aral,
@aral@mastodon.ar.al avatar

Direct messages (DMs) on / / the are not end-to-end encrypted () and you should never include sensitive/private information in them.

Until they are e2ee, this is all we should be telling people. Anything else is irresponsible and could cause vulnerable people harm.

Specifically, it doesn’t matter:

  • if your instance admin is ethical or not
  • whether Elon Musk can read DMs easier on Twitter
  • etc.

It’s not end-to-end encrypted. It’s not private. End of.

not2b,
@not2b@sfba.social avatar

@aral Certainly journalists should never use DMs on Mastodon or Twitter to communicate with sources. I was disturbed to learn how many journalists use DMs heavily on Twitter.

david,

@aral @mvsde at best direct messages are a “hailing frequency” of sorts… a way to initiate communication and then switch to more appropriate communications channel.

Flux,
@Flux@social.fluxfox.dev avatar

@aral People need to realise that the only way to improve privacy on the web is to use e2e (p2p is an even better bonus on top) communication

aral,
@aral@mastodon.ar.al avatar

@Flux Yep.

murk,

@aral Yeah, DM functionality on here is useless. I just keep my Matrix handle in my bio and I plan on ignoring any messages on here.

nanoelquant,
@nanoelquant@c.im avatar

@aral Why anybody should ever think they are ?

Which is not a problem in general, the main point is to understand the limitations of the method.

Edelruth,
@Edelruth@mastodon.online avatar

@aral

@ellenor2000 This seemed like something you would want to know and share.

zachariah,
@zachariah@mas.to avatar

@aral

The “DM” settings on Fediverse should just let you put in your Threema / Signal / etc. contact details instead of having any DM functionality—unless it’s going to let you use public key encryption to deliver your messages.

HikerGeek,
@HikerGeek@mas.to avatar

@aral I am not sure you can say even e2ee is secure. The weak point is you if don't know if the person at the other end of tunnel is actually who you think it is. If Mastodon implemented e2ee but someone else got into your recipient's account, how would you know? In a more extreme case the secret police torture the unlock and try to work you for info.

On the other end of my spectrum if I wanted to send a read only password to my cloud storage of moss pictures a I would consider a DM here

mousey,
@mousey@seattlematrix.org avatar

@aral

if you want decentralized for social networking, the protocol is where it's at. Though its more discord than twitter. The protocol will probably never have it. Which is fine, different tools for different things...

smallcircles,
@smallcircles@social.coop avatar

@mousey @aral

The recently published a RFC for Message Layer Security protocol and lists @matrix foundation as one of the adopting parties:

https://www.ietf.org/blog/mls-protocol-published/

m0xee,

@aral I don't think that this should be "solved" at all. There are a lot of good IM protocols out there and great apps for that. Don't like the pace of IM? There are privacy-centric e-mail providers. People should use whatever they are comfortable with! Tighter integration — maybe, but there is no need to reinvent the "Mastodon wheel".

guiltmanager,
@guiltmanager@gm-cloud.org.uk avatar

@aral sadly correct. will be good if they ever do become end to end encrypted. becuase I think but could be wrong, the instance admin of the other instance can read them too, ie this is my own instance, but if I sent you a dm, your instance admin could prob read my dms to you? or only your dms that you send me.

terrygillis,

@aral It would be much quicker and more interoperable if they could just marry ActivityPub (Mastodon) with the Matrix chat protocol somehow to provide e2ee chat with the same @ handle.

M8_,

@aral e2e even can't make sure 100% privacy, bc it's admin controlled platform still, hh

DemocritusDiscoBall,

@aral

That’s good to know, thanks for the awareness.

circsarlatan,

@aral Has there been any movement on e2ee in the fediverse at all? I can find articles covering proposals and such dating from 2020~ or so, but not much else.

mkranz,
@mkranz@hachyderm.io avatar

@aral This is profoundly good advice. I believe there was a recent case of law enforcement seizing a server admin’s computer while a backup was on the machine. No matter how much you trust your community, as you said, all unencrypted communication should be considered public and discoverable

dnkrupinski,
@dnkrupinski@hannover.town avatar

@aral
That's the reason why we have and .
@FlippoFlip

michael_robinson,

@aral

Light a candle, don't curse the darkness:

https://getsession.org/

aral,
@aral@mastodon.ar.al avatar

@michael_robinson I use Signal. This isn’t about cursing the darkness. It‘s about countering an article that appears to be making the rounds on the fediverse today that appears to downplay the issue.

werdenfels,
@werdenfels@troet.cafe avatar

@aral for sensitive information, I would always use a messenger like for instance Signal.

aral,
@aral@mastodon.ar.al avatar

@werdenfels Indeed.

fishidwardrobe,
@fishidwardrobe@social.tchncs.de avatar

@aral And this is also true of Twitter, for example.

A fediverse "direct message" is just a message that is direct. That's all.

sintrenton,
@sintrenton@todon.nl avatar

@aral

-----BEGIN PGP MESSAGE-----

jA0ECgMCi3PE+mtctkpg0lMBmCr0apjBNAkbuvOt56TSWQBLVyx8+Qfx+nFfjn1C
lGxj9OpMdqtYlIb39vAnoNKdgKKDUyhxf8mq/mulG9W7Qo42I0YBs1Nu9m4A5n/x
4LxLew==
=QivQ
-----END PGP MESSAGE-----

aral,
@aral@mastodon.ar.al avatar

@sintrenton Indeed.

werdenfels,
@werdenfels@troet.cafe avatar

@aral @sintrenton is there a way to decode this on a mobile app (Tusky)?

LibertyBeta,

@aral Yeah, you need E2E jump on one of the many good E2E apps.

coloco,
@coloco@mastodon.social avatar

@aral
Es cierto, siempre hemos dicho que para cosas importantes esta por ejemplo xmpp.

No son privados ni seguros los md de Mastodon.

fathermcgruder,
@fathermcgruder@jorts.horse avatar

@coloco @aral Creo que hay instancias de Mastodon que incluyen mensajes XMPP para sus usuarios.

PNeurona,

@fathermcgruder
Y sino hay multitud de ellas donde te puedes registrar libremente.
@coloco @aral

fathermcgruder,
@fathermcgruder@jorts.horse avatar

@PNeurona @coloco @aral Es verdad, pero ¿como puedo verificar para otros que @fathermcgruder es lo mismo que crimedad@crimedad.work? No es imposible, pero es mas facil si hay integracion con Mastodon.

coloco,
@coloco@mastodon.social avatar

@fathermcgruder Tienes de tener un contacto previo, via mail o como quieras para saber con quien hablas.

@PNeurona @aral

coloco,
@coloco@mastodon.social avatar

@fathermcgruder si, ya en , antes de mastodon ya las había.

@aral

pierostrada,
@pierostrada@sociale.network avatar

@aral and let it be, (r)amen.

torb,

@aral They shouldn’t even be called DMs. Private mention is better, but even the ‘private’ indicates more privacy than you truly have.

Granted, I actually think they are a cool concept. Sometimes you only want to mention a specific person and not really bother someone else, but it’s doesn’t need to be private as such.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • mastodon
  • kavyap
  • thenastyranch
  • tester
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • tacticalgear
  • Youngstown
  • ethstaker
  • osvaldo12
  • slotface
  • everett
  • rosin
  • khanakhh
  • megavids
  • ngwrru68w68
  • Leos
  • modclub
  • cubers
  • cisconetworking
  • Durango
  • InstantRegret
  • GTA5RPClips
  • provamag3
  • normalnudes
  • anitta
  • JUstTest
  • lostlight
  • All magazines