ok look the "DMs are not secure" stuff is missing the point of DMs -- yes, they arent secure, but they are ~private to not-admins
@nire LIKE TWITTER
@boots right, but also twitter has less admins who are going to be specifically going through your tweets, so its kind of a moot point
@boots i really hate the 'its just like twitter' thing because volume of relevant things is much higher there than here -- reading your DMs as a twitter admin would be pretty tiring and hard to do on a visual scan
@boots but here if you really wanted to it wouldnt be that hard, especially if you made a domain hacking one to impersonate people
@nire hm
i didnt think about much of that
@boots basically twitter being able to read your DMs doesnt really matter because theres no possible personal interest in twitter reading your DMs, but everyone acts as if there is so says the threat pattern is the same
@boots bc right now on things that arent masto they just show up as regular messages