Direct messages (DMs) on #Mastodon /#ActivityPub / the #fediverse are not end-to-end encrypted (#e2ee) and you should never include sensitive/private information in them.

Until they are e2ee, this is all we should be telling people. Anything else is irresponsible and could cause vulnerable people harm.

Specifically, it doesn’t matter:

- if your instance admin is ethical or not
- whether Elon Musk can read DMs easier on Twitter
- etc.

It’s not end-to-end encrypted. It’s not private. End of.

@aral They shouldn’t even be called DMs. Private mention is better, but even the ‘private’ indicates more privacy than you truly have.

Granted, I actually think they are a cool concept. Sometimes you only want to mention a specific person and not really bother someone else, but it’s doesn’t need to be private as such.

Follow

@torb
They are neither direct (P2P), nor they are private (E2EE), it should be called something like "restricted scope". People should just stop trying to use social networks for *private* communication, they are not a great tool for that and they never will be. It's yet another case of putting all eggs in one basket.
@aral

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml