The reporter took down the tweet, and it's still now effectively abandoned (despite it still being an issue; I've spoken to quite a few mods about it). This is honestly really disappointing behaviour from a platform owner.
The reporter took down the tweet, and it's still now effectively abandoned (despite it still being an issue; I've spoken to quite a few mods about it). This is honestly really disappointing behaviour from a platform owner.
I suggested that GrapheneOS stopped enumerating potential ways to attack Matrix rooms on Twitter if they actually wanted to discourage attacks.
Meanwhile, that issue has not remotely been abandoned, and has continued to be worked on in private (given the risk it might have security impact) - although as it's a rare edge case without a known security impact, it's competing with a lot of the other work we do to support Matrix, hence slow progress; especially with highly constrained funding.
I know it's incredibly hard to not take it personally when people call your baby ugly, but you're not helping things by being defensive. People seem to have issues with how you (as a company) handle bugs and criticism, and while it may not seem fair or accurate, at very least, it's likely that your company's responses contribute to the perception.
If nothing else, it points out a communication problem.
My intent isn't to "pile-on"; it's to provide insight into the issues people have with Matrix. I understand that it's your creation, but judging by this and the GitHub thread, it seems like you get quite defensive in these situations. Ultimately, these are valid criticisms of the platform; people aren't personally attacking you or the project. Personally I commend what you've created.
> I suggested that GrapheneOS stopped enumerating potential ways to attack Matrix rooms on Twitter if they actually wanted to discourage attacks.
Well, the issue was posted above. The Graphene guy posted it on Twitter, and by doing so you claimed he "slagged [you] off"[0].
> Meanwhile, that issue has not remotely been abandoned, and has continued to be worked on in private (given the risk it might have security impact) - although as it's a rare edge case without a known security impact, it's competing with a lot of the other work we do to support Matrix, hence slow progress; especially with highly constrained funding.
This is the part I don't understand. If you're working on it in private, you acknowledge it may be a security risk (plus your use of the word "attack"), but you've also de-prioritized it because it's not a security risk?
[0]: "what the hell is this? We have burnt a bunch of time investigating this and trying to help you on this today, and in return we get slagged off on twitter?!" https://github.com/matrix-org/synapse/issues/14481#issuecomm...
I forget the precise contents of their deleted tweets, and I'd be first to admit that for better or worse I try to be authentic when typing here or elsewhere, rather than faking being calm & anodyne. Based on the feedback here & elsewhere, that's probably a mistake. In this instance, having Graphene screaming about how awful Matrix is and enumerating ways to cause moderation problems was not helpful during a moderation incident, especially where we had been scrambling to help them.
> This is the part I don't understand. If you're working on it in private, you acknowledge it may be a security risk (plus your use of the word "attack")
Correct. Any bug in the state resolution algorithm could potentially eventually turn out to have security implications.
> but you've also de-prioritized it because it's not a security risk?
We haven't explicitly de-prioritised, but other things have come along at higher priority. The reason we haven't bumped its priority higher is because it happens rarely, and the chances of security impact look to be relatively low.
To be fair, from what I hear GrapheneOS doesn't have the best reputation for its communication with other people, but strcat did appear rather apologetic in the thread. Regardless, we're experiencing the bug I linked, so it's definitely still an issue.
> especially where we had been scrambling to help them.
Hmm, this is where I disagree -- if you've been scrambling to help, wouldn't the issue have been fixed by now?
We scrambled to investigate and fix this particular instance (and previous unrelated instances where they'd had problems). When we realised that they were simultaneously screaming about how shit we were, we put it back on the shelf.
Fixing fundamental basic functionality of your app should not be classified as having "burnt a bunch of time investigating this".
Right, but this is where your response baffles me: they've reported a genuine issue with the implementation, so why not fix it for everybody instead of "put[ting] it back on the shelf" and letting others suffer too?
It sort of sounds like "they complained about us, so fuck them and their issue" (except it's not just their issue). Wouldn't it be better to work around disagreements to benefit everybody, instead?
Matrix and Element are consistently one of the buggiest messaging applications I interact with, and I've waited years for it to be better.
Oh same, though I've found that Nheko Reborn is a much better client than Element (like, it's not even close). There's no getting around Synapse though; we're actually experiencing the bug I linked above, and it's absolutely dreadful to deal with.