Have you seen this news?
-
mastodon is doing DM encryption because users want it
that's all
"WhatsApp, Instagram"
why are you using those spy apps? you complain about bloat and intrusion, and use these?
i mean use them if you want to. but it's just odd to take a stand on a point of purity, then in the same comment, betray that very sense of purity
-
@benroyce @benpate @rusty__shackleford @dusk you guys are on an instance whose admin has decided to block most of the fediverse because someone somewhere might say a mean word at you and your admin thinks you can't handle it.
@sampler @rusty__shackleford @benpate @dusk
i give your troll attempt a... 3/10
nice try troll
keep working at it
remember: the point of trolling is entertainment, so you want to make me feel like i should go get the buttered popcorn
i believe in you. you can do it. be the best troll you can be!

-
that's what *you* are doing
so you put the "dictating what we all want" out there. but how dare anyone push back?
it's absolutely fine to get your opinion out there
but you can't fallback to the comment you just made, expecting as if you won't receive any other opinion in response to yours. that's not the way it works
i'm not in charge here. and *you* aren't in charge here. get your opinion out, receive some pushback: welcome to life
-
“Inviolate” is a pretty strong word..
I’d say that this will make it prohibitively expensive for most “people in the middle” of your conversations (like server mods, IT workers, web scrapers, or general looky-loos) to intercept your encrypted messages. MUCH better than what we have now.
There’s always other ways that a well funded or morally unhindered group can break into your stuff.
Relevant comic: https://xkcd.com/538/
@benpate Thanks for opining. I like my word choice, and I like you for answering my question.
-
@benpate Thanks for opining. I like my word choice, and I like you for answering my question.
@Lizette603_23 notes like this are why I wish Mastodon would let me like things with little hearts and smiles instead of just stars.
I’ll have to put it here instead
️ -
@Lizette603_23 notes like this are why I wish Mastodon would let me like things with little hearts and smiles instead of just stars.
I’ll have to put it here instead
️@benpate Hi and you're welcome and thank you again. Let's beat the system and flamenco appreciation

-
@reflex @benpate @earth_walker
I'm not trying to be snide here, I mean this very literally.
I don't know what I don't know about operating an E2EE, patio, porn, or recycling business. All I know is they are all regulated, require licensing, insurance, have wildly different requirements in different jurisdictions.
I've done the work for operating social media services.
I have no intention of doing the work for any of the other services listed.
(Export controls come to mind though.)
@jaz @benpate @earth_walker I understand you do not know, but my point is if you are operating a mastodon instance, and you are connecting users via https, you are already operating a E2EE service. That is what https is (via TLS, used to be SSL). You do not need to know more to have your messaging be E2EE within the instance unless they have done something very wrong with the masto instance.
It's an international standard, the concerns you have can be raised, but likely are not valid.
-
@jaz @benpate @earth_walker I understand you do not know, but my point is if you are operating a mastodon instance, and you are connecting users via https, you are already operating a E2EE service. That is what https is (via TLS, used to be SSL). You do not need to know more to have your messaging be E2EE within the instance unless they have done something very wrong with the masto instance.
It's an international standard, the concerns you have can be raised, but likely are not valid.
@jaz @benpate @earth_walker HTTPS is E2EE between the server (instance) and client (app/browser/etc). It ensures data in transit cannot be intercepted easily. E2EE messaging is the same thing but user to user, essentially keeping the data invisible to the server (instance). Same principle. It's commonly used and typically invisible to the admin.
It does not block screenshots, reporting mechanisms will still be valid.
Again, assuming this implementation does not do something weird.
-
@jaz @benpate @earth_walker HTTPS is E2EE between the server (instance) and client (app/browser/etc). It ensures data in transit cannot be intercepted easily. E2EE messaging is the same thing but user to user, essentially keeping the data invisible to the server (instance). Same principle. It's commonly used and typically invisible to the admin.
It does not block screenshots, reporting mechanisms will still be valid.
Again, assuming this implementation does not do something weird.
@reflex @benpate @earth_walker I believe you may be underestimating my understanding of and experience with internetworking including the network and transport layers, but I'll just say that encryption in transit is not end to end , and the simple fact that I can moderate user-to-user (end to end) content on my service expressly informs that fact.
Let me put it another way, I have no intention of operating an unmoderatable community service.
-
@jaz @benpate @earth_walker I understand you do not know, but my point is if you are operating a mastodon instance, and you are connecting users via https, you are already operating a E2EE service. That is what https is (via TLS, used to be SSL). You do not need to know more to have your messaging be E2EE within the instance unless they have done something very wrong with the masto instance.
It's an international standard, the concerns you have can be raised, but likely are not valid.
Sorry. We are talking about a different end. E2EE means encrypting messages from my device all the way through to your device, and not being decrypted by the server in the middle. HTTPs://does not do this, so this message I’m sending to you is readable by the admins of several intermediate servers.
It’s a very different model for communication.
-
@reflex @benpate @earth_walker I believe you may be underestimating my understanding of and experience with internetworking including the network and transport layers, but I'll just say that encryption in transit is not end to end , and the simple fact that I can moderate user-to-user (end to end) content on my service expressly informs that fact.
Let me put it another way, I have no intention of operating an unmoderatable community service.
@jaz @benpate @earth_walker To be clear, your line is one that leaves users vulnerable to malicious admins. I am unclear how it hinders moderation since again, screenshots are a thing.
Also referring people to a separate centralized service that cannot be simply moved out of a hostile jurisdiction and is easily blocked is not ideal.
-
Sorry. We are talking about a different end. E2EE means encrypting messages from my device all the way through to your device, and not being decrypted by the server in the middle. HTTPs://does not do this, so this message I’m sending to you is readable by the admins of several intermediate servers.
It’s a very different model for communication.
@benpate @jaz @earth_walker I did make this distinction, pointing out that it's server to client. My point, however, is that it raises the same concerns Jaz raised previously, namely things like insurance, licensing, export controls, etc etc. If that is a real concern, we are already operating under it.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login