Does this mean they may have accidentally published a message intended as private, to the public?
If so, I don’t think I can imagine a more efficient way to rob me of any confidence I ever had in Mastodon…
Does this mean they may have accidentally published a message intended as private, to the public?
If so, I don’t think I can imagine a more efficient way to rob me of any confidence I ever had in Mastodon…
All of this without breaking compatibility across instances running different versions; quite a nice piece of engineering IMHO.
This solution was discussed at length with mastodon devs before the implementation of the private messages. It was ignored. Now we have a situation were Mastodon is likely to switch off OStatus soon, leaving behind all those projects that don't have the dev resources to rewrite their core federation systems every few years.
The Ostatus/AP dual stack is also pretty hacky and not even valid according to the AP spec, although it's getting better all the time.
If you want to keep something private, don't post it on a social media platform -- or at least, encrypt it out of band before you do.
Really, the only time I should expect the content I share on a social media platform to be public is if I shared it as public content.
[Note that I am talking about technical capabilities and privacy here. Of course somebody with whom I shared private information can re-post it publicly, but solving that is out of scope for a technical solution - and is also true outside of social media platforms]
[1] http://www.washingtonpost.com/wp-dyn/content/article/2010/01...
If they are incompatible, they aren't orthogonal, they are opposed.
For some people, this is strictly limited to the technical capability to prevent (or allow) the flow of information. I'd long subscribed to this point of view, but have found it inadequate, if only because capabilities have been changing so dramatically on this point.
Rather, and this is something of a personal definition, though I'm not certain it's specific or original to me is that privacy is the ability to define and defend limits and boundaries on information sharing.
You might ask "why use that definition?"
My principle answer is that if it isn't possible to share information in a limited context, then there's something immense and profound which is lost. Two people, or twenty, or even several tens of thousands (say: a large company or government bureaucracy) might need to share information without disclosure.
I've been following the ICIJ's multiple projects on various data leaks, which are particularly poignant in revealing both sides of the argument. On the one hand, the ICIJ itself farms out its data to several hundred journalists from numerous organisations, and keeps a lid on the project until an agreed-on release date. (The group has produced a video showing just this process.)
On the other, ICIJ's stock in trade have been leaks of information from other organisations whose privacy has been breached.
The question of "which of these is right?" should very much arise. And it's not an easy question to answer, though I believe there are some guides which can be used.
As such, privacy is not an inviolable right, but it is a crucial element of social organisation.
The definition draws in part on Jeffrey Rosen's The Unwanted Gaze, published in the late 1990s, and apparently quite underappreciated and/or known. Though it's been a while since I've read it.
But it's like saying that publishing is opposite to privacy. Yeah... It is so by design and definition.