[OOC] After watching this for a bit, the general problem seems to be something like this:
1. A DM is submitted to the server
2. The server seems to default to a public view for a brief while
3. After the toot is processed, it is set to being a DM
For a brief moment I was able to view the public atom feed link and see the DM from an anonymous browsing window, which is why I'm announcing this- it's a big problem for private communications.
-Crom