관리자가 공개 프로필에서 개인 메시지를 확인할 때 경고 표시 추가

관리자가 다른 사람들의 직접 메시지를 읽을 수 있어야 하는 이유나 방법에 대해서는 여기서 다루지 않겠습니다(이미 수없이 많은 논의가 있었기 때문입니다). 또한, 여기서 ‘private message’ 대신 'direct messages’라는 용어를 사용한 것은 현명한 선택이었습니다. Discourse Encrypt에 대해서도 언급하지 않겠습니다. 제 메시지는 이 플러그인을 사용하지 않는 커뮤니티에 관한 것입니다.

다만, 제가 여기서 설명한 경험에 기반한 작은 요청이 있습니다:
https://meta.discourse.org/t/feature-request-regular-mode-for-admins-and-moderators-something-like-sudo-for-the-ui-basically/211617/19?u=canapin


:warning: 또한, 어떤 이유로든 포럼에서 공개 프로필의 스크린샷을 붙여넣어야 할 경우, 사용자가 사용자 공개 프로필의 “direct messages” 탭이 포함된 스크린샷을 보고 놀랄 수 있다는 점도 덧붙입니다.


인터넷에서 'private message’가 '진정으로 비공개’를 의미한다고 생각하는 사용자가 99% 이상이며, 그들은 이에 대해 교육받은 적이 없기 때문에, 관리자가 쉽게 ‘비공개’ 메시지를 읽을 수 있다고 암시하거나 말하거나 설명하는 것은 (반드시) 역효과를 낳을 것입니다.

몇 년 전, 저는 여기에서 짧은 증언을 읽었습니다(검색 엔진으로 찾을 수 없었지만, 누군가 찾아내면 다시 읽고 싶습니다!). 한 사용자가 이 상황을 겪었고, 그의 포럼에서 50명의 사용자가 떠났다고 설명했습니다.
누군가는 인터넷 전반, 적어도 이 유형의 소프트웨어에서 비공개 메시지가 그렇게 작동하는 것이라고 답했습니다.
하지만 첫 번째 사람은 "그래도 내 사용자 50명이 떠났다"는 식으로 답했습니다.

당신이 원하는 만큼, 그리고 가장 좋은 논거를 가지고 사용자에게 설명하더라도, 사람들은 1) 이해하지 못하고 2) 결국 당신을 신뢰하지 않기로 결정할 수 있습니다.


Discourse에서는 많은 모더레이션 도구나 동작이 명확합니다. 추가 메뉴, 도구, 버튼, 다양한 경고, 빨간색 요소, 이런 것들이요…
하지만 공개 사용자 프로필에서는, 특히 이 ‘direct message’ 탭에서는 아무것도 없습니다: 사용자의 직접 메시지 목록을 표시하는 일반적인 ‘direct message’ 버튼뿐입니다(제가 틀리지 않았다면, 여기에 우리 자신을 새로운 참여자로 추가할 수도 있습니다!).

물론, 우리는 관리자로서 책임감 있고 윤리적이며, 사용자는 우리 웹사이트에 등록할 때 우리에게 암묵적으로 신뢰해야 합니다.

하지만 직접 메시지를 읽을 수 있는 기능에 작은 무언가를 추가하는 것이 좋은 일이라고 생각합니다.

"다른 사람의 직접 메시지를 읽으려는 중입니다: 확인 / 취소"와 같은 확인 팝업이거나, 기본적으로 이 탭을 숨기되 관리자 설정을 통해 표시되도록 하거나(체크 해제할 때까지, 또는 특정 기간 동안), 또는 ‘direct message’ 탭의 색상을 다르게 하는 것 등…
저는 잘 모르겠습니다. 하지만 이 탭을 클릭하는 것이 일반적인 동작이 아니라 모더레이션 또는 관리 동작임을 명시적으로 알려주는 작은 무언가가 있으면 좋겠습니다.

16개의 좋아요

Yes, that makes sense. “This action might expose information that is perceived as private by this user, do you want to proceed?”

I would also suggest making Admin - Users - Log personal message views by Admin for other users/groups. default to true,

and if enabled, include a warning ‘This action will be logged’ in that popup.

9개의 좋아요

You mean this right?

3개의 좋아요

Yes exactly. My remembering was wrong and mixed up 50 users and 50% (but maybe he had 100 users total, who knows :sweat_smile: ). Thanks for finding this out. :slight_smile:

I always enable it on my forums, and I admit that I don’t exactly see the point of having this togglable: why one wouldn’t want to log this? Almost everything is logged anyway, and reading other users’ direct messages is a particularly sensitive/intrusive action.
I’m also in favor of having it enabled by default.

6개의 좋아요

Yeah this is a bit alarming. Does Full Mod also have this access to Messages when in User Menu? Or is this just Admin?

Imho this should be togglable if a mod does have the ability without needing to use a plugin. If not mistaken this could cause issues with European countries that have stricter privacy laws.

2개의 좋아요

Administrators only. I used “moderation” in my message, but it was meant as “a moderation action as an admin”.
Again, the goal of the topic is just a proposition to make the direct messages button on public profiles visually (from a confirmation popup or hiding it by default in some admin settings or whatever) more an administration action than a regular action. :slight_smile:


Edit I’d prefer not the discussion derivates on legal/privacy stuff, just on design stuff, please, though I understand the concerns (which has been discussed many times, as said in my topic). :slight_smile:

3개의 좋아요

You’re mistaken. There is no law that says moderators cannot access PM’s :wink:
(There is no law that says admins can - or cannot - access them either).

If you’re referring to the GDPR then that is more complex. It basically boils down that there has to be a good reason and a good process around it.

1개의 좋아요

That’s a relief. But wholeheartedly agree there should be a warning with exploring that option as it can pose all sorts of issues.

We had a mod promoted to admin that was using that to invade and insert themselves into Direct Messages. Fortunately he was not permitted to hold the position long after his transgressions were reported.

I myself was not aware as Admin I have that function until your post. I have clicked a topic link that a user posted that turned out to be link to a PM/DM and was able to view it. In which that scenario should also give a popup imho as well.

Thank you for exposing this issue.

1개의 좋아요

That is what I am referring to. While not over familiar with it. I imagine you might be able to be okay if it is disclosed that pm/dm are not private maybe.

With respect to the op though. We should let this part of the conversation conclude. Though if you have some insights to share please do in a pm. Thanks for clarification.

1개의 좋아요

Yes, absolutely, the proposed warning would be an important part of the forementioned process.

3개의 좋아요

Another thing I experienced yesterday.

An admin selected the content of a direct message, quoted it, and copy-pasted the result in our moderation private category. It looked like this (I’m allowing myself to show it since there absolutely no sensitive information):

So I clicked the quote’s title to see the topic (which led to one of the last messages, not the first message of the direct discussion):

I liked both messages because I first thought it was a public topic. The only clue on my screen that indicated it was a direct message where I wasn’t a participant was the user list under the title, in the header… On which my attention was absolutely not focused. Because I was reading the messages.

I scrolled up to read the other messages and the first thing I saw was the envelope icon in front of the topic’s title (I could have seen the section with the participants, but again, my brain ignored it):

So I realized my “mistake” and un-liked the messages.

Obviously, I understand that I was able to see the topic’s content as I was an admin.
But maybe some sort of similar warning (see my first post and other people’s suggestions) could be set-up? Maybe a popup warning when clicking the topic’s link, similar to what @RGJ suggested, something like “you’re about to see a direct message in which you’re not a participant” or something like that?

I’m not sure. I didn’t face this issue for 3 years using Discourse, so it might be a rare case… But anyway, my little mistake happened and it’s very possible that I could have even replied to the topic without even knowing it was a direct message in which I was not included, which could trigger an issue (regular users seeing an admin directly replying in their “private” discussion :scream:)

10개의 좋아요

As a community manager who has dealt with communities with incredibly sensitive topics (Mental Health communities, Fringe Adult communities, Crypto communities) I heavily support this, including a seperate log file for Admin perusal every time it is used, who used it, and to view which user.

For instance, in one community I helped manage (Which was really a large quantity of smaller, more tight knit communities), I had to create and implement a policy as we had situations where Admins were viewing messages from people in their hyperlocal community, just because. Eventually we setup a conflict of interest situation where you couldn’t deal with a case if it was someone you had dealings with, or was in your local area (large remote group of CMs)

When we enabled logging, we had to fire FOUR CMs, as it turned out that they were using their powers to effectively spy on their local community. Other CMs had admitted to doing the action also until we wrote policy against it.

8개의 좋아요

I continue to advocate for something like this or removing admin’s ability to view PMs and impersonate. Possibly as a site setting at install… there are so many discourse communities which are not typical message boards. So many of us who don’t need/want the admin role to me the eyes that can see all info as some of us use it for sensitive info and in business groups.

There’s been a constant push back from the devs and others here always justifying why admins should have the current access levels to manage a community, but rarely do they actually listen to the fact that there are admins of communities literally asking to either heavily restrict and log any of that activity or remove the functionality.

I think it would be useful to have an at install/initial setup, disabling impersonate and DM access… with an all admin/moderator required input to approve a global setting change to enable it on a live community with a disabled install.

Call it a max privacy vs standard community installation.

There are too many use cases and applications at this point for discourse communities not to think about this kind of stuff..

4개의 좋아요

In my opinion there should be 2 tiers for admins. Instead of just admin and Mod. With top admin with full access but as mentioned a clear warning if venturing so-to-speak in sensitive areas. As it is not made clear that someone is going to view personal messages. A top admin should be able to be trusted. A secondary admin may have elevated access to be able to update forum or add/modify themes & components.

Even adding a command that needs to be ran on the root server to enable/disable might be an idea as an added security peace of mind.

On one side if a user needs a mod/admin in a pm they can invite one. Or if say a site thar has youth involved then the commandline switch can be used when required.

2개의 좋아요

I fully support this, related to impersonating users from top-level admin with server access account.

And I hope reading people private messages will gone with encrypt plugin.

3개의 좋아요

That’s not completely related, but we have some “protection” of this kind (sort of) for permanently delete a post:

1개의 좋아요

I would recommend the Encrypt plugin as it sdds end to end encryption to pm/dm. Not easy to circumvent. Only members invited in the pm/dm can read those messages.

Not sure if this applies to Group mailboxes. Probably not.

2개의 좋아요

For people interested, here is a theme component that moves users’ PMs initial access from their page to the admin page with a new button (keeping the intent in the admin context): Alternative User PMs Button For Admin. I hope that helps!

6개의 좋아요