social apps quit adding unencrypted DMs challenge 2026, difficulty still impossible
guys, I've been warning about this for the past decade. many parts of the world have slipped into authoritarianism, and the CIA gladly admits they kill based on metadata -- not even messages. what are we even doing?
@ariadne Have you checked out https://swicg.github.io/activitypub-e2ee/mls ?
@evan I have. adopting MLS is good. but adding unencrypted DMs is not, especially given what we know.
I think as technologists we have an obligation to consider the harms and potential harms of the features we build. it would be better for new social apps to put unencrypted DMs behind a feature flag for testing the DM user experience instead of exposing users to the risk of unencrypted DMs, especially in today's geopolitical environment
fwiw MLS on activitypub is great. i'm 110% here for it. the SWICG is doing good work that is absolutely meaningful.
basically my point is that unencrypted messaging should not be exposed to end users without them having to opt in and acknowledge the risks.
@ariadne My understanding is that E2EE is very hard to implement properly, especially if one wants good UX and metadata encryption. Matrix failed miserably at both.
Are there good libraries that handle 90%+ of the work? I don’t just mean the cryptography, but also the UI, abuse reporting, and everything else needed for a production-quality implementation.
this isn't a theoretical btw. DMs in loops should not be a thing if they are unencrypted, here is an example showing why:
1. consider a female creator who talks about women's rights and women's health. I am told that many such creators exist on tiktok, for example.
2. an American DMs that creator asking for abortion advice.
3. that creator responds, providing advice on how to get and use misoprostol.
4. irregardless of whether the American gets misoprostol and takes it, she has a miscarriage. her phone is taken, imaged and analyzed.
5. the FBI discovers that she followed said creator and subpoenas the loops instance and/or uses legal pressure such as MLATs to force the hosting provider into providing a disk image of the loops instance server.
6. the FBI discovers the DM.
7. the American woman is tried and convicted based solely on the DM.
and this isn't a wild hypothetical. this shit happens all the time!
@ariadne Can one provide a good user experience for E2EE DMs without reimplementing half or more of Signal?
@ariadne personally, I think people should he forced into learning proper #InfoSec, #OpSec, #ITsec & #ComSec before being allowed to ise comms & #tech at all…
@alwayscurious I'm skeptical that they can, but MLS would at least be a start.
to be clear, this is definitely not a call to rescind the DM feature, or to harass/cancel/whatever @dansup about this decision.
he was likely approaching this from a user empowerment perspective, in which case DMs are an obvious feature to pursue, encrypted or otherwise
rather I am saying that we need to move as quickly as possible to deprecate unencrypted DMs across the entirety of fedi.
and aside from the unencrypted DM misfeature, loops looks neat
@ariadne I totally agree. While we did just roll out DMs like 5 days ago, I am in the process of implementing MLS for supported actors and will make this available in the next release due this month.
when I criticize fedi projects it isn't to dunk on them, but out of a genuine desire to see them be successful
until 2011 I was a social worker, not an engineer. tech was a hobby.
social work influences my approach to systems analysis and design. I will think of things the average software engineer won't.
that's OK. we need many perspectives to build successful apps and platforms.
@noisytoot yes, that's why I propose putting it behind a feature flag.
@ariadne do you get a sense the Fediverse movers and shakers share your priorities, or at least have them slotted somewhere in their own priorities list?
@ariadne the solution: Teach people proper comms!
- Run a #CryptoParty or something…
@F3715H @ariadne relying on user education is unlikely to work. Ordinary non-technical users deserve secure communications by default.
That's why for all Meta's faults, WhatsApp is such a major win for user privacy, in that there is no way to run it insecurely unlike, say, iMessage that falls back randomly to unencrypted SMS (for some reason, it's doing that with my wife, just because she had a temporary new phone number after her phone was stolen). Signal is definitely better, but there are some areas where WhatsApp's more polished UI protects users from real-world pitfalls that wouldn't even occur to us technical types.
@ariadne what's your opinion of Soatok's Fediverse-e2ee project?
https://soatok.blog/category/technology/open-source/fediverse-e2ee-project/
@evan @ariadne That's sort of what I assumed the answer would be. But then that would also make me very skeptical of MLS as a practical path to a solution until we see an implementation that actually works well.
Now I'm curious how this may be similar or differ from what's being done with Germ and ATproto.
@F3715H @malte rejecting features that are harmful to humans in their most vulnerable moments is an element of human-centric design
I think as technologists who just want to build cool shit (nothing wrong with that!), it is easy to think about positive uses of technology, because those provide motivation. we also need to think about negative uses, however. how technology can betray humans.
@ariadne Then that is why most applications won’t have E2EE. It’s just too difficult.
The only thing I can think of that could change it would be “Signal as a library”. You embed it in your app, and it takes care of everything, UI and VOIP included. You can replace the UI with a custom one if you want, but it at least lets you get started.
@alwayscurious that's my point: do these applications actually *need* DMs, or can a more suitable application handle it instead?
@ariadne Have a field on the profile for “Signal username”?
@ariadne though honestly, Signal being the only secure messaging app is somewhat unfortunate
@fazalmajid @ariadne until the users know ~ WHY ~ #NSAbook et. al. are bad, they won't understand and see any reason to change.
- It's the same with other bad actors, like #Nestlé…
@fazalmajid @ariadne
So don't think for a second @Mer__edith or anyone else at @signalapp is gonna risk jailtime till the end of their lives for non-paying users.
https://web.archive.org/web/20210606070919/twitter.com/thegrugq/status/1085614812581715968
@F3715H @ariadne @Mer__edith @signalapp
My VPN is DIY: https://GitHub.com/fazalmajid/edgewalker
@fazalmajid @ariadne @Mer__edith Espechally when @signalapp still peddles a Shitcoin so bad it makes the NFT-Bullshit of Solana look reasonable in comparison…
And I hate NFTs with every cell of my body, cuz that shit's just irredeemably bad!
The only "advantage" MobileCoin has that it's allegedly a cheaper way to wore remittances to Nigeria, which already gets people to side-eye it.
https://www.youtube.com/watch?v=0DSGq9FQKU4
https://en.wikipedia.org/wiki/MobileCoin
@ariadne @malte and that's why we must never ever assume any provider will cover our asses and assume they'll handwaive any demand for data regardless of legality and type through.
The only person who can exercise their right to remain silent is the end-user. (self-custody!)
And if people just STFU and never provide access, there's no way in hell stuff like OMEMO will tell it's contents.
As for "idiot proof-solutions" that don't require extra infra: @delta, #OnionShare & #WebCall exist!
@ariadne This kind of threat model makes me nervous because, in that example, the FBI would have access to the endpoint and so would get the messages in plaintext unless they were deleted. So now you have a requirement to add self-deleting messages. But what about things like Windows Recall, which screenshots the window every 10 seconds and lets the FBI recover the data? Okay, so now DMs need to integrate with OS facilities to block screenshots. And you need to make sure that every Fediverse client that someone might use does this correctly, including ones that run in browsers.
Or you can say ‘if you need to contact me confidentially use [other secure messaging system] that does all of these things correctly’.
But even then, end to end encryption isn’t enough. The ‘we kill people based on metadata’ was specifically about the shape of the social graph. It didn’t matter what the contents of the messages were, it mattered who was talking to whom. Imagine in your example the creator is using E2EE in the Fediverse and the FBI get a dump of the server state for her instance. The can’t see the messages, but they run a correlation and a hundred of the people she’s messaged have had miscarriages that Gilead considers suspicious. So they prosecute her and show the correlations. A court is still likely to convict (after all, if she has nothing to hide she can just provide the keys to decrypt the messages and show that they’re innocuous).
Adding E2EE to the Fediverse makes it more trusted but no more trustworthy and that’s absolutely the most dangerous for any system. Unless you can protect the shape of the social graph, you don’t have secure messaging, and that protection is largely impossible with the Fediverse, as currently designed. Every server operator knows everyone who follows members of their instance and everyone that their members follow, and must due to the design of ActivityPub. They know who everyone has sent messages to or received them from.
@david_chisnall @ariadne (Thank you for writing out the major concern that I had in a much better form than I could have managed.)
@david_chisnall @ariadne there are messaging systems that are designed to be resistant to traffic analysis, e.g. MIT’s Vuvuzela/Alpenhorn, and their more bandwidth-efficient successors Karaoke, Yodel, Groove and Stadium. They work by deliberately generating noise (wasting bandwidth to protect privacy). Still research prototypes, not deployed at any production scale, however.
@david_chisnall that's really my point, I think that social apps should direct people to *good* messengers rather than actually add its own secure DM functionality.
but there is this belief that social apps must have messaging even though social apps are about 1:N broadcasts rather than messaging, so I see MLS as maybe some path to harm reduction. maybe.