/d/Dread

N/A subscribers

N/A


How does Dread respect our privacy ?

by /u/Razorbeard · 0 votes · 17th September, 2023 17:40

This question comes after some research I made.

From an Opsec perspective we should all presume this website is operated by the NSA, but it would be interesting to have official feedback. If the admins are currently under a gag order, please ignore this message.

Does Dread log connections ? "Private" messages are stored in plaintext and freely accessible by the mods right ?

Comments (4)
/u/Paris · N/A votes · 17th September, 2023 - 18:01 · Link

Everyone should assume that dread and other dread services are compromised. As we have said before, don't trust us. Verify yourself and never risk more than you are willing to lose. We operate on the Tor network with onion services. Onion services not only protect our clusters' privacy but the privacy of users visiting the site. Everyone looks the same. PMs are stored in the database. Even if we said we encrypt your shit on rest and all that stuff it doesn't make it true. We can see messages sent to people if we need to. If you don't want us reading the content encrypt it with PGP. Like on any market.

/u/ratapeluaqw · N/A votes · 17th September, 2023 - 18:28 · Link

Right on!

/u/Zunero · N/A votes · 17th September, 2023 - 18:40 · Link

It's interesting to hear that this website could potentially be operated by NSA (but of course that's not true). As Paris said, we should assume all sites are compromised. Never wholeheartedly trust a site. Always have your guard up and never trust a person wholeheartedly either. Private messages aren't really "private" but it's for the right reasons. They are private in the sense that no regular user can read those messages but the Dread team can. A level of surveillance is needed by the Dread team just to keep everything under control and not have any ongoing scams going in place. It'll be pointless for them to say that our messages are encrypted because Dread is closed-source and without it being open we could never validate their claims. Anyway, any private message you want to send, you could send it via PGP :)

/u/cestpaslafete · N/A votes · 18th September, 2023 - 12:10 · Link

Over the DN, assume than any site, market could be compromised at any moment, same goes with vendors, admin, so caution should be taken. Same goes with any type of communication which aren't encrypted, considere those as stored and in plain text, thats being said, dont trust anything with "auto encrypt" and assume than your PM are in plain text and could be used against you, in the future.

/u/freem0ney · N/A votes · 23rd September, 2023 - 11:08 · Link

Trust the man that says not to trust him.