Mastodon is a microblogging service, it's perfectly fine to not sign all messages (though ActivityPub does support signing)
Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
Mastodon is a microblogging service, it's perfectly fine to not sign all messages (though ActivityPub does support signing)
Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
Note it IS signed. It's just not encrypted. It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Additionally... should I be some location and post something, I'd be broadcasting my location, even if that isn't intended. All because it's not encrypted, where it should be.
>Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
That'd be true if it was peer-to-peer encrypted. But it is not; all messages are plaintext on the wire.
Can you tell me how and where you would broadcast your location via Mastodon? There are no geolocation features in Mastodon.
>It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Has anyone attempted to encrypt a message to 64,000 recipients yet? I don't think restricting a message to followers is an applicable model for e2ee. Direct messages yes, I can see the point in that.
For a network observer, your IP address, associated with your account name.
>I don't think restricting a message to followers is an applicable model for e2ee
But requiring TLS between clients and servers, and between servers (for the federation), is applicable.
>Direct messages yes, I can see the point in that.
The average joe expects direct messages to really be private. If they're not, that's bad.
>The average joe expects direct messages to really be private. If they're not, that's bad.
They're not "really private" in Twitter DMs and Facebook Messenger and PMs on phpBB and Discourse forums, they were not "really private" in ICQ, AIM and XMPP (unless you installed the OTR plugin on the last one). E2EE is cool but most private messages on the internet do not use it and they are still called things like "private" and "direct".
Citation needed. I was told it's optional in a recent thread.
>They're not "really private" in...
Doesn't address the argument you quoted:
>The average joe expects direct messages to really be private. If they're not, that's bad.
If you use TLS they aren't.
>should I be some location and post something, I'd be broadcasting my location, even if that isn't intended.
you broadcast it to your mastodon instance. In P2P you would actually be broadcasting your position to any network observer. In Federation only your instance knows.