Brutkey

GrapheneOS
@GrapheneOS@grapheneos.social

Federating with open registration Matrix servers leads to endless raids including people spamming CSAM and gore. Not federating makes it quite useless. A large portion of our Matrix community moved to Discord due to the CSAM spam across Matrix and we don't bridge media from it.


GrapheneOS
@GrapheneOS@grapheneos.social

Discord has very good configurable server-side filtering and dramatically better mod tools. Matrix heavily enables abuse through federation and doesn't even support restricting inline media. Matrix also lacks channels within rooms so communities like ours rely on moderation bots.

Demi Marie Obenour
@alwayscurious@infosec.exchange

@GrapheneOS@grapheneos.social Is federation inherently bad from an abuse perspective? Are federated platforms worse than non-federated ones?

Aidan
@aem@infosec.exchange

@GrapheneOS@grapheneos.social

The only officially supported mod tools being paywalled is likely going to be the death of this stack and I guess that makes sense.

https://element.io/server-suite/admin-console

GrapheneOS
@GrapheneOS@grapheneos.social

@aem@infosec.exchange There isn't even a way to disable inline media for rooms. We have no way to stop people who use Matrix being forcibly exposed to CSAM. That alone is causing the majority of our active Matrix community to move to Discord. Every time the CSAM raids start up again, there's a mass exodus to Discord. It's not only our rooms being targeted this way. Many major open source project Matrix rooms have experienced it. Our rooms have been raided far more than others but it's often not specific to us.

GrapheneOS
@GrapheneOS@grapheneos.social

@aem@infosec.exchange There isn't even a way to disable inline media for rooms. We have no way to stop people who use Matrix being forcibly exposed to CSAM. That alone is causing the majority of our active Matrix community to move to Discord. Every time the CSAM raids start up again, there's a mass exodus to Discord. It's not only our rooms being targeted this way. Many major open source project Matrix rooms have experienced it. Our rooms have been raided far more than others but it's often not specific to us.

Aidan
@aem@infosec.exchange

@GrapheneOS@grapheneos.social

I help run a moderately sized instance and have been effected by a number of raids like this. We deployed Mjolnir to do some blocking from public blocklists (which is definitely not a very resilient way to do it), but also I suspect it wont work when we need it. It might also do image CWing but I haven’t toyed with that much.

Regardless, the damage was done and a fair number of people were exposed to really vile content.

Aidan
@aem@infosec.exchange

@GrapheneOS@grapheneos.social

I help run a moderately sized instance and have been effected by a number of raids like this. We deployed Mjolnir to do some blocking from public blocklists (which is definitely not a very resilient way to do it), but also I suspect it wont work when we need it. It might also do image CWing but I haven’t toyed with that much.

Regardless, the damage was done and a fair number of people were exposed to really vile content.