New "general admin, security & privacy" category?

There is a usability issue when All around Qubes posts are linked to from the public. Users who can access it (i.e. trust level 2 or above) will be just fine. But the rest of the users will see the following:

Which looks like a broken link and provides no explanation.

There are two solutions:

  • avoid linking to those other (more private threads)
  • when mentioning those discussions add a link to this thread so people know what it’s about.
  • detailed 404s

For detailed 404s, it is briefly discussed here:

That could be a bit less confusing as users would at least see:

e9b3f7efce9b0146b2d728d98a3e50bd66d488e3

The main problem is that discourse has a that as a binary setting. Either for all 404s or for none. And this has information disclosure risks, particularly for private messages. Not sure how to measure those risks, but I don’t thing such a site-wide option should be adopted.

If a more granular approach were to be adopted (i.e. only show it on categories), I think it would be a reasonable approach.

So for the time being, I think we’re stuck with:

  • avoid linking to those other (more private threads)
  • when mentioning those discussions add a link to this thread so people know what it’s about.
1 Like