Running your own secure communication service with Matrix and Jitsi
matrix.org
matrix.org
*.organise.earth
*.rebellion.global
OWN3D OWNED (self hosted)
Team Chat Slack Mattermost (Team Edition)
Cloud Storage Google Drive Nextcloud (2 instances)
Collaborative docs Google docs Only Office Etherpad-Lite
Surveys Google Forms LimeSurvey
Video Conferencing Zoom Jitsi-Meet
Webmail Gmail, etc Rainloop (Postfix, Dovecot)
Collaborative Dev Github gitlab
Mailinglist manager Mail Chimp Mailtrain
Actions/Operations WhatsApp, Skype Signal, Wire
Social Twitter Mastodon
Video Youtube Peertube
Site Jekyll
Admin Gender Bros Any
https://media.ccc.de/v/36c3-11008-server_infrastructure_for_...> In this talk Julian will outline his work as sysadmin, systems and security architect for the climate and environmental defense movement Extinction Rebellion. Responsible for 30 server deployments in 11 months, including a community hub spanning dozens of national teams (some of which operate in extremely hostile conditions), he will show why community-owned free and open source infrastructure is mission-critical for the growth, success and safety of global civil disobedience movements.
Extinction Rebellion is fostering Inclusion & Diversity, I think is what he is trying to say.
If you don't like what Julian wrote, please contact him.
They call it "Diagnostics" to hide its true purpose, but really it's phone-home. Silently and with no notification, on f/oss self-hosted software; it's really a letdown.
To disable it, you must use the following entirely undocumented environment variables:
MM_LOGSETTINGS_ENABLEDIAGNOSTICS=false
MM_SERVICESETTINGS_ENABLESECURITYFIXALERT=false
I go the further step of using a small Dockerfile that contains the following to patch the binary itself: FROM mattermost/mattermost-team-edition:latest
RUN sed -i 's#api.segment.io#xx.example.com#gI' /mattermost/bin/mattermost
RUN sed -i 's#securityupdatecheck.mattermost.com#xxxxxxxxxxxxxxxxxxxxxx.example.com#gI' /mattermost/bin/mattermostI am always surprised to find that kind of spying in self-hosted apps. People self-host specifically to keep their data private!
The identity server is optional and you can use your own, but you will lose the federation that Matrix is so proud of, and the instructions to set up the reference home server don't make it clear that this is necessary in order to avoid a leak of your users' identities.
The clients also attempt to connect to this hostname.
> Matrix identity server, which is required to have federation,
The identity server is not required to have federation to work. All it does is let you optionally discover users on Matrix by their email address or phone number.
> 3rd party identity server operated by the Matrix organization retains a list of your usernames.
Not sure what this means, but the identity service does not retain a "list of your usernames". All it does is keep track of email->matrix ID mappings for users who have published them. When you look up an email address (or phone number), a hashed representation is sent to the service, and even then, they're not retained.
> They don't tell you up front about this
We do; to use the identity service you have to click through a very explicit GDPR terms of use which explains precisely how it works. You only get prompted with this when you actually use the identity service though (i.e. when inviting someone by email address) which might be why you've never seen it, however.
> You have to really pay attention during setup to realize that the federation technology relies on a bastion operated by matrix.org.
Again, Matrix federation does not depend on identity servers (and I kinda wish we'd never even implemented the feature, given how confused and upset people get about them).
https://matrix.org/blog/2019/09/27/privacy-improvements-in-s... goes into this all in much more detail.
> All it does is keep track of email->matrix ID mappings for users who have published them
This is what I mean by "it leaks the userlist." Matrix (the organization) stores the email addresses of my users, along with some mapping that could allow Matrix the organization to correlate email addresses with my server. To me, as a server operator, this is a deal-breaker, even if it was just email addresses with no mapping. I see this as a privacy violation against my users who trust me to hold their information privately and securely. My understanding is that you cannot join another Matrix homeserver server with an identity established on a homeserver disconnected from the vector.im identity server, which effectively forces the homeserver operator to use the vector.im centralized identity server if you want, as an end user, to actually take advantage of federation. I do not know how a user is supposed to take their login from one homeserver to log into another one if the first homeserver is not connected to vector.im.
Please correct me if the above is wrong.
Additionally, when I set up Synapse I was not presented with any kind of GDPR info, and it wouldn't make sense that I would be, because the GPDR is for end users, not site operators. Maybe this is presented to new users who connect to the public reference Synapse instance using Riot.im or something, but I'm not talking about this issue from the perspective of an end user, I'm talking about it from the perspective of a homeserver operator. I got about halfway through the homeserver setup before I realized that vector.im was necessary for identity lookup and I realized it only by carefully following the docs. This was long before the 9/27/2019 blog post was published, so I guess maybe this has been addressed somewhat. I have been following Matrix now for the better part of a decade.
If federation is possible without identity mapping done on a central server, then I too wish that identity mapping was never implemented.
Yup, this is still wrong, sorry.
> My understanding is that you cannot join another Matrix homeserver server with an identity established on a homeserver disconnected from the vector.im identity server
This is not true. The identity server is an optional feature, which users can use if they want to try to discover a user's matrix ID based on their email address. Matrix itself operates using matrix IDs to federate and establish conversations.
A good analogy is using LDAP as an address book in an email client. LDAP addressbook lookups are very clearly optional, not relevant to all people, and don't stop email itself working.
> Additionally, when I set up Synapse I was not presented with any kind of GDPR info, and it wouldn't make sense that I would be, because the GPDR is for end users, not site operators.
Because the identity server is an optional feature for users (just like a user, not a sysadmin, would configure LDAP lookups in Thunderbird), the GDPR terms of use are shown to users if they try to use an identity server to make sure they understand what they're doing.
I hope the team has clarified this in the documentation.
https://docs.mattermost.com/administration/telemetry.html
I think this telemetry should be opt-in for self-hosted, but the data they send doesn't seem to push it to the level of spyware (i.e., no message contents or PII as far as I can tell). It's still much more private than Slack.
"The following information [a boolean, not the event details] is sent when the specified event occurs: - Sign-in Error - Account creation - Login succeeded - reset password - updated password - Joined a channel - Created, edited or deleted a message - searched for a term" … and the list goes on: https://docs.mattermost.com/administration/telemetry.html
Thanks for letting us know…
I strongly would recommend Zulip - https://zulipchat.com/
```
You are licensed to use compiled versions of the Mattermost platform produced by Mattermost, Inc. under an MIT LICENSE
- See MIT-COMPILED-LICENSE.md included in compiled versions for details
You may be licensed to use source code to create compiled versions not produced by Mattermost, Inc. in one of two ways:
1. Under the Free Software Foundation’s GNU AGPL v.3.0, subject to the exceptions outlined in this policy; or 2. Under a commercial license available from Mattermost, Inc. by contacting commercial@mattermost.com
You are licensed to use the source code in Admin Tools and Configuration Files (templates/, config/default.json, model/, plugin/ and all subdirectories thereof) under the Apache License v2.0.
We promise that we will not enforce the copyleft provisions in AGPL v3.0 against you if your application (a) does not link to the Mattermost Platform directly, but exclusively uses the Mattermost Admin Tools and Configuration Files, and (b) you have not modified, added to or adapted the source code of Mattermost in a way that results in the creation of a “modified version” or “work based on” Mattermost as these terms are defined in the AGPL v3.0 license.
```
[1] https://github.com/mattermost/mattermost-server/blob/master/...
Their enterprise version has a different license; the source for that one is not available and the binaries are released under a much more restrictive license, but that's nothing to do with the normal one.
Venture-funded Open Core software like Mattermost is an awkward place for the terminology. The free version is distributed under an open source license, as so there is a thing that is "open source", but the clear intent of Open Core licensing policies is primarily to achieve the goals of: (1) Being able to market the software as open source. (2) Maximizing the portion of users who buy the paid/proprietary version.
While in theory open core can be run responsibly, the incentive structure is to intentionally not include features important for typical use cases in the "open source" version of the software that any similar community-driven open source project would have considered an essential, early feature.
FOSS means different things to different people, but my personal perspective is that venture-funded open core software like Mattermost feels like FOSS to me about as much as proprietary software with a free plan like Slack or GitHub does.
For Mattermost in particular, this thread is a good reference: https://news.ycombinator.com/item?id=21820583. They made changes to the specific items mentioned there in response to the community pressure, but that doesn't change their fundamental business strategy.
Instead of generating the certs with prosody (there was some issue since my system uses p11-kit), I found it easier to just generate them all with certbot. update-ca-trust doesn't seem to correctly add them to the Java keystore and then you'll encounter problems. Certbot does. If you're on a debian based distro you shouldn't have to worry, however.
All you really have to do is copy/paste configs and then also change the url in the config.
Here's the process for adding the certs using p11-kit. https://github.com/jitsi/jitsi-meet/issues/2842#issuecomment... and the comment below.
Last time I tested it, it seemed to be very open by default, letting anyone create meetings. I got lost when digging deeper.
If I install-and-forget, I want to avoid situations where strangers are using my Jitsi server and overloading the system, or pretending to be our company. Last I checked, it was not possible to have simple auth, or monitor/list calls.
I also run an Asterisk VoIP server with a WebRTC bridge (because most Linux SIP clients have terrible usability). That can make one pretty paranoid :)
I followed these instructions to add the auth https://github.com/jitsi/jicofo#secure-domain
https://github.com/jitsi/jitsi-meet/blob/master/doc/example-...
cat '{ "m.server": "matrix.dangerousdemos.net:443" }' > server
be
echo '{ "m.server": "matrix.dangerousdemos.net:443" }' > server
instead?I assume its my server block, but I have made many changes / adjustments and still getting a 404 on all my pages??
Otherwise you risk overloading people on devices which can't render >12 simultaneous video streams without melting. You can push the limit higher if you know everyone is on a fast machine however.
One thing worth noting is that if a one or more user connects via Firefox then quality degrades for everyone - but fixes for this look to be in flight over at https://github.com/jitsi/jitsi-meet/issues/4758
Can you please point me to where this can be done.
1:1 video uses P2P and doesn't require video going through the Jitsi bridge.
Is this configurable on the client-side via configOverwrite.constraints when using the external API?
Thought about running it semi-public for my homewtown/area to support businesses, but how many of the 350k people will join? Or be concurrent users?
Quite a few question marks for me...
Depending on the amount of work you are willing to put into this, you could even start with a load-balanced setup were one or more web servers, jicofos and prosodys are distributing the load to several videobridges. That would make it easier to scale the system up by adding additional instances.
https://www.scaleway.com/en/docs/deploy-jitsi-meet-with-dock...
Running it on the DEV1-L which is 16 Euro's a month.
Last I read was that synapse requires a lot to memory and I guess that managing audio/video streams will be cpu intensive.
Yes, because those of us who run their own vidconf setup want automagically mangled nginx configs.
Other than that, thank you for the guide.
* https://github.com/matrix-org/synapse/blob/master/INSTALL.md... is the official Docker instructions
* https://github.com/dacruz21/matrix-chart is a Helm one
etc
edit: for docker with synapse living on subdomain.domain.tld and addresses like @user:domain.tld, I don't know ^^.
https://github.com/matrix-org/synapse/blob/master/docs/deleg...
Just in case you weren't already aware of it :)
My goal is to set in way I could use docker swarm in future. Any advises or links? thanks in advance
My only tip is that you really have to get the DNS name right. There is no easy way to change it post install. I had a typo on the first pass.
Next step is securing the launch screen. Since it sits behind NGINX, do the configuration there.
A small number of people in a call, 3-5, streaming to thousands. Live podcasts etc?
Is this intended as a criticism? You wanted it to do a job it was never designed to do.
I'd like to hop on this, and think it will work great, but would like to make sure there's a way to right size a particular installation.
"Jitsi offers a telephony interface that allows users to dial into a conference or for placing dial-out reminder calls. You can try this for free on meet.jit.si. Self-installed Jitsi Meet deployments will need to setup and configure Jigasi with a SIP provider to connect to the phone network. "
Synapse resource usage is dependent on the complexity of the rooms that it participates in, not the number of users.
So if you intend to use it just to talk to a few friends, you'll have no problems at all. If you want to join rooms with 1000s of other servers participating then it will be hungrier.
Open source software needs to be as easy to use and configure as the alternative if they really hope to gain wise adoption.
Yesterday my kids used it for a 4hr call, no interruptions though audio quality dropped on occasions - I think it was the remote iPad's multiplexing that was struggling but couldn't be sure.
Open source software doesn't owe you anything and you can use the alternative if that doesn't satisfy you.
People want self hosted, free software with privacy BUT also all other features that big companies add to their software. I'm sorry but you have to make compromises. Most people decide to compromise their freedom and privacy.
If you really want the software to improve the best way is to contribute (or donate if that's an option), complaining things could be better on the other hand don't help much.
As for history, you could just import your key backup, if the room history is set to visible. Truly decentralized accounts will likely come at a later point, especially with all the work surrounding p2p matrix, where each p2p client is a server.
Who can read history?
Members only (since the point in time of selecting this option)
but this option doesn't seem to work for me. The history didn't synchronize when i added my own homeserver account and verified it with other accounts - do i need to import the keys from the old account first for it to show up or am i misunderstanding how this option works?
So the messages are likely there, but you won't see them until you import your e2e keys.
Then I just hit the url and it worked perfectly.
The biggest surprise was when I tried to access that same page from an Android phone. It prompted me to install the jitsi app. After I installed it, it directed me to my jitsi server.
For me it was flawless and even better that I expected. It's a strong competitor to zoom because of the fact that it works right inside the browser really well.
https://github.com/jitsi/jitsi-meet/blob/master/doc/quick-in...