Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
We Distribute
  1. Home
  2. Technical Discussion
  3. #mastondon Friends!

#mastondon Friends!

Scheduled Pinned Locked Moved Technical Discussion
mastondon
167 Posts 71 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • scottjenson@social.coopS scottjenson@social.coop

    #mastondon Friends!

    There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
    * getting them out of the public timeline
    * Having a stronger notification tied to the Private Mention tab
    * (amount other things)

    But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

    If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

    jackryder@infosec.exchangeJ This user is from outside of this forum
    jackryder@infosec.exchangeJ This user is from outside of this forum
    jackryder@infosec.exchange
    wrote last edited by
    #141

    @scottjenson Hi Scott, I believe the option is complex, honestly.

    Encryption is tricky but I also think it provides layers on top of the communication that might make it feel larger than a quick "dm"? I can't speak to others obviously but Mastodon should consider what solutions you are providing and if they make sense for the platform.

    Encryption is useful, but does it make sense for Mastodon? Is that the direction the social media tool is moving? Encryption-focused 1:1 communication?

    scottjenson@social.coopS 1 Reply Last reply
    0
    • scottjenson@social.coopS scottjenson@social.coop

      @neal OOOOOh, that's a cool point! Thank you. What are you suggesting, that PMs are ONLY 1:1?

      gbargoud@masto.nycG This user is from outside of this forum
      gbargoud@masto.nycG This user is from outside of this forum
      gbargoud@masto.nyc
      wrote last edited by
      #142

      @scottjenson @neal

      As a related issue: replies to "followers only posts" being "my followers only" is a strange behavior.

      I think if there was a "replies can only restrict the audience compared to the audience of the replied post, not expand it" constraint, that would solve both issues

      1 Reply Last reply
      0
      • scottjenson@social.coopS scottjenson@social.coop

        @benpate Could not agree with you more! Do you have any ideas on how to improve threads? Any products that do it well for example? Branching threads are a bit like merging PRs, the dependency tree can get crazy complex!

        jesseplusplus@mastodon.socialJ This user is from outside of this forum
        jesseplusplus@mastodon.socialJ This user is from outside of this forum
        jesseplusplus@mastodon.social
        wrote last edited by
        #143

        @scottjenson @benpate is there a reason private messages need to support threading? Most DMs on other platforms are flattened to a single thread for simplicity.

        If threading is still necessary, iOS’s design for replies to specific messages in iMessage feels easy to follow for me

        benpate@mastodon.socialB 1 Reply Last reply
        0
        • scottjenson@social.coopS scottjenson@social.coop

          #mastondon Friends!

          There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
          * getting them out of the public timeline
          * Having a stronger notification tied to the Private Mention tab
          * (amount other things)

          But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

          If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

          roastbeefhashtag@mastodon.socialR This user is from outside of this forum
          roastbeefhashtag@mastodon.socialR This user is from outside of this forum
          roastbeefhashtag@mastodon.social
          wrote last edited by
          #144

          @scottjenson I'm not against interface improvements, or even doing that first, but I'm all in on encryption.

          Mastodon is all about privacy and putting users first. When I DM someone the whole point is that the message is only for them. I prefer that administrators not be able to see.

          1 Reply Last reply
          0
          • phillycodehound@indieweb.socialP phillycodehound@indieweb.social

            @scottjenson I think just knowing that the DMs are not encrypted is enough IMHO. If you want something encrypted use Signal.

            roastbeefhashtag@mastodon.socialR This user is from outside of this forum
            roastbeefhashtag@mastodon.socialR This user is from outside of this forum
            roastbeefhashtag@mastodon.social
            wrote last edited by
            #145

            @phillycodehound @scottjenson I love Signal, but there is something to be said for being about to communicate with fediverse people directly in the fediverse.

            1 Reply Last reply
            0
            • jackryder@infosec.exchangeJ jackryder@infosec.exchange

              @scottjenson Hi Scott, I believe the option is complex, honestly.

              Encryption is tricky but I also think it provides layers on top of the communication that might make it feel larger than a quick "dm"? I can't speak to others obviously but Mastodon should consider what solutions you are providing and if they make sense for the platform.

              Encryption is useful, but does it make sense for Mastodon? Is that the direction the social media tool is moving? Encryption-focused 1:1 communication?

              scottjenson@social.coopS This user is from outside of this forum
              scottjenson@social.coopS This user is from outside of this forum
              scottjenson@social.coop
              wrote last edited by
              #146

              @jackryder all fair questions! All I can say is that there are many within the community that are quite adamant that DMs must be encrypted. The most common reason is that they don't want admins to spy on their posts.

              My concern is just that setting up E2EE is rarely a simple process. I expect it to be a ux challenge to make it easy.

              jackryder@infosec.exchangeJ 1 Reply Last reply
              0
              • scottjenson@social.coopS scottjenson@social.coop

                #mastondon Friends!

                There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                * getting them out of the public timeline
                * Having a stronger notification tied to the Private Mention tab
                * (amount other things)

                But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                fisher@toots.nuF This user is from outside of this forum
                fisher@toots.nuF This user is from outside of this forum
                fisher@toots.nu
                wrote last edited by
                #147

                @scottjenson Encription should be an option, not a must.
                Not everything should be hidden, and by reducing the cpu time you'll reduce the carbon footprint, too.

                (I'm talking about end-to-end encryption here, not about user's AAA or inter-server comms).

                Personally, I hate this modern trend of hosting public blogs via HTTPS. Not everything should be encrypted!

                1 Reply Last reply
                0
                • scottjenson@social.coopS scottjenson@social.coop

                  @jackryder all fair questions! All I can say is that there are many within the community that are quite adamant that DMs must be encrypted. The most common reason is that they don't want admins to spy on their posts.

                  My concern is just that setting up E2EE is rarely a simple process. I expect it to be a ux challenge to make it easy.

                  jackryder@infosec.exchangeJ This user is from outside of this forum
                  jackryder@infosec.exchangeJ This user is from outside of this forum
                  jackryder@infosec.exchange
                  wrote last edited by
                  #148

                  @scottjenson I appreciate the response and transparency.

                  I believe I understand the fear for concern and secrecy. I don't believe there will be a simple & straight forward solution. As you said, "just setting up..." is often a lot trickier than we anticipate.

                  I'm not familiar enough with the stack to know what would need to change. I imagine there are quite a few underlying systems that would need at least partial rework and that alone would cause for a trickle down effect on literally everything. Ouch. I wouldn't envy sitting in on those prioritization calls.

                  Personally, though I don't mean to sound diminishing to the population I would do exactly what it looks like you guys are doing. Checking the temperature and prioritizing the needs. Kind of glad to see people actually asking.

                  1 Reply Last reply
                  0
                  • scottjenson@social.coopS scottjenson@social.coop

                    #mastondon Friends!

                    There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                    * getting them out of the public timeline
                    * Having a stronger notification tied to the Private Mention tab
                    * (amount other things)

                    But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                    If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                    davemasondotme@mastodon.socialD This user is from outside of this forum
                    davemasondotme@mastodon.socialD This user is from outside of this forum
                    davemasondotme@mastodon.social
                    wrote last edited by
                    #149

                    @scottjenson
                    Signal is my go-to when I feel there's a need for #Encryption. If it was available in Mastodon for private messages, I'd probably use it.

                    I don't think the Fediverse is on the radar of the current administration here in the US yet, but they might be someday. What happens when law enforcement types show up at a Masto admin's doorstep? Do they give up all the data willingly? Even without a subpoena or judge's order?

                    davemasondotme@mastodon.socialD 1 Reply Last reply
                    0
                    • davemasondotme@mastodon.socialD davemasondotme@mastodon.social

                      @scottjenson
                      Signal is my go-to when I feel there's a need for #Encryption. If it was available in Mastodon for private messages, I'd probably use it.

                      I don't think the Fediverse is on the radar of the current administration here in the US yet, but they might be someday. What happens when law enforcement types show up at a Masto admin's doorstep? Do they give up all the data willingly? Even without a subpoena or judge's order?

                      davemasondotme@mastodon.socialD This user is from outside of this forum
                      davemasondotme@mastodon.socialD This user is from outside of this forum
                      davemasondotme@mastodon.social
                      wrote last edited by
                      #150

                      @scottjenson
                      It would be nice to know my private conversations really are private, regardless of the legality of a search.

                      Until then, all my Private Mention conversations here are benign, boring stuff kept away from the public eye. Knowing it's not truly private, I carefully consider what information I share.

                      *My apologies if my responses have done nothing more than regurgitate common knowledge. Hopefully this is the type of input you're seeking.

                      1 Reply Last reply
                      0
                      • jesseplusplus@mastodon.socialJ jesseplusplus@mastodon.social

                        @scottjenson @benpate is there a reason private messages need to support threading? Most DMs on other platforms are flattened to a single thread for simplicity.

                        If threading is still necessary, iOS’s design for replies to specific messages in iMessage feels easy to follow for me

                        benpate@mastodon.socialB This user is from outside of this forum
                        benpate@mastodon.socialB This user is from outside of this forum
                        benpate@mastodon.social
                        wrote last edited by
                        #151

                        @jesseplusplus @scottjenson

                        Hey Jesse ~ great point. It would probably depend on how people use it. And private/direct messages are probably different from comment threads on public posts.

                        For public messages (like this one) it feels like people have the expectation of real threads.

                        For private messages, I agree with you & have been considering iMessage's method: showing everything chronologically, with 1) a note if something is a direct reply and 2) the ability to "zoom" in on replies.

                        1 Reply Last reply
                        0
                        • scottjenson@social.coopS scottjenson@social.coop

                          #mastondon Friends!

                          There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                          * getting them out of the public timeline
                          * Having a stronger notification tied to the Private Mention tab
                          * (amount other things)

                          But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                          If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                          isagalaev@mastodon.socialI This user is from outside of this forum
                          isagalaev@mastodon.socialI This user is from outside of this forum
                          isagalaev@mastodon.social
                          wrote last edited by
                          #152

                          @scottjenson count me in "use secure messengers for private communication". I know people will keep trying to use social media for it no matter what, but in my mind it's a misuse, and shouldn't be a priority for fixing. (I didn't do any research, just speaking from vibes!)

                          1 Reply Last reply
                          0
                          • scottjenson@social.coopS scottjenson@social.coop

                            #mastondon Friends!

                            There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                            * getting them out of the public timeline
                            * Having a stronger notification tied to the Private Mention tab
                            * (amount other things)

                            But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                            If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                            isaacfreeman@cloudisland.nzI This user is from outside of this forum
                            isaacfreeman@cloudisland.nzI This user is from outside of this forum
                            isaacfreeman@cloudisland.nz
                            wrote last edited by
                            #153

                            @scottjenson I'm excited that you're asking this question!

                            My preference is for usability improvements first. Other platforms already do encrypted private messages, and adding it won't make Mastodon easier to use. I think that's the core problem for the platform: removing barriers to sticking around without taking the cop-out of just copying what people are familiar with on other platforms.

                            My primary use of private messages is to ask people for email or Signal addresses when I only know how to contact them on Mastodon.

                            Secondary would occasionally be a “You OK?” message in reply to someone's post.

                            Apart from those, I think of Mastodon as a public space. Private communication isn't what it's for, and the UI shouldn't centre it.

                            1 Reply Last reply
                            0
                            • scottjenson@social.coopS scottjenson@social.coop

                              #mastondon Friends!

                              There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                              * getting them out of the public timeline
                              * Having a stronger notification tied to the Private Mention tab
                              * (amount other things)

                              But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                              If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                              johannab@cosocial.caJ This user is from outside of this forum
                              johannab@cosocial.caJ This user is from outside of this forum
                              johannab@cosocial.ca
                              wrote last edited by
                              #154

                              @scottjenson

                              I'm probably just one more vote on a "me too" pile, but it's not critical to me that social timeline 1:1 messaging be *encrypted*. It's important that I (the generic user) *understand* whether it is or isn't and behave accordingly.

                              If you have to pick a focus, I do strongly prefer that 1:1 or 1:few comms have a distinct workflow apart from regular/public timeline appearances, though. It makes mishaps less likely, like forgetting or mis-clicking "private" in that dropdown.

                              1 Reply Last reply
                              0
                              • knapjack@snac.gruntle.ccK knapjack@snac.gruntle.cc
                                For sure. Mainly I'm thinking about "Pretty Good Obfuscation" than a good solution. Something better than in the clear.

                                Really, delivery isn't guaranteed, so there are already potential issues about tampering that encryption won't necessarily fix, just maybe make abusing it harder.
                                dmaonr@mastodon.onlineD This user is from outside of this forum
                                dmaonr@mastodon.onlineD This user is from outside of this forum
                                dmaonr@mastodon.online
                                wrote last edited by
                                #155

                                @knapjack I understand where you are coming from. I might have agreed a few years ago. But encrypted messages need to be rock solid. Recently many governments the world over have shown they are more than willing to use the courts to subvert encrypted communications. Including forcing service providers like your friendly Masto admin to both hand over data and backdoor encryption.

                                knapjack@snac.gruntle.ccK 1 Reply Last reply
                                0
                                • dmaonr@mastodon.onlineD dmaonr@mastodon.online

                                  @knapjack I understand where you are coming from. I might have agreed a few years ago. But encrypted messages need to be rock solid. Recently many governments the world over have shown they are more than willing to use the courts to subvert encrypted communications. Including forcing service providers like your friendly Masto admin to both hand over data and backdoor encryption.

                                  knapjack@snac.gruntle.ccK This user is from outside of this forum
                                  knapjack@snac.gruntle.ccK This user is from outside of this forum
                                  knapjack@snac.gruntle.cc
                                  wrote last edited by
                                  #156
                                  I hear you.

                                  I guess for me, I'm not going to use social media for that kind of thing, but I've exchanged snail mail addresses with online acquaintances and not sure if I would ever do that via the Fediverse with the current implementations.

                                  I can also see that in my head, my implementation would never have the private key server-side on a shared server, which would make it useless via the web. Honk and snac have spoiled me. But I could see having a private key in one of the mobile clients and never on a server.
                                  1 Reply Last reply
                                  0
                                  • scottjenson@social.coopS scottjenson@social.coop

                                    #mastondon Friends!

                                    There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                                    * getting them out of the public timeline
                                    * Having a stronger notification tied to the Private Mention tab
                                    * (amount other things)

                                    But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                                    If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                                    ? Offline
                                    ? Offline
                                    Guest
                                    wrote last edited by
                                    #157

                                    @scottjenson In my opinion, encryption is moot as long as the behaviour of not having a distinction between “recipients” and “mentioned accounts” persists.
                                    @gracjan

                                    1 Reply Last reply
                                    0
                                    • scottjenson@social.coopS scottjenson@social.coop

                                      #mastondon Friends!

                                      There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                                      * getting them out of the public timeline
                                      * Having a stronger notification tied to the Private Mention tab
                                      * (amount other things)

                                      But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                                      If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                                      reiver@mastodon.socialR This user is from outside of this forum
                                      reiver@mastodon.socialR This user is from outside of this forum
                                      reiver@mastodon.social
                                      wrote last edited by
                                      #158

                                      @scottjenson

                                      I use Mastodon DMs.

                                      I want encryption, but there is something higher priority for me —

                                      Being able to see ALL the DMs for a single user (that I have talked to) in a single place. Rather than having them scattered all over the place.

                                      I get that these scattered DMs are the result of separate conversational threads, but — I would still like to see them all (from a single user) in one place.

                                      1 Reply Last reply
                                      0
                                      • scottjenson@social.coopS scottjenson@social.coop

                                        #mastondon Friends!

                                        There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                                        * getting them out of the public timeline
                                        * Having a stronger notification tied to the Private Mention tab
                                        * (amount other things)

                                        But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                                        If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                                        wjmaggos@liberal.cityW This user is from outside of this forum
                                        wjmaggos@liberal.cityW This user is from outside of this forum
                                        wjmaggos@liberal.city
                                        wrote last edited by
                                        #159

                                        @scottjenson

                                        imo social media and social networking are different things. mastodon is the former and doesn't need privacy. it's public and about going viral. encryption is needed for the latter. direct messaging and groups. #ActivityPub vs #matrix.

                                        1 Reply Last reply
                                        0
                                        • scottjenson@social.coopS scottjenson@social.coop

                                          #mastondon Friends!

                                          There is a TON of improvements we could make to Private Mentions (often called DMs on other platforms) e.g.
                                          * getting them out of the public timeline
                                          * Having a stronger notification tied to the Private Mention tab
                                          * (amount other things)

                                          But here is my MAIN question: How critical is it that these message are encrypted? I'm not against encryption! It's just complex and will take time. If we were to make some UX changes as a first pass WITHOUT encryption would you be OK with that (at least for now?)

                                          If you MUST have encryption, that's fine, please do me the favor of replying explaining why you need it.

                                          varpie@peculiar.floristV This user is from outside of this forum
                                          varpie@peculiar.floristV This user is from outside of this forum
                                          varpie@peculiar.florist
                                          wrote last edited by
                                          #160

                                          @scottjenson Private mentions aren't really private if they're not end-to-end encrypted. On a federated platform, you put a lot of trust on the servers, and it's not just the one you're on but also the one receiving the messages. What if I want to message a friend on Threads for instance? I don't know about you, but I don't trust Meta to just deliver the messages without using them to build a profile on me or improve their AI models, which are things I can't really opt out of since it's not my platform. The only way to avoid these things (to some extent) is to make it impossible for them to read my messages.

                                          The good thing is you don't have to reinvent the wheel here, there are already a few attempts at standardizing encryted messages for ActivityPub: Evan put together the
                                          MLS over AP, Hollos also did something similar. Make sure to talk to them so we don't end up with yet another standard.

                                          scottjenson@social.coopS 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups