Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Like most social networks, Mastodon is not end-to-end encrypted.

Like most social networks, Mastodon is not end-to-end encrypted.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
feditipsmastodone2ee
15 Indlæg 9 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • feditips@social.growyourown.servicesF feditips@social.growyourown.services

    Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

    Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

    More info about the risks and how to mitigate them in the guide at:

    ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

    TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

    #FediTips #Mastodon #E2EE

    jamesmarshall@sfba.socialJ This user is from outside of this forum
    jamesmarshall@sfba.socialJ This user is from outside of this forum
    jamesmarshall@sfba.social
    wrote sidst redigeret af
    #2

    @FediTips yes, this is important to know! It's also worth mentioning that the ActivityPub folks are working to add end-to-end encryption to the protocols, so hopefully we'll get that at some point.

    1 Reply Last reply
    0
    • feditips@social.growyourown.servicesF feditips@social.growyourown.services

      Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

      Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

      More info about the risks and how to mitigate them in the guide at:

      ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

      TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

      #FediTips #Mastodon #E2EE

      kev@mcr.wtfK This user is from outside of this forum
      kev@mcr.wtfK This user is from outside of this forum
      kev@mcr.wtf
      wrote sidst redigeret af
      #3

      @FediTips as a server admin I think it's worth mentioning that the techy skills required to read users' DMs are pretty trivial. I could do it very easily if I wanted.

      Of course I don't, and won't, but I assume there are circumstances where I could be compelled to hand them over to law enforcement or something and I don't think I or the users would want to be in that position!

      feditips@social.growyourown.servicesF 1 Reply Last reply
      0
      • feditips@social.growyourown.servicesF feditips@social.growyourown.services

        Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

        Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

        More info about the risks and how to mitigate them in the guide at:

        ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

        TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

        #FediTips #Mastodon #E2EE

        farooqkz@mastodon.bsd.cafeF This user is from outside of this forum
        farooqkz@mastodon.bsd.cafeF This user is from outside of this forum
        farooqkz@mastodon.bsd.cafe
        wrote sidst redigeret af
        #4

        @FediTips

        If you need an E2EE messaging but with a UI that even your toddler can work with, you can try #DeltaChat https://delta.chat

        Other than that, you can also try #Matrix, and #XMPP. They are all #decentralized and #opensource

        rogue_cells@chaos.socialR 1 Reply Last reply
        0
        • kev@mcr.wtfK kev@mcr.wtf

          @FediTips as a server admin I think it's worth mentioning that the techy skills required to read users' DMs are pretty trivial. I could do it very easily if I wanted.

          Of course I don't, and won't, but I assume there are circumstances where I could be compelled to hand them over to law enforcement or something and I don't think I or the users would want to be in that position!

          feditips@social.growyourown.servicesF This user is from outside of this forum
          feditips@social.growyourown.servicesF This user is from outside of this forum
          feditips@social.growyourown.services
          wrote sidst redigeret af feditips@social.growyourown.services
          #5

          @kev

          If you're a techy person they're trivial, but if you're e.g. running it on managed hosting the admin doesn't even get database access (though of course the hosting company staff do).

          There's also the complication of moderating DMs, if someone reports it it becomes visible to the admin through Mastodon itself.

          kev@mcr.wtfK 1 Reply Last reply
          0
          • feditips@social.growyourown.servicesF feditips@social.growyourown.services

            @kev

            If you're a techy person they're trivial, but if you're e.g. running it on managed hosting the admin doesn't even get database access (though of course the hosting company staff do).

            There's also the complication of moderating DMs, if someone reports it it becomes visible to the admin through Mastodon itself.

            kev@mcr.wtfK This user is from outside of this forum
            kev@mcr.wtfK This user is from outside of this forum
            kev@mcr.wtf
            wrote sidst redigeret af
            #6

            @FediTips oh good point. I forget about the hosted services.

            1 Reply Last reply
            0
            • farooqkz@mastodon.bsd.cafeF farooqkz@mastodon.bsd.cafe

              @FediTips

              If you need an E2EE messaging but with a UI that even your toddler can work with, you can try #DeltaChat https://delta.chat

              Other than that, you can also try #Matrix, and #XMPP. They are all #decentralized and #opensource

              rogue_cells@chaos.socialR This user is from outside of this forum
              rogue_cells@chaos.socialR This user is from outside of this forum
              rogue_cells@chaos.social
              wrote sidst redigeret af
              #7

              @farooqkz @FediTips 100% team Matrix here 😛

              1 Reply Last reply
              0
              • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                More info about the risks and how to mitigate them in the guide at:

                ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                #FediTips #Mastodon #E2EE

                S This user is from outside of this forum
                S This user is from outside of this forum
                spacelifeform@infosec.exchange
                wrote sidst redigeret af
                #8

                @FediTips

                I am not worrird about Grampa @jerry

                He has another thing on his hands.

                1 Reply Last reply
                0
                • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                  Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                  Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                  More info about the risks and how to mitigate them in the guide at:

                  ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                  TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                  #FediTips #Mastodon #E2EE

                  qgustavor@urusai.socialQ This user is from outside of this forum
                  qgustavor@urusai.socialQ This user is from outside of this forum
                  qgustavor@urusai.social
                  wrote sidst redigeret af
                  #9

                  @FediTips

                  -----BEGIN PGP SIGNED MESSAGE-----
                  Hash: SHA256

                  I wonder how many Fedi users are using PGP or similar schemes.
                  -----BEGIN PGP SIGNATURE-----

                  wnUEARYIAB0FgmqkjuYWIQRfwYaAQ1bC5Ge/wrr1vjwiBlASJgAKCRD1vjwiBlAS
                  Jk3CAP4pMaf55bsWtYFHRA2dvSN2ZhLpi86TvEaSlBPQ/fr7kwD+MWD6ZwmIb0rW
                  W4aXPpOuNsBOLol92h9V71m3l6HoWg0=
                  =9zQN
                  -----END PGP SIGNATURE-----

                  1 Reply Last reply
                  0
                  • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                    Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                    Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                    More info about the risks and how to mitigate them in the guide at:

                    ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                    TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                    #FediTips #Mastodon #E2EE

                    collective_truth@mastodon.socialC This user is from outside of this forum
                    collective_truth@mastodon.socialC This user is from outside of this forum
                    collective_truth@mastodon.social
                    wrote sidst redigeret af
                    #10

                    @FediTips But better than usnig gmail right?

                    feditips@social.growyourown.servicesF 1 Reply Last reply
                    0
                    • collective_truth@mastodon.socialC collective_truth@mastodon.social

                      @FediTips But better than usnig gmail right?

                      feditips@social.growyourown.servicesF This user is from outside of this forum
                      feditips@social.growyourown.servicesF This user is from outside of this forum
                      feditips@social.growyourown.services
                      wrote sidst redigeret af
                      #11

                      @collective_truth

                      Well yeah, email is totally unencrypted and Google is a surveillance company.

                      Sensitive info should never ever be sent by email, it is totally insecure.

                      1 Reply Last reply
                      0
                      • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                        Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.

                        Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).

                        More info about the risks and how to mitigate them in the guide at:

                        ➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted

                        TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.

                        #FediTips #Mastodon #E2EE

                        pvtejas@mstdn.socialP This user is from outside of this forum
                        pvtejas@mstdn.socialP This user is from outside of this forum
                        pvtejas@mstdn.social
                        wrote sidst redigeret af
                        #12

                        @FediTips I think the ""they would need techy skills to do this" is moot for someone being a server admin

                        feditips@social.growyourown.servicesF 1 Reply Last reply
                        0
                        • pvtejas@mstdn.socialP pvtejas@mstdn.social

                          @FediTips I think the ""they would need techy skills to do this" is moot for someone being a server admin

                          feditips@social.growyourown.servicesF This user is from outside of this forum
                          feditips@social.growyourown.servicesF This user is from outside of this forum
                          feditips@social.growyourown.services
                          wrote sidst redigeret af feditips@social.growyourown.services
                          #13

                          @PVTejas

                          A lot of admins use managed hosting services which do all the techy stuff for them (e.g. https://fedihost.co or https://masto.host or https://cloud68.co etc), so they aren't necessarily techy people.

                          pvtejas@mstdn.socialP 1 Reply Last reply
                          0
                          • feditips@social.growyourown.servicesF feditips@social.growyourown.services

                            @PVTejas

                            A lot of admins use managed hosting services which do all the techy stuff for them (e.g. https://fedihost.co or https://masto.host or https://cloud68.co etc), so they aren't necessarily techy people.

                            pvtejas@mstdn.socialP This user is from outside of this forum
                            pvtejas@mstdn.socialP This user is from outside of this forum
                            pvtejas@mstdn.social
                            wrote sidst redigeret af
                            #14

                            @FediTips Doesn't that just pass the buck to whoever is actually doing the techy job of hosting?
                            Although it does mean there are a lot fewer people who can snoop than I thought.

                            feditips@social.growyourown.servicesF 1 Reply Last reply
                            0
                            • pvtejas@mstdn.socialP pvtejas@mstdn.social

                              @FediTips Doesn't that just pass the buck to whoever is actually doing the techy job of hosting?
                              Although it does mean there are a lot fewer people who can snoop than I thought.

                              feditips@social.growyourown.servicesF This user is from outside of this forum
                              feditips@social.growyourown.servicesF This user is from outside of this forum
                              feditips@social.growyourown.services
                              wrote sidst redigeret af feditips@social.growyourown.services
                              #15

                              @PVTejas

                              Main thing I was trying to get across with the "techy" comment is that there is nothing in Mastodon's own software that allows admins to view DMs, there is no admin tool for doing that (I was saying this because some people thought there was). You have to step outside Mastodon and look at the raw database directly, which requires tech skills and database access.

                              And yes that does mean the hosting company would have access, so it's always best to avoid sensitive data.

                              1 Reply Last reply
                              0
                              Svar
                              • Svar som emne
                              Login for at svare
                              • Ældste til nyeste
                              • Nyeste til ældste
                              • Most Votes


                              • Log ind

                              • Har du ikke en konto? Tilmeld

                              • Login or register to search.
                              Powered by NodeBB Contributors
                              Graciously hosted by data.coop
                              • First post
                                Last post
                              0
                              • Hjem
                              • Seneste
                              • Etiketter
                              • Populære
                              • Verden
                              • Bruger
                              • Grupper