Okay, i'm going to say something, may not be very popular but oh well. It's regarding Thrive messenger. I've seen so many comments about it, please, bear in mind this is a new application. Things will be corrected/fixed in time and some of the wording in these comments has been rude at best. Developers work damn hard to make sure something is right, give them some damn respect. #ThriveMessenger
@ChocolatePie I am giving them respect.
@TomGrant91 @ChocolatePie Yup, and that's good dude.
@alexchapman @TomGrant91 @ChocolatePie I also respect what the devs are trying to do. however, I also expect the developers to have a solid roadmap and set of legal and security policies
@freya @TomGrant91 @ChocolatePie You're forgetting, this is not a company, but a couple of people working on this in their spair time, so yeah, expecting all that to be in place right out of the gate is expecting a lot.
@alexchapman @TomGrant91 @ChocolatePie I do not care that this is a company or not dude. you are running, a public service. you are running a service, where people may communicate sensitive data, including personally identifiable information (PII). you are responsible, at that point, for ensuring the security of that data and the media over which it is communicated. whether you're a single developer, a group of 5 people, or a 20000 employee company, it doesn't matter, the same legal and policy requirements apply. I want to see thrive messenger, well, thrive. but it's going to be the source of a massive data breech if yous aren't careful and I don't wanna see yall go through that
@freya @TomGrant91 @ChocolatePie OK, well people know what they are getting into when the phrase, public alpha, or just, alpha, is right there in the releases. Its a proof of concept stage, and all this is being worked on, but its not gonna be there within a click of a finger.
@alexchapman @TomGrant91 @ChocolatePie you are running it as a public service with insufficient security. shut it down, add security, then relaunch. you shouldn't be offering this right now, in its current state, it's not safe
@freya @TomGrant91 @ChocolatePie It doesn't need to be shut down, but the security is being added.
@alexchapman @TomGrant91 @ChocolatePie I'd like to see proof of that. Who's your designated security lead?
@alexchapman @TomGrant91 @ChocolatePie based on what I've heard from you, you don't know much about security. I then ask: what do you thinkl is required to make a truly secure messenger? and how aware are you of the current threat models? what *is* your threat model in fact?