so it seems the privacy issues on here are going to be its undoing - if admins can view your dms and so on its not going to work
@firstdogonthemoon heads up - twitter can read your DMs to, they're totally unencrypted.
@firstdogonthemoon fortunately i do not have DMs
@upulie but what if you did? imagen!
@firstdogonthemoon I suppose it will happens one day. At the moment its like Shit Twitter but also Calmer and Nicer
@firstdogonthemoon If you need secure comms, use something like Signal instead. You don't write private stuff on a public website.
@jpwarren no you don’t write stuff on a public website - i write all sorts of things and i want it to be private like it is on twitter - if that is a feature rather than a bug it is not going to work - i’m not going to tell people to come here if that is the case
@firstdogonthemoon Ah, I see. You might want to re-evaluate Twitter DMs, and check how private they are as well for your needs, but I think I better understand your concerns now. It's a good point.
@jpwarren @firstdogonthemoon yeah I have no idea who the .cloud @admin is but I trust them more than Jack Dorsey and a Manila body shop with a content moderator contract.
@GordyPls I do want to understand the risk of "motivated malicious person sets up new instance to try to get your DMs" threat vector more.
There's a lot of FUD from people who seem weirdly concerned about other people enjoying themselves in ways they disapprove of.
But unlike Twitter, we can actually check the code for how this thing works.
@jpwarren @GordyPls I think any dm is only going to involve the instances of those users involved. Would have to confirm but mitm attacks should be minimal
@firstdogonthemoon look son if you've done nothing wrong you've got nothing to fear β„’
@firstdogonthemoon Same as twitter. That didn’t work either :)
@firstdogonthemoon I can live without DMs and Twitter can read the ones over there already
@firstdogonthemoon it's fixable, something like a client-side PGP library would mean that federated admins would only see encrypted data rather than messages
@je_au that would be good and β€œthey” should do that