XSF Discussion - 2026-06-16


  1. Polarian

    re: UK social media ban, under further analysis, it seems to be a direct target at big tech, from the looks of things the law will ban everything, but it will be selectively enforced by OFCOM on mainly big tech, and the government has pledged to not ban Whatsapp or Signal.

  2. Cynthia

    Whatever Mr. Gooner says

  3. moparisthebest

    big tech only not facebook's whatsapp or amazon's signal ? that's hilarious

  4. Cynthia

    Where did you bring the "Amazon's signal" thing from

  5. Polarian

    > big tech only not facebook's whatsapp or amazon's signal ? that's hilarious moparisthebest, Not my wording :p

  6. Polarian

    In any case, with further analysis, XMPP could capitalise on this.

  7. Cynthia

    I cannot see any ties between Amazon and Signal Foundation and Signal Messenger LLC

  8. Polarian

    moparisthebest, theres some controversy as theres rumours bluesky *will not* be banned

  9. Polarian

    > I cannot see any ties between Amazon and Signal Foundation and Signal Messenger LLC funding afaik

  10. moparisthebest

    Cynthia: signal runs entirely on AWS no ?

  11. Cynthia

    That's like if I said Servers.Guru's Queer Spark

  12. Cynthia

    Or Hetzner's whatever XMPP server

  13. moparisthebest

    except AWS is big tech and neither of those are ?

  14. Polarian

    Although I agree with moparisthebest about the concern with using servers provided by others, especially those in big tech, I do think the most important thing is decentralisation. I see the point on signal relying on Amazon, but I wouldn't say Amazon _owns_ it, only _controls_ the infra.

  15. Cynthia

    Exactly

  16. gnemmi

    Polarian: no, I just wanted to let you know about that Mastodon toot I shared earlier

  17. Polarian

    > Polarian: no, I just wanted to let you know about that Mastodon toot I shared earlier oh right, thx!

    👍 1
  18. gnemmi

    And make sure you have your kern.ipc.mb_use_ext_pgs sysctl set to 0

  19. Polarian

    > And make sure you have your kern.ipc.mb_use_ext_pgs sysctl set to 0 hah...

    👍 1
  20. Polarian

    That vulnerability has been patched in 15.0-RELEASE-p10

  21. gnemmi

    That was the other option 💪

  22. Polarian

    see: https://www.freebsd.org/security/advisories/FreeBSD-SA-26:26.ktls.asc

  23. gnemmi

    Yup 👍

  24. gnemmi

    The vulnerability page is hilarious though 🤣

  25. Polarian

    yeah

  26. moparisthebest

    Polarian: woah did you ... have to reboot?

  27. Polarian

    > Polarian: woah did you ... have to reboot? indeed.

  28. Polarian

    In fact when you patch a freebsd system you have to reboot twice :)

  29. moparisthebest

    I thought you said that was a linux-ism

  30. Polarian

    The first reboot loads the new kernel, but then with the new kernel you need to update the userspace then reboot again :)

  31. Polarian

    > I thought you said that was a linux-ism No the linuxism is pkgbase, which makes this all into hundreds of small packages

  32. gnemmi

    >> I thought you said that was a linux-ism > No the linuxism is pkgbase, which makes this all into hundreds of small packages Fact

  33. Polarian

    > The first reboot loads the new kernel, but then with the new kernel you need to update the userspace then reboot again :) This is the original way of doing it, either through buildworld/buildkernel or through freebsd-update

  34. Polarian

    freebsd-update is now deprecated, pending removal in 2027 within 16.0-RELEASE

  35. Polarian

    moparisthebest, being a rust fan you might want to take a look at freebsd-rustdate, its freebsd-update but fast :p

  36. Cynthia

    I was expecting it to be slow

  37. kuyuhi

    if you're using rust and its not fast then what's even the point anymore

  38. Cynthia

    Was joking at the fact Polarian needed to emphasize

  39. Fishbowler

    > lol the UK can't extradite a citizen in another country for breaking UK law, it doesn't apply at all Yes, they can. That's exactly why treaties exist. Almost all countries have laws that don't stop at the water's edge. > for people outside of the UK, unless you are the US in which you have a extradition agreement with the UK, you are mostly safe. Lots of other places where an extradition arrangement exist - Canada, Australia, New Zealand, and the EU. > Will literally never happen Strong agree. The likelihood of anyone wanting an extradition arrangement for this are really really low though. Unless it's a big tech CEO. Also, quick opinion: the idea that social media is bad for young people ignores that it's also bad for grown-ups, but I guess the UK cares less about that. I'm really hoping VPN providers don't get caught up in all of this. They're just a tool vendor. Sorry, all caught up :)

  40. debacle

    We now have fixed the "working hours" for the Berlin sprint. Friday 15 to 20 CEST, Saturday and Sunday 10 to 19 CEST. Btw. there will be *stickers*! https://wiki.xmpp.org/web/Sprints/2026-06_Berlin

    🎉 3
  41. erebion

    >> lol the UK can't extradite a citizen in another country for breaking UK law, it doesn't apply at all > > Yes, they can. That's exactly why treaties exist. Almost all countries have laws that don't stop at the water's edge. > >> for people outside of the UK, unless you are the US in which you have a extradition agreement with the UK, you are mostly safe. > > Lots of other places where an extradition arrangement exist - Canada, Australia, New Zealand, and the EU. > > >> Will literally never happen > > Strong agree. The likelihood of anyone wanting an extradition arrangement for this are really really low though. Unless it's a big tech CEO. > > Also, quick opinion: the idea that social media is bad for young people ignores that it's also bad for grown-ups, but I guess the UK cares less about that. > > I'm really hoping VPN providers don't get caught up in all of this. They're just a tool vendor. > > Sorry, all caught up :) Can't comment on UK law, but I know Germany had a lède majesté law, often called "Insulting a foreign Majesty", or "Insulting a head of state" until the end of 2017, which in 2016 caused a Comedian to get in trouble for insulting Erdogan. However, the case has been dropped after a shitstorm. However, insulting the federal president is still illegal, but as it is already illegal to insult anyone else... whatever.

  42. erebion

    >> lol the UK can't extradite a citizen in another country for breaking UK law, it doesn't apply at all > > Yes, they can. That's exactly why treaties exist. Almost all countries have laws that don't stop at the water's edge. > >> for people outside of the UK, unless you are the US in which you have a extradition agreement with the UK, you are mostly safe. > > Lots of other places where an extradition arrangement exist - Canada, Australia, New Zealand, and the EU. > > >> Will literally never happen > > Strong agree. The likelihood of anyone wanting an extradition arrangement for this are really really low though. Unless it's a big tech CEO. > > Also, quick opinion: the idea that social media is bad for young people ignores that it's also bad for grown-ups, but I guess the UK cares less about that. > > I'm really hoping VPN providers don't get caught up in all of this. They're just a tool vendor. > > Sorry, all caught up :) Can't comment on UK law, but I know Germany had a lèse majesté law, often called "Insulting a foreign Majesty", or "Insulting a head of state" until the end of 2017, which in 2016 caused a Comedian to get in trouble for insulting Erdogan. However, the case has been dropped after a shitstorm. However, insulting the federal president is still illegal, but as it is already illegal to insult anyone else... whatever.

  43. dwd

    > > lol the UK can't extradite a citizen in another country for breaking UK law, it doesn't apply at all > > Yes, they can. That's exactly why treaties exist. Almost all countries have laws that don't stop at the water's edge. > … Sort of. Generally the treaties require something to be a crime in both countries.

  44. stratself

    if i were to host xmpp over tor, I'd have to use the default 5269 ports for federation right? will host-meta-v2 allow me to define custom ports?

  45. singpolyma

    Maybe, but no one supports that and you'd need to support port 443 to even use that xep anyway

  46. singpolyma

    plus you can't do HTTPS over tor so it may not comply with that xep anyway?

  47. singpolyma

    you can use SRV and DNS like normal with tor connections, but if you want a tor hidden service then yeah the only well supported way is to use the default ports AFAIK

  48. stratself

    i see. interesting theres the acmeforonions.org project, but i don't get the benefits very much

  49. stratself

    i did mean having an onionsite, yes

  50. singpolyma

    with an onionsite there's really no good reason not to use default ports anyway. since you can always have tor expose different "actual" local ports as the default ports on the site

  51. Cynthia

    > plus you can't do HTTPS over tor so it may not comply with that xep anyway? You can just... use HTTP

  52. Cynthia

    Like bend the rules a little and use HTTP then HTTPS for .onion sites

  53. singpolyma

    >> plus you can't do HTTPS over tor so it may not comply with that xep anyway? > > You can just... use HTTP sure but that's not what the XEP says to do

  54. contrapunctus

    > plus you can't do HTTPS over tor so it may not comply with that xep anyway? singpolyma: you can't do HTTPS over Tor? wot?? 😵‍💫

  55. singpolyma

    >> plus you can't do HTTPS over tor so it may not comply with that xep anyway? > > singpolyma: you can't do HTTPS over Tor? wot?? 😵‍💫 you can't get a CAB signed cert for an onionsite

  56. stratself

    > You can just... use HTTP I need some agreements on conventions in order to federate properly

  57. Cynthia

    stratself: Have you heard of sauteed onions?

  58. Cynthia

    A guy from the Tor dev mailing list told me about it

  59. stratself

    was that the link you sent few days back?

  60. Cynthia

    https://www.sauteed-onions.org/

  61. Cynthia

    Well, I don't remember

  62. stratself

    interesting, i may wanna have a look at that

  63. Cynthia

    The point of it is you put a subdomain that has your full onion address (without the dot) in your TLS certificate

  64. Cynthia

    Like `qvrbktnwsztjnbga6yyjbwzsdjw7u5a6vsyzv6hkj75clog4pdvy4cydonion.www.sauteed-onions.org`

  65. Ge0rG

    So it's a bunch of people who could get a certificate for any onion service, or let the domain slip to squatters if their research grant runs out?

  66. Ge0rG

    reminds me of some other community-powered infrastructure... 💡

  67. Cynthia

    Mullvad does use sauteed onions in their TLS certificate

  68. Cynthia

    https://crt.sh/?q=mullvad.net

  69. Cynthia

    (notice some xxxxxxxonion.mullvad.net and xxxxxxxonion.www.mullvad.net)

  70. moparisthebest

    > if i were to host xmpp over tor, I'd have to use the default 5269 ports for federation right? will host-meta-v2 allow me to define custom ports? stratself: not will, already does and yes things support it lol

  71. stratself

    > > if i were to host xmpp over tor, I'd have to use the default 5269 ports for federation right? will host-meta-v2 allow me to define custom ports? > > stratself: not will, already does and yes things support it lol which things? also do they mandate the HTTPS requirements?

  72. moparisthebest

    it's true there is no wide ecosystem support , you can't expect it to work with most servers or clients today , but it's not none

  73. Cynthia

    > So it's a bunch of people who could get a certificate for any onion service, or let the domain slip to squatters if their research grant runs out? You still need the onion service itself to serve the same certificate as your clear web one

  74. Cynthia

    So that's a limitation squatters have to somehow get around

  75. moparisthebest

    yes it mandates they be fetched over a secure channel because that's required for secure delegation , but https to .onion with TLS hostname validation disabled counts

  76. Cynthia

    > yes it mandates they be fetched over a secure channel because that's required for secure delegation , but https to .onion with TLS hostname validation disabled counts I think this is good for mutual auth

  77. Cynthia

    Like .onion -> https

  78. moparisthebest

    TLS to .onion for an .onion domain just universally shouldn't look at names in TLS certs

  79. Cynthia

    Or .onion -> .onion

  80. Cynthia

    Oh wait, this is about meta

  81. Cynthia

    > TLS to .onion for an .onion domain just universally shouldn't look at names in TLS certs I mean yeah, if you're fetching host-meta-v2, you can do it over HTTPS like the XEP wants you to do, but not care about the certificate the server gives you

  82. moparisthebest

    the tricky part and the reason I worded it funny is that if a non-onion domain say xmpp.org has a SRV or host-meta entry pointing at an .onion that still needs to validate cert the same as not-onion

  83. moparisthebest

    > Oh wait, this is about meta well it's the same for both

  84. Cynthia

    >> Oh wait, this is about meta > > well it's the same for both For mutual, how would you handle .onion -> https or .onion -> .onion

  85. Cynthia

    (https: clearweb)

  86. Cynthia

    I should have said clearweb XMPP, but it's the same shit lol

  87. moparisthebest

    for mutual the only good way I know of currently is make sure the TLS pubkey from the incoming connection is the same as the one from the outgoing connection

  88. Cynthia

    What

  89. moparisthebest

    still not ever looking at cert names

  90. Cynthia

    So we're still doing dialback?

  91. moparisthebest

    nope

  92. Cynthia

    We're doing dialback with TLS validatiob

  93. Cynthia

    We're doing dialback with TLS validation

  94. moparisthebest

    if you do host-meta2 you can simply put the pubkey hash in there

  95. Cynthia

    Are we allowed to talk about other companies or design some thing to be compatible with a proprietary(?) standard just because it's the most used?

  96. moparisthebest

    seems a bit open ended to be a definitive yes but probably ?

  97. moparisthebest

    as long as XEP IP rules are satisfied I guess

  98. Cynthia

    > as long as XEP IP rules are satisfied I guess I'm drafting a XEP based off of User Gaming but for applications in general too, but I wanted to make a section for compatibility with Discord RPC/Rich Presence

  99. Cynthia

    An optional section, it has its own namespace

  100. stratself

    do you want a dedicated "rich presence" namespace and work out the specific data schemas later?

  101. Cynthia

    The XEP is about a generic rich presence scheme (name, details and state about the app) but you can put a child element within the same element container with its own namespace

  102. Cynthia

    So the section is basically defining a child element with a namespace like `urn:xmpp:user_app:drpc:0`

  103. Cynthia

    That contains all the info specific to Discord Rich Presence (like buttons, activity type, etc.)