I can't in good faith recommend Mastodon.
I can't in good faith recommend Mastodon.
Also, lack of encryption allows for selective censorship on the fly.
Either offer it properly or do not offer it at all. It's irresponsible otherwise.
Twitter by default broadcasts everything you write to the entire world!
Why should open source solutions be held to a higher standard?
To be fair, at least your connection to twitter is encrypted. This means that an observer can't tell it's your IP that's posting on twitter as you.
That is, your location.
Thus twitter is actually better. A court order would be needed for them to disclose IP addreses, at least.
What!? Are you talking about TLS? Because this is true for Mastodon as well then.
Mastodon is a microblogging service, it's perfectly fine to not sign all messages (though ActivityPub does support signing)
Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
Note it IS signed. It's just not encrypted. It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Additionally... should I be some location and post something, I'd be broadcasting my location, even if that isn't intended. All because it's not encrypted, where it should be.
>Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
That'd be true if it was peer-to-peer encrypted. But it is not; all messages are plaintext on the wire.
Can you tell me how and where you would broadcast your location via Mastodon? There are no geolocation features in Mastodon.
>It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Has anyone attempted to encrypt a message to 64,000 recipients yet? I don't think restricting a message to followers is an applicable model for e2ee. Direct messages yes, I can see the point in that.
For a network observer, your IP address, associated with your account name.
>I don't think restricting a message to followers is an applicable model for e2ee
But requiring TLS between clients and servers, and between servers (for the federation), is applicable.
>Direct messages yes, I can see the point in that.
The average joe expects direct messages to really be private. If they're not, that's bad.
>The average joe expects direct messages to really be private. If they're not, that's bad.
They're not "really private" in Twitter DMs and Facebook Messenger and PMs on phpBB and Discourse forums, they were not "really private" in ICQ, AIM and XMPP (unless you installed the OTR plugin on the last one). E2EE is cool but most private messages on the internet do not use it and they are still called things like "private" and "direct".
Citation needed. I was told it's optional in a recent thread.
>They're not "really private" in...
Doesn't address the argument you quoted:
>The average joe expects direct messages to really be private. If they're not, that's bad.
If you use TLS they aren't.
>should I be some location and post something, I'd be broadcasting my location, even if that isn't intended.
you broadcast it to your mastodon instance. In P2P you would actually be broadcasting your position to any network observer. In Federation only your instance knows.
Connect to post something without encryption means your location is revealed to anybody observing the network.
This is indeed dangerous.
Where are you taking this from? You think connecting to your Mastodon server you have an account on somehow broadcasts to the whole network?
- Your message
- Your account name
- Your ip address (thus location)
- The time at which this happens
If the message is sent through an encrypted connection, but the federation connection between the servers is unencrypted, a powerful enough observer could still deduce the above.
Most Mastodon servers have TLS, exceptions usually included instances deployed to localhost.
Mastodon doesn't technically require it but all clients I've seen do and the web interface relies on some features that are only available in a trusted context (HTTPS and localhost)
I don't really see the problem though, which instance you sign up to is up to you. You can sign up to a HTTP-only instance if you want.
The privacy of your data is in the hands of your local administrator more than any powerful observer (and servers you send messages too, like with email, for which all your complains are valid too since it functions similarly).
That's a serious issue. If plaintext is allowed, then expect getting people to downgrade to plaintext will be trivial, because "it just works".
It's a serious mistake, but a well understood one by today. Mastodon is relatively new, and they should have known better than to do this.
So yes, Mastodon did know better but it's not an inherent property of ActivityPub to use HTTPS.