

  271. jonasw

    or maybe use that cuteborg alpha software which schedules prunes automatically. (shameless plug)

  273. pep.

    My computer has decided to be angry at me this morning, should be here soon

  274. jonasw

    okay, now I’m getting wary, why hasn’t any of my stuff failed today.

  275. winfried

    bad digital karma today, what did we do to our computers to make them so upset?

  277. pep.

    made it!

  279. jonasw


  280. jonasw

    I’m not up for chairing or anything, having mild headache.

  281. winfried bangs a gavel and looks around in mild bewilderment, what to do now?

  282. pep.


  283. winfried

    Would it be ok, to slowly progress through the list at the wiki?

  284. jonasw

    seems good

  285. pep.

    Ah I haven't updated with last week's

  286. Ge0rG

    Yes please

  287. winfried

    Ge0rG: you mentioned there are discussions about ip-adresses being pii or not, maybe we should settle that one first

  288. Ge0rG

    winfried: I don't think we should.

  289. jonasw

    I don’t think that’s useful.

  290. pep.

    Can _we_ settle anything?

  291. winfried

    ok, we don't settle it ;-)

  292. Ge0rG

    winfried: in our context it's best to consider them as PII

  293. jonasw

    first, what pep. says, lots of laywers have been fighting over that already before the GDPR, and second I think that would let us lose ourselves in details.

  294. Ge0rG

    winfried: my point was just to show the ambiguity of the legal framework

  295. winfried

    Ge0rG: clear and good course of action

  297. winfried

    Q1.1d, do we dig into that one further?

  299. Ge0rG

    For the logs and newcomers: https://wiki.xmpp.org/web/GDPR

  300. Ge0rG

    winfried: I think we weren't done with 1.1c for s2s

  301. winfried

    ok, 1,1c it will be

  302. pep.

    I want s/Archiving/user content/ on the notes to make it just like the others

  303. pep.

    I would s/Archiving/user content/ on the notes to make it just like the others

  304. Ge0rG

    Yes please

  305. winfried


  310. Ge0rG

    We are also lacking logs of 1.1b s2s in the wiki

  311. pep.

    yes, let me put last week's in there

  312. Ge0rG

    Maybe somebody could paste from the minutes

  313. Ge0rG

    So that we can proceed from there

  314. winfried

    maybe it is good to make clear: transfer itself is a processing, but needs explicitation about what data is transfered, what processing is done on the other side and with what purpose...

  315. jonasw

    can we know the processing on the other side, really?

  316. jonasw

    since there’s no contract or something which would be binding for the other side.

  317. pep.

    I don't think we can

  318. jonasw

    they could store the message forever even without advertising MAM

  319. pep.

    I think we'd best assume the worst once the messages are gone over s2s

  320. jonasw

    yes. the question is: how do we tell the users?

  321. pep.

    Just as I did? :/

  322. winfried

    maybe we can define a xep & service discovery that just says: this server keeps to these rules....

  323. jonasw

    and how do we tell the users in a way that they can give consent properly, and don’t wander off to silo services?

  325. jonasw

    winfried, hmm, you mean the GDPR-policy-XEP pep. wanted to write for c2s could be used for s2s too?

  326. jonasw


  327. jonasw

    question is, would a user still have to consent for each remote domain?

  328. pep.

    Also, I trust my own server, I'm not sure I trust many others

  329. Ge0rG

    jonasw: I tend to slightly disagree

  332. winfried

    jonasw: think that in many cases it does't, but it is our task to find out

  333. jonasw

    Ge0rG, with what exactly? I think I mostly asked questions at this point :D

  334. Ge0rG

    as winfried said last time, this is handing off of data to another controller. The other controller is also bound by GDPR rules, so they can't just do anything they want with the data. In theory

  335. winfried

    pep.: yeah, we move to the delicate field legal trust...

  336. jonasw

    Ge0rG, sooo... if one federates with servers which have users which are inside the EU you’re under GDPR?

  337. jonasw

    Ge0rG, sooo... if you federate with servers which have users which are inside the EU you’re under GDPR?

  338. Ge0rG

    What I'd like to know more about is whether we need some explicit legal framework for handing off data, or if this is covered by the user's implicit consent of wanting the message delivered

  339. Ge0rG

    jonasw: basically, yes.

  340. jonasw


  341. jonasw

    so everything is under GPDR now.

  342. Ge0rG

    jonasw: as if it wasn't before

  343. jonasw

    yeah, with "now" I mean "when it takes effect"

  344. Ge0rG

    winfried: I suggest we have a look at the "incoming s2s" situation first, and then try to reverse the approach for "outgoing"

  345. winfried

    Ge0rG: smart!

  346. Ge0rG

    obviously, with incoming s2s we are already required to be GDPR compliant.

  347. winfried

    Ge0rG: if you are situated in the EU or if you are targeting EU users

  348. Ge0rG

    We receive data via s2s (s2s meta-data, user content, user meta-data), and we are kindly asked to process that data in some way that was implied by the user

  349. Ge0rG

    winfried: s/targeting/not explicitly blocking/ ;)

  350. winfried

    Ge0rG: hmmm... my reading up to now was targeting, but that maybe the old legal framework....

  351. jonasw

    you can’t block EU users s2s-wise

  352. jonasw

    but also you can’t really target EU users s2s-wise

  353. jonasw

    so I’m like 😕

  354. pep.

    jonasw, not like it's impossible

  355. Ge0rG

    winfried: targeting is implied if you don't exclude them explicitly, AFAIU

  356. Ge0rG

    winfried: but back to the topic.

  357. winfried is diving in his bible

  358. pep.

    When does a service become "accepting EU users" exactly? Say as an EU citizen I go to a japanese website, with their server located in Japan, there's not GDPR applying is there

  359. pep.

    (I'm here to ask the dumb questions)

  360. Ge0rG

    I'd say that processing of received data is covered by Art6 1.f "processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party" - the legitimate interest is to deliver the message to the appropriate user

  361. jonasw

    if LQ1 evaluates to "yes", it’s more tricky than that though

  362. winfried

    We are moving a bit forward and backward trough the topics...

  363. Ge0rG

    This means two things basically: a) we are allowed to do everything appropriate to deliver the content; b) we are not allowed to do anything that's not directly required for that

  364. jonasw

    winfried, okay, where were we?

  365. Maranda processing hints mandatory *coughs*

  366. Ge0rG

    GDPR hints.

  367. pep.

    Maranda, we can see for technical details later

  368. winfried

    1.1c s2s wasn't it?

  369. Ge0rG

    winfried: yes please

  370. winfried

    incoming and outgoing

  371. winfried


  374. winfried

    - store in roster of peer

  375. Ge0rG

    We should cover each one of these: s2s meta-data (IPs, hostnames, sessions, server logs?) - GDPR probably doesn't apply user meta-data (presence, subscriptions, message routing) user content (messages, pubsub, etc.) MUC history, MUC MAM Remote components (e.g., roster management)

  376. winfried

    Ge0rG: yes that was what I was looking for

  377. Ge0rG

    s2s meta-data: R49 if at all

  378. jonasw

    user metadata: minimal: forwarded to receiving users connections typical: stored while receiving user is online (to avoid having to send out probes for new resources)

  379. Ge0rG

    jonasw: subscription requests and roster info is stored

  380. jonasw

    Ge0rG, that’s content though?

  381. jonasw

    from the categories in Q1.1b

  382. pep.

    (update the wiki I added 1.1c from the minutes)

  383. Ge0rG

    jonasw: ah, right

  384. jonasw

    user content: minimal: forwarded to receiving users connections if online; storage of roster-related things with account. typical: minimal + offline-storage if offline or even MAM for undefined period of time for messages

  385. Ge0rG

    I'm not sure if A in user B's roster is subject to user B's privacy laws, user A's or both'.

  386. jonasw

    probably mostly B

  387. winfried


  388. jonasw

    I can have you in my phone book and you can’t force me to erase that, I think, due to private use.

  389. winfried

  390. Ge0rG

    jonasw: but I can get you fined it you upload my phone number to whatsapp.

  391. jonasw

  392. pep.

    Which is what's happening here

  393. jonasw

  394. pep.

    Well not whatsapp

  395. Ge0rG

    jonasw: so maybe I can also get you fined if you store my JID and name on your server?

  396. jonasw


  397. pep.

    Ge0rG, so what do you propose? When a user calls for their right to erasure, that's propagated to every other server? And they magically disappear from everybody's roster at the same time?

  398. winfried

    no, when I am uploading pii of somebody else to a server without consent from that somebody I can be fined. Not because of that server but because of the uploading

  399. ralphm has joined

  400. jonasw

    sooo..... spammers are in violation of the GDPR?

  401. winfried

    s/consent/groud for processing/

  402. jonasw

    because they upload my email adress to some server?

  403. winfried

    jonasw: yes

  404. pep.

    That wouldn't really surprise me

  405. pep.

    It's not like they weren't already in violation of any other laws

  406. Ge0rG

    we have two s2s data specials not yet covered in 1.1c: - MUC (is that different from plain s2s?) - remote roster management

  407. jonasw

    hm, delivering a message is probalby "ground for processing"

  409. winfried

    jonasw: it is needed for delivering a service you have agreed to (or not, in the case of spam)_

  410. jonasw

    I think for (semi-)anonymous MUCs, we really need to show users a message that the MUC is anonymous and they have to assume that all messages are public?

  411. jonasw

    For (semi-)anonymous MUCs, do we need to show users a message that the MUC is anonymous and they have to assume that all messages are public?

  412. pep.

    What about adding 170 when MAM MUC is enabled

  414. jonasw

    because we can’t have any type of s2s-consent in that case because we don’t know to which domains the messages may go

  415. jonasw

    pep., mandatory, IMO

  416. pep.


  417. pep.

    I asked something similar on jdev@ not so long ago

  418. pep.

    And I think maranda also did talk about that

  419. Maranda


  420. jonasw

    the exact definition is:> Inform occupants that room logging is now enabled

  421. jonasw

    the exact definition is: > Inform occupants that room logging is now enabled which fits this use-case exactly.

  422. jonasw

    (note that it does not include "public")

  423. jonasw

    (we might want to have a different status code for *public* logging)

  424. jonasw

    (as opposed to members-only MUC MAM access)

  425. Ge0rG

    jonasw: MAM is subject to the same rules as room access

  426. Ge0rG

    in theory.

  427. jonasw

    Ge0rG, yes.

  428. Maranda

    Gajim does exactly that for status 170/171 without making dumb distinctions

  429. Ge0rG

    I wouldn't be surprised if some implementations make MAM access public ;)

  430. winfried

    so a possible processing may be "publicising the MUC logs on different channels or to non-members"? (bringing it back to 1.1c)

  431. jonasw

    winfried, yes.

  432. Maranda

    Aka just "room logging" enabled/disabled

  433. pep.

    Nothing prevents a muc owner from changing the member-only policy though, and suddenly everything that's been said before is public

  434. Ge0rG

    pep.: nothing prevents a muc owner to publish their local log of the MUC in the New York Times

  436. winfried

    maybe some laws prevent that?

  437. vanitasvitae has joined

  438. Ge0rG

    I would consider that all these deliberate actions by a MUC participant to leak data fall under their respective responsibility

  439. jonasw

    winfried, one processing is at least "store the whole conversation on the MUC service"

  440. Ge0rG

    and not under "s2s data processing"

  441. jonasw

    +1 Ge0rG

  442. winfried


  443. pep.


  444. Ge0rG

    so it's "store on the service and make it available to room members"

  445. winfried

    and it /may/ be also publishing it

  446. jonasw

    I’d like to have a status code for that, btw

  447. jonasw

    because that could save us from 9.1 trouble (there’s something about "manifestly made public" in there, and if we can get clients to show "THIS ROOM IS PUBLICLY LOGGED", we’re out of trouble there I think)

  448. jonasw

    do we have a technical ToDo list?

  449. winfried

    jonasw: not yet ;-)

  450. pep.

    Can make one

  451. jonasw

    pep., that’d be great

  452. pep.

    I can add EULA XEP in there :x

  453. jonasw

    I wouldn’t act on this right away, but instead keep it a WIP until we figure that we really need it.

  454. jonasw

    I wouldn’t act on the ToDo list right away, but instead keep it a WIP until we figure that we really need it.

  455. winfried

    (BTW one of my cats is hunting my phiysical mouse, the other one the cursor on the screen, am a bit distracted)

  456. winfried

    jonasw: +1

  457. pep.

    jonasw, the status code you're talking about is 170 or similar right

  458. jonasw

    pep., yes

  459. jonasw

    winfried, pics or it didn’t happen ;-)

  460. winfried

    jonasw: my cats have their privacy, I am not publishing them on the internet!

  461. pep.

    So.. what do we have atm, 1.1c S2S is split in two,

  462. Maranda

    And attach those to the Meeting Minutes.

  463. Maranda

    (cat pictures)

    Don't forget remote roster management. It's technically well designed, so no problems there, but we need to mention it

  466. winfried

    Ge0rG: +1

  467. pep.

    Ge0rG, what about it

  468. winfried

    it is a nice example of privacy by design, but it is a possible processing of the s2s case

  469. winfried

    thinking about it, it is also a processing of the c2s case...

  470. winfried

    we need to list it and mention it is covered by explicit consent

  472. jonasw

    RRM ist really good, taking a look at it for the first time now

  473. pep.

    I'm not sure I get all these comments. How is it privacy by design

  474. pep.

    What changes from normal roster management

  475. jonasw

    except that it has XMPP-technical flaws

  476. jonasw

    pep., the roster is managed by an entity which may be outside the domain of the user

  477. jonasw


  478. pep.

    jonasw, yeah I get that, so it's worse possibly

  479. pep.

    I mean GDPR-speaking

  480. pep.

    Than normal c2s

  481. jonasw

  482. winfried

    it is privacy by design because the spec demands explicit consent

  484. winfried

    I lost my overview over 1.1c

  485. winfried

    have we covered the s2s cases there?

  486. pep.

    jonasw, I see

  487. pep.

    just inbound?

  488. pep.

    And even then I'm not sure

  489. Ge0rG

    winfried: I think so

  490. Ge0rG

    the difference to c2s is probably that there are different retention times for data, and no explicit consent from the user

  491. Ge0rG

    oh, there is also the "transport component" use case

  492. jonasw

    mmm, a whatsapp transport <3

  493. jonasw

    for super fubar

  494. Ge0rG

    If I register with icq.evildomain.com, it will store/process my ICQ credentials

  495. winfried

    Ge0rG: that is an interesting one

  496. pep.

    Isn't that another normal s2s case?

  497. jonasw

  498. pep.

    "We don't know what can happen on the other side"

    pep.: that one is

  500. pep.

    And they won't get more than what we give them

  501. winfried

    but whatsapptransport.trusteddomain.com is different

  502. jonasw

    I wonder if we want a way to give consent to the processing done by an s2s domain. then there could be something pubsubby where clients can query which s2s domains the user consented with and show that in the UI. warn the user when sending a message to a non-consented domain with "review the privacy policy" and offer doing the in-band consent thing as per the EULA XEP.

  503. winfried

    because trusteddomain is transfering it to a third server

  505. jonasw

    fwiw, I’m going to head out in four minutes.

  506. pep.

    How long do you want to go btw?

  507. pep.

    jonasw, I see value in that, I'm not sure it's not going to be an annoying process though

  508. pep.

    It's the annoying "yes I agree" that everybody is going to overlook in the end

  509. jonasw

    could be simplified in the UX of course, but technically we might need something like that

  510. jonasw

    and the server could even block stanzas to non-trusted s2s domains in strict deployments.

  511. lnj has left

  513. winfried

    maybe set a next session? Maybe we should wrap up this one and move on to the interesting stuff....

  514. pep.


  515. pep.

    Date of next?

  516. jonasw

    following weeks this time won’t work for me

  517. jonasw

    (I know I’m special with scheduling and I’m sorry)

  518. pep.

    I can do any

  519. Ge0rG

    winfried: actually I'd argue that a remote transport is subject to a direct relationship with the user as a data controller

  520. Maranda

    Can I make an addition to s2s message processing? If hints are made mandatory that could pose a disclaimer caveat, in which if a user doesn't give explicit consent to treatment by a remote entity and I flagged all messages with "no-store" or "no-permanent-storage" it could be argued the responsibility falls directly on the 3rd uncompliant party

  522. pep.

    Tomorrow? Wed 12:30 or 13:30CEST? (like before)

  523. Maranda

    Because that'll be an impeding problem for sure

  524. lumi has joined

  525. jonasw

    pep., tomorrow is Tue in my calendar

  526. jonasw

    Wed won’t work for me

  527. pep.

    jonasw, yes it was two questions :p

  528. jonasw

    I’d prefer the time we did today actually, I can arrange that any day except mondays.

  529. winfried

    both work for me

  530. pep.

    If same time, I can't do Tue/Thu

  531. jonasw

    (and wednesdays, sorry)

  532. jonasw

    but 12:30 CEST also works, except on wednesdays

  533. pep.

    Tue 12:30CEST then?

  534. jonasw


  535. winfried


  536. Ge0rG


  537. jonasw


  538. pep.


  539. jonasw

    okay, gotta head out, see you folks

  540. winfried


  541. winfried


  542. pep.

    I need my coffee now

  543. pep.

    You guys caught me early

  544. winfried

    pep.: :-D

  545. winfried

    pep.: are you taking notes/logs again? maybe coordinate who puts them in the Wiki

  546. pep.

    I'll try to come up with the minutes before noon

  547. pep.

    If you can put that on the wiki that'd be great :p

  550. winfried

    I'll try, won't be home from work meetings till 0:30 today, but I will have some time in trains...

  551. Ge0rG

    trains. The place where you can work on the really important things, while telling your employer that you were too tired to do the after-meeting reports.

  552. rtq3 has left

  553. winfried

    Ge0rG: watch out, this MUC has a public log :-D

  557. daniel

    > trains. The place where you can work on the really important things, while telling your employer that you were too tired to do the after-meeting reports. Trains. Those things that don't run if there is a signal failure. What ever that means. A rat bit through a cable maybe? Because apparently something as important as signals doesn't have redundancy

  558. Ge0rG

    winfried: my employer isn't paying overtime. Sometimes I have days when I need to get out of bed at 4AM, have some 12hrs of train time with a business meeting in the middle. They can't expect me to work 16hrs ;)

  559. Ge0rG

    daniel: the most frequent cause of delay at Deutsche Bahn is copper theft, I've heard.

  560. Ge0rG


  561. Valerian has left

  562. Valerian has joined

  567. alexis has joined

  568. lnj has left

  569. moparisthebest has joined

  570. winfried

    daniel Ge0rG here in the netherlands it is / was a major cause for delays too. They do have more theft-proof infrastructure nowadays

  574. Ge0rG

    winfried: do you have any news regarding the 112 app?

  580. Maranda

    And from my point of view, after glancing at it, GDPR is made to "make it impossibile" for complex decentralised environments to exist, so whatever will be done here will be for naught beside that when a user registers he'll get a message stating "do you give consent to treatment of your data by third parties", "I give consent" == s2s enabled, else s2s disabled.

  581. Maranda


  582. Ge0rG

    Maranda: your point of view is cynically pessimistic.

  585. Ge0rG

    Like with the cookie directive. The intention was to inform users and to allow them to opt out. Then it was perverted by the "content providers" to blame the EU

  586. rtq3 has joined

  588. Maranda

    Ge0rG: too bad that it looks to me that for what we could ever attempt to do to be compliant, due to the nature of xmpp we could never fully be.

  589. Maranda

    But we will see as usual

  590. winfried

    Ge0rG: yes, I have the interview done and a concept-blog, still working on the whitepaper. They have to check with their security persons I don't publicise any confidental information before I can show you the results

  592. xnyhps has joined

  593. Ge0rG

    winfried: I'm a security person. I can do a closed-group review ;)

  594. winfried

    Ge0rG: :-D

  595. winfried

    Ge0rG: I got a fascinating insight in the world of Belgian organisation and security. I can already reveal the organisation operating *all* of the telecom infrastructure in Belgium has more firewalls then employees ;-)

  596. winfried

    (all of the governmental telecom infrastructure)

  597. Ge0rG

    winfried: that sounds like much better data hygiene than T-Mobile Austria

  599. blabla has joined

  600. Valerian has left

  601. lskdjf has joined

  602. ralphm has joined

  604. ralphm has left

  605. Syndace has joined

  606. Syndace has joined

  607. ralphm has joined

  608. matlag has left

  609. xnyhps has joined

  610. Dave Cridland has left

  611. Dave Cridland has left

  612. rtq3 has left

  613. rtq3 has joined

  614. matlag has joined

  615. SaltyBones has left

  626. MattJ has left

  627. lskdjf has joined

  628. MattJ has joined

  629. ludo has left

  630. ludo has joined

  631. moparisthebest has joined

  632. MattJ has left

  633. moparisthebest has joined

  634. MattJ has joined

  635. Alex has joined

  636. lnj has joined

  637. lumi has joined

  638. jubalh has joined

  645. jonasw

    > winfried: my employer isn't paying overtime.

  646. jonasw

    > winfried: my employer isn't paying overtime. […] have some 12hrs of train time with a business meeting in the middle. Ge0rG, you’re not good at advertising.

  649. Ge0rG

    jonasw: my employer will gladly pay for the hotel room so you can arrive on the day before and have a pleasant day on site. I just prefer to sleep in my own bed.

  650. jonasw

    I hate hotels, exactly.

  651. Kev

    I often take my own pillow with me when I go to the office, if I'm driving (not so much with carrying it on the train).

  652. Ge0rG

    I don't hate them. I just love to sleep at home

  653. jonasw

    Ge0rG, yeah, that’s what i meant.

  654. jonasw

    also see what I wrote in the other muc.

  655. Ge0rG

    I'm still catching up with last night.

  658. SaltyBones has left

  659. winfried

    Ge0rG: I was pretty impressed with the data infrastructure they are using, they even build a (rudimentary) application firewall for XMPP!

  662. jonasw

    does conversations get consent from the user for using google cloud push? :)

  663. lumi has joined

  664. Dave Cridland has left

  665. Dave Cridland has left

  666. jonasw

    okay, so since I have merge powers, I need advice on what to do with this: https://github.com/xsf/xmpp.org/pull/425

  667. jonasw

    I was actually happy that pidgin dropped off the list and was silently hoping that it wouldn’t re-appear.

  668. jonasw

    but apparently that didn’t happen

  669. jonasw

    so what to do now?

  670. jonasw

    possibly a question for board

  671. Ge0rG

    jonasw: the right way would be for the Board or some other Official Entity to say "no" to this request. The loophole workaround would be to reject the PR until it's vouched for by an identified pidgin developer

  672. jonasw

    Ge0rG, maybe you should add your "ceterum pidgin delendam esse" to board agenda instead of council ;)

  673. Ge0rG

    jonasw: I don't have the power to add things to Board's agenda

  674. Ge0rG

    jonasw: and I don't have the karma either. Whatever I wanted from Board so far was vetoed.

  675. marmistrz has joined

  676. jonasw

    Ge0rG, ask Guus or MattJ to add "Vote for elimination of all pidgin references from xmpp.org" to it :)

  677. jonasw

    Ge0rG, the laws of probability say that this time it’ll work!!k

  678. jonasw

    Ge0rG, the laws of probability say that this time it’ll work!!1

  680. jubalh has joined

  681. jubalh has left

  682. ralphm has joined

  685. flow

    Ge0rG, I note that there is a carbons plugin for libpurple: https://github.com/gkdr/carbons

  686. jonasw

    plugins for libpurple are always good.

  687. jonasw

    they rarely break anything or introduce security issues or something like that.

  688. Ge0rG

    flow: do you want to explain to my aunt how to install it?

  691. Kev

    BTW, I think the easiest way to (potentially) resolve the Pidgin thing is to ask the project if they mind not being listed.

  692. Kev

    If they say "Yeah, that's fine, it's not very current", there's no need to make difficult decisions.

  693. jonasw

    Kev, they made a release a few weeks ago

  694. Kev

    Does that contradict anything I said? :)

  696. jonasw

    I’m not awake.

  704. Maranda

    So, dead-end for GDPR is.. 25th May again?

  705. jonasw


  706. jonasw

    towel day

  707. Maranda

    And I see Ge0rG with an avatar feels strange compared to the usual "G"

    jonasw, ok I suppose I'll go with my cynical, pessimistic idea, until I see more definite developments.

  710. Maranda

    (which I do not)

  719. alexis has joined

  720. marmistrz has left

  723. valo has joined

  724. daniel has left

  725. daniel has joined

  731. Ge0rG

    Dave Cridland: I'd like to put up "kill GC1.0" onto the Council agenda for this week. I've collected some numbers, and I'll write a mail if I manage somehow.

  732. Ge0rG

    I'm also sure there was some other thing I promised / intended to PR.

  735. alexis has left

  736. alexis has joined

  737. marmistrz has joined

  738. Valerian has left

  739. Valerian has joined

  740. marmistrz has left

  741. daniel has left

  742. daniel has joined

  748. alexis has left

  749. alexis has joined

  750. ludo has left

  751. ludo has joined

  752. j.r has joined

  760. marmistrz has joined

  761. alexis has joined

  766. SamWhited has left

  767. SamWhited has joined

  777. ralphm has joined

  778. waqas has joined

  779. Kev has left

  783. Maranda has joined

  784. Maranda has joined

  785. Martin has left

  799. Martin has joined

    https://arstechnica.com/tech-policy/2018/04/hours-after-zuck-deletion-scandal-facebook-announces-new-unsend-feature/ - this totally triggers the GDPR

  809. Ge0rG

    "You can't delete sent or received messages from someone else's device." -- unless you are Mark Zuckerberg.

  810. Andrew Nenakhov

    What's next, unsend email? 😂

  811. Andrew Nenakhov

    I always thought that features like last message correction are just silly

  812. Ge0rG

    Andrew Nenakhov: that's old. https://support.office.com/en-us/article/recall-or-replace-an-email-message-that-you-sent-35027f88-d655-4554-b4f8-6c0729a723a0

  813. Ge0rG

    LMC is utter shit.

  814. Ge0rG

    LMC is actually useful in most cases.

  815. MattJ

    /load display_corrections

  816. Andrew Nenakhov

    Ge0rG, > Message recall is available after you click Send and is available only if the recipient has an Exchange account within the same organization. Not really working in federated environment

  817. Ge0rG

    Andrew Nenakhov: tough luck.

  818. Zash

    I motion that we all get ice cream! (everyone says +1) /correct I motion that we do evil things!

  819. daniel has left

  820. Maranda

    Ge0rG sucks.

  821. Maranda


  822. Maranda


  823. Ge0rG

    so.... everyone licking ice cream, except for Maranda who's licking toads?

  824. Maranda

    Ge0rG, who knows maybe they'll turn into something else, or kill me, or both.

  825. waqas

    I haven't had ice cream in days…

  826. Andrew Nenakhov

    I get a feeling that xsf has entered a steep decline

  827. Ge0rG

    I have a fridge full of ice cream at my old home, and no sensible logistic way to get it into the new home.

  828. Ge0rG

    Andrew Nenakhov: the xsf MUC is not representative of the XSF.

  829. waqas

    Ge0rG: "sensible"

  830. Maranda

    Ge0rG, it's not?

  831. Maranda


  832. Ge0rG

    Andrew Nenakhov: the only decline the XSF is facing is that of available time of its members.

  833. Maranda

    Disclaimer 😚 ™

  834. Maranda


  843. rtq3 has joined

  847. jonasw

    I just came back from having ice cream.

  848. jonasw

    that’s relevant, r ight?

    /topic Ice Cream

  851. jonasw

    that’s relevant, right?

  852. Ge0rG

    Luckily there is no XMPP off-topic MUC.

  853. jonasw

    /topic Chips

  871. goffi has joined

  895. rtq3 has joined

  896. lovetox has joined

  959. lovetox

    if a XEP says stuff like : Given the foregoing discussion, it is evident that an entity could receive any combination of iq:register, x:data, and x:oob namespaces

  960. lovetox

    then i know im in for a lot of fun

  961. moparisthebest

    what are email providers doing with their identical S2S problem?

  965. Valerian has left

  966. Valerian has joined

    moparisthebest, nobody knows

  975. jonasw

    moparisthebest, but the expectations might be different for email which might be relevant for law stuff

  976. moparisthebest

    why would expectations matter? they are 100% identical as far as I can tell

  977. jonasw

    moparisthebest, I’m not sure. people might not expect their IM to be stored indefinitely on some server. for mail, this might be different.

  978. moparisthebest

    why? maybe they think everyone uses pop3 and has the 'delete from server' box ticked?

  979. Zash

    moparisthebest: wasn't the box for "don't delete from server"?

  980. moparisthebest

    depends on the client I guess :)

  981. moparisthebest

    I'm just saying from a technical perspective, with regard to s2s issue, email and xmpp are identical, and since email is far more widely used by much bigger companies, I feel like we should just see what they are doing

  985. ralphm has joined

  986. Dave Cridland has left

  987. Maranda

    Identical me... thinks not.

  988. Maranda

    Comparing mail data with a xmpp s2s stream is weird at best.

  989. SamWhited has left

  990. Maranda

    One it's just a singler envelope the other... is... a stream? With potentially much more data passing by.

  991. Maranda mutters says the word.

  992. marmistrz has left

  993. moparisthebest

    Maranda, sorry, how is it not identical?

  994. Maranda

    I just said.

  995. moparisthebest

    you send individual messages to a federated server

  996. moparisthebest

    they may or may not keep them

  997. moparisthebest

    the 'potentially more data' seems totally wrong too

  998. Maranda

    You just send individual messages? Oh rly?

  999. alexis has left

    how often do you send/recieve xmpp messages with 25mb attachments sent with bob or whatever :P

  1001. jonasw

    I tend to agree that they’re pretty much identical regarding the data which passes.

  1002. moparisthebest

    that happens regularly with email

  1003. alexis has joined

    Hmmm nay, but okay.

  1009. Dave Cridland has left

  1010. moparisthebest

    Maranda, how do you think they are different? because xmpp often sends multiple messages over a single connection?

  1011. moparisthebest

    because smtp does that too, and so does imap, pop3, etc

  1012. Maranda

    <incoming-routed presence="2078391" message="644568" iq="1050302"/> <outgoing-routed presence="428397" message="152432" iq="985607"/>

  1013. Maranda coughs.

  1014. moparisthebest

    that's 2 messages I guess, still not getting the point

  1015. Maranda


  1016. SamWhited

    Please try to explain with words and not just examples, because I don't understand what you mean either.

    ... except that lots of stuff doesn’t work with only normal messages.

  1039. jonasw

    like OMEMO.

  1040. Maranda

    mod_gdpr blocks everything going s2s, before user consented to the agreement and mainly 3rd parties treatment of his data passing by s2s.

    how does the user consent, and which agreement?

  1042. moparisthebest

  1043. Maranda


  1044. Maranda

    jonasw, ^

  1045. Ge0rG

    Maranda: you need to gain consent for each individual s2s domain, and link to their respective data privacy policy.

  1046. Dave Cridland has left

    that seems utterly impossible Ge0rG

  1048. Maranda

    Ge0rG, do I? Me thinks that the above is legally valid.

  1049. SamWhited has left

  1050. Ge0rG

    Also, I don't understand how email and xmpp are different either, from a data protection / data retention point of view

    .oO(plot twist: user is currently negotiating for a power exchange relationship and replies with "I consent" to the wrong message.)

  1054. jonasw

    Maranda, I don’t think that works either. you need to make the user aware of the specific data and metadata which may be sent to the remote domain.

  1056. jonasw

    users might not be aware that the timestamp of their last online presence would be shared for exampale

  1058. Maranda

    Ge0rG, it's implicit that if a from capuleti.is user chooses to have a contact to romeo.is then whatever data gets shared with romeo.is is *his/her sole* responsibility and that the data going to romeo.is will be treated by romeo.is

  1059. Maranda

  1060. jonasw

    Maranda, which ToS?

  1061. Maranda

    The one which I'll add options to add you can't cover everything In-Band, else I need to send a never ending wall.

  1062. Maranda

    The one which I'll add options to add you can't cover everything In-Band, else I need to send a never ending wall of text.

  1063. jonasw

    that’s why we were discussing the EULA XEP

  1064. alexis has left

  1067. Andrew Nenakhov has joined

  1068. alexis has joined

  1069. Maranda

    jonasw, which brings to the problem good luck getting every implementation and expecially every server federating to compliant by the 25th.

    moparisthebest, true, but they may be gambling on the fact that nobody is going to risk to burn down all of email with a lawsuit.

    Problem is that the deadline is too near now we should have moved as soon as GDPR got out in 2016 imho

  1082. jonasw


  1083. moparisthebest

    that's a fine bet for my person email, but gmail/hotmail surely would just have to pay germany a few trillion dollars or something

  1084. Maranda didn't even know about it before just recently.

  1085. moparisthebest

  1086. Dave Cridland has left

  1087. Dave Cridland has left

  1088. moparisthebest

    but still as soon as there's a draft of "EULA" xep I'll link to that jonasw (obviously)

  1094. Chobbes has joined

  1095. moparisthebest

    that's true Zash , every IP/port combo needs another EULA, also from every switch/router along the way, right?

  1096. Zash


    Zash, yeah

  1098. moparisthebest

    I think even the concept of a EULA xep is a terrible idea for the above reason

  1099. moparisthebest

    if widely implemented, it'd kill xmpp

  1100. jonasw

    I was thinking about that too during the last meeting. I wonder if we’re colossally missing something here.

    unfortunately not

  1105. Dave Cridland has left

  1134. jonasw

    moparisthebest, I am not talking about federation.

  1135. Dave Cridland has left

  1136. Maranda

    No time for xep-0389

  1137. moparisthebest

    ok, then I think it's a good idea

  1138. Maranda

    I feel

  1139. moparisthebest

    I just really don't want federation crippled due to some legislators with a superiority complex, and a likely wrong reading of the law by non-lawyers

  1140. Dave Cridland has left

  1141. Maranda

    Well I don't have 200k

  1142. Maranda


  1143. moparisthebest

    try voting for better people, or move :)

  1144. moparisthebest

    I mean we aren't writing code to cripple XMPP to china or russian standards

  1145. jonasw

    moparisthebest, I like the legislation actually.

  1146. Maranda

    All I want as a server operator is at least a blanket covering most of my ass

  1147. moparisthebest

    why write code to cripple XMPP to EU standards

  1148. Maranda

    moparisthebest, we need to get informative documentation done first, the most problematic bits are the data types descriptions, behaviour and garden-to-garden transits

    not sure exactly what you mean, but are you still just talking about registration?

  1166. moparisthebest

    in general when I've had to present lawyer-stuff to users, they like to lay stuff out themselves, and I always end up providing text as written

  1167. moparisthebest

    just a giant wall of text...

  1168. Maranda

    No, I said it anything protocol dependant wont see the light by the 25th

  1169. moparisthebest

    just turn off IBR and make them sign up with a web page?

  1170. moparisthebest

    the free world can continue to support IBR

  1171. sezuan has left

    Because beside the servers, there's clients and the "Pidgin" effect

  1174. pep.

    moparisthebest: make them sign up what with a web pave

  1175. pep.


  1176. pep.

    Please do provide input during the meetings if you have insight

  1177. Maranda

    The registration method is irrelevant we need documentation, and stuff to add to single service agreements

  1178. Maranda

    In the mean time

    moparisthebest: and it's not just to new users

  1180. moparisthebest

    well, web page registration lets you display a proper terms of service, and record them agreeing to it?

  1181. pep.

    Yeah but what goes into the EULA

  1182. Maranda

    moparisthebest, yes

  1183. pep.

    That's the whole poiny

  1184. andy has left

  1185. moparisthebest

    pep., ask your lawyer

  1186. pep.


  1187. Maranda

    But we need to know what to add to the service agreements...

  1188. alexis has left

  1211. Dave Cridland has left

  1212. alexis has left

  1213. alexis has joined

  1214. Maranda

    moparisthebest, but yes essentially that module should cover the edgy cases, in where if users stay in your garden it's "easy". When they get outside it's troubles they wrote the regulation specifically that way

  1215. SamWhited has left

  1217. Maranda

    (And they'll get prompted the first time they try to cross the wall)

  1219. pep.

    What really annoys/confuses me, is that everybody talks about companies when this is going to reach a lot more than that

  1223. moparisthebest

    that's the problem, they seem to have written the legislation to specifically target walled gardens like facebook/whatsapp etc

  1224. moparisthebest

    and it does a good job at that

  1225. moparisthebest

    but they totally ignored federated systems, and it seems to almost outright ban federated systems

  1226. moparisthebest

  1228. moparisthebest

    except they probably think 'email' and 'gmail' are the same thing...

  1229. Zash

    Has anyone reached out to those involved in drafting this and asked "how does this relate to email?"

  1238. sezuan has joined

  1239. Dave Cridland has left

  1240. rion has joined

  1241. moparisthebest

    davmail is what I used to use for that

  1242. Maranda has joined

  1243. Lance has joined

  1244. Dave Cridland has left

  1245. Dave Cridland has left

  1246. rion has left

  1292. Ge0rG

    The new CLOUD Act allows US agencies to obtain data hosted in Europe. I wonder how many days it will take for Russia to create a comparable legal framework.

  1293. lovetox

    but i read EU wanted to do this frist

  1294. lovetox

    but i read EU wanted to do this first

  1295. lovetox

    get data stored in US

  1296. lovetox

    so everybody gets all the data :)

  1301. ralphm has joined

  1449. Dave Cridland has left

