Reminder (or maybe eye-opener) to Mastodon users:

Direct Messages on Mastodon are NOT encrypted.

What does this mean: The message is in the database un-encrypted. Anyone with access to the database could potentially read the messages.

For mastodon.world, only the admins have database access (@jeroen, @spaceriker and myself).

If you have really sensitive info, don't share it on Mastodon. There are secure messaging apps for that.

@ruud @jeroen @spaceriker

Don’t use Mastodon for private information, it’s a community sharing platform.
- Toots are stored unencrypted incl. DM’s.
- Toots are stored on a server you do not control (same as twitter)
- Toots are synced to all servers where your messages and boosts of your messages are followed.
- DM Toots are stored on your community server and on the server of your addressee.
- DM Toots can be shared (by accident) by the addressee.

@smhoekstra @ruud @jeroen @spaceriker good to repeat, use #Signal for anything you want to keep private would be my suggestion, also opensource and not-for-profit.