• 0 Posts
  • 4 Comments
Joined 1Y ago
cake
Cake day: Jun 21, 2023

help-circle
rss

What @delirious_owl@discuss.online seemed to be implying is that direct messages on Mastodon should be considered “public” rather than “private”.

I’m assuming that’s along the same lines of how Lemmy users generally think that their upvotes/downvotes are private when in reality, if you know how to look for them, you can see them.


Ah, I see. So it’s the same mistake that Lemmy users make when thinking that Upvotes/Downvotes aren’t public.

It sounds like DMs on Mastodon are public, but are commonly mistaken to be private then?


They’re called DMs not PMs

? Did you mean that the other way around? And if you did… forgive me, I don’t really use Mastodon. I was never much of a twitter fan. I don’t really like how all of my likes are public (although I guess I have had to get used to that with Lemmy).


Hmmm it was even able to pull in private DMs.

Maybe private DMs on Mastadon aren’t as private as everyone thinks… that, or the open nature of Activity Pub is leaking them somehow?

Edit - From the article:

Even more shocking is the revelation that somehow, even private DMs from Mastodon were mirrored on their public site and searchable. How this is even possible is beyond me, as DM’s are ostensibly only between two parties, and the message itself was sent from two hackers.town users.

From what @delirious_owl@discuss.online mentioned below, it sounds like this shouldn’t be very shocking at all.