4 ms·
> Instance owners can read DMs. "Admins of <website> can read data on <website>" is just a tautology. It's true of everything you use on the internet where you
by stormbrew 4y ago
> Instance owners can read DMs.
"Admins of <website> can read data on <website>" is just a tautology. It's true of everything you use on the internet where you don't own the server, and even then it's dubious.
If people don't get that about mastodon they probably don't get it about everything else they use either, so this recurring argument just seems like FUD...
[note: Edited <service> to <website> above because people keep coming at this from the angle of chat clients that run on your phone, and we're talking about websites here - a website can't have "e2e" encryption because it is both ends. That said, some of y'all believe way too hard in the perfectness of e2e in general and I addressed that in some of my replies]
- vgel 4y agoyeah, but on twitter you're probably a nobody, the staff have no incentive to read your dms. on mastodon, you're at least a friend-of-a-friend of the operator unless you're on a huge instance.
- stormbrew 4y agoOthers have pointed out that this is fallacious -- even on big services sometimes employees are creepy stalkers, sometimes they're malicious actors of other sorts -- but even if you ignore that on twitter you are a target of advertising and if you think they aren't slurping up all the data they can about you and storing it in a database somewhere, you're fooling yourself. Anyways, down this logic path is an internet where we somehow put all our trust in megacorporations and absolutely none in our fellow human beings and I dunno about you but one of those sounds a lot more dystopian to me than the other.
- vgel 4y agotwitter has hundreds of millions of users and 7,000 (less now, unfortunately) employees, not all of which have production access. i don't know anyone at twitter, so them accessing my data would need to be a random choice from the whole userbase. they'd need to evade internal checks (which, however weak they are, are infinitely stronger than the average fediverse instance). could it happen? could i be eaten by an escaped zoo leopard during my morning walk? having my data "read" by a non-sentient advertising model, while irritating, is nowhere near the same as having it read by a human being. that is a false equivalence. i made no argument about the absolute merit of twitter vs the fediverse. this is simply a downside of small communities that people excitedly migrating to the fediverse with little understanding of how it works or experience with its predecessors will soon run into—twitter is neutral ground, on mastodon you might be arguing with the instance admin's friend and find yourself retaliated against. anyone who used a forum or IRC in the 90's/00's knows what i'm talking about.
- e12e 4y agoWell, now you've posted about it here, so maybe someone will get curious? As for: > they'd need to evade internal checks (which, however weak they are, are infinitely stronger than the average fediverse instance). Did you watch Mudge's testemony? Even if Musk wants to, it'll take a total re-org to get a semblance of security at Twitter, by the sound of it... Mudge Twitter whistleblower testimony [video] https://news.ycombinator.com/item?id=32824504 https://news.ycombinator.com/item?id=32824504 https://www.judiciary.senate.gov/meetings/data-security-at-risk-testimony-from-a-twitter-whistleblower https://www.judiciary.senate.gov/meetings/data-security-at-r...
- stormbrew 4y ago> having my data "read" by a non-sentient advertising model, while irritating, is nowhere near the same as having it read by a human being. that is a false equivalence. I agree they're not equivalent. One is a small harm guaranteed to be perpetrated every day against every single person using Twitter, numbering in the hundreds of millions of people, largely without those people knowing or consenting to it. The other is a large harm sometimes inflicted on a small number of people, and when it does happen is isolated to a small community where people can find out about it and act on that knowledge how they see fit. I've been around a long time. I've seen power abused on irc and forums and even small social networks. To me, the idea that we need supposedly benevolent megacorporations to keep us from doing harm to each other is a repulsive idea, far and away above "my instance admin might read something I wrote on their server." If we've forgotten how to exist in community with each other, we should relearn that skill.
- klabb3 4y ago> Admins of <service> can read data on <service>" is just a tautology. Huh? This is certainly not true for Signal and Matrix, heck even whatsapp and telegram sounds better than some random instance operator. That said, truly private messages aren't always necessary, as long as the platform is crystal clear about this.
- stormbrew 4y agoSignal is not a "hosted website," which is more the context we're talking about here. But even on those services, yes, there are ways that the owners of the service could tap or impersonate you through exploiting their own key exchange service. You are trusting that they won't do that. This might be less true for matrix, since you could in theory be using an open source client where you have somehow guaranteed it will alert you to an attempt to add an unwanted device key to your e2e chat, but on signal you're running a binary you didn't compile against a service you can't see. I don't think you shouldn't trust them. But you are doing so to some extent.
- danielheath 4y agoIn the case of signal, they would have to forge the SGX enclave signature (by an intel held key) or release a client that didn’t validate that sig. Definitely possible but if I had an SGX bypass I’d want to use it on something known to be high value, and releasing a non-verifying client would at least be noticeable on android and desktop.
- stormbrew 4y agoI think the latter (manipulating the client) is far more likely than the former, and I think it would also be pretty difficult to detect in practice. But the point is less "I think they will do this" than "there is still an element of trust here, even if it is a much harder hoop to jump through." I don't think any situation where signal does anything like this is likely.
- viraptor 4y agoYou don't need to release a non-verifying client. Just one that generates a key which is known to the other side. What about existing clients? "Your identity in the database became corrupted and can't be recovered. Would you like to generate a new key and continue using the service?" or just release a version which is both verifying and lying to you about which key has been verified... or a low effort "hey, new phone, key changed".
- crazygringo 4y agoI don't know much about Mastodon, but I know that it's main selling point is that it's decentralized, and it's pretty easy to assume that decentralized means there isn't anybody with special privileges who can read private messages. The same way decentralized finance (blockchain) means there isn't anybody with special privileges who can take your money. And I would certainly assume that in 2022, any service would be built using encryption for the parts that are private, and aren't DM's private? Why would admins be able to read them? Is there a justification for that?
- stormbrew 4y ago> it's pretty easy to assume that decentralized means there aren't admins who can read private messages. I'm not sure why you would assume that? It's not something you run on your computer, it's still a website (or set of websites). Admins of your email can also read your email, if they want, and even with gmail in the mix it's probably one of the most "federated" systems ever built. > I would certainly assume that in 2022 it would built using encryption for the parts that are private, and aren't DM's private? Why would admins be able to read them? Is there a justification for that? They could potentially be encrypted at rest, in the database, but that doesn't really help much. The owner of the site would have the keys to decrypt them, and on smaller sites it's very unlikely that there'd be any real chain of custody involved. If you've ever sent a DM on a forum did you think that was encrypted? It wasn't. Or twitter or facebook for that matter. It's not really practical for any data stored on a central server to be encrypted in a way that irrevocably prevents the owner of the service from accessing it.
- crazygringo 4y ago> I'm not sure why you would assume that?... If you've ever sent a DM on a forum did you think that was encrypted? The whole assumption here is that Mastodon is supposed to be better than those, right? Or else why are we switching? Twitter is centralized and can read all your stuff and censor it too. So isn't the point that Mastodon isn't and can't do those bad things? We expect WhatsApp and iMessage to provide E2EE. Similarly open-source Signal and Telegram are encrypted. So why wouldn't you assume another high-profile open source project isn't adopting those same best practices for the private-messages part of it?
- palata 4y agoThat's wrong. If it is end-to-end encrypted, then the server admins still cannot read it. Use e2ee messengers (like Signal) for DMs, use Mastodon (or whatever you want) for public posts.
- gnull 4y agoMastodon is "service", not "website". You can use dedicated client software.