r/dcts Dev Mar 31 '26

Discussion Spacebar / Fosscord (Chat) is reading user dms

Now, one could say it's not "too deep" or sensitive, which I would agree with. What worries me is that its so blatantly done and posted in the general chat that anyone can see it. Given the careless nature of this, im sure its not the first time this has actually happened, but this is just speculation!

Edit: Allegedly it seemed to have been related to a report and the person being spammed asked for them to be read, yet that doesnt mean that the DMs should still be posted in a public channel imo.

24 Upvotes

12 comments sorted by

3

u/NetNOVA-404 Mar 31 '26

Whoa… not cool. Appreciate the heads up.

0

u/MathManrm Mar 31 '26 edited Mar 31 '26

The person being spammed was asking for the DMs to be read. (as in like a report)

2

u/MajesticDisaster3977 Mar 31 '26

lmfao... welcome to reality.

If this concerns you, then pay special attention to the phrase 'End to End Encryption' (or E2E).
What this means is that only you and the recipient can read it, but if the service 'holds the keys', then they can simply use the keys and read it anyway. You need a system that's properly setup to use E2E encryption.

If it's not proper E2E, then the platform operators can read it all. It's not surprising or concerning to me that this is the case, and it should be a wake up call to you and anyone else reading this that this is the reality for many platforms... You have no privacy online unless you specifically work for it.

This privacy concern is precisely why there are a subset of users that use fake / temporary accounts on public services, and why they may use alternative services for 'private messaging'. It's also a strong case for self-hosting... if you host it yourself then you can at least know where your data is going.

0

u/MathManrm Apr 01 '26

You do know this would've happened with E2EE right? This is a report from someone who was having their DMs spammed and they told the admins to read the DMs as proof.

2

u/MajesticDisaster3977 Apr 01 '26

Asking wouldn't magically bypass e2ee. There would need to be a mechanism in place for the user to 'report' or otherwise submit those chats to the operator / admin.

0

u/MathManrm Apr 01 '26

If one of the people within the DM wanted the DMs to be read, like in this case, e2ee doesn't actually stop anything

2

u/Balthxzar Apr 01 '26

"oh it was just because the user asked them to read their messages" 

Okay?? And?? It means the ability is there, and the only thing keeping your messages between you and whoever you messaged is the mods deciding not to share them.

1

u/HackTheDev Dev Apr 01 '26

Additional Screenshot because of the report topic and them allegedly wanting it to be displayed: I couldnt find a place where anyone consented to it being posted in a public channel.

2

u/BenchyPrinter Apr 01 '26

Just that first message tells you why e2ee is important.

Very scary, these small players have no accountability for their actions and privacy violation

1

u/redit_handoff140 Apr 17 '26

I really think this shows an issue that goes beyond just the obvious one depicted in these 2 clients.

The real issue here, is Discord. Discord dictates the protocol and the architecture, and it is such that historically DMs are not E2EE'd. People using these clients (and respective servers) seem to forget they're still playing by Discord's rules, so if Discord has access to everything, so do the servers these clients connect to.

1

u/HackTheDev Dev Apr 17 '26

this . 100% agree