292

jointhefediverse.net seems to be a commonly linked resource for directing people to join the Fediverse.

Curiously, it does not list Lemmy under the list of Reddit alternatives. Their GitHub README explains why.

Previous relevant discussion: https://lemmy.ml/post/78808

you are viewing a single comment's thread
view the rest of the comments
[-] Azzu@lemm.ee 62 points 1 month ago* (last edited 1 month ago)

They can do whatever shit they want with their instance and believe whatever they want. The software they make provably doesn't have any more biases than any other software. As long as that's the case, I'm fine.

[-] SleafordMod@feddit.uk 5 points 1 month ago

Maybe there's something in the codebase that sends all our data to North Korea... who knows.

[-] EllaSpiggins@lemm.ee 48 points 1 month ago

We do, because it’s open source

[-] SleafordMod@feddit.uk 5 points 1 month ago

Have you read all the code though? Everyone assumes that somebody else will read every single file of the source code, and understand it all. Malicious code can be obfuscated.

[-] EllaSpiggins@lemm.ee 13 points 1 month ago

Personally, no. However the technical lead of our instance has, and in fact wrote and debugged some of it.

[-] SleafordMod@feddit.uk 1 points 1 month ago

Even a technical lead of an instance may not have read every single line of code because codebases these days are pretty large. Typically you might look at the code you're working on, but not necessarily the entire codebase.

Hopefully Lemmy doesn't have anything malicious in it, but it's possible to sneak malware into open source projects. This sort of thing happened to XZ Utils last year.

[-] Blaze@feddit.org 6 points 1 month ago

If you are worried about the Lemmy codebase, there is https://piefed.social/

It's still another codebase you need to trust, but in this case the devs don't have specific political views

[-] SleafordMod@feddit.uk 2 points 1 month ago

Yeah I've heard of that, maybe I should look at it more. Hopefully the Lemmy codebase is fine though. I'm just saying it's possible, even if perhaps unlikely, that something could be lurking in the code which nobody has discovered yet. The XZ Utils backdoor was well-hidden and happened to be discovered, but maybe malicious code isn't always discovered.

[-] lambalicious@lemmy.sdf.org 4 points 1 month ago

Next time, do something like suggesting that vaccines don't work, to entertain me.

[-] SleafordMod@feddit.uk 4 points 1 month ago

I'm not raising a conspiracy theory point, I'm raising what is surely a valid point: everybody assumes that someone else will read all of the source code and understand it all.

Codebases are large, and malicious code can be obfuscated. Hopefully Lemmy's code is fine, but I definitely don't know for certain that it's completely clean. I just hope that it is.

this post was submitted on 09 Jan 2025
292 points (100.0% liked)

Fediverse

30297 readers
594 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 2 years ago
MODERATORS