Who exactly can see a private message on Lemmy? Anyone who runs a server? Or only the sending/receiving server?

And what all is your experience with Matrix? I don’t have an account, and imagine I would need one if someone wants to message me there.

  • e0qdk@reddthat.com
    link
    fedilink
    arrow-up
    34
    ·
    18 hours ago

    I believe the intention of DMs is that they are supposed to be accessible only to the sending/receiving server admins and sending/receiving users – but given the many ways that distributed systems which are not built specifically for secure comms can go wrong, you should simply assume anything you transmit through Lemmy is or will eventually be public, period.

    If you are concerned that some information you transmit through Lemmy may be exposed the correct security stance is simply: DO NOT SEND IT.

    • schipelblorp@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      7
      ·
      18 hours ago

      That’s a bummer, man, because what you’d want to do is send the user a DM with a more secure service, but then you’d be exposing your user account and linking it your lemmy id.

      • NeatNit@discuss.tchncs.de
        link
        fedilink
        arrow-up
        9
        ·
        17 hours ago

        If you’re paranoid, you can use PGP and send encrypted messages through Lemmy. But obviously that’s overkill.

        My approach: assume that DMs are probably going to stay private, but acknowledge that there’s always a chance they leak out one way or another. If you want to send a link to a more secure service, perhaps that service allows you to generate a temporary link that you can deactivate after the recipient has used it. That would still be untraceable, as long as the eavesdropper isn’t opening that link immediately after you sent it.