Live data from Hacker News

Financial situation of the Matrix.org Foundation

github.com

31–40 of 68 posts

Re: Financial situation of the Matrix.org Foundation

#31
"Please use the original title, unless it is misleading or linkbait; don't editorialize." - https://news.ycombinator.com/newsguidelines.html

If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...

(Submitted title was "Non-profit Matrix.org Foundation seems to be moving funds to for-profit Element")

Re: Financial situation of the Matrix.org Foundation

#32
post #21

Earlier quoted context omitted.

I get that we're operating in a low trust environment, and you don't yet have any reason to trust me. I will say this: I'm not here to carry water for past performance. I _am_ here to build the foundation into the organization the community deserves, and I have a track record when it comes to making organizations more responsive to the communities they serve. Not only will I respond to the questions and concerns, I a…

Put up (the financials and data), or shut up.

Josh literally started less than six months ago and is the first employee of the foundation – do you think that there are some papers ready here and now for him to hand out?

Needlessly aggressive tone from you…

Re: Financial situation of the Matrix.org Foundation

#33
post #12

I am following the thread for years now and their financials were always a shitshow. I believe they never released anything on time or without the community begging for it. Well, except some fluff blog post at the end of the year without real data. I love Matrix but it's a fishy foundation. With this and Element not releasing server code under apache 2 anymore, it looks more and more like Element is going for entshit…

> Edit: Well, Josh is here so he will again start to deflect for some weeks and hope everyone will just forget about it until the next merry go round.

This is more of a meta-comment, but responding to a reply by editing your comment isn't fair play. It retroactively colors their response, and if they want to reply to your edit then the whole thread becomes a mess to follow for anyone else.

Let Josh have his say and reply to him if you think his response is deflection, but please don't preempt him with a sarcastic edit.

Re: Financial situation of the Matrix.org Foundation

#34

Earlier quoted context omitted.

wow, the pile-on is real tonight. I suggested that GrapheneOS stopped enumerating potential ways to attack Matrix rooms on Twitter if they actually wanted to discourage attacks. Meanwhile, that issue has not remotely been abandoned, and has continued to be worked on in private (given the risk it might have security impact) - although as it's a rare edge case without a known security impact, it's competing with a lot…

> wow, the pile-on is real tonight. My intent isn't to "pile-on"; it's to provide insight into the issues people have with Matrix. I understand that it's your creation, but judging by this and the GitHub thread, it seems like you get quite defensive in these situations. Ultimately, these are valid criticisms of the platform; people aren't personally attacking you or the project. Personally I commend what you've creat…

> The Graphene guy posted it on Twitter, and by doing so you claimed he "slagged [you] off"[0].

I forget the precise contents of their deleted tweets, and I'd be first to admit that for better or worse I try to be authentic when typing here or elsewhere, rather than faking being calm & anodyne. Based on the feedback here & elsewhere, that's probably a mistake. In this instance, having Graphene screaming about how awful Matrix is and enumerating ways to cause moderation problems was not helpful during a moderation incident, especially where we had been scrambling to help them.

> This is the part I don't understand. If you're working on it in private, you acknowledge it may be a security risk (plus your use of the word "attack")

Correct. Any bug in the state resolution algorithm could potentially eventually turn out to have security implications.

> but you've also de-prioritized it because it's not a security risk?

We haven't explicitly de-prioritised, but other things have come along at higher priority. The reason we haven't bumped its priority higher is because it happens rarely, and the chances of security impact look to be relatively low.

Re: Financial situation of the Matrix.org Foundation

#35
post #3

OK? What do we expect them to do with the money, exactly? As a donor, I would expect they fund the development of Matrix, which I believe Element is doing?

Luckily, it doesn't matter what individuals expect. There is written documentation on what the foundation is supposed to do or not to do: https://github.com/matrix-org/matrix-spec-proposals/blob/mai... Notably, "Code Core Team members must arrange their own funding for their time", which I understand as such that the Foundation does not pay directly the developers (same as other standards organizations like IETF). Th…

Without looking at how this organization works, let me clarify: a 501(c)(3) cannot be paying for software development insofar as this constitutes Product Development. Product Development is outside the scope of charitable work and, if caught, would open them up to back taxes on those 'charitable' contributions plus fines. This is not something that applies just to Matrix, but to the Free Software Foundation for that matter. Not one fucking dime you give them ever goes to software development, and the fact that they don't make this clear upfront given the obvious misunderstanding on the part of the public and what they think they're funding, is fraudulent.

TL;DR Donations to 501(c)(3)'s managing open source projects might as well be lit on fire because they do not and can not go to software development.

Re: Financial situation of the Matrix.org Foundation

#36

Earlier quoted context omitted.

Why not Matrix? Here's one reason: it has incredibly hard-to-debug edge cases, and plenty of bugs. One of my favourites is the one where people are kicked out of your room at random, which was reported a year ago[0]. It wasn't fixed, however, because the head of the Matrix foundation (Matthew) didn't seem to like the issue being posted on Twitter. The reporter took down the tweet, and it's still now effectively aband…

wow, the pile-on is real tonight. I suggested that GrapheneOS stopped enumerating potential ways to attack Matrix rooms on Twitter if they actually wanted to discourage attacks. Meanwhile, that issue has not remotely been abandoned, and has continued to be worked on in private (given the risk it might have security impact) - although as it's a rare edge case without a known security impact, it's competing with a lot…

Talking about a serious bug where thousands of people appear to be kicked from rooms that's been going on for over a year is not a "pile-on". It's a very bad experience for everyone involved, and people are just pointing it out. Your inability to empathize with other people having a bad experience using your product is not doing you favors here.

Matrix and Element are consistently one of the buggiest messaging applications I interact with, and I've waited years for it to be better.

Re: Financial situation of the Matrix.org Foundation

#37
post #12

I am following the thread for years now and their financials were always a shitshow. I believe they never released anything on time or without the community begging for it. Well, except some fluff blog post at the end of the year without real data. I love Matrix but it's a fishy foundation. With this and Element not releasing server code under apache 2 anymore, it looks more and more like Element is going for entshit…

> Edit: Well, Josh is here so he will again start to deflect for some weeks and hope everyone will just forget about it until the next merry go round. This is more of a meta-comment, but responding to a reply by editing your comment isn't fair play. It retroactively colors their response, and if they want to reply to your edit then the whole thread becomes a mess to follow for anyone else. Let Josh have his say and r…

That edit was here before that comment received any replies, so this is not a response by edit.

Re: Financial situation of the Matrix.org Foundation

#38
post #16

Earlier quoted context omitted.

> Well, Josh is here so he will again start to deflect for some weeks and hope everyone will just forget about it until the next merry go round This has been my experience with how Matrix handles critique in general, e.g. the response to "why not matrix?" which left me disappointed. Looking at this, and also at low quality of the reference clients and servers, over-engineered protocols and the poor UX in general it d…

Why not Matrix? Here's one reason: it has incredibly hard-to-debug edge cases, and plenty of bugs. One of my favourites is the one where people are kicked out of your room at random, which was reported a year ago[0]. It wasn't fixed, however, because the head of the Matrix foundation (Matthew) didn't seem to like the issue being posted on Twitter. The reporter took down the tweet, and it's still now effectively aband…

FYI I'm referring to the specific "why not matrix?" piece which was posted on telegraph and then was replied to by a matrix developer on lobsters. I don't want to link to them directly, hopefully you can find them both, but it's a good read if you thought about going all in on Matrix. The response particularly left me disappointed, since we still experience lots of bugs, which were allegedly fixed.

Re: Financial situation of the Matrix.org Foundation

#39

Earlier quoted context omitted.

What's interesting about this is that if the CLA didn't exist I would entirely support this move. The AGPL is (imo) a better license for a keeping a hosted project public and Open, it's good for things being built on top of Matrix's server implementation to be openly licensed. And the company is right that the Apache 2 license would not prevent them from taking the code in a proprietary direction later; Apache 2 allo…

Element requiring a CLA has only 1 practical effect: Element are effectively saying that in their repo of Synapse/Dendrite, they won't integrate any copyleft code they can't relicense. Other organisations could still choose to maintain a repo of Synapse/Dendrite that integrates any AGPL code, including all code released by Element. That might be a better upstream than Element! — but it would take work. For it to happ…

> they won't integrate any copyleft code they can't relicense.

Right, that's exactly the controversy, people are scared of the code being relicensed.

Rather than a CLA, a limited license grant from contributors to allow dual licensing but not the transition away from AGPL might potentially be a way to provide that kind of funding and to close off companies building proprietary products on top of Element without contributing back, while simultaneously decreasing the danger of the code being relicensed entirely; which the company is claiming they have no plans to do anyway.

The inclusion of copyleft code into Element that isn't owned by the company is the safety measure, accepting contributor-owned GPL code is a way for companies to credibly signal that they will not move to a source available model in the future. Sure, a separate upstream could be maintained, but unless Element is planning to pull from that upstream repo then a separate upstream is indistinguishable from a hostile fork and an abandonment of Element as the primary contributor. It's not about the repository, it's about whether the flagship implementation of the Matrix server code has the possibility of being turned into a proprietary product.

If we're going to go with a different upstream, what we're saying is that Element is not going to be providing the flagship implementations -- and I don't think people are eager to make that kind of decision.

Re: Financial situation of the Matrix.org Foundation

#40

Earlier quoted context omitted.

Element requiring a CLA has only 1 practical effect: Element are effectively saying that in their repo of Synapse/Dendrite, they won't integrate any copyleft code they can't relicense. Other organisations could still choose to maintain a repo of Synapse/Dendrite that integrates any AGPL code, including all code released by Element. That might be a better upstream than Element! — but it would take work. For it to happ…

If next there is "Synapse Pro" that is proprietary and sold by Element and includes features not present in the open source version of Synapse but relevant to company or government use of Matrix, the AGPL-only version of Synapse will lack those features. This will hinder companies that (potentially) require "Synapse Pro"-features from contributing to the AGPL-only version of Synapse. We have seen this happen before.

This situation is no different than it was when Synapse was licensed under Apache, though.
Post reply on HN