• davel [he/him]@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 hours ago

    ActivityPub DMs are not encrypted between servers

    It is insofar as TLS/SSL/HTTPS encryption is used in transit. That’s what I mean by encrypted in transit.

    i could read anyone’s DMs to users on other servers

    If you’re an administrator for (WordPress) ActivityPub server A, you can see all the DMs coming to and leaving from your server, yes. And they’re not encrypted at rest, so you can read them any time. But how would you see DMs going between server B and server C, when your server isn’t involved in the transaction?