Hacker News new | ask | show | jobs
by Arathorn 2608 days ago
firstly - thank you for supporting the project :)

wrt the security practices on the old infra; yes - clearly they were major screw-ups. all I can do is spell out what we did wrong, and that we are painfully aware of the errors, and what we are doing to fix it going forwards.

> why wasn't the matrix.org infrastructure fixed before launching a new product.

because we put all our energy into getting modular sorted properly to try to increase $ to fund the team, rather than tidying up the old infra, with the expectation of eventually moving matrix.org over to the new hosting infra RSN.

> Though I'm surprised that you seem to see public offerings of Matrix homeservers to be a negative

It's very much a positive from the protocol's perspective. But from the painful practicality of keeping the team funded, it's a problem to spend time supporting Librem-specific issues if there's no $ to cover the time, as it just ends up sucking time from the core project. There is a massive risk of the tragedy of the commons here. In other words: from the perspective of keeping the team paid to work on Matrix as their day job, we'd rather users bought Matrix hosting from providers who funnel some of the revenue back to the core team. Hopefully Purism will end up doing so.

1 comments

I look forward to reading your write-up. And I really do hope that Purism gives money back to you folks and the other original projects (unfortunately there are many more counterexamples than examples of this happening in the past). Wasn't there already some agreement with them in order for them to have decided to use Matrix on the Librem 5 -- or is there no such revenue-sharing arrangement? (Or was the arrangement "host your own homeserver"?)
> Wasn't there already some agreement with them in order for them to have decided to use Matrix on the Librem 5 -- or is there no such revenue-sharing arrangement?

We were hoping they would funnel $ from the Librem 5 campaign to help support Matrix, and there was an agreement to do so if the campaign reached a given threshold. So far we haven't seen anything, but live in hope.