Decentralization is mostly about power distribution, it doesn't imply privacy. There are a couple of decentralized projects that are worse for privacy (for the sake of decentralization) and ended up being used for OSINT.
Achtung: Decentralize, decentralize, decentralize
31–40 of 174 posts
Re: Achtung: Decentralize, decentralize, decentralize
#32Also I'd like to hear the author's thoughts on GPG's viability, as discussed below:
https://moxie.org/blog/gpg-and-me/
Eventually I realized that when I receive a GPG encrypted email, it simply means that the email was written by someone who would voluntarily use GPG. I don’t mean someone who cares about privacy, because I think we all care about privacy. There just seems to be something particular about people who try GPG and conclude that it’s a realistic path to introducing private communication in their lives for casual correspondence with strangers.
Re: Achtung: Decentralize, decentralize, decentralize
#33I think that these points have to click before people move from FB: Simple -> Start the app and commicate (on all devices) Minimum features -> Feed, Chat, Groups, Events, Friends Fast -> No one will use a slow App Ownership -> All self-owned data can be removed from everywhere Decentralized -> And no one else can remove your data Privacy -> With simple sharing control So far, I've not seen anything that has all of th…
So here's the rub: 1) you post stupid stuff, but by the time you realize this, you've already forgotten your password and the account recovery doesn't work, 2) someone gets hold of your account, posts stupid stuff, and 'throws away any means to recover the account', 3) someone posts stupid stuff that is determined to violate law, how do you take that down?
Re: Achtung: Decentralize, decentralize, decentralize
#34Mastodon does everything signed and unencrypted. This includes followers-only and private messages. I can't in good faith recommend Mastodon.
Re: Achtung: Decentralize, decentralize, decentralize
#35Mastodon does everything signed and unencrypted. This includes followers-only and private messages. I can't in good faith recommend Mastodon.
All of the messages I post on Mastodon and twitter are intended to be public, just like the things I write on my website. End to end encryption would only make things harder without actually protecting anyone's privacy.
Also, lack of encryption allows for selective censorship on the fly.
Re: Achtung: Decentralize, decentralize, decentralize
#36Decentralization is mostly about power distribution, it doesn't imply privacy. There are a couple of decentralized projects that are worse for privacy (for the sake of decentralization) and ended up being used for OSINT.
Re: Achtung: Decentralize, decentralize, decentralize
#37It would be more convincing if the author had their Mastodon account info at the bottom, not their Github / Twitter account. Also I'd like to hear the author's thoughts on GPG's viability, as discussed below: https://moxie.org/blog/gpg-and-me/ Eventually I realized that when I receive a GPG encrypted email, it simply means that the email was written by someone who would voluntarily use GPG. I don’t mean someone who c…
Re: Achtung: Decentralize, decentralize, decentralize
#38Mastodon does everything signed and unencrypted. This includes followers-only and private messages. I can't in good faith recommend Mastodon.
Why does it need to be signed and encrypted? We have PGP, Signal and Co. for that. Mastodon is a microblogging service, it's perfectly fine to not sign all messages (though ActivityPub does support signing) Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
Note it IS signed. It's just not encrypted. It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Additionally... should I be some location and post something, I'd be broadcasting my location, even if that isn't intended. All because it's not encrypted, where it should be.
>Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
That'd be true if it was peer-to-peer encrypted. But it is not; all messages are plaintext on the wire.
Re: Achtung: Decentralize, decentralize, decentralize
#39Earlier quoted context omitted.
Not end-to-end encrypted. TLS is recommended (or even required, not sure), but the instances involved can see the contents of private messages.
Out of curiosity, if the messages themselves were encrypted externally, would this solve most people's concerns? Or is the metadata that is leaked (I assume to/from, timestamp, size) also unacceptable? Also curious for those that have this beef with Mastodon, would transit anonymity help alleviate some of the concerns w/ data transparency?
Connect to post something without encryption means your location is revealed to anybody observing the network.
This is indeed dangerous.
Re: Achtung: Decentralize, decentralize, decentralize
#40Mastodon does everything signed and unencrypted. This includes followers-only and private messages. I can't in good faith recommend Mastodon.
Oh come on! Twitter by default broadcasts everything you write to the entire world! Why should open source solutions be held to a higher standard?
To be fair, at least your connection to twitter is encrypted. This means that an observer can't tell it's your IP that's posting on twitter as you.
That is, your location.
Thus twitter is actually better. A court order would be needed for them to disclose IP addreses, at least.