Oh we’re doing “your admins can see your DMs” again?

You’ll never guess what’s true about literally every website that has a DM feature
I’ve worked for Big Companies and I could see real production data for real customers without even being an admin or support person

The difference with fedi is I have literally met the admin of this instance in real life and I know they would not do this
@olivvybee I've worked for big companies and there where very serious hoops you'd have to jump before being allowed anywhere near private data
@Atridas (sometimes)

but yes the point is you
can do it, it's not impossible – the same as on fedi

@olivvybee the only thing that could prevent it on the fedi is some kind of end to end encryption, and that'd be untrivial to build.

As of other companies, not only the friction to get there is important, but the accountability of something goes wrong too. And I've seen high standards there. It is possible.

@Atridas @olivvybee okay but the latest trendy thing to do is for companies to sell your DM data to large language model training companies
@eniko @olivvybee ok. Should fedi then sell your DMs to LLM?
@Atridas accountability for the average employee maybe. For the whole enterprise, not so much. @olivvybee
@Atridas @olivvybee CEOs can get someone else to jump through hoops for them.
@quietmarc @olivvybee again, this is not a good excuse to copy them
@Atridas @olivvybee I interpreted the OP as cautioning folks that all sensitive data is vulnerable online, not that we should be copying big companies, but this is not my wheelhouse.
@olivvybee i trust the nonbinary gay furry fox on the internet much more than Twitter
@rail_ @olivvybee you trust yourself? Wow, couldn't be me
@darkphoenix @olivvybee i mean Dalite and yeah i realize how familiar that description is……………
@rail_ @olivvybee half of fedi is, in fact, non-binary gay furry foxes
I'm still not sure I'm not one myself... the fox bit I mean, everything else I definitely am already so
@darkphoenix @rail_ @olivvybee Umm  some of us aren't foxes. (Okay primarily  )
@rail_ @JasperSparks @olivvybee I trust my sleazy ass local politician more than twitter
@[email protected] End-to-end encryption should be implemented nevertheless.

@olivvybee Eh, I feel like this is kinda the point, the admins know you personally.

And yeah, that is mostly a good thing, but in this case people probably do feel awkward, because someone who knows them can potentially be interested in their messages. This could get extra hairy if at any point there's personal drama involved.

The security properties are the same in both cases, but the social ones are not.

It doesn't mean DMs are useless here, I still use them to have a little chat related to something on here, and I've used them to discuss commissions with artists, but when people are more uncomfortable with this than say Discord they're not being unreasonable.

@olivvybee to back this up:

each single mastodon instance has about the same level of protection over DMs for that single instance as a previous workplace had over the current location of a plurality of long-haul freight in the united states

that is, you have to actually have access to the server and database to read it

at the big social media sites? not so much.

and to head off the question, yes, twitter too, even if they started encrypting at rest:

Currently, we do not offer protections against man-in-the-middle attacks. As a result, if someone–for example, a malicious insider, or X itself as a result of a compulsory legal process--were to compromise an encrypted conversation, neither the sender or receiver would know.

@olivvybee I trust my fedi admins when they screw up more than I trust the big companies when they don't
@olivvybee I don’t gonna a f* if my admin can read my DMs (wich they won’t do, they’re busy people who care about privacy, I know how they smell.)
I trust my admin here to burn my DMs as soon as the cops ask for them. Much, much more important.