Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. One of the common misnomers around the migration away from toxic tech stacks is that the options are either 1) services managed by a company or 2) everyone #selfhosting themselves.

One of the common misnomers around the migration away from toxic tech stacks is that the options are either 1) services managed by a company or 2) everyone #selfhosting themselves.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
selfhosting
32 Indlæg 5 Posters 21 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • julianoliver@mastodon.socialJ julianoliver@mastodon.social

    @xr1st0ph Matrix/Element is great in many ways (E2EE) but memberships I've deployed for have found it too geeky, whereas alt platform averse can generally smoothly bump from Slack to MM with little to no complaints. Matrix/Element is also too sluggish for big channels of 1k+ members, even on powerful machines. Runs hot & starts to crawl in the thousands, whereas MM cruises through it. Matrix on smaller scales? Fine. I think their Olm, implementation of Double Ratchet holds them back a bit there.

    julianoliver@mastodon.socialJ This user is from outside of this forum
    julianoliver@mastodon.socialJ This user is from outside of this forum
    julianoliver@mastodon.social
    wrote sidst redigeret af
    #12

    @xr1st0ph MM Team Edition is FLOSS. Enterprise not so.

    1 Reply Last reply
    0
    • julianoliver@mastodon.socialJ julianoliver@mastodon.social

      @xr1st0ph Matrix/Element is great in many ways (E2EE) but memberships I've deployed for have found it too geeky, whereas alt platform averse can generally smoothly bump from Slack to MM with little to no complaints. Matrix/Element is also too sluggish for big channels of 1k+ members, even on powerful machines. Runs hot & starts to crawl in the thousands, whereas MM cruises through it. Matrix on smaller scales? Fine. I think their Olm, implementation of Double Ratchet holds them back a bit there.

      xr1st0ph@mastodon.socialX This user is from outside of this forum
      xr1st0ph@mastodon.socialX This user is from outside of this forum
      xr1st0ph@mastodon.social
      wrote sidst redigeret af
      #13

      @JulianOliver we moved from rocket chat to matrix 2 yr ago. we have alot of groups. some with over 1k+ users. Our userbase is 60+. it works. Not saying it is all smooth. but mattermost is us based, and isnt real open. you have to pay the http://sso.tax/ ... yea the nice ui ... ok but element is getting there. the element X app is so good!
      remarkable, that in your sphere of influence, UX is more important than opsec to you. why?

      xr1st0ph@mastodon.socialX julianoliver@mastodon.socialJ 2 Replies Last reply
      0
      • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

        @JulianOliver we moved from rocket chat to matrix 2 yr ago. we have alot of groups. some with over 1k+ users. Our userbase is 60+. it works. Not saying it is all smooth. but mattermost is us based, and isnt real open. you have to pay the http://sso.tax/ ... yea the nice ui ... ok but element is getting there. the element X app is so good!
        remarkable, that in your sphere of influence, UX is more important than opsec to you. why?

        xr1st0ph@mastodon.socialX This user is from outside of this forum
        xr1st0ph@mastodon.socialX This user is from outside of this forum
        xr1st0ph@mastodon.social
        wrote sidst redigeret af
        #14

        @JulianOliver well... https://github.com/mattermost/mattermost/issues/34271

        julianoliver@mastodon.socialJ 1 Reply Last reply
        0
        • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

          @JulianOliver well... https://github.com/mattermost/mattermost/issues/34271

          julianoliver@mastodon.socialJ This user is from outside of this forum
          julianoliver@mastodon.socialJ This user is from outside of this forum
          julianoliver@mastodon.social
          wrote sidst redigeret af
          #15

          @xr1st0ph Can compile that out easily if handy with Go, or just use the drop in binary from Frama:

          https://framagit.org/framasoft/framateam/mostlymatter

          xr1st0ph@mastodon.socialX 1 Reply Last reply
          0
          • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

            @JulianOliver we moved from rocket chat to matrix 2 yr ago. we have alot of groups. some with over 1k+ users. Our userbase is 60+. it works. Not saying it is all smooth. but mattermost is us based, and isnt real open. you have to pay the http://sso.tax/ ... yea the nice ui ... ok but element is getting there. the element X app is so good!
            remarkable, that in your sphere of influence, UX is more important than opsec to you. why?

            julianoliver@mastodon.socialJ This user is from outside of this forum
            julianoliver@mastodon.socialJ This user is from outside of this forum
            julianoliver@mastodon.social
            wrote sidst redigeret af
            #16

            @xr1st0ph The opsec with Mattermost is great when self-hosted & push notifications running through your own push server. Metadata quiet on the wire & FLOSS (team edition).

            Again, we have deployed Matrix for groups, but IME it is a higher risk migration target with more ontraining req. Many are coming from Slack too, so for this case esp MM is by far the smoother journey.

            If tech-averse get cold feet they will never move again & stay on US bigtech.

            You either listen to people or you lose them

            julianoliver@mastodon.socialJ xr1st0ph@mastodon.socialX 2 Replies Last reply
            0
            • julianoliver@mastodon.socialJ julianoliver@mastodon.social

              @xr1st0ph The opsec with Mattermost is great when self-hosted & push notifications running through your own push server. Metadata quiet on the wire & FLOSS (team edition).

              Again, we have deployed Matrix for groups, but IME it is a higher risk migration target with more ontraining req. Many are coming from Slack too, so for this case esp MM is by far the smoother journey.

              If tech-averse get cold feet they will never move again & stay on US bigtech.

              You either listen to people or you lose them

              julianoliver@mastodon.socialJ This user is from outside of this forum
              julianoliver@mastodon.socialJ This user is from outside of this forum
              julianoliver@mastodon.social
              wrote sidst redigeret af
              #17

              @xr1st0ph I use Matrix every day btw (with Element). As for SSO, we urge groups that choose MM to steer clear of it. Rather 2FA to email, ideally at their selfhosted MTA.

              However some employ OAuth2 for auth flow from selfhosted platforms like GitLab, Nextcloud etc. This can work very well.

              xr1st0ph@mastodon.socialX 1 Reply Last reply
              0
              • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                @xr1st0ph Can compile that out easily if handy with Go, or just use the drop in binary from Frama:

                https://framagit.org/framasoft/framateam/mostlymatter

                xr1st0ph@mastodon.socialX This user is from outside of this forum
                xr1st0ph@mastodon.socialX This user is from outside of this forum
                xr1st0ph@mastodon.social
                wrote sidst redigeret af
                #18

                @JulianOliver there is no active upstream or someone maintaining this. thats honestly cant be a good or safe way for infrastructure.

                julianoliver@mastodon.socialJ 1 Reply Last reply
                0
                • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                  @xr1st0ph The opsec with Mattermost is great when self-hosted & push notifications running through your own push server. Metadata quiet on the wire & FLOSS (team edition).

                  Again, we have deployed Matrix for groups, but IME it is a higher risk migration target with more ontraining req. Many are coming from Slack too, so for this case esp MM is by far the smoother journey.

                  If tech-averse get cold feet they will never move again & stay on US bigtech.

                  You either listen to people or you lose them

                  xr1st0ph@mastodon.socialX This user is from outside of this forum
                  xr1st0ph@mastodon.socialX This user is from outside of this forum
                  xr1st0ph@mastodon.social
                  wrote sidst redigeret af
                  #19

                  @JulianOliver thats kindof true. but you really only have to convince a small group and the rest will follow.

                  No E2EE in Mattermost would be a no go in infra for activism for me. people should and must learn how to protect their communictaion. You should educate not lower the bar.
                  Make some youtube videos and a good wiki entry and people will use it or ask someone. my experience.

                  We proclaim it as a WhatsApp replacement, and it works well. people help out each other. 🙂

                  julianoliver@mastodon.socialJ 1 Reply Last reply
                  0
                  • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                    @xr1st0ph I use Matrix every day btw (with Element). As for SSO, we urge groups that choose MM to steer clear of it. Rather 2FA to email, ideally at their selfhosted MTA.

                    However some employ OAuth2 for auth flow from selfhosted platforms like GitLab, Nextcloud etc. This can work very well.

                    xr1st0ph@mastodon.socialX This user is from outside of this forum
                    xr1st0ph@mastodon.socialX This user is from outside of this forum
                    xr1st0ph@mastodon.social
                    wrote sidst redigeret af
                    #20

                    @JulianOliver yea there is this hack right? is it still possible to use the gitlab in the teams version for some keycloak i.e.?

                    1 Reply Last reply
                    0
                    • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

                      @JulianOliver there is no active upstream or someone maintaining this. thats honestly cant be a good or safe way for infrastructure.

                      julianoliver@mastodon.socialJ This user is from outside of this forum
                      julianoliver@mastodon.socialJ This user is from outside of this forum
                      julianoliver@mastodon.social
                      wrote sidst redigeret af
                      #21

                      @xr1st0ph It's just a few lines and a diff quickly shows it's gtg. If concerned about the fork, just grab the source, patch and compile. Takes a few mins.

                      Even so, Framasoft have a longstanding great rep.

                      xr1st0ph@mastodon.socialX 1 Reply Last reply
                      0
                      • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                        @xr1st0ph It's just a few lines and a diff quickly shows it's gtg. If concerned about the fork, just grab the source, patch and compile. Takes a few mins.

                        Even so, Framasoft have a longstanding great rep.

                        xr1st0ph@mastodon.socialX This user is from outside of this forum
                        xr1st0ph@mastodon.socialX This user is from outside of this forum
                        xr1st0ph@mastodon.social
                        wrote sidst redigeret af
                        #22

                        @JulianOliver sure. but something like this adds up in DevOps and administration. How anyone can tell this will work next year? or the apps will get this limit to? i will definitly not compiling android and ios apps by hand everytoime an update hits. how to distribute?
                        Shouldnt this be taken in concideration when using such a fork?

                        julianoliver@mastodon.socialJ 1 Reply Last reply
                        0
                        • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

                          @JulianOliver thats kindof true. but you really only have to convince a small group and the rest will follow.

                          No E2EE in Mattermost would be a no go in infra for activism for me. people should and must learn how to protect their communictaion. You should educate not lower the bar.
                          Make some youtube videos and a good wiki entry and people will use it or ask someone. my experience.

                          We proclaim it as a WhatsApp replacement, and it works well. people help out each other. 🙂

                          julianoliver@mastodon.socialJ This user is from outside of this forum
                          julianoliver@mastodon.socialJ This user is from outside of this forum
                          julianoliver@mastodon.social
                          wrote sidst redigeret af
                          #23

                          @xr1st0ph If a group using WhatsApp &/or Slack &/or Teams trials your alt & they don't bite despite your efforts to educate, you go with 2nd best bc it's better than no migration.

                          Every week I work with groups on migration plans, educating, & one rule sticks: you cannot force people.

                          BTW if a group trusts their sysadmin(s), the machine is FDE AES-XTS/LUKS2 and tightly locked down in a rack or on-prem, E2EE affordances at the service layer are practically meaningless in most threat models.

                          julianoliver@mastodon.socialJ xr1st0ph@mastodon.socialX 2 Replies Last reply
                          0
                          • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                            @xr1st0ph If a group using WhatsApp &/or Slack &/or Teams trials your alt & they don't bite despite your efforts to educate, you go with 2nd best bc it's better than no migration.

                            Every week I work with groups on migration plans, educating, & one rule sticks: you cannot force people.

                            BTW if a group trusts their sysadmin(s), the machine is FDE AES-XTS/LUKS2 and tightly locked down in a rack or on-prem, E2EE affordances at the service layer are practically meaningless in most threat models.

                            julianoliver@mastodon.socialJ This user is from outside of this forum
                            julianoliver@mastodon.socialJ This user is from outside of this forum
                            julianoliver@mastodon.social
                            wrote sidst redigeret af
                            #24

                            @xr1st0ph You can have E2EE up to your ears and it's futile if the end-point is powered on (even with FBE) & in the hands of adversary. This is by far the biggest threat to frontline activism I see almost daily with those insisting on taking phones to protests. Chats exposed, Signal, MM, Matrix, does not matter. If you don't have a path and means to centrally disable accounts all is lost. Signal is very troubled like this. The group admin removes arrested from the group, but prior chat remains

                            1 Reply Last reply
                            0
                            • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                              @xr1st0ph If a group using WhatsApp &/or Slack &/or Teams trials your alt & they don't bite despite your efforts to educate, you go with 2nd best bc it's better than no migration.

                              Every week I work with groups on migration plans, educating, & one rule sticks: you cannot force people.

                              BTW if a group trusts their sysadmin(s), the machine is FDE AES-XTS/LUKS2 and tightly locked down in a rack or on-prem, E2EE affordances at the service layer are practically meaningless in most threat models.

                              xr1st0ph@mastodon.socialX This user is from outside of this forum
                              xr1st0ph@mastodon.socialX This user is from outside of this forum
                              xr1st0ph@mastodon.social
                              wrote sidst redigeret af
                              #25

                              @JulianOliver normally people who fight for a good cause never despite anything imho and xp.

                              thats true and this is why you use matrix. the element admin app is exactly for that: remove all tokens and shut down the app for a specific user. even if someone has now access to the phones storage, its all E2EE with no way of getting those messages. you can even deice forceing a reset of all messages.

                              julianoliver@mastodon.socialJ 1 Reply Last reply
                              0
                              • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

                                @JulianOliver sure. but something like this adds up in DevOps and administration. How anyone can tell this will work next year? or the apps will get this limit to? i will definitly not compiling android and ios apps by hand everytoime an update hits. how to distribute?
                                Shouldnt this be taken in concideration when using such a fork?

                                julianoliver@mastodon.socialJ This user is from outside of this forum
                                julianoliver@mastodon.socialJ This user is from outside of this forum
                                julianoliver@mastodon.social
                                wrote sidst redigeret af
                                #26

                                @xr1st0ph All the official apps work fine. I use patched MM server (the MM Go binary) on a bunch of instances.

                                xr1st0ph@mastodon.socialX 1 Reply Last reply
                                0
                                • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                                  @xr1st0ph All the official apps work fine. I use patched MM server (the MM Go binary) on a bunch of instances.

                                  xr1st0ph@mastodon.socialX This user is from outside of this forum
                                  xr1st0ph@mastodon.socialX This user is from outside of this forum
                                  xr1st0ph@mastodon.social
                                  wrote sidst redigeret af
                                  #27

                                  @JulianOliver thats not my why of doing things. out activists and i go the extra mile. but i think its great that it works for you. 🙂

                                  julianoliver@mastodon.socialJ 1 Reply Last reply
                                  0
                                  • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

                                    @JulianOliver thats not my why of doing things. out activists and i go the extra mile. but i think its great that it works for you. 🙂

                                    julianoliver@mastodon.socialJ This user is from outside of this forum
                                    julianoliver@mastodon.socialJ This user is from outside of this forum
                                    julianoliver@mastodon.social
                                    wrote sidst redigeret af
                                    #28

                                    @xr1st0ph We work very hard at this, and have been at it for years. Nonetheless, you may be better at convincing groups to use tools you think they should use than we are.

                                    We find trying to convince folk is not always the wisest end game. Rather, a compromise is sometimes necessary for a successful staged migration away from jurisdictionally or materially compromised services, with outcomes of higher platform morale, so lower chance of regression &/or splintering, & better overall org opsec.

                                    xr1st0ph@mastodon.socialX 1 Reply Last reply
                                    0
                                    • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                                      @xr1st0ph We work very hard at this, and have been at it for years. Nonetheless, you may be better at convincing groups to use tools you think they should use than we are.

                                      We find trying to convince folk is not always the wisest end game. Rather, a compromise is sometimes necessary for a successful staged migration away from jurisdictionally or materially compromised services, with outcomes of higher platform morale, so lower chance of regression &/or splintering, & better overall org opsec.

                                      xr1st0ph@mastodon.socialX This user is from outside of this forum
                                      xr1st0ph@mastodon.socialX This user is from outside of this forum
                                      xr1st0ph@mastodon.social
                                      wrote sidst redigeret af
                                      #29

                                      @JulianOliver THIS!

                                      Are you interrested in a videocall? taking this further? I would love to learn something about your work.

                                      1 Reply Last reply
                                      0
                                      • xr1st0ph@mastodon.socialX xr1st0ph@mastodon.social

                                        @JulianOliver normally people who fight for a good cause never despite anything imho and xp.

                                        thats true and this is why you use matrix. the element admin app is exactly for that: remove all tokens and shut down the app for a specific user. even if someone has now access to the phones storage, its all E2EE with no way of getting those messages. you can even deice forceing a reset of all messages.

                                        julianoliver@mastodon.socialJ This user is from outside of this forum
                                        julianoliver@mastodon.socialJ This user is from outside of this forum
                                        julianoliver@mastodon.social
                                        wrote sidst redigeret af
                                        #30

                                        @xr1st0ph I am well aware. This is a feature I like both in MM and Matrix.

                                        I am not the one to convince.

                                        julianoliver@mastodon.socialJ 1 Reply Last reply
                                        0
                                        • julianoliver@mastodon.socialJ julianoliver@mastodon.social

                                          @xr1st0ph I am well aware. This is a feature I like both in MM and Matrix.

                                          I am not the one to convince.

                                          julianoliver@mastodon.socialJ This user is from outside of this forum
                                          julianoliver@mastodon.socialJ This user is from outside of this forum
                                          julianoliver@mastodon.social
                                          wrote sidst redigeret af
                                          #31

                                          @xr1st0ph In summary, Mattermost also has its problems, in particular the dumbing down of finer-grained admin controls to push people to Enterprise. The seat limit is also absurd and patronising.

                                          Matrix with Element (X) however has UX issues that while not a big issue for those more enthusiastic about tech, they can be total breaking points for the tech and/or migration averse. Some of the gripes here I heard verbatim from climate activists we trialed on Matrix: https://xn--gckvb8fzb.com/giving-up-on-element-and-matrixorg/

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper