ActivityPub, the protocol that powers the fediverse (including Mastodon – same caveats as the first two times, will be used interchangeably, deal with it) is not private. It is not even semi-private. It is a completely public medium and absolutely nothing posted on it, including direct messages, can be seen as even remotely secure. Worse, anything you post on Mastodon is, once sent, for all intents and purposes completely irrevocable. To function, the network relies upon the good faith participation of thousands of independently owned and operated servers, but a bad actor simply has to behave not in good faith and there is absolutely no mechanism to stop them or to get around this. Worse, whatever legal protections are in place around personal data are either non-applicable or would be stunningly hard to enforce.

  • bathrobe
    link
    fedilink
    102 years ago

    @TiffyBelle

    @Bloonface

    Maybe you didn’t read where it says even DIRECT MESSAGES aka private messages you send to people, and don’t choose to post in public, is easily and easily available.

    This place is already an echo chamber. Jesus that’s bad. Everyone is on a new team and now we love this team and this team is never wrong and all criticisms are invalid. Even the really bad ones.

    I don’t really care. I’m old enough to have never trusted the internet. But let’s not pretend this isn’t a huge fucking deal, and isn’t completely fucked just because Reddit bad and fediverse good

    • Deceptichum
      link
      fedilink
      102 years ago

      Huh funny how a direct message is not a private message, almost like they’re even called completely different things.

      Everything is public here, some stupid Euro anti-user ideals on privacy aren’t the be all and end all .

      Things put in public are public. There is no privacy concern because there has never any privacy, nor will there ever be any privacy to be concerned about in a non-private platform such as this.

        • Deceptichum
          link
          fedilink
          22 years ago

          Does Twitter have private messages? I’d have assumed they have access to everything you’ve posted.

          IMs, PMs, and DMs are all pretty different things.

          • bathrobe
            link
            fedilink
            32 years ago

            @Deceptichum

            Yes. DMs on Twitter are Direct Messages and are supposed to be private messages send to someone else that no one else can see (except server admins, et al, as we are talking about here). If you send a DM to someone on Twitter or whatever social media (they use DMs to mean private messages on Instagram as well) it’s not on the public feed, no one can search it. Like having a text message conversation

    • Melpomene
      link
      fedilink
      122 years ago

      Direct messages, private messages, whatever you want to call them… have ALWAYS been available to your social media hosts. Reddit, Twitter, Facebook, Instagram, Discord… they can all read your private communications if they choose to do so. While I’d support E2EE for private messages for kBin etc, pretending that this is some sort of flaw inherent to the fediverse is inaccurate. It’s fair to want the fediverse to be better. It is not fair to hold it to a standard no one has ever applied to other social media.

      • melmc
        link
        fedilink
        4
        edit-2
        2 years ago

        Of course you can have encrypted group chats on Signal, if you’re not concerned about meta data. Or xmpp group chats with encryption if you want decentralization. You can keep your secret stuff secret and your public stuff public simply by using different apps.

      • bathrobe
        link
        fedilink
        32 years ago

        @TiffyBelle

        @Bloonface

        And if other instance owners have access to the private messages of people on every instance, that is a shockingly large flaw. I’m not exactly sure how insecure private messaging would be here. Not that I have people to message. But it being centralized would be more secure if decentralization would allow a much larger number of people to have access to something that, really, should be private.

        There are an overwhelming number of people I don’t think are savvy or cynical enough, call it what you will, to understand that just because they call something a private message - or just because it’s supposed to be a one to one interaction - doesn’t mean no one else can see it. I would think, if anything, an overwhelming majority of people who send a private message/DM on a social media assume that no one else at ALL has access to that information.