15,819 karma · joined December 8, 2010
> speaking of weird: how is it that these models, in a sandbox, with supposedly no way to communicate with other agents, manage to find the same public wikis as a scratch pad for agent communication?
It feels somewhat plausible that they're defaulting to the same search and picking the same top result?
The "portable Matrix" idea is currently nicknamed Tachyon, and is earlier stage at this point, although I did a Matrix Live about it a few months back: https://www.youtube.com/watch?v=jc7yfec3iIQ
Speaking as the CTO at Element (and proj lead for Matrix), i feel like i've spent a bit too much time coming to chat about Matrix on HN over the years ;)
That said, I agree that Bluesky is doing well in terms of breaking through into mainstream awareness - much more so than Matrix (although obviously big-world-social-media is something of a different beast to distributed-instant-messaging).
The reason Matrix hasn't done better here is primarily economic: we spent too much time and money building out Matrix for everyone in the early days... and not enough time focusing on building either consumer (as Bluesky has) or enterprise or government specialised products. We then got traction at Element on the government side of things (https://element.io/en/matrix-in-europe etc) as it turns out governments love their digital sovereign communications - which in turn meant that in order to get sustainable and survive we had to focus hard on building stuff for that market. Now, ideally the stuff which works for Govt would work for mainstream too (after all, we're generally competing with Signal and WhatsApp, which are of course mainstream apps) - but in practice it has been hard to get that balance right. You can see my <del>TED Talk</del> FOSDEM 2025 talk about the road to mainstream matrix here: https://www.youtube.com/watch?v=lkCKhP1jxdk
Meanwhile, the plan on Matrix is to get to profitability via Govtech and then invest the money back into improving Element (and Matrix) so it also works well for mainstream usage - so hopefully we'll get back on the radar then. It's a long haul though. Meanwhile, kudos to Bluesky for getting to focus on the mainstream use case; I'm jealous, and I hope they find a good sustainability model!
* Projection (it seems to love to describe one data structure as a projection of another)
* Strand (if some data gets isolated/stuck, it's "on a strand" or simply "a strand")
* Load-bearing (obviously)
* Frontier (the leaf on a tree)
* Quiescence (waiting for an algorithm to settle - I guess this one is legit)
* Honest (obviously)
* Residuals (any kind of data which hasn't been consumed by an algorithm)
* Rescission (something which has been rescinded; rather than saying "a rescinded offer" it enthusiastically calls it A Rescission!)
* Supersession (it's not a session which is a superset of another session... it's the word supercession; something that supercedes; similar to preferring the participle form of rescind).
I wonder how much of this is due to it mirroring proximate things to my code's own weird vocab though.
My favourite so far has been that I accused it at one point of playing whackamole by patching issues rather than getting to the bottom of a problem, and a few hours later it started to say things like "and i found mole 2 in CI" etc. For one minute I thought it was talking about the avogadro constant or backdoors or something until I realised it had committed to start calling newly discovered bugs 'moles' in its ongoing game of whackamole...
https://github.com/matrix-org/matrix-content-scanner
https://github.com/element-hq/matrix-content-scanner-python
etc.
This is nothing to do with ChatControl or Online Safety Act where you can see our position here:
https://element.io/blog/the-online-safety-bill-an-attack-on-...
Meanwhile the rest of Europe (and much of the rest of Germany) seems to have converged on Matrix as a genuine open standard with various different commercial vendors (Element, Rocket Chat, Famedly, connect2x etc), avoiding vendor lock and so giving actual digital sovereignty: https://element.io/matrix-in-europe
(There are still a few scenarios where e.g. if you delete your identity keys by logging out of all your clients, you may get "expected" decryption errors. We're still working on those.)
Auth for clients is also specified in the spec - there is some scope for homeservers to freestyle, but nowadays they have to implement OIDC: https://spec.matrix.org/latest/client-server-api/#client-aut...
Whereas I literally select count(*)'d from the destinations table on matrix.org, filtered on servers which had been federating in the last week(?) in order to get the specific stats above. (And then count(*) of all time for the 150K figure).
The problem is more that Element team is seriously stretched (particularly after the various misadventures outlined here: https://youtu.be/lkCKhP1jxdk?t=740) - so even if there was a pot of money to (say) merge custom emoji PRs... the team is more than overloaded already with commitments to folks like NATO and the UN. Meanwhile, onboarding new folks and figuring out how to do the Discordy features and launch a separately Discordy app under a Discordy server would also be a major distraction from ensuring Element gets sustainable by selling govtech messaging solutions.
So, we're caught in a catch-22 for now. One solution would be for other projects to build Discordy solutions on top of Matrix (like Cinny or Commet), or fork Element to be more Discordy (and run their own crowdfunders, perhaps in conjunction with The Matrix Foundation). Otherwise, we have to wait for Element to get sustainable via govtech work so it can eventually think about diversifying back into consumer apps.
The difference with Discord is that Matrix is a protocol, not a service. It's made up of thousands of servers run by different people in different countries. Public instances may choose to verify users in affected countries to abide by the law; others may choose to run a private instance instead.
19. "media downloads are unauthenticated by default" -> fixed in Jun 2024: https://matrix.org/blog/2024/06/26/sunsetting-unauthenticate...
20. "ask someone else’s homeserver to replicate media" -> also fixed by authenticated media
21. "media uploads are unverified by default" - for E2EE this is very much a feature; running file transfers through an antivirus scanner would break E2EE. (Some enterprisey clients like Element Pro do offer scanning at download, but you typically wouldn't want to do it at upload given by the time people download the AV defs might be stale). For non-encrypted media, content can and is scanned on upload - e.g. by https://github.com/matrix-org/synapse-spamcheck-badlist
22. "all it takes is for one of your users to request media from an undesirable room for your homeserver to also serve up copies of it" - yes, this is true. similarly, if you host an IMAP server for your friends, and one of them gets spammed with illegal content, it unfortunately becomes your problem.
In terms of "invisible events in rooms can somehow download abusive content onto servers and clients" - I'm not aware of how that would work. Clients obviously download media when users try to view it; if the event is invisible then the client won't try to render it and won't try to download the media.
Nowadays many clients hide media in public rooms, so you have to manually click on the blurhash to download the file to your server anyway.
> isn't Matrix based out of the UK and primary hosted instances on AWS in the UK?
It doesn't matter what country you run your server in or where your company is based; if you're providing public signup to a chat server then the countries (UK, AU, NZ etc) which require age verification will object if you don't age verify the users from those countries. (This is why Discord is doing it, despite being US HQ'd). In other words, the fact that The Matrix.org Foundation happens to be UK HQ'd doesn't affect the situation particularly.
(Edit: also, as others have pointed out, Matrix is a protocol, not a service or a product. The Matrix Foundation is effectively a standards body which happens to run the matrix.org server instance, but the jurisdiction that the standards body is incorporated in makes little difference - just like IETF being US-based doesn't mean the Internet is actually controlled by the US govt).
> Their solution is for everyone to pay for Matrix with a credit card to verify age.
Verifying users in affected countries based on owning a credit card is one solution we're proposing; suspect there will be other ways to do so too. However: this would only apply on the matrix.org server instance. Meanwhile, there are 23,306 other servers currently federating with matrix.org (out of a total of 156,055) - and those other servers, if they provide public signup, can figure out how to solve the problem in their own way.
Also, the current plan on the matrix.org server is to only verify users who are in affected countries (as opposed to try to verify the whole userbase as Discord is).
However, in practice, this was not exploitable: the only way to exercise these primitives was over the network, where network latency and request rate limiting mitigates such attacks.
Meanwhile, we had already rewritten and replaced libolm with vodozemac, a pure rust implementation using robust primitives, shipped in the major Matrix SDKs and implementations like Element and Element X.
I’m not sure this counts as alarmingly cavalier. I do regret libolm ever going into production with substandard primitives from a hygiene perspective, but we fixed it as soon as we could via vodozemac, and meanwhile included the safety warning.
matui looks super fun - you should come tell https://matrix.to/#/#twim:matrix.org about it :)