<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: ThisТайна Team</title>
    <description>The latest articles on DEV Community by ThisТайна Team (@thistaina_max).</description>
    <link>https://dev.to/thistaina_max</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4084959%2Ff204426b-4d5f-4c1a-b7a6-c3261a8e2265.png</url>
      <title>DEV Community: ThisТайна Team</title>
      <link>https://dev.to/thistaina_max</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/thistaina_max"/>
    <language>en</language>
    <item>
      <title>How to Build Anonymous Messaging Without Deanonymizing Users</title>
      <dc:creator>ThisТайна Team</dc:creator>
      <pubDate>Wed, 19 Aug 2026 11:34:58 +0000</pubDate>
      <link>https://dev.to/thistaina_max/how-to-build-anonymous-messaging-without-deanonymizing-users-5d7c</link>
      <guid>https://dev.to/thistaina_max/how-to-build-anonymous-messaging-without-deanonymizing-users-5d7c</guid>
      <description>&lt;p&gt;Anonymous messaging products often create engagement by promising identity reveals. That is also where trust breaks.&lt;/p&gt;

&lt;p&gt;We are building &lt;strong&gt;ThisTayna&lt;/strong&gt;, a social bot inside the MAX messenger, around a stricter rule: sender identity is neither revealed nor sold. This post explains the engineering decisions behind that promise.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Treat identity as a separate security domain
&lt;/h2&gt;

&lt;p&gt;The message service should not need a sender's public identity to deliver a message. Use opaque identifiers and conversation-scoped aliases between domains.&lt;/p&gt;

&lt;p&gt;A transport response should contain only what the client needs:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;an opaque message ID;&lt;/li&gt;
&lt;li&gt;an opaque conversation ID;&lt;/li&gt;
&lt;li&gt;display-safe metadata;&lt;/li&gt;
&lt;li&gt;server-owned permission state.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Never return an internal account binding "just in case."&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Make hints non-identifying by construction
&lt;/h2&gt;

&lt;p&gt;A safe hint is a fact derived from interaction history inside the product, not a shortcut to identity.&lt;/p&gt;

&lt;p&gt;Examples of acceptable categories:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;whether the two users interacted before;&lt;/li&gt;
&lt;li&gt;whether a reply exists;&lt;/li&gt;
&lt;li&gt;coarse, policy-reviewed engagement facts.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Unsafe categories include names, phone numbers, locations, contacts, device fingerprints, or any combination that narrows the sender to a real person.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;If a paid feature can reveal a sender, privacy is not an invariant — it is a price tier.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  3. Enforce blocks in every write path
&lt;/h2&gt;

&lt;p&gt;A block check only in the UI is not protection. Enforce it server-side for:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;anonymous messages;&lt;/li&gt;
&lt;li&gt;replies;&lt;/li&gt;
&lt;li&gt;matching and likes;&lt;/li&gt;
&lt;li&gt;gifts and other indirect contact;&lt;/li&gt;
&lt;li&gt;notifications and queued retries.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This prevents alternate endpoints and workers from bypassing the user's boundary.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Separate adult and minor discovery pools
&lt;/h2&gt;

&lt;p&gt;Age-based isolation belongs in the matching query and server-side policy, not in a client filter. The two pools must never overlap, including recommendations, retries, cached feeds, and experiments.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Audit money and moderation separately
&lt;/h2&gt;

&lt;p&gt;Money mutations should be idempotent, append-only ledger operations. Moderation access should require a scoped case and append-only audit. Neither system should become an unofficial identity lookup.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the user should feel
&lt;/h2&gt;

&lt;p&gt;Good privacy architecture is invisible. The user should feel that it is easy to start a conversation, easy to leave, and impossible to buy someone else's identity.&lt;/p&gt;

&lt;p&gt;That is the product direction behind &lt;strong&gt;ThisTayna / ThisТайна&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;anonymous messages with replies;&lt;/li&gt;
&lt;li&gt;new conversations inside MAX;&lt;/li&gt;
&lt;li&gt;blocks and reports across interaction paths;&lt;/li&gt;
&lt;li&gt;no paid identity reveal.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Try the bot in MAX:&lt;/strong&gt; &lt;a href="https://max.ru/id010511198702_2_bot" rel="noopener noreferrer"&gt;Open ThisТайна&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Product site:&lt;/strong&gt; &lt;a href="https://thistaina.ru/" rel="noopener noreferrer"&gt;thistaina.ru&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Disclosure: ThisТайна is our project. The architecture principles above describe the product constraints we are implementing, not an independent review.&lt;/em&gt;``&lt;/p&gt;

</description>
      <category>security</category>
      <category>privacy</category>
      <category>webdev</category>
      <category>go</category>
    </item>
  </channel>
</rss>
