this post was submitted on 19 Jun 2023
157 points (100.0% liked)

Technology

37738 readers
375 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
 

Federated services have always had privacy issues but I expected Lemmy would have the fewest, but it's visibly worse for privacy than even Reddit.

  • Deleted comments remain on the server but hidden to non-admins, the username remains visible
  • Deleted account usernames remain visible too
  • Anything remains visible on federated servers!
  • When you delete your account, media does not get deleted on any server
(page 2) 50 comments
sorted by: hot top controversial new old
[–] The_Terrible_Humbaba@beehaw.org 11 points 1 year ago* (last edited 1 year ago) (6 children)

After reading some more comments, I think I came up with a good analogy to explain this issue, and I wanted to share.

Think of websites like a bar that also has an open mic.

Now, when I go to a bar, I don't want to have to give the bouncers and staff my full name as well as my address. I also wouldn't want them to know that I just came, for example, from a store where I was looking for a vacuum, and then have them warn a vacuum seller about it. A vacuum seller who is then going to sit next to me, while I'm trying to have a drink, and show me a pamphlet regarding the "amazing vacuum" he has for sale.

Ideally, I can also look for a bar that will allow me to come in costumed and not show my face. Or I could ask the bar to delete footage of me at some point, and to not store my ID if I do have to show it to a bouncer at the entrance.

All of that is relatively feasible and within the realm of reason; and all of that are things that privacy advocates might advocate for.

However, what is not feasible, or within the realm of reason, or what privacy advocates tend to advocate for, is the ability for me to willingly go up on stage, say something on the mic which I immediately regret, and then ask everyone present to forget it ever happened and delete any footage they might have of it. No reasonable person would ask for something like that, because it is not a reasonable request.

That is how regular websites work. With federated websites, that becomes enhanced; it's like if the bar you're in has a camera pointed at the microphone, and transmits both video and audio directly into several other bars. So when you go up to that mic, you better make sure you're okay with what you are saying being made public and available to anyone.

load more comments (6 replies)
[–] VexCatalyst@lemmy.fmhy.ml 11 points 1 year ago* (last edited 1 year ago)

In both services you are basically shouting into a giant megaphone. What’s so private about it? If you don’t want say it in public, don’t say it there.

If you need privacy there are much better tools available such as pgp encrypted email or encrypted Matrix DMs (a nonfederated Matrix sever would be even more secure but rather overkill).

Edit: specified encrypting Matrix DMs. I forgot for a moment that you can send unencrypted DMs over Matrix.

[–] slartibartfast42@beehaw.org 10 points 1 year ago (1 children)

I would encourage you to stay as far away from Raddle as possible. It has an incredibly toxic site-wide culture, and some serious security problems.

load more comments (1 replies)
[–] tiny_electron@beehaw.org 10 points 1 year ago (2 children)

This is a big issue because in the EU you have the right to remove your data. It could make Lemmy illegal in the EU

load more comments (2 replies)
[–] AllonzeeLV@vlemmy.net 9 points 1 year ago

I wasn't planning on doing any banking through Lemmy.

[–] Penguincoder@beehaw.org 9 points 1 year ago

In order for me to be offended, I'd first have to care about that opinion. I don't.

[–] GadgeteerZA@beehaw.org 8 points 1 year ago (4 children)

Not sure what the point of "Mastodon's" opinion is? Firstly, Mastodon is pretty big and decentralised, and it has no-one who really speaks on behalf of all its users. Lemmy is not a privacy central network like a direct messenger service. It never claimed to be privacy centric as far as I know. The point is to share posts in communities, and the more that see them, the better.

But it is federated which means posts do get shared to other servers everywhere, and deleting those is not as easy as for a centralised server. Whatever I post on any sharing type service, I consider to be public.

load more comments (4 replies)
[–] ISometimesAdmin@the.coolest.zone 7 points 1 year ago (1 children)

Other people have already commented on how federated social media often requires certain data just for implementations to work and make sense, and there's not much more to add to that.

If you want private, end-to-end-encrypted, decentralized communication, the best modern solution to that is #matrix.

load more comments (1 replies)
[–] exoteefs@kbin.social 6 points 1 year ago

I'm not sure what this has to do with mastodon all I see are some salty idiots on raddle moaning.

[–] grizzzlay@beehaw.org 6 points 1 year ago

I don't think much of Mastodon as it is, so they're free to rag on Lemmy all they want.

[–] ellabella@beehaw.org 6 points 1 year ago (1 children)

If I wanted privacy, I wouldn't be browsing online.

[–] Contend6248@feddit.de 6 points 1 year ago* (last edited 1 year ago)

That's a poor answer to be honest. Total privacy is an illusion, but having the tools to delete some of the traces if wanted should be there. I would argue that the EU law about the right to be forgotten might want a word with someone.

I escaped Reddit, but i hold anyone else to a standard too.

Lemmy, do better or it wont end well. https://gdpr.eu/right-to-be-forgotten/

[–] trent@kbin.social 5 points 1 year ago

The stuff listed in OP doesn't really seem like much concern. "What you put on the internet is there forever!" is completely true, and things like this should only make it more concrete that you can't rely on your service provider to delete information somebody else already archived.
With that being said, default privacy settings - at least on Kbin - seem pretty bad.

load more comments
view more: ‹ prev next ›