Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Zak :1password:
Zak :1password:
@zak@infosec.exchange  ·  activity timestamp 10 hours ago

@Em0nM4stodon I think this one is tough because as much as I love to see E2EE, I think that dating apps are prime grounds for horrible abuse, and moderation may be necessary to some degree to prevent it. Either that, or you'd just need to accept that your privacy on the platform would come with a trade-off in the form of potential abuse, spam, etc.

  • Copy link
  • Flag this post
  • Block
Em :official_verified:
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 9 hours ago

@zak It's a complex and important consideration indeed.

I think it could be technically possible to implement a mechanism where encryption keys for one specific post could be willingly shared with moderators if either party that are part of the conversation decide to share them. This mechanism would have to be per-post of course. That way, conversations would be fully end-to-end encrypted unless one of the included party decides to report the post to moderators themselves.

  • Copy link
  • Flag this comment
  • Block
Zak :1password:
Zak :1password:
@zak@infosec.exchange replied  ·  activity timestamp 9 hours ago

@Em0nM4stodon I think this theoretically could work. But there are two issues with it:

  • This would lack the context of a conversation. So it'd be great for reporting dick pics, but not for conversational abuse.
  • This also depends on one having to see and interact with said dick pic so that it can be actioned. This sounds exhausting, assuming consistent (or even automated) abuse or spam.

I'm sure there's more nuance here. I don't envy people working on dating platforms.

  • Copy link
  • Flag this comment
  • Block
Em :official_verified:
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 9 hours ago

@zak Yes, absolutely.

  • Copy link
  • Flag this comment
  • Block
Adam Caudill
Adam Caudill
@adam_caudill@infosec.exchange replied  ·  activity timestamp 9 hours ago

@zak @Em0nM4stodon I was thinking about this as well. Trying to figure out how to do this in a way that's both privacy protecting and abuse resistant would be an interesting challenge.

  • Copy link
  • Flag this comment
  • Block
Zak :1password:
Zak :1password:
@zak@infosec.exchange replied  ·  activity timestamp 9 hours ago

@adam_caudill @Em0nM4stodon Some solutions that Em will absolutely love:

  • On-device AI scanning for banned subjects or media
  • Identity and age verification at sign-up
  • E2EE, but your keys are also shared with the server for your safety
  • Copy link
  • Flag this comment
  • Block
Em :official_verified:
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 9 hours ago

@zak @adam_caudill 😭

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.27 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct