3 ms·
>Connect to post something without encryption means your location is revealed to anybody observing the network. Where are you taking this from? You think conne
by daveid 9y ago
>Connect to post something without encryption means your location is revealed to anybody observing the network.
Where are you taking this from? You think connecting to your Mastodon server you have an account on somehow broadcasts to the whole network?
- snvzz 9y agoIf a message is sent through an unencrypted connection, anybody sniffing the network gets: - Your message - Your account name - Your ip address (thus location) - The time at which this happens If the message is sent through an encrypted connection, but the federation connection between the servers is unencrypted, a powerful enough observer could still deduce the above.
- zaarn 9y agoA powerful enough observer will be able to observe two of the three properties no matter if TLS is used or not. Most Mastodon servers have TLS, exceptions usually included instances deployed to localhost. Mastodon doesn't technically require it but all clients I've seen do and the web interface relies on some features that are only available in a trusted context (HTTPS and localhost) I don't really see the problem though, which instance you sign up to is up to you. You can sign up to a HTTP-only instance if you want. The privacy of your data is in the hands of your local administrator more than any powerful observer (and servers you send messages too, like with email, for which all your complains are valid too since it functions similarly).
- snvzz 9y ago>Mastodon doesn't technically require it That's a serious issue. If plaintext is allowed, then expect getting people to downgrade to plaintext will be trivial, because "it just works". It's a serious mistake, but a well understood one by today. Mastodon is relatively new, and they should have known better than to do this.
- zaarn 9y agoThere is no downgrade. Mastodon will in it's default configuration not allow non-HTTPS connections. The protocol doesn't require it, so Mastodon technically doesn't. With a few code changes you can do that. So yes, Mastodon did know better but it's not an inherent property of ActivityPub to use HTTPS.