top | item 47069923

(no title)

xethos | 11 days ago

> Author analyzed the IRC and Matrix deficiencies as not being acceptable.

Which I have all kinds of questions for; my Synapse install is the FOSS community release, and pmap -d shows <1.5G of RAM usage even without the paid-org-optimizations. I thought maybe that was including postgres, but that shows only ~2M. This isn't a single-user instance either - I'm running half a dozen bridges, and use Matrix with my fiancee. Not much above single-user, but also less than half the claimed 4Gig at idle.

I do see ~3Gig mapped (still <4), but that hardly feels fair - any process will start to consume unused RAM, and it can be pushed out when under pressure.

The E2EE breaking for OP is something I haven't seen in somewhere between months and years either, which suggests the entire thing was last trialled before (or shortly after) one of the major performance improvement pushes

The point regarding Soatok's blog about the vuln is absolutely not a good look, though I'd want to dig into it a bit more to see if it's "a malicious admin can break the encryption", "a malicious actor can break the encryption", or "a malicious actor can access metadata". Not great whichever the case may be though.

discuss

order

No comments yet.