Post B9Cj5IlBucXqtCKQ7c by ariadne@social.treehouse.systems
 (DIR) More posts by ariadne@social.treehouse.systems
 (DIR) Post #B9BNHUAev9N7bXgYwC by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       social apps quit adding unencrypted DMs challenge 2026, difficulty still impossible
       
 (DIR) Post #B9BNQ5Kgdd5nAzTb4C by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       guys, I've been warning about this for the past decade.  many parts of the world have slipped into authoritarianism, and the CIA gladly admits they kill based on metadata -- not even messages.  what are we even doing?
       
 (DIR) Post #B9BNZejgNaR9aEjQrA by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @ariadne <sarcasm but-kind-of-true>Adding more metadata to be indexed</sarcasm>
       
 (DIR) Post #B9BNuiaHGaurbGNMW0 by evan@cosocial.ca
       0 likes, 0 repeats
       
       @ariadne Have you checked out https://swicg.github.io/activitypub-e2ee/mls ?
       
 (DIR) Post #B9BO7TgJz8kV94HrFo by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @evan I have.  adopting MLS is good.  but adding unencrypted DMs is not, especially given what we know.
       
 (DIR) Post #B9BOO9veg7Ooo3Phi4 by ariadne@social.treehouse.systems
       1 likes, 0 repeats
       
       I think as technologists we have an obligation to consider the harms and potential harms of the features we build.  it would be better for new social apps to put unencrypted DMs behind a feature flag for testing the DM user experience instead of exposing users to the risk of unencrypted DMs, especially in today's geopolitical environment
       
 (DIR) Post #B9BP5dmJZhqNpnmJRw by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       fwiw MLS on activitypub is great.  i'm 110% here for it.  the SWICG is doing good work that is absolutely meaningful.basically my point is that unencrypted messaging should not be exposed to end users without them having to opt in and acknowledge the risks.
       
 (DIR) Post #B9BRSkBU7ivEGrhBr6 by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       this isn't a theoretical btw.  DMs in loops should not be a thing if they are unencrypted, here is an example showing why:1. consider a female creator who talks about women's rights and women's health.  I am told that many such creators exist on tiktok, for example. 2. an American DMs that creator asking for abortion advice.3. that creator responds, providing advice on how to get and use misoprostol. 4. irregardless of whether the American gets misoprostol and takes it, she has a miscarriage.  her phone is taken, imaged and analyzed.5. the FBI discovers that she followed said creator and subpoenas the loops instance and/or uses legal pressure such as MLATs to force the hosting provider into providing a disk image of the loops instance server. 6. the FBI discovers the DM.7. the American woman is tried and convicted based solely on the DM.and this isn't a wild hypothetical.   this shit happens all the time!
       
 (DIR) Post #B9BSK0RGQ7XC20TPsm by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @alwayscurious I'm skeptical that they can, but MLS would at least be a start.
       
 (DIR) Post #B9BSdW3L6VMFaCaOa8 by F3715H@rubber.social
       0 likes, 0 repeats
       
       @ariadne the solution: Teach people proper comms!- Run a #CryptoParty or something…https://tech.lgbt/@Netzblockierer/117063454267620853
       
 (DIR) Post #B9BSnwbjEGhwpvdys4 by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       to be clear, this is definitely not a call to rescind the DM feature, or to harass/cancel/whatever @dansup about this decision.he was likely approaching this from a user empowerment perspective, in which case DMs are an obvious feature to pursue, encrypted or otherwiserather I am saying that we need to move as quickly as possible to deprecate unencrypted DMs across the entirety of fedi.
       
 (DIR) Post #B9BSvWJuqfj1cmvOMK by dansup@mastodon.social
       0 likes, 0 repeats
       
       @ariadne I totally agree. While we did just roll out DMs like 5 days ago, I am in the process of implementing MLS for supported actors and will make this available in the next release due this month.
       
 (DIR) Post #B9BT6Jt9PSPyFnYTey by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       and aside from the unencrypted DM misfeature, loops looks neat
       
 (DIR) Post #B9BTLWvDEbNh1GlwIK by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @dansup thanks ❤️
       
 (DIR) Post #B9BTvbIaREfd1GuBA8 by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       when I criticize fedi projects it isn't to dunk on them, but out of a genuine desire to see them be successful
       
 (DIR) Post #B9BUCvOkxhl2HQ3Gt6 by ariadne@social.treehouse.systems
       0 likes, 1 repeats
       
       until 2011 I was a social worker, not an engineer.  tech was a hobby.social work influences my approach to systems analysis and design.  I will think of things the average software engineer won't.that's OK.  we need many perspectives to build successful apps and platforms.
       
 (DIR) Post #B9BVJfbCCa77GCeNzU by shlee@aus.social
       0 likes, 0 repeats
       
       @ariadne the classic problem… I’ve pissed off the mastodon devs by trying to influence the projects they just try to ignore me…. But I keep sending them recommendations and PRsFediverse projects as a whole refuse to acknowledge that you need to move past “proof of concept” or even acknowledge faults.
       
 (DIR) Post #B9BWVfrp89WXWNiRsm by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @noisytoot yes, that's why I propose putting it behind a feature flag.
       
 (DIR) Post #B9BdWhLpnWE45oBkfo by tknarr@mstdn.social
       0 likes, 0 repeats
       
       @ariadne Exactly. The approach needs to be that anything not strongly encrypted with keys only the parties to the exchange control is completely public. Sounds like an extreme position, but that's the reality today. If it doesn't meet that mark, don't try to suggest it's somehow not visible to anyone who looks.I wouldn't even store the encrypted messages on a server if there's a way to avoid it.
       
 (DIR) Post #B9Bs4SJTc7UOeo4oc4 by dahukanna@mastodon.social
       0 likes, 0 repeats
       
       @ariadne Also, appreciate + consider existing human expectations, behaviour and tools.It’s not a “private message”. That wording and naming  raises expectations that it will and can only be seen by the participants. It’s a post with a specific audience. Currently no post is encrypted but from prior digital tool experience and culture, humans expect private messages to be “private”.
       
 (DIR) Post #B9ByAXeDIDJCfF3rrU by fazalmajid@vivaldi.net
       0 likes, 0 repeats
       
       @ariadne do you get a sense the Fediverse movers and shakers share your priorities, or at least have them slotted somewhere in their own priorities list? I am fairly new to Fedi myself, but I get the sense that they have a blind spot on the need for effective moderation tools, e.g. to block abusive instances.
       
 (DIR) Post #B9C14SSXy95AhMOYsa by fazalmajid@vivaldi.net
       0 likes, 0 repeats
       
       @ariadne what's your opinion of Soatok's Fediverse-e2ee project?https://soatok.blog/category/technology/open-source/fediverse-e2ee-project/
       
 (DIR) Post #B9Cj5IlBucXqtCKQ7c by ariadne@social.treehouse.systems
       0 likes, 1 repeats
       
       @F3715H @malte fundamentally the problem with his argument is that even with education (which education is always good), people do not think rationally when they have been hit with something heavy.that's exactly why I used a young woman seeking information about misoprostol as my example.
       
 (DIR) Post #B9CjnIISzoUwC5s05g by ariadne@social.treehouse.systems
       0 likes, 1 repeats
       
       @F3715H @malte rejecting features that are harmful to humans in their most vulnerable moments is an element of human-centric designI think as technologists who just want to build cool shit (nothing wrong with that!), it is easy to think about positive uses of technology, because those provide motivation.  we also need to think about negative uses, however.  how technology can betray humans.
       
 (DIR) Post #B9CkxOf2I0XymWo8rQ by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @alwayscurious that's my point: do these applications actually *need* DMs, or can a more suitable application handle it instead?
       
 (DIR) Post #B9D9opdh73twhYC1ZY by F3715H@rubber.social
       0 likes, 0 repeats
       
       @ariadne @malte and that's why we must never ever assume any provider will cover our asses and assume they'll handwaive any demand for data regardless of legality and type through.The only person who can exercise their right to remain silent is the end-user. (self-custody!)And if people just STFU and never provide access, there's no way in hell stuff like OMEMO will tell it's contents.As for "idiot proof-solutions" that don't require extra infra: @delta, #OnionShare & #WebCall exist!
       
 (DIR) Post #B9DAo0LPvS11ZFoUBU by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @malte @delta @F3715H cool anyway, my point is as technologists we can choose to design our software to be kinder to vulnerable humans, because in a fight or flight situation humans forget their training much of the time.
       
 (DIR) Post #B9FrOnynRg4mKANnmq by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @david_chisnall that's really my point, I think that social apps should direct people to *good* messengers rather than actually add its own secure DM functionality.but there is this belief that social apps must have messaging even though social apps are about 1:N broadcasts rather than messaging, so I see MLS as maybe some path to harm reduction.  maybe.
       
 (DIR) Post #B9H4nJyzbSCn5nSHC4 by F3715H@rubber.social
       0 likes, 0 repeats
       
       @ariadne @malte @delta OFC.And we have to up the game.re: #documentation so everyone can use stuff with step-by-step tutorials!