News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

Are Private Messages REALLY Private?

Started by CenTexPatriot, May 21, 2015, 12:34:07 PM

Previous topic - Next topic

CenTexPatriot

I am using SMF v2.0.9...

When I receive an email notification from the forum regarding a PM, the email address "From" field shows as the email address of the forum administrator.

Is the forum administrator receiving copies of my private messages? Is this a relay of some sort? How does this work?

Any information would be most helpful.

Thanks in advance!

margarett

This is really a tricky question.

How private are PMs? It depends on a buch of factors, really.

First of all, PMs are stored in the database. Although SMF does not offer any way to easily check them via admin panel (eg, we don't accept MODs to do this), they are still stored in the database in plain text. Any admin that has database access and wants to see your PMs, he can.

Then, there's the report PM functionality. If someone reports a PM, admins will get a copy of it (of course, how could they check the report if they don't see the content? :P )

Finally, there's the "PM flow via email". What you mention is not a problem. All emails have to be sent from someone, so SMF uses the "webmaster's email address) as the "from". And from this point alone, there is no privacy issue.
This issue does exist when a forum is configured to use SMTP to send emails. If the admin uses, eg, gmail to send SMF's emails, this means that every "sent" email from the forum (PM or otherwise) WILL be stored in the "Sent Items" folder of the user in gmail. I don't think that there's a way to prevent this, it's how gmail works...

In short: if you don't receive email notifications from your PMs, neither do your "recipients", you are mostly private, except from the direct database access.

Do note that this is not specific to SMF. AFAIK, it's how ALL forum softwares work...
Se forem conduzir, não bebam. Se forem beber... CHAMEM-ME!!!! :D

QuoteOver 90% of all computer problems can be traced back to the interface between the keyboard and the chair

a10

QuoteIs the forum administrator receiving copies of my private messages?

Not if using PHP default, but the following errors occurs now and then on my forum (which discloses some PM content (to admin):

1: The 'not-so-awake' member writes a reply to the notification email and hit send, instead of logging in to the forum to do the PM work. Ends up in the forum admin email inbox.
2: The PM notification email bounces back to sender (forum admin) due to some error with the intended members email.

Am providing a guide for PM use, basically telling members to never PM anything that would not tolerate beeing seen in plain daylight, & that the general forum rules for conduct\content applies to PM as well.

2.0.19, php 8.0.23, MariaDB 10.5.15. Mods: Contact Page, Like Posts, Responsive Curve, Search Focus Dropdown, Add Join Date to Post.

CenTexPatriot

Thank you both so much!

Very helpful.

aegersz

#4
i wrote a simple php script to dump the message database


marg edit: As stated, we don't endorse any way of reading members PMs. So please don't brag about it ;)
The configuration of my Linux VPS (SMF 2.0 with 160+ mods & some assorted manual tweaks) can be found here and notes on my mods can be found here (warning: those links will take you to a drug related forum). My (House) music DJ dedication page is here

Advertisement: