Please upgrade here. These earlier versions are no longer being updated and have security issues.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Options

Security: Private Messages

ZebraZebra New
edited September 2012 in Vanilla 2.0 - 2.8

How secure are private messages between users?

Can admin read the private messages between users?

If not, can webmaster of the site bypass the restrictions and read the private messages of all users? Or are they encrypted?

Answers

  • Options
    aeryaery Gtricks Forum in 2.2 :) ✭✭✭

    Admin can from the database but usually they are very much hidden from moderators and other users.

    There was an error rendering this rich post.

  • Options

    Very few forums are goign to encrypt PMs by default. It is a waste of resource. People should not use forum PM for highly sensitive stuff.

    How private they are are depends policy. But moderators, and admins who don't have access to the database can’t read them.

    It is a knife edge issue, becuase, arguably you have a responsibility to do something about harassment, but there are also misunderstandings, unless you can put some type of disclaimer. It not a decentralised system it is all held in one place.

    Even a decentralised federated system like emails, server may store for some time. There is different data protection requirements in different countries. There is a difference depending on which system you use, like IMAP, or POP.

    Security doesn't come without personal responsibility. it is highly context based. If you want to discuss something out of the forum content, then don't use the context to contact them, it is that simple.

    It really irks me when parents want specific guarantees, and then governments pander to this without out a clue what they are talking about.

    It is very simple supervise your children there is no other alternative. End of argument. it make no different whether it its the internet, or some monitored network, you still cannot make these guarantees. There is a saying "what makes you dive safer, having airbags, or having a massive spike sticking.

    "Personal responsibility", repeat the mantra 10 times.

    grep is your friend.

Sign In or Register to comment.