Gajim - 2025-08-23


  1. ninjago

    πŸ…·πŸ…ΎπŸ…»πŸ…»πŸ…ΎπŸ†† πŸ…ΊπŸ…½πŸ…ΈπŸ…ΆπŸ…·πŸ†ƒ πŸ†‚πŸ…ΈπŸ…»πŸ…ΊπŸ†‚πŸ…ΎπŸ…½πŸ…Ά https://youtu.be/HYFyIinfyyc

  2. hau

    > But of course 5 minutes is debateable is a timer really necessary at all if it's restricted to last message anyway? I'd say either or makes sense but both is a bit much imo

  3. cal0pteryx

    hau: it all depends on the other clients as well. If other clients don't _accept_ corrections after a certain time, raising the time on one side does nothing

  4. deutschland

    Pictures are not encrypted in xmpp

  5. deutschland

    They are send over links

  6. deutschland

    And not being deleted after receiving

  7. luca

    They are end to end encrypted when sent with omemo. To decrypt the link you need the key

  8. deutschland

    > They are end to end encrypted when sent with omemo. To decrypt the link you need the key The problem is the link exist

  9. deutschland

    And anyone with the link can access the photo

  10. deutschland

    Every photo is stored by a link

  11. cal0pteryx

    deutschland: no, that's wrong

  12. deutschland

    I made a video proof https://monocles.eu/file_share/068a970b-a659-7a70-b411-627d0233cf9f/recording_20250822_221617.mp4

  13. deutschland

    Basically monocles is another account than the one on conversations

  14. luca

    Try opening the link in a browser

  15. deutschland

    > Try opening the link in a browser Just watch the video 🀣 you can try it yourself

  16. new user

    hi! i'm new to gajim/xmpp. thanks to anyone that can help me... i see where to select PGP encryption before sending a msg but where do i go to upload the PGP key?

  17. deutschland

    I know you can do the video in double speed because I'm hellish slow

  18. luca

    All you did was copy a link. Someone else outside of that chat can't get the image with that link

  19. deutschland

    > All you did was copy a link. Someone else outside of that chat can't get the image with that link But the video shows the opposite

  20. deutschland

    > All you did was copy a link. Someone else outside of that chat can't get the image with that link I pasted it in another chat with another account in another app and downloaded it

  21. deutschland

    And it showed as shown in the private chat with omemo

  22. deutschland

    Quantum computing will be funny for xmpp

  23. deutschland

    But I think for quantum computing crypto will be the first target before governments spy our chats

  24. luca

    Ah opsy, I misunderstood Yeah seems like the link you copied had the keys to decrypt it as well. So the link encrypted with omemo, and the image is encrypted with AES-256 and the keys are in that link. So someone with the link can't access the image, they need the stuff after the # to open it https://xmpp.org/extensions/xep-0454.html#aesgcm

  25. deutschland

    That's a security issue

  26. deutschland

    Should be fixed

  27. deutschland

    Omemo has to be rebuild

  28. luca

    Have at it

  29. deutschland

    > Have at it A possible solution would be already if the link destroys after arrival

  30. luca

    As for quantum computing check out "Quantum attacks" under https://en.wikipedia.org/wiki/Advanced_Encryption_Standard

  31. deutschland

    > As for quantum computing check out "Quantum attacks" under https://en.wikipedia.org/wiki/Advanced_Encryption_Standard I know what quantum computing is, I mean technically it will be possible, what I said in the near future.

  32. deutschland

    Well you can work with quantum computers against quantum computers

  33. deutschland

    Make every second randomly links being destroyed

  34. lovetox

    deutschland: servers have retention periods. Files are not forever on a server. If it's not secure enough use your own server and set the retention period to a minute, but that's nothing Gajim can change.

    😒 1
  35. deutschland

    > deutschland: servers have retention periods. Files are not forever on a server. If it's not secure enough use your own server and set the retention period to a minute, but that's nothing Gajim can change. You could bring me in your security team, and we figure out a way to make server protected. But I only got ideas I can't implement the ideas but I can tell people what they should do

  36. deutschland

    And in the end you will have government protection. But idk if that's something someone would want to have if there is briar...

  37. deutschland

    Actually maybe what I said already exists on linphone maybe it's not worth what I said

  38. deutschland

    I don't understand shit about lime in linphone πŸ˜‚

  39. deutschland

    I don't understand why people instead of signing a document with a key _***delivering_*** it decrypting it local on device.

  40. deutschland

    Such that the document is only seconds on the server

  41. deutschland

    Lightly encrypted

  42. luca

    If the server you are using does not match your needs consider switching or hosting your own

  43. luca

    Gajim can't do much from here

  44. jjj333_p (any pronouns)

    anyone gonna do anything about 0xCatPKG, ansper08 and Gurteltier just spamming connects disconnects? its driving my gajim insane every time i open this chat

  45. jjj333_p (any pronouns)

    https://downloadable.pain.agency/file_share/068a9790-4252-75ac-a5e0-371c19bc4c45/ffeb5904-56fd-4efd-a87c-0ffde12a5225.png

  46. jjj333_p (any pronouns)

    its like 50 reconnects a second

  47. jjj333_p (any pronouns)

    test

  48. lovetox

    yes give me a moment

  49. lovetox

    Thanks for mentioning it, but is this really useful to have joins/leaves shown in a big chat?

  50. jjj333_p (any pronouns)

    i normally dont mind leaving it, i like to see the general activity, but i figure even if i had the activity hidden the memberlist updating would still be putting load, and its probably putting load on the server

  51. lovetox

    yeah no definitly, im not suggesting ignoring it, if i know i kick them

  52. lovetox

    i just wondered that someone notices at all, because i never have this option enabled here

  53. lolhdhxhchc removed by cal0pteryx

    Spam

    ❓ 1
  54. deutschland

    https://monocles.eu/file_share/068a970b-a659-7a70-b411-627d0233cf9f/recording_20250822_221617.mp4

    ❓ 1
  55. a moderator removed a message

    Spam

  56. cal0pteryx

    deutschland, both your file and the link are encrypted. only you can decrypt the link. only if you have the link, you can decrypt the file. so the file is safe on the server, and only you can decrypt it. if someone spies on you _on your computer_, all hope is lost anyway.

  57. cal0pteryx

    this is how WhatsApp/Signal works as well, btw

  58. deutschland

    > deutschland, both your file and the link are encrypted. only you can decrypt the link. only if you have the link, you can decrypt the file. so the file is safe on the server, and only you can decrypt it. if someone spies on you _on your computer_, all hope is lost anyway. But watch the video that I have posted

  59. deutschland

    Maybe you can't see it because I turned off orbot to send t wait I'm sending from another account

  60. lolhdhxhchc

    There we go

  61. lolhdhxhchc

    https://share.conversations.im/lolhdhxhchc/message/PazHtK2Ontv2Sims/recording_20250822_221617.mp4

  62. cal0pteryx

    deutschland, I think there is a misunderstanding here. If you share the _full_ link, others can download and decrypt the file.

  63. lolhdhxhchc

    Basically what I did is to send a video privately with omemo then I copy the link pasted it in another account and the other account could fetch the video

  64. lolhdhxhchc

    Gif

  65. lolhdhxhchc

    > deutschland, I think there is a misunderstanding here. If you share the _full_ link, others can download and decrypt the file. That's the issue :D

  66. cal0pteryx

    There is a `#fragment` attached to the link, which is required to decrypt the file.

  67. cal0pteryx

    So an admin can't decrypt the file, because the fragment is not part of the file's path

  68. lolhdhxhchc

    > There is a `#fragment` attached to the link, which is required to decrypt the file. It should be deleted from server after arrival

  69. lolhdhxhchc

    But if for example a file being deleted then the server knows this is a file which can be decrypted :D

  70. cal0pteryx

    Only people having both path and fragment can decrypt the file.

  71. lolhdhxhchc

    > Only people having both path and fragment can decrypt the file. What holds you back from finding out the key?

  72. cal0pteryx

    encryption?

  73. lolhdhxhchc

    > encryption? the key can be found out by quantum computing

  74. cal0pteryx

    Nobody but you have that fragment decrypted. If you share the link, that's on you

  75. cal0pteryx

    > > encryption? > the key can be found out by quantum computing Now you're trolling.

  76. lolhdhxhchc

    Not at all

  77. lolhdhxhchc

    Give it a few years and we will have to decrypt it for attacks of quantum computers

  78. lolhdhxhchc

    Encrypt*

  79. lolhdhxhchc

    My poor english

  80. cal0pteryx

    Let's give it a few years then πŸ™„

  81. lolhdhxhchc

    Afaik Intel processors are not even using 1% of their regular potential, they just stopped optimizing

  82. lolhdhxhchc

    Ok 1% is a bit overvalued

  83. lolhdhxhchc

    Maybe they could optimize 10x out of their CPUs if they would work on it

  84. lolhdhxhchc

    Even the very old CPUs of Intel could be made 20 times faster

  85. cal0pteryx

    At this point I have to ask you to stop, since this leads nowhere and has no connection the Gajim.

  86. Codimp

    cal0pteryx : don't waste your time, lolhdhxhchc and deutschland are just trolling on multiple XMPP channels since 3 days and sending the same images

  87. cal0pteryx

    Codimp, it's not wasted time if people (in this room) have a better understanding of the matter afterwards

  88. Codimp

    hum, you're right

  89. deutschland

    > Codimp, it's not wasted time if people (in this room) have a better understanding of the matter afterwards Well I would simply delete the file from the server

  90. lolhdhxhchc

    > hum, you're right Not a troll

  91. lolhdhxhchc

    Well you need a server that is very resistent against quantum attacks too

  92. lolhdhxhchc

    So that they can't fetch the data

  93. betarays

    what do you think quantum computing is?

  94. cal0pteryx

    lolhdhxhchc, final warning :) stop now, or be gone

  95. betarays

    the fragment uses AES, which isn't specifically vulnerable to quantum computers as far as I know

  96. lolhdhxhchc

    > what do you think quantum computing is? Solving merge sort in lightning speed

  97. bot

    wurstsalat pushed 1 commits to branch gajim/master fix: VCard grid: Fix setting birthday - https://dev.gajim.org/gajim/gajim/-/commit/e0598f34f25aa17e1c57b9e633216b2896f8f9da

  98. mesonium

    lolhdhxhchc: you got no idea

  99. lolhdhxhchc

    > lolhdhxhchc: you got no idea When you can go all ways the same speed then you solve the key fast

  100. betarays

    it doesn't do "all possibilities at the same time", it's much more boring than that

    πŸ‘ 1
  101. lolhdhxhchc

    > it doesn't do "all possibilities at the same time", it's much more boring than that It will do

  102. mesonium

    lolhdhxhchc: the speed up comes from having negative intereference amplitudes

  103. bot

    wurstsalat pushed 1 commits to branch gajim/master cfix: Quit dialog: Fix dialog name - https://dev.gajim.org/gajim/gajim/-/commit/705091d4edb9a238b922f0b205e932ff0995f958

  104. lolhdhxhchc

    > lolhdhxhchc: the speed up comes from having negative intereference amplitudes Don't underestimate the inventions

  105. lolhdhxhchc

    It might not be a teleporter

  106. lolhdhxhchc

    But doing what I said will be very likely

  107. lolhdhxhchc

    :-)

  108. bot

    wurstsalat pushed 1 commits to branch gajim/master fix: VCard: Catch timeout error while receiving VCard - https://dev.gajim.org/gajim/gajim/-/commit/22719bb189e859fd362b2114359dd59d27bee3a4

  109. bot

    wurstsalat pushed 1 commits to branch gajim/master fix: File transfers: Fix cancelling file transfers - https://dev.gajim.org/gajim/gajim/-/commit/8e969eaa10b6cf6f07095613213080f513d88cc8

  110. dvdtgravwe11

    > Click your account avatar, on the page there is a menu, search the archiving preferences menu, and check if the dropdown says always Thank you! This worked!

  111. shodan

    > We only support currently correcting the last message and only if it was sent by Gajim and only within I think 5 mijutes Only last message AND only last 5 minutes is too restrictive Don't have a number of last message limit if it's a 5 minute limit Also should make that 1 hour limit

  112. clonki removed by cal0pteryx

    Spam

  113. clonki removed by cal0pteryx

    Spam

  114. clonki removed by cal0pteryx

    Spam

  115. clonki removed by cal0pteryx

    Spam

  116. clonki removed by cal0pteryx

    Spam

  117. clonki removed by cal0pteryx

    Spam

  118. clonki removed by cal0pteryx

    Spam

  119. clonki removed by cal0pteryx

    Spam

  120. clonki removed by cal0pteryx

    Spam