Bitcoin Forum
November 24, 2017, 10:11:23 AM *
News: Latest stable version of Bitcoin Core: 0.15.1  [Torrent].
 
   Home   Help Search Donate Login Register  
Pages: [1]
  Print  
Author Topic: "PM privacy is not guaranteed. Encrypt sensitive messages. "  (Read 2039 times)
Andrew Bitcoiner
Sr. Member
****
Offline Offline

Activity: 397


Send correspondance to GPG key A372E7C6


View Profile WWW
September 10, 2012, 01:28:30 AM
 #1

Can the mods elaborate on this policy and in what contexts admins may read private messages?

MAKE MONEY! ADVERTISE FOR BITCOINS http://www.bitcoinadvertising.com
Bitcoin News Site http://coinbits.com
Bitcoin Blackjack http://bitjack21.com
Bitcoin, Darknet, IT consulting http://cryptophene.com
1511518283
Hero Member
*
Offline Offline

Posts: 1511518283

View Profile Personal Message (Offline)

Ignore
1511518283
Reply with quote  #2

1511518283
Report to moderator
Join ICO Now A blockchain platform for effective freelancing
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1511518283
Hero Member
*
Offline Offline

Posts: 1511518283

View Profile Personal Message (Offline)

Ignore
1511518283
Reply with quote  #2

1511518283
Report to moderator
1511518283
Hero Member
*
Offline Offline

Posts: 1511518283

View Profile Personal Message (Offline)

Ignore
1511518283
Reply with quote  #2

1511518283
Report to moderator
1511518283
Hero Member
*
Offline Offline

Posts: 1511518283

View Profile Personal Message (Offline)

Ignore
1511518283
Reply with quote  #2

1511518283
Report to moderator
Stephen Gornick
Legendary
*
Offline Offline

Activity: 2324



View Profile
September 10, 2012, 04:52:50 AM
 #2

Can the mods elaborate on this policy and in what contexts admins may read private messages?

This was touched on here:

Deleted posts are almost never removed from the database. A PM is removed from the database if the sender and all recipients delete it.

Full database backups are created daily, and all global moderators and admins can download the (encrypted) backups and implement their own rotation policies.


they can download the backup to have it at multiple locations, but it's useless for them because they don't have the decryption key

This.

Only me, Gavin, Satoshi, and Sirius can decrypt it.


Global moderators can download the encrypted database backups. Admins and past admins (Gavin, Satoshi, Sirius, me, and now justmoon) can decrypt them -- they therefore have complete access to the database and can read PMs, etc. Justmoon and I can also query the live database.


Ah, so you're already reading the pms.  Good to know.  Who else are you snooping through?

I only scanned through them to make sure that the SQL query (to archive them) worked as I intended. The PGP message blocks stood out.

I only read others' PMs without their permission during scam investigations, and I've only read a user's entire inbox a few times.

That thread, starting from this quote tells more on the topic:

You are going to make PMs public or give it to the police?

I will give them to the police if the police ask for them. Otherwise, I may post them publicly to help people find Pirate and obtain justice.

Pirates are hostis humani generis. Wink I'm not going to preserve the privacy of someone who stole 500,000 BTC.

 - http://bitcointalk.org/index.php?topic=104261.msg1145182#msg1145182



Since that time was an addition:

Stefan Thomas (justmoon) is now a forum administrator. He can therefore access the database directly and see IP addresses, etc.


And apparently one subtraction:

How many admins do we have on bitcointalk now?

Two. Gavin recently decided to stop being an admin.




The cautionary statement added to the bottom when you send a PM was requested here:

Legality aside, decency would suggest you should put a notice on the "private message" page stating that the messages are not private and may be read by moderators.

They're "personal messages", not "private messages". Wink

I think it's obvious that the administrators of a site will check PMs when necessary, but I added a note to the page.

[Edited: Added some additional references]

Raize
Donator
Legendary
*
Offline Offline

Activity: 1409


View Profile
September 10, 2012, 05:10:17 AM
 #3

SMF stores PMs in a string on a database. There are ways to retrieve this information and there has to be for you to even read them. While Theymos and others are correct in saying that any admin can read a PM, there's more to it than that: so can whoever is hosting the machine providing the forums, technically.

I don't think this is reason to not use the PM system, but I wouldn't use it for anything you really truly wanted to remain strictly between you and the person you've PM'd.

OrganofCorti's Neighbourhood Pool Watch - The most informative website on blockchain health
Pages: [1]
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!