Privacy concerns about ability to look at DMs

(#1324) Feature Under consideration privacy self-hosting

Problem

As an instance owner, it is possible to look at the DMs of a specific user and their chat logs and such, having that as a feature is a huge privacy concern, on the contrary, it is not possible to check guilds chat logs as easily, which would make sense instead to have ability to read as an instance owner Letting the instance owner be able to see DMs logs of users opens the door for a lot of potential for targeted harassment, blackmailing, etc... by getting private information about the user from private conversations

Proposal

Remove ability for the instance owner to check DMs of users completely, make it easier for guilds instead, and keep this functionality for reports only.

3 comments

Sign in with Fluxer to comment and vote.
Comment by Rex
RexSystem 1 vote
Status changed from Shipped to Under consideration
Reopened because staff described encrypting DMs and limiting admin access to reports as a long term plan, so nothing has shipped yet.
Comment by @SteveLinkNoah
RexSystem 1 vote originally by @SteveLinkNoah on GitHub
In my opinion this isn't really a big concern. You could read the Database directly anyway, so it would only prevent people that don't know what they are doing (and if they don't know what they are doing there is a good chance they couldn't setup the instance in the first place). Besides that you need to trust your instance owner anyway to keep your stuff safe. The only other option is to wait for E2EE for DMs at which point the instance owner can't see anything.
Comment by @WarLordElite
RexSystem 1 vote originally by @WarLordElite on GitHub
This also falls under a compliance issue. Those hosting the instance are liable and responsible for the content and data hosted on their server.