> Office.EU is a service offered and operated by EUfforic Europe BV, registered with the Dutch chamber of commerce under registration number 98746243 and having its address at Dr. Kuyperstraat 10-A at (2514 BB) The Hague, the Netherlands.
"fuite" is french which means to escape, to flee. Flight is only in context of planes or flying transportation.
As for the sense of it, you're right, it's either do something, go away, or do nothing.
I recently bought a Tuxedo InfinityBook Pro 15 [1] which has 2 USB-C ports with one being USB 4 (equivalent to Thunderbolt4), 3 USB-A, 1 Ethernet, 1 HDMI, 1 audio jack and 1 SD card reader.
I'm very much happy with the laptop and its build quality.
But most of all, I love the flexibility to not be stuck with just 2 USB-C and needing dongles/docks. I can have them if I want to, but I don't need to rely on them.
I think you don't need to compromise: laptops do exist that can have everything.
And then the customers will open support requests for code generated by an AI that misuse that very SDK. It doesn't look like OP's issue is with the code per say, only with the lack of skills of its customers, regardless of the code they write...
And yet Thib, mentioned in the article, does say in an another comment that they are employed by Element but working for The Foundation, making it quite hard to know the difference between the two: https://news.ycombinator.com/item?id=39369239
If you dig a bit, I'm sure you'll find this is true for quite a bit of the people either in Element or in The Foundation.
I can only be happy to see that the research we made and the documents [1] we produced some months back have lead to changes that improve privacy in Matrix. It is a huge win for our nonprofit Libre Monde [2].
We are especially happy to see you will now be lawfully processing GDPR Access requests by keeping the scope tight, and no longer include the full account history, confirming our statements in the Part 2 of the research that it was indeed unlawful to do so, and will inform the ICO accordingly.
Hopefully the remaining points in terms of privacy will be addressed!
> "It's so commonly used exactly because it's a very simple one-size-fits-all approach".
ICO says this [1] about choosing a lawful basis: "You must not adopt a one-size-fits-all approach. No one basis should be seen as always better, safer or more important than the others, and there is no hierarchy in the order of the list in the GDPR."
I guess then New Vector is actually our best sponsor: they always give us those very important things to write about, like a personal data breach that has a federation-wide scope.
They certainly are generous! I'll ask them to renew our contract!
Because our document could be collected and processed illegally under GDPR. That the operator makes the conscious choice to have their name listed on their own organisation's website they are from is their own choice. Their organisation is processing their data, not us. They have the right to object to that, and the right to erasure of their personal data if having their name is listed.
They were not given the choice to be part of our publication and therefore, we have no lawful basis to use their name since 1) they did not give us consent and 2) they would not have understood (we didn't say) nor expect (it was a private chat) that we will use their personal data - making Legitimate Interest not possible.
The only way we could be GDPR compliant for being Accountable and not break a lawful basis was to not use their name but the name of their role under their obligations towards us, and linking to the blog post instead (Accountability of what we claim).
Thank you for bringing our "failing out", which has an impact on the Personal Data leak itself, so I really hope people will look into it.
As for "with the general matrix community", I believe the amount of projects and people we talk to, and still are in rooms with (which are public) will be the proof of that.
I hope you'll enjoy the read, since we believe this is not the first data leak of this kind and that your personal data might very well have been leaked if you're a Matrix user.
Allowing a user to make themselves discoverable is fine. The real question is why was "vector.im" used and not "matrix.org", or the user simply prompted? And why is that data queryable without any kind of authentication?
Also, the Identity servers are part of a closed cluster where data is replicated. We are aware of vector.im and matrix.org but you did not answer the following question of the research document: is there other servers in that closed cluster? If yes, which?
(One of the author of the research doc that triggered this blog entry here)
It's good to finally see a reply, and it's good to see you are addressing some of the issues we have highlighted. It's a shame it took a whole research document posted on Hacker News and other websites to start getting your attention. I am personally surprised about this blog entry (and reply to some extend), given that the research doc was labeled as "FUD" by the lead dev.
Now that we have it, and that you answered in a blog post, there is one question we asked several times and that you still did not answer, even in our GDPR data request: Given that the research document clearly highlights that users are totally unaware of how their personal data was collected, how its going to be used, and that they did not given consent (e.g. storing their email addresses for a lookup query mechanism) under EU GDPR:
1. Under which lawful basis do you collect, process and allow others to use such data?
2. Are you going to keep storing/using all the data you have collected using all the methods highlighted in the research doc, or will you purge all that was collected without clear knowledge and consent of the users?
We have answered to your claims of "being alarmist", "disproportionate FUD" and that we did not forget to disclose we are working on a fork which is not hostile.
Or what about joining the room given on the research paper and actually participating in the discussion? We would love to have some proper interaction where we can exchange network output and screen recordings that simply show first hand what we are talking about...
Replying to a blog to a living research document intended to be used by another project/protocol feels silly. Whatever you write certainly is not all up to date anymore with the corrections we made thanks to the Matrix community that joined the room, and the Grid community that kept on discussion the doc.
Where is Matrix.org tho? This could also be a good occasion for the three new guardians to join the community.
> Office.EU is a service offered and operated by EUfforic Europe BV, registered with the Dutch chamber of commerce under registration number 98746243 and having its address at Dr. Kuyperstraat 10-A at (2514 BB) The Hague, the Netherlands.
[1]: Link to PDF, no HTML version: https://hel1.your-objectstorage.com/officeeuaa001/officeeu-p...