Bitcoin Forum

Other => Meta => Topic started by: BTCTalkAccounts on June 12, 2013, 12:18:27 PM



Title: -
Post by: BTCTalkAccounts on June 12, 2013, 12:18:27 PM
-


Title: Re: Question about the security of PM's
Post by: greyhawk on June 12, 2013, 12:32:31 PM
All admins and past admins have access to PMs.


Global moderators can download the encrypted database backups. Admins and past admins (Gavin, Satoshi, Sirius, me, and now justmoon) can decrypt them -- they therefore have complete access to the database and can read PMs, etc. Justmoon and I can also query the live database.



Title: Re: Question about the security of PM's
Post by: tysat on June 12, 2013, 01:29:31 PM
I have some questions about the security of PM's. Are they stored on the server encrypted? Which forum staff have access to them? When I delete them from my inbox and the sender deletes from his sentbox is the PM completely deleted, or is it possible a copy has been saved?

I believe copies are saved.  There are backups of the forum around, but there are very few people who are able to decrypt those backups.  If both parties delete the PMs I don't think they'd be stored anywhere except for old backups (prior to the PM deletion).


Title: Re: Question about the security of PM's
Post by: BadBear on June 12, 2013, 01:31:58 PM
I have some questions about the security of PM's. Are they stored on the server encrypted?

No, anyone with access to the server itself could read your pm's. PM privacy isn't, and can't be guaranteed by anyone.

It's entirely possible deleted pm's could be accessed using backups.


Title: Re: Question about the security of PM's
Post by: kodo on June 12, 2013, 05:01:32 PM
Most forums allow admins to read PM's so I doubt theres any privacy.


Title: Re: Question about the security of PM's
Post by: 🏰 TradeFortress 🏰 on June 13, 2013, 09:28:42 AM
If both parties delete the PMs I don't think they'd be stored anywhere except for old backups (prior to the PM deletion).
This is correct in stock SMF.


Title: Re: Question about the security of PM's
Post by: Phinnaeus Gage on June 15, 2013, 02:19:18 AM
Most forums allow admins to read PM's so I doubt theres any privacy.

Here's the problem I have with this: What stops a rogue admin from accessing PMs to glean information from its users to profit from the knowledge gained?


Title: Re: Question about the security of PM's
Post by: 🏰 TradeFortress 🏰 on June 15, 2013, 03:19:14 AM
GPG, or a read seal hosted on your server. I think I'll make the latter.