Discord defends itself against efforts to stop piracy on its platform by saying no to more invasive data collection. Even though Discord isn’t exactly known for privacy, this is a great move for its users. What are your thoughts?

      • Aatube@kbin.melroy.org
        link
        fedilink
        arrow-up
        23
        ·
        2 months ago

        They do have to retrieve old messages when new users join though. I’m sure the government can force them to lett them in a server and unlock the roles

        • fruitycoder@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 months ago

          Keep the data but encrypted. Let users send links that contain the pki info to decrypt the messages. Have that pki info generated client side.

          Discord would only need to shuffle data, provide authentication, and provide the web app data down to the client. But every bit of user shared and generated content would be encrypted to them.

            • fruitycoder@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 months ago

              If the the pki is generated by users client side by a secret discord doesn’t control it wouldn’t be an issue.

              • Aatube@kbin.melroy.org
                link
                fedilink
                arrow-up
                1
                ·
                2 months ago

                Either you share the message history to new users (which includes feds) or you don’t have any history. I don’t understand what you mean

                • fruitycoder@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  2 months ago

                  The server provides the data to authenticated users and helps facilitate pki between the clients.

                  If someone is added by the server to have access to the data but wasn’t given a key capable of decryption by an actual user they wouldn’t have actual access, just encrypted data.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 months ago

      Sync from another online user. If each message is signed by the author, there’s a built-in protection against tampering.

      It’s really not hard, they just have to care enough to build it that way.

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 months ago

          Sure, if they’re granted access to the channel. But that access would come from users of the channel, not the service itself, and if the service doesn’t store the keys (i.e. you need at least one user online to get access), the service can’t really help the feds.

          And whether to provide access to history for new users can absolutely be a setting on the channel. I’m just saying that having the messages only on the clients doesn’t preclude sharing those messages with a newcomer.