!gMNSNKSoNpoumBnBLI:matrix.org

Lapce

178 Members
Talk about the Lapce editor. https://lapce.dev/27 Servers

Load older messages


SenderMessageTime
13 Jan 2023
@panekj:matrix.orgpjwhyyy is my session still unverified ffs15:03:05
@Porkepix:matrix.orgPorkepixEh, I also have one unverified that fails pretty much everytime on phone :D15:04:24
@panekj:matrix.orgpj * whyyy is my session still unverified ffs (ok, i fix)15:04:26
@welteam:matrix.orgwelteamYeah and let's not talk about the quality of Element when it's supposed to be the reference implementation, I believe15:04:27
@Porkepix:matrix.orgPorkepixThe perfect communication tool doesn't exist anyway, needs to consider the best deal and strike a balance with the most important needs15:04:52
@panekj:matrix.orgpj I verified new Element session from unverified Cinny session, I don't think that should be possible hmmmmmm 15:05:19
@Porkepix:matrix.orgPorkepix welteam: There's an org I'm part of and that pushes a lot for Matrix, but I'm still doing some resistance and only accessing legacy (bridged) channels from irc, and can't access the others. The org have its own matrix server where members have an account. Problem: the reference clients, Element, is still unable to manage multiple accounts after all these years.
And on a more personal needs, I want and needs my personal, local logs I can grep though.
15:06:54
@panekj:matrix.orgpjThe only viable option of using Matrix is when not federating15:07:42
@panekj:matrix.orgpjLike a locked-down completely defederated instance, will be fine (the clients still suck although Cinny is somewhat ok)15:08:42
@Porkepix:matrix.orgPorkepixThat's particularly a problem when a solution is pushed for a corporate use besides the personal one. People don't want to mix corporate and personal use from a single account.15:08:54
@Porkepix:matrix.orgPorkepixHeard of Cinny, installed and launched it, saw all these icons to connect with facebook, google OAuths and others; didn't take the time yet to see if it was done cleanly or if data is sent to them so I didn't connected with it.15:10:04
@panekj:matrix.orgpj
In reply to@Porkepix:matrix.org
Heard of Cinny, installed and launched it, saw all these icons to connect with facebook, google OAuths and others; didn't take the time yet to see if it was done cleanly or if data is sent to them so I didn't connected with it.
I don't understand the concern
15:13:05
@panekj:matrix.orgpjimage.png
Download image.png
15:13:12
@panekj:matrix.orgpjOAuth is OAuth15:13:12
@Porkepix:matrix.orgPorkepixYup, but the same way there were issues with the "share" buttons, such as the facebook thumb and so on, depending on how it was implemented, only displaying those icons can already lead to sending data to these OAuth providers. And I'd rather not sending them anything. But as I said I didn't checked if anything is sent/shared or not before any login through them happens.15:15:22
@panekj:matrix.orgpjshare buttons are different because they were done by embedding custom JS from service15:17:00
@welteam:matrix.orgwelteamYes, OAuth and tracking beacons, while they may look similar, aren't implemented the same way. OAuth is just a link15:18:27
@panekj:matrix.orgpjwhat you could do is implement OAuth in insecure way (which would leak critical info to public)15:19:13
@panekj:matrix.orgpjor idk, send whatever data to OAuth endpoint but it would just bounce with 5xx error15:19:37
@panekj:matrix.orgpjOAuth is nice in a way that it has very strict information that you need to send (which is usually API key, nonce, etc.) and nothing else15:20:36
@panekj:matrix.orgpj OAuth is bad because it allows for deviation from spec and some services implement it in own way (shakes fist at Tumblr) 15:21:17
@welteam:matrix.orgwelteam
In reply to @panekj:matrix.org
OAuth is bad because it allows for deviation from spec and some services implement it in own way (shakes fist at Tumblr)
Shakes fist at adfs
15:22:03
@panekj:matrix.orgpjbut it's always good to verify source code anyway :)15:22:14
@Porkepix:matrix.orgPorkepixAnd also because it serves as an excuse for a fake choice in some situations. I've got a couple of cases for FLOSS gitlabs for example where you have the choice of OAuth (I don't want to depend on a third-party for my auth, especially for FLOSS) or regular register… through Google's reCAPTCHA: purely illegal in Europe if done without user consent for data collection, and not very ethical for FLOSS projects, imho15:23:26
@Porkepix:matrix.orgPorkepix pj: Problem is, it's probably pulled from some dependencies and you gotta search this a lot, as searchs in the source code for oauth or some of the provider's name bring no results 15:24:18
@panekj:matrix.orgpjI'm usually wary of people who are interested in FLOSS, quite often they are not mentally stable or not open to difference in opinions (:15:30:05
@welteam:matrix.orgwelteam
In reply to @panekj:matrix.org
I'm usually wary of people who are interested in FLOSS, quite often they are not mentally stable or not open to difference in opinions (:
Too true
15:30:42
@Porkepix:matrix.orgPorkepixThat's maybe generalizing a little too much :p ; but you sure could find people like that, and not only around FLOSS topic but among many other ones15:32:24
@panekj:matrix.orgpjI'm not disagreeing15:32:51
@panekj:matrix.orgpjUnfortunately (at least in topics adjacent to Linux) they are quite loud15:34:04

Show newer messages


Back to Room ListRoom Version: 9