elekk.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.

Server stats:

73
active users

Ellie
Public

I've updated my brief introduction to Mastodon with a new heading: "How private is "Private"?": gist.github.com/joyeusenoelle/

I've reprinted it here because it should be read.

I cannot stress this enough: Private toots are not encrypted or secure.

The admin of your server can read any toot posted on their server, as well as any toot sent to a user on their server. This is a necessary security precaution.

gist.github.comAn increasingly less-brief introduction to MastodonAn increasingly less-brief introduction to Mastodon - Mastodon.md
Ellie

Admins don't want to read your private toots, but they have to be able to because otherwise private toots allow some users to secretly harass others or to conduct illegal dealings without the admin's knowledge, and under many laws the admin will be responsible for enabling the harassment or illegal behavior even if they didn't know it was happening.

Ellie
Public

That said, in general, your admin will only look over the toots you've marked Private if they have reason to believe harassment or illicit dealings are going on. Make sure you trust your admin to act like this, and if you don't, it might be time to look for another instance.

As a general rule, if an application you're using isn't peer-to-peer and relies on an intermediary like a server, the information you're sending isn't secure unless you take extra steps outside the application to secure it.

jim
Public

@noelle I don't think “we have to be able to read private toots” is really true. If it were, how come WhatsApp / Signal etc are able to do what they do, legally or ethically.

Is it a design decision, or just the result of the complexity of implementing e2e encryption? I suspect the latter.