Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Taggart
Taggart
@mttaggart@infosec.exchange  ·  activity timestamp 2 hours ago

@rootwyrm Last I checked the moderation tools were still nowhere near adequate, and that is a dealbreaker for me.

  • Copy link
  • Flag this post
  • Block
Brett Haines
Brett Haines
@bretthaines@infosec.exchange replied  ·  activity timestamp 6 minutes ago

@mttaggart the first company I worked for used Rocket.Chat for their IMs and it worked better than MS Teams or Google Chat, both of which I've used at later employers. Didn't look as flashy but it was far more stable. I really hope they stick with it for my old coworkers' sake.

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 5 minutes ago

@bretthaines It's very good! And their native federation protocol has entered general availability.

  • Copy link
  • Flag this comment
  • Block
Murdoc
Murdoc
@murdoccc@infosec.exchange replied  ·  activity timestamp 55 minutes ago

@32x33 I miss the CrankySec community, but I really don't miss Discord.

  • Copy link
  • Flag this comment
  • Block
George Ellenburg (he/him/his)
George Ellenburg (he/him/his)
@gme@bofh.social replied  ·  activity timestamp 59 minutes ago

@mttaggart@infosec.exchange
Technically though Matrix is a more functional equivalent than Discourse.

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 51 minutes ago

@gme I'm not sure what criteria you're using, but for public communities it absolutely is not. The utter lack of moderation capability makes it unsafe for that use case. Private comms? Fine. But that's not really Discord's primary purpose.

  • Copy link
  • Flag this comment
  • Block
George Ellenburg (he/him/his)
George Ellenburg (he/him/his)
@gme@bofh.social replied  ·  activity timestamp 13 minutes ago

@mttaggart@infosec.exchange When's the last time you used Matrix or Element? Because I'm staring at a user in one of my rooms and these look like moderation controls to me (as the room's owner/ creator):

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 7 minutes ago

@gme That is not what I'm talking about. When you run a community, moderation is per room, which doesn't scale in the least. The automation via bots like Draupnir is rudimentary at best, and incredibly hamfisted (especially for E2EE). Yes, I can take action on individual users. I cannot prevent attacks usefully at scale. And setting all of the additional tooling up for what does exist is the kind of sysadmin nightmare that Discord successfully abstracted away.

Meanwhile, Discourse has these tools out of the box. They serve different purposes, but I contend that for community building, one is far superior.

  • Copy link
  • Flag this comment
  • Block
George Ellenburg (he/him/his)
George Ellenburg (he/him/his)
@gme@bofh.social replied  ·  activity timestamp 5 minutes ago

@mttaggart@infosec.exchange
> Meanwhile, Discourse has these tools out of the box. They serve different purposes, but I contend that for community building, one is far superior.

Couldn't agree with you more. I love Discourse (self-hosting) but the reality is for 99.9999% of Discord (not Discourse) users, Matrix is an open, private, and secure alternative.

To be fair, Discourse doesn't have E2EE either.

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 3 minutes ago

@gme Ah, but what has a community profited to gain E2EE, only to lose trust and safety? As always, "it depends," but IME a public Matrix server is just courting disaster.

  • Copy link
  • Flag this comment
  • Block
Mike Siegel
Mike Siegel
@mikesiegel@infosec.exchange replied  ·  activity timestamp 1 hour ago

@mttaggart I'll just go back to IRC. Wait I never left...

  • Copy link
  • Flag this comment
  • Block
RootWyrm 🇺🇦:progress:
RootWyrm 🇺🇦:progress:
@rootwyrm@weird.autos replied  ·  activity timestamp 2 hours ago

@mttaggart Stoat has actually moved SHOCKINGLY quickly and I would say it is easily 85%+ parity for the majority of users at this point. The biggest sticking point would probably be servers with >100 custom emojis or highly dependent on bots (which are relatively easy to port.)

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 hours ago

@rootwyrm Last I checked the moderation tools were still nowhere near adequate, and that is a dealbreaker for me.

  • Copy link
  • Flag this comment
  • Block
leberschnitzel
leberschnitzel
@leberschnitzel@existiert.ch replied  ·  activity timestamp 59 minutes ago

@mttaggart ah yeah if you manage big communities that might be a problem. For my 25 friends it doesn't really matter.
I tried it when it was still revolt and really liked it, but never actually made the move

@rootwyrm

  • Copy link
  • Flag this comment
  • Block
RootWyrm 🇺🇦:progress:
RootWyrm 🇺🇦:progress:
@rootwyrm@weird.autos replied  ·  activity timestamp 2 hours ago

@mttaggart most of Discord's power user moderation tools are reliant on third-party bots or demonstrably ineffective. Baseline moderation tools are at this point, 1:1 or better. Channel visibility can be set per-role, you can include a reason along with a ban. The UI could use some polish, but it's there.

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 hours ago

@rootwyrm

most of Discord's power user moderation tools are reliant on third-party bots or demonstrably ineffective.

As an admin of a 3000+ user server, I strongly disagree. AutoMod is a lifesaver and I can't imagine running a public space without something equivalent.

  • Copy link
  • Flag this comment
  • Block
RootWyrm 🇺🇦:progress:
RootWyrm 🇺🇦:progress:
@rootwyrm@weird.autos replied  ·  activity timestamp 2 hours ago

@mttaggart I also admin on rather large servers. If Discord makes one more claim their 'automod' actually stops the hacked account spamming, I will stab that employee in the face.
It absolutely does not. Literally 99% of the 'moderation' I do, is cleaning up after spammers posting obvious phishing links in every single channel that their 'suspected spam' block continuously lets through.

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 hours ago

@rootwyrm That's true, but the ability to create useful blocklists of terms limits the attacks to one per technique. The lists I have block the vast majority of attempts. If Stoat has that capacity, great.

  • Copy link
  • Flag this comment
  • Block
Joe Nash
Joe Nash
@joenash@hachyderm.io replied  ·  activity timestamp 2 hours ago

@mttaggart uh oh what did they do now

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 hours ago

@joenash Paternalism as a service: https://discord.com/press-releases/discord-launches-teen-by-default-settings-globally

Discord Launches Teen-by-Default Settings Globally

Discord is announcing enhanced teen safety features rolling out globally that reinforce its long-standing commitment to creating a safer and more inclusive experience for users over the age of 13.
  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 hours ago

Since I wrote this, many have introduced me to movim, and it's pretty slick! I'm still experimenting, but I like a lot of what I see. Still missing moderation tools for groups, though.

https://movim.eu

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 hours ago

Let me add that I am keenly aware of the cryptographic issues you are about to bring up about any of these options. I read and deeply respect the work of @soatok and others, and understand the concerns around OMEMO for XMPP, Matrix, etc.

Security is a balance between risk and value. I cannot decide for you what the right balance is, but I know from hard-won experience that building a community is about more than "perfect" security.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct