-
danielstein
Even with using gajim on xp on known xmpp servers can attack sending a sta za exploiting some underlying xp library gajim will call (emoji rendering, http download many others
-
danielstein
So please stop promoting windows xp
-
danielstein
As of hardware you can use a unix derivate with recent security updates if you still.like the old hw
-
bodqhrohro
danielstein: > emoji Heresy. Legacy systems don't even support 4-byte Unicode.
-
bodqhrohro
BTW, they often are a cause of vulnerabilities on different systems last years, because they are overcomplicated. So I would strip them out server-side at all and teach users to use ASCII smileys. Many websites using the utf8mb3 encoding in the database still don't support emojis anyway. Should I post a ticket for removing emoji support in Gajim, so it won't be a complete off-topic? ×DDDD
-
bodqhrohro
danielstein: and the problem of combining old hardware with new software is that new software is too bloated for old hardware. And less bloated enthusiast FOSS projects don't receive that much bug-hunting attention.
-
bodqhrohro
So despite something like links2 is still updated and did even receive WebP support recently, I wouldn't be sure it lacks severe vulnerabilities. The downside is that they're barely searched there as well, and exploit packs don't cover non-typical software. Untraceable Joe.
-
bodqhrohro
Well… ×DD https://linuxsecurity.com/advisories/debian/debian-dsa-2807-1-links2-security-update
-
bodqhrohro
> Should I post a ticket for removing emoji support in Gajim, so it won't be a complete off-topic? ×DDDD Actually, given the reason to deprecate and remove XHTML support is concocted out of thin air with similar arguments, I won't be surprised it would gain traction, hehehe.
-
bodqhrohro
https://im.ebala.net:5821/upload/6xeGhyxX9u2swqx5-xQSMkUW/Screenshot%202023-12-12%20at%2013-21-19%20Emoji%20Shellcoding%20%F0%9F%9B%A0%EF%B8%8F%20%F0%9F%A7%8C%20and%20%F0%9F%A4%AF%20-%20DEF%20CON%2030%20-%20Hadrien%20Barral%20-%20Emoji%20Shellcoding%20%F0%9F%9B%A0%EF%B8%8F%20%F0%9F%A7%8C%20and%20%F0%9F%A4%AF%20-%20Presentation.pdf.png
-
bodqhrohro
> Legacy systems don't even support 4-byte Unicode. ↑
-
cal0pteryx
bodqhrohro: stay on topic. This is a gajim support chat.
-
bodqhrohro
cal0pteryx: Gajim has an emoji picker.
-
bodqhrohro
That's a problem.
-
cal0pteryx
Please take your ramblings elsewhere
-
bodqhrohro
https://dev.gajim.org/gajim/gajim/-/issues/11722
-
lovetox
bodqhrohro: What's your goal here?
-
lovetox
To get on my nerves and getting banned?
-
lovetox
Because that's the way this is going
-
bodqhrohro
lovetox: my goal is to bring to light you're acting in an authoritarian way and not listening.
-
Geld
bodqhrohro: You and one guy from Conversations group should team up. Two security retards that would strip everything from the apps.
-
Geld
Go make a fork without emojis then and get lost.
-
bodqhrohro
Geld: lol no, I'm not a security retard, I'm a troll mocking the security retards. It would be even more hilarious if they take this for serious. (And I see no reasons they shouldn't, given the rationale is pretty the same as for XHTML-IM: it *may* be implemented in an insecure way, so it's better to deprecate it at all so no one is seduced to implement it in a simple and dangerous way lol.)
-
cal0pteryx
bodqhrohro: you are wasting our time. Last warning.
-
Immaculate Taste
> Immaculate Taste: use Windows XP, it's not as full of spyware as modern versions are. > > Gajim 0.16 worked there for sure, not sure about newer versions. Very secure ™️
-
cal0pteryx
Immaculate Taste: please leave it alone
-
beduk
>> can you give me the adress of that onion service https://conference.gajim.org:5281/pastebin/0aa8f519-351f-4205-9125-86a1cc40c91b
-
beduk
lovetox: the message above is for you.
-
lovetox
no not yet,
-
lovetox
did you give me the onion adress for testing?
-
umu
you used to be able to sign onion domains idk what happened to that
-
umu
https://walla.rneetup.com:5281/file_share/11794af3-8cbf-44f3-bb39-46f6cd4811e1/uBGD3-wJTeWopXRMFKPGXg.jpg
-
umu
o ye they there
-
umu
this mornings breakfast is biscotti yogurt with coffee
-
beduk
> did you give me the onion adress for testing? lovetox: I can create an account for you. S2S is disabled
-
lovetox
i dont need an account for connecting
-
lovetox
just give me the address
-
polarian
beduk, https://security.stackexchange.com/a/105647
-
polarian
Every single article I have read on this says you are wrong
-
polarian
soooo
-
polarian
have you got any links to an explanation on how tor doesn't require any encryption
-
polarian
cause I can't find a single one
-
lovetox
the connection to the onion server does not leave the tor network via exit node
-
polarian
oh...
-
polarian
and that finally explains it, thanks :)
-
Paul Gupta
how do I check which XEP are supported on any given server via gajim?
-
Paul Gupta
like is there a way to query my server and say "do you support this feature"?
-
ssweeny
Accounts -> Server Info works for the server you're connected to
-
ssweeny
Not sure if it can be done for any arbitrary remote server
-
Paul Gupta
aah, just found that
-
Paul Gupta
but it doesn't list XEP-0357 PUSH notifications
-
Paul Gupta
doesn't say it's there or not there ssweeny
-
ssweeny
Might have to PR in support for it? Or hand-write the XMPP stanza into the XML console 😅️
-
ssweeny
Looks like Conversations checks for it so it should be possible
-
lovetox
ssweeny, no Paul Gupta, no Server Info does only show things that Gajim wants, that the server supports
-
lovetox
as Gajim does not need push notifications, it also does not check this for the server
-
Paul Gupta
fair enough
-
lovetox
so server info dialog is not useful for that info
-
Paul Gupta
I was wondering if there's a raw XML command that I can send the server that sends back a report of XEP enabled
-
Paul Gupta
https://compliance.conversations.im/about/ << This is doing *something* similar I'm sure to test that
-
lovetox
yes use that site, its exactly for that purpose
-
Paul Gupta
yeah, I just was curious how *I* can run that test
-
lovetox
not easily because the site runs many tests
-
lovetox
there is something called disco info
-
lovetox
you can craft a stanza that will give you *some* info
-
lovetox
but why would you do that if that site does it for you
-
lovetox
https://xmpp.org/extensions/xep-0357.html#sect-idm45584195739856
-
lovetox
here its described in examples how to query for protocol support
-
polarian
Hm... I am getting request entity too large uploading a 2MB file, but http upload is 1GiB, I assume 413 is being returned by the http server?