Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Like most social networks, Mastodon is not end-to-end encrypted.

Like most social networks, Mastodon is not end-to-end encrypted.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
feditipsmastodone2ee
15 Indlæg 9 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • feditips@social.growyourown.servicesF feditips@social.growyourown.services

    Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

    Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

    More info about the risks and how to mitigate them in the guide at:

    ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

    TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

    #FediTips #Mastodon #E2EE

    kev@mcr.wtfK This user is from outside of this forum
    kev@mcr.wtfK This user is from outside of this forum
    kev@mcr.wtf
    wrote sidst redigeret af
    #3

    @FediTips as a server admin I think it's worth mentioning that the techy skills required to read users' DMs are pretty trivial. I could do it very easily if I wanted.

    Of course I don't, and won't, but I assume there are circumstances where I could be compelled to hand them over to law enforcement or something and I don't think I or the users would want to be in that position!

    feditips@social.growyourown.servicesF 1 Reply Last reply
    0
    • feditips@social.growyourown.servicesF feditips@social.growyourown.services

      Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

      Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

      More info about the risks and how to mitigate them in the guide at:

      ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

      TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

      #FediTips #Mastodon #E2EE

      farooqkz@mastodon.bsd.cafeF This user is from outside of this forum
      farooqkz@mastodon.bsd.cafeF This user is from outside of this forum
      farooqkz@mastodon.bsd.cafe
      wrote sidst redigeret af
      #4

      @FediTips

      If you need an E2EE messaging but with a UI that even your toddler can work with, you can try #DeltaChat https://delta.chat

      Other than that, you can also try #Matrix, and #XMPP. They are all #decentralized and #opensource

      rogue_cells@chaos.socialR 1 Reply Last reply
      0
      • kev@mcr.wtfK kev@mcr.wtf

        @FediTips as a server admin I think it's worth mentioning that the techy skills required to read users' DMs are pretty trivial. I could do it very easily if I wanted.

        Of course I don't, and won't, but I assume there are circumstances where I could be compelled to hand them over to law enforcement or something and I don't think I or the users would want to be in that position!

        feditips@social.growyourown.servicesF This user is from outside of this forum
        feditips@social.growyourown.servicesF This user is from outside of this forum
        feditips@social.growyourown.services
        wrote sidst redigeret af feditips@social.growyourown.services
        #5

        @kev

        If you're a techy person they're trivial, but if you're e.g. running it on managed hosting the admin doesn't even get database access (though of course the hosting company staff do).

        There's also the complication of moderating DMs, if someone reports it it becomes visible to the admin through Mastodon itself.

        kev@mcr.wtfK 1 Reply Last reply
        0
        • feditips@social.growyourown.servicesF feditips@social.growyourown.services

          @kev

          If you're a techy person they're trivial, but if you're e.g. running it on managed hosting the admin doesn't even get database access (though of course the hosting company staff do).

          There's also the complication of moderating DMs, if someone reports it it becomes visible to the admin through Mastodon itself.

          kev@mcr.wtfK This user is from outside of this forum
          kev@mcr.wtfK This user is from outside of this forum
          kev@mcr.wtf
          wrote sidst redigeret af
          #6

          @FediTips oh good point. I forget about the hosted services.

          1 Reply Last reply
          0
          • farooqkz@mastodon.bsd.cafeF farooqkz@mastodon.bsd.cafe

            @FediTips

            If you need an E2EE messaging but with a UI that even your toddler can work with, you can try #DeltaChat https://delta.chat

            Other than that, you can also try #Matrix, and #XMPP. They are all #decentralized and #opensource

            rogue_cells@chaos.socialR This user is from outside of this forum
            rogue_cells@chaos.socialR This user is from outside of this forum
            rogue_cells@chaos.social
            wrote sidst redigeret af
            #7

            @farooqkz @FediTips 100% team Matrix here 😛

            1 Reply Last reply
            0
            • feditips@social.growyourown.servicesF feditips@social.growyourown.services

              Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

              Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

              More info about the risks and how to mitigate them in the guide at:

              ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

              TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

              #FediTips #Mastodon #E2EE

              S This user is from outside of this forum
              S This user is from outside of this forum
              spacelifeform@infosec.exchange
              wrote sidst redigeret af
              #8

              @FediTips

              I am not worrird about Grampa @jerry

              He has another thing on his hands.

              1 Reply Last reply
              0
              • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                More info about the risks and how to mitigate them in the guide at:

                ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                #FediTips #Mastodon #E2EE

                qgustavor@urusai.socialQ This user is from outside of this forum
                qgustavor@urusai.socialQ This user is from outside of this forum
                qgustavor@urusai.social
                wrote sidst redigeret af
                #9

                @FediTips

                -----BEGIN PGP SIGNED MESSAGE-----
                Hash: SHA256

                I wonder how many Fedi users are using PGP or similar schemes.
                -----BEGIN PGP SIGNATURE-----

                wnUEARYIAB0FgmqkjuYWIQRfwYaAQ1bC5Ge/wrr1vjwiBlASJgAKCRD1vjwiBlAS
                Jk3CAP4pMaf55bsWtYFHRA2dvSN2ZhLpi86TvEaSlBPQ/fr7kwD+MWD6ZwmIb0rW
                W4aXPpOuNsBOLol92h9V71m3l6HoWg0=
                =9zQN
                -----END PGP SIGNATURE-----

                1 Reply Last reply
                0
                • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                  Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                  Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                  More info about the risks and how to mitigate them in the guide at:

                  ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                  TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                  #FediTips #Mastodon #E2EE

                  collective_truth@mastodon.socialC This user is from outside of this forum
                  collective_truth@mastodon.socialC This user is from outside of this forum
                  collective_truth@mastodon.social
                  wrote sidst redigeret af
                  #10

                  @FediTips But better than usnig gmail right?

                  feditips@social.growyourown.servicesF 1 Reply Last reply
                  0
                  • collective_truth@mastodon.socialC collective_truth@mastodon.social

                    @FediTips But better than usnig gmail right?

                    feditips@social.growyourown.servicesF This user is from outside of this forum
                    feditips@social.growyourown.servicesF This user is from outside of this forum
                    feditips@social.growyourown.services
                    wrote sidst redigeret af
                    #11

                    @collective_truth

                    Well yeah, email is totally unencrypted and Google is a surveillance company.

                    Sensitive info should never ever be sent by email, it is totally insecure.

                    1 Reply Last reply
                    0
                    • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                      Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                      Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                      More info about the risks and how to mitigate them in the guide at:

                      ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                      TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                      #FediTips #Mastodon #E2EE

                      pvtejas@mstdn.socialP This user is from outside of this forum
                      pvtejas@mstdn.socialP This user is from outside of this forum
                      pvtejas@mstdn.social
                      wrote sidst redigeret af
                      #12

                      @FediTips I think the ""they would need techy skills to do this" is moot for someone being a server admin

                      feditips@social.growyourown.servicesF 1 Reply Last reply
                      0
                      • pvtejas@mstdn.socialP pvtejas@mstdn.social

                        @FediTips I think the ""they would need techy skills to do this" is moot for someone being a server admin

                        feditips@social.growyourown.servicesF This user is from outside of this forum
                        feditips@social.growyourown.servicesF This user is from outside of this forum
                        feditips@social.growyourown.services
                        wrote sidst redigeret af feditips@social.growyourown.services
                        #13

                        @PVTejas

                        A lot of admins use managed hosting services which do all the techy stuff for them (e.g. https://fedihost.co or https://masto.host or https://cloud68.co etc), so they aren't necessarily techy people.

                        pvtejas@mstdn.socialP 1 Reply Last reply
                        0
                        • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                          @PVTejas

                          A lot of admins use managed hosting services which do all the techy stuff for them (e.g. https://fedihost.co or https://masto.host or https://cloud68.co etc), so they aren't necessarily techy people.

                          pvtejas@mstdn.socialP This user is from outside of this forum
                          pvtejas@mstdn.socialP This user is from outside of this forum
                          pvtejas@mstdn.social
                          wrote sidst redigeret af
                          #14

                          @FediTips Doesn't that just pass the buck to whoever is actually doing the techy job of hosting?
                          Although it does mean there are a lot fewer people who can snoop than I thought.

                          feditips@social.growyourown.servicesF 1 Reply Last reply
                          0
                          • pvtejas@mstdn.socialP pvtejas@mstdn.social

                            @FediTips Doesn't that just pass the buck to whoever is actually doing the techy job of hosting?
                            Although it does mean there are a lot fewer people who can snoop than I thought.

                            feditips@social.growyourown.servicesF This user is from outside of this forum
                            feditips@social.growyourown.servicesF This user is from outside of this forum
                            feditips@social.growyourown.services
                            wrote sidst redigeret af feditips@social.growyourown.services
                            #15

                            @PVTejas

                            Main thing I was trying to get across with the "techy" comment is that there is nothing in Mastodon's own software that allows admins to view DMs, there is no admin tool for doing that (I was saying this because some people thought there was). You have to step outside Mastodon and look at the raw database directly, which requires tech skills and database access.

                            And yes that does mean the hosting company would have access, so it's always best to avoid sensitive data.

                            1 Reply Last reply
                            0
                            Svar
                            • Svar som emne
                            Login for at svare
                            • Ældste til nyeste
                            • Nyeste til ældste
                            • Most Votes


                            • Log ind

                            • Har du ikke en konto? Tilmeld

                            • Login or register to search.
                            Powered by NodeBB Contributors
                            Graciously hosted by data.coop
                            • First post
                              Last post
                            0
                            • Hjem
                            • Seneste
                            • Etiketter
                            • Populære
                            • Verden
                            • Bruger
                            • Grupper