HEY GUYS:

Adrienne Leigh has a truly excellent and very important run down on the SEVERE AND PERVASIVE PRIVACY ISSUES ON THIS SERVICE. i'm not taking about OPSEC, I'm talking about BASIC PRIVACY SAFETY AND IMPERSONATION ISSUES.

PLEASE READ AND SHARE, Y'ALL

https://twitter.com/adrienneleigh/status/850061121184604160

π–†π–‰π–—π–Žπ–Šπ–“π–“π–Š on Twitter

β€œSo, Mastodon. Just FYI, if a SINGLE hostile user on a SINGLE malicious instance follows you, all your posts may be kept forever --”

Twitter
@ohtazer this is why ive set up a dischord, which is encrypted

@ohtazer She apparently doesn't know that this sort of content capture is possible on Twitter and the impersonation issue is a non-issue.

PLEASE DON'T ALL-CAPS ENGAGEMENT SOLICITATION FOR FUD ON TWITTER, Y'ALL

@pete what is FUD?

from my admittedly limited understanding, i thought admins of instances end up having access to your private messages if you engage with a person hosted in their instance

and just to clarify do you mean impersonation has not been a problem or does not have the capacity to become a problem?

@ohtazer "Fear, Uncertainty, and Doubt", coined by an ex-IBM employee to describe their marketing strategy.

Admins have access to PMs you send to their server. All PMs you send through Twitter are potentially accessible to anyone they hire as an SRE or DBA, and you've got zero control over that. You trust the admins or you don't. (You shouldn't, I don't.)

Her impersonation argument is anyone can register her username and "it's like email". That's a non-issue. Impersonation in general:

@ohtazer Impersonation in general is another issue. It's an issue on Twitter with the "ETH Giveaway" problem. Their SMS-based 2FA is an issue, because the cell networks are not secure. https://www.wired.com/2016/06/hey-stop-using-texts-two-factor-authentication/ . Impersonation is not a bigger problem here than there.

The only way to solve the problems she brings up is a decentralized platform like Twister ( http://twister.net.co ). Mastodon is not less secure than Twitter, and is in several ways better.

Happy to elaborate. Will stop textwall.

So Hey You Should Stop Using Texts for Two-Factor Authentication

A string of recent SMS hacks means security-conscious users should switch to a more secure login system.

WIRED
@ohtazer yeah this concerns me... nowhere is safe
@ohtazer the idea is mainly that theres rly no such thing as private messages on mastodon, everything you post is out there for someone you might not have intended it for, and dont assume instances are a safe way around that
@mediumvillain yeah, that's pretty much the main thing i want to get across to people. i don't think it's necessary implicitly understood how many people could possibly have access to your words that are ostensibly set for certain eyes only.
@ohtazer There are no proper Sybil-Attack or Astoturfing defenses either. You kind of need to draw your own walls by retreating into other instances. This is not the last time a Mastodon Instance / Fork goes viral...
@ohtazer This is not more concerning here than any other social platform. Multiple people can have the same names on Facebook and your PMs there can be read by FB staff. Free Gmail isn't 100% private, and the same name can be used across different email services. Yes, there is vulnerability to harassment and impersonation here, but not more than most everywhere else.
@ohtazer Just as with every other social platform out there, and that includes some email platforms, if you want to have truly private communication use encrypted services like Threema, build strong communities as well as you can (including your own well-adminned instances if need be), and stay aware that we are all vulnerable in ALL public social spaces online right now.
@schmutzie thanks for this, my goal was to keep people aware that nothing is really safe and that this is no opsec utopia. i appreciate your additional information
@ohtazer It's always good to keep up awareness about our relative lack of privacy and security. Lots of people don't know much on this area.