3 ms·
I host my own Synapse instance and for the most part it's very reliable. I don't bridge to anything. So far it's been like pulling teeth to get my friends to si
by 0xNippon 7y ago
I host my own Synapse instance and for the most part it's very reliable. I don't bridge to anything. So far it's been like pulling teeth to get my friends to sign up but once they do it's been super reliable. I'm traveling through Japan right now and the server hosted in NYC has been fine.
There are a few problems. First the UI for approving new client connections in encrypted chat rooms is complete crap. It needs to be clear and concise what is happening and currently it starts a super complicated verification process which is frankly confusing.
It simply needs to say "$user has signed in on a new device $deviceName. Is it okay to send messages to this device? Yes/No"
That's it.
Also there needs to be a better way to integrate third party plugins. One thing I miss from Facebook messenger is being able to paste a Spotify link and have the song come up as an embed.
Finally the bot API could use work. I spent some time professionally maintaining a Slack bot for a major American cable company and currently it's much harder to make a Matrix bot and documentation is lacking.
- cyphar 7y ago> There are a few problems. First the UI for approving new client connections in encrypted chat rooms is complete crap. It needs to be clear and concise what is happening and currently it starts a super complicated verification process which is frankly confusing. Device cross-signing has nearly landed and will solve this problem by creating a pseudo-WoT between users meaning that you need to do verifications very infrequently (ideally, only once when you first start talking to the user). > It simply needs to say "$user has signed in on a new device $deviceName. Is it okay to send messages to this device? Yes/No" Doing it this way would open the door to a malicious homesever (or a user's account being hacked into) being able to eavesdrop on you. Device names aren't cryptographically relevant. Device cross-signing (where a user's devices sign each other) solves the problem in a much safer way. > Finally the bot API could use work. I spent some time professionally maintaining a Slack bot for a major American cable company and currently it's much harder to make a Matrix bot and documentation is lacking. This boils down to the fact that bots are basically just normal Matrix clients (with a few extra features if you've set them up as an application service). You might be better served by using a library (like matrix-nio or the Matrix SDKs).