this post was submitted on 26 Jan 2024
44 points (100.0% liked)
sh.itjust.works Main Community
7730 readers
1 users here now
Home of the sh.itjust.works instance.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Good to know thas it was patched. Indeed, an issue with federated app is that, instance admin could be dishonest and spy us (while proprietary app will do it). But to my understanding the bug was fully public so a message like call me , on 0123 456 789 could reveal your phone number
Even with this patched I would not advise stating your phone number expecting full security.
I can confirm that DMs are not encrypted and are stored in clear text and therefore could technically be read by admins with database access.
While we are not actively looking or browsing through DMs, I'd still recommend not sharing anything sensitive through lemmy DMs and instead use something like Matrix or Signal.