<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this.]]></title><description><![CDATA[<p>Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this.</p><p>For example, here there are ‘follower-only’ posts. The user perception is simple: only your followers can see your posts. But that’s never enforced by the technology for any system that doesn’t use end-to-end authenticated encryption. In a centralised system, you trust that the service provider doesn’t look at these messages. When it’s ad supported and has a two-hundred page privacy policy, that trust is probably misplaced, but there’s only one place to audit.</p><p>In a federated system, <em>any</em> of your followers’ admins can potentially see these messages. Maybe you get all of your followers, but do you vet everyone with admin access on their instance? </p><p>Confidentiality in federated systems is <em>really</em> hard to do right. And message confidentiality is the easy part, keeping the connection graph confidential is even harder (that matters less for the Fediverse, but can get people killed if you get it wrong for messengers) and really needs designing in from the start. There are a few interesting projects that are trying to do this but don’t assume that it’s a thing that can be retrofitted to a protocol that was not designed with a different threat model.</p>]]></description><link>https://board.circlewithadot.net/topic/256ea4b7-8b29-45b8-8cf6-56a5bca7bfbc/federation-makes-it-very-easy-to-accidentally-mislead-users-about-the-security-of-a-system-and-i-wish-people-building-federated-systems-would-be-more-careful-of-this.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 01:47:44 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/256ea4b7-8b29-45b8-8cf6-56a5bca7bfbc.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 28 Apr 2026 08:23:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this. on Tue, 28 Apr 2026 09:02:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/naturemc%40mastodon.online" rel="nofollow noopener">@<span>NatureMC</span></a></span> </p><p>I agree.  I don't use follower-only posts because I don't think that there's any real restriction in distribution once you have more than a couple of dozen followers on different instances.  It might have some benefits for reducing harassment, but only against not-very-motivated individuals.  But that's not how it's described</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/david_chisnall/statuses/116481521512212281</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/david_chisnall/statuses/116481521512212281</guid><dc:creator><![CDATA[david_chisnall@infosec.exchange]]></dc:creator><pubDate>Tue, 28 Apr 2026 09:02:46 GMT</pubDate></item><item><title><![CDATA[Reply to Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this. on Tue, 28 Apr 2026 08:57:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/david_chisnall%40infosec.exchange">@<span>david_chisnall</span></a></span> This brings memories flooding back of the NIST (NSA) related multicast group key distribution drafts from the late 90s.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116175731239673526/statuses/116481500501205501</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116175731239673526/statuses/116481500501205501</guid><dc:creator><![CDATA[bms48@mastodon.social]]></dc:creator><pubDate>Tue, 28 Apr 2026 08:57:25 GMT</pubDate></item><item><title><![CDATA[Reply to Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this. on Tue, 28 Apr 2026 08:56:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/mhd%40tilde.zone">@<span>mhd</span></a></span> <span><a href="/user/david_chisnall%40infosec.exchange">@<span>david_chisnall</span></a></span> You may therefore find this humorous: <a href="https://people.freebsd.org/~bms/humour/" rel="nofollow noopener"><span>https://</span><span>people.freebsd.org/~bms/humour/</span><span></span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116175731239673526/statuses/116481497675869082</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116175731239673526/statuses/116481497675869082</guid><dc:creator><![CDATA[bms48@mastodon.social]]></dc:creator><pubDate>Tue, 28 Apr 2026 08:56:42 GMT</pubDate></item><item><title><![CDATA[Reply to Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this. on Tue, 28 Apr 2026 08:54:41 GMT]]></title><description><![CDATA[<p><span><a href="https://aus.social/@bencourtice">@<span>bencourtice</span></a></span> <span><a href="/user/david_chisnall%40infosec.exchange">@<span>david_chisnall</span></a></span> this!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.online/users/NatureMC/statuses/116481489700830711</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.online/users/NatureMC/statuses/116481489700830711</guid><dc:creator><![CDATA[naturemc@mastodon.online]]></dc:creator><pubDate>Tue, 28 Apr 2026 08:54:41 GMT</pubDate></item><item><title><![CDATA[Reply to Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this. on Tue, 28 Apr 2026 08:53:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/david_chisnall%40infosec.exchange">@<span>david_chisnall</span></a></span> It's the same with private messages in the Fediverse (but you get warnings that it's not secure.)</p><p>I write in social media only what I would say in public on a marketplace or in a newspaper.<br />For everything more private, people should use secure messengers!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.online/users/NatureMC/statuses/116481486670876439</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.online/users/NatureMC/statuses/116481486670876439</guid><dc:creator><![CDATA[naturemc@mastodon.online]]></dc:creator><pubDate>Tue, 28 Apr 2026 08:53:54 GMT</pubDate></item><item><title><![CDATA[Reply to Federation makes it very easy to accidentally mislead users about the security of a system and I wish people building federated systems would be more careful of this. on Tue, 28 Apr 2026 08:25:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/david_chisnall%40infosec.exchange" rel="nofollow noopener">@<span>david_chisnall</span></a></span> Noted. When I finally get around to creating my ICQ-as-Fediverse-DMs, I'm going to ROT13 the heck out of it.</p>]]></description><link>https://board.circlewithadot.net/post/https://tilde.zone/users/mhd/statuses/116481373242036792</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tilde.zone/users/mhd/statuses/116481373242036792</guid><dc:creator><![CDATA[mhd@tilde.zone]]></dc:creator><pubDate>Tue, 28 Apr 2026 08:25:04 GMT</pubDate></item></channel></rss>