Viewing a single comment thread. View all comments

dnstommy t1_ixjz7kk wrote

Mastodon saves all DM clear text in the sql database. So the admins can read all your DMs for ever. This is a non-starter for most people.

25

jsled t1_ixkhc1d wrote

Wait until I tell you about pretty much every service you use online...

In any case E2EE DMs in mastodon are in development

8

dnstommy t1_ixki85f wrote

This isn’t an argument.

I absolutely use no services that save my DMs clear text. Should not have even started the app with on service, non-public messages.

it’s a non starter and I recommend no one use it. If this is the the security they thought was ok, imagine the rest of it. Join Mastodon and just wait for the alert that your information has been compromised.

3

rufustphish t1_ixlp1ky wrote

Couldn't you just use it knowing what you say might be read in the future? How are you ok with Reddit?

5

jsled t1_ixlsgs4 wrote

> Should not have even started the app with on service, non-public messages.

Maybe the service you think they should have built is not the one they wanted to?

It's not a private messaging protocol. It's an ActivityPub implementation, a public-posting protocol.

In fact, DMs in Mastodon are broadcast to anyone mentioned in them; if you @jsled@mstdn.io in a DM to your buddy, talking shit about me, it gets posted to my inbox!

If you want secure private comms, use Signal, use Cwtch, use SSB.

5

EmeraldAlicorn t1_ixkrxxo wrote

Just send an sql injection attack as a dm. Dogshit security.

6