Goddamn "private mention" is hard to use safely.
-
@adamshostack @mattblaze In the past month, I discovered I:
a) Had accidentally published API keys on a public github repo for months
b) Had misconfigured MTA-STS on one of my email domains even though I co-authored the specMy conclusion is that users* are in fact idiots and everything is their fault.
* "User" here being, of course, me. :(
-
Goddamn "private mention" is hard to use safely.
@adamshostack if it’s not a criminally negligent feature it’s damn close
-
Goddamn "private mention" is hard to use safely.
@adamshostack Yeah, @alice and I found that out lol
-
@adamshostack Yeah, @alice and I found that out lol
-
@static in what way is it an elegant solution?
-
Goddamn "private mention" is hard to use safely.
I don't use it for anything nontrivial; any conversations with anything I'm not OK ending up in public go to Signal.
Not only does this create an actually end-to-end assured container, but it changes the context from Masto's assumed-public to Signal's assumed-private, thus allowing for a separation of content cognitively as well as logistically.
-
Goddamn "private mention" is hard to use safely.
@adamshostack It should be called "tiny email (which sysadmins can also read)"
-
@spiegelmama @catsalad twice 😅
But as long as we're talking privately, I had this weird dream about you Cat—in it we...
-
I don't use it for anything nontrivial; any conversations with anything I'm not OK ending up in public go to Signal.
Not only does this create an actually end-to-end assured container, but it changes the context from Masto's assumed-public to Signal's assumed-private, thus allowing for a separation of content cognitively as well as logistically.
This is also why I have a signal username in my profile; I expect to be contacted for anything actually sensitive on that channel.
-
-
Goddamn "private mention" is hard to use safely.
@adamshostack
I found this out the easy way: someone @'d me in a private DM and I saw the intended-private message. I recommend this over finding out the hard way. -
Goddamn "private mention" is hard to use safely.
@adamshostack this is one of the major things I’m personally hoping to accomplish through my own app development
I’ve been working a lot on trying to get private mentions to feel less like they’re just posts and more like a typical DM interface
Hopefully as I refine this and share with the public, along with E2EE which is being worked on separately, we can start to have a better experience for them
Because yeah, right now it’s unpleasant
-
@adamshostack hard agree. to the point where that's why i don't use it. also, sometimes hard to tell when someone has sent you a private message, especially when there are multiple people on the private message.
@briankrebs I have publicly "privately" mentioned people a couple times—only one of which was about me dreaming of them. But we ended up dating because of it, so 🤷🏼♀️ YMMV.
Then I discovered the merits of having no shame, so now I just say everything publicly 😁
-
Goddamn "private mention" is hard to use safely.
@adamshostack agreed.