167

Federated services have always had privacy issues but I expected Lemmy would have the fewest, but it's visibly worse for privacy than even Reddit.

  • Deleted comments remain on the server but hidden to non-admins, the username remains visible
  • Deleted account usernames remain visible too
  • Anything remains visible on federated servers!
  • When you delete your account, media does not get deleted on any server
(page 2) 50 comments
sorted by: hot top controversial new old
[-] Stimmed@reddthat.com 12 points 1 year ago

If you think anything on the Internet can ever be forgotten... Your going to have a bad time. Passwords, one of the most protected data types, are compiled from beaches into huge databases so that hackers can use them to try to log into website. There are literally dozens of not hundreds of those password databases on the public Internet to be downloaded, not to mention private or dark web collections. If passwords are not safe, what makes you think publicly available social media would be any different?

Even if somehow the whole federation agreed to purge all post every year, things like the Internet archive and Google cache of pages would retain the data.

[-] Forcen@lemmy.one 12 points 1 year ago* (last edited 1 year ago)

One thing that mastodon does is proxying all the media from the federated servers, lemmy does not do this.. (yet)

For example on this comment page there are 9 domains trying to connect directly to me according to ublock origin. I suggest blocking all third party requests on your instance using ublock origins advanced mode because the website works fine without them, it might be mostly avatars?

[-] BitOneZero@beehaw.org 10 points 1 year ago

For example on this comment page there are 9 domains trying to connect directly to me according to ublock origin.

ublock origin isn't a firewall. They aren't connecting inbound to your system, you are loading content from those servers.

load more comments (1 replies)
[-] The_Terrible_Humbaba@beehaw.org 11 points 1 year ago* (last edited 1 year ago)

After reading some more comments, I think I came up with a good analogy to explain this issue, and I wanted to share.

Think of websites like a bar that also has an open mic.

Now, when I go to a bar, I don't want to have to give the bouncers and staff my full name as well as my address. I also wouldn't want them to know that I just came, for example, from a store where I was looking for a vacuum, and then have them warn a vacuum seller about it. A vacuum seller who is then going to sit next to me, while I'm trying to have a drink, and show me a pamphlet regarding the "amazing vacuum" he has for sale.

Ideally, I can also look for a bar that will allow me to come in costumed and not show my face. Or I could ask the bar to delete footage of me at some point, and to not store my ID if I do have to show it to a bouncer at the entrance.

All of that is relatively feasible and within the realm of reason; and all of that are things that privacy advocates might advocate for.

However, what is not feasible, or within the realm of reason, or what privacy advocates tend to advocate for, is the ability for me to willingly go up on stage, say something on the mic which I immediately regret, and then ask everyone present to forget it ever happened and delete any footage they might have of it. No reasonable person would ask for something like that, because it is not a reasonable request.

That is how regular websites work. With federated websites, that becomes enhanced; it's like if the bar you're in has a camera pointed at the microphone, and transmits both video and audio directly into several other bars. So when you go up to that mic, you better make sure you're okay with what you are saying being made public and available to anyone.

load more comments (6 replies)
[-] j0s3f@feddit.de 11 points 1 year ago

That's a non issue. You just cannot expect to be able to delete anything you post on the internet. Even the great reddit with the awesome deletion feature cannot help you. You might be able to delete your comment there, but there is https://www.unddit.com/ https://archive.is/ https://web.archive.org/ and many others, where your comment will still be available.

load more comments (4 replies)
[-] GadgeteerZA@beehaw.org 10 points 1 year ago

Not sure what the point of "Mastodon's" opinion is? Firstly, Mastodon is pretty big and decentralised, and it has no-one who really speaks on behalf of all its users. Lemmy is not a privacy central network like a direct messenger service. It never claimed to be privacy centric as far as I know. The point is to share posts in communities, and the more that see them, the better.

But it is federated which means posts do get shared to other servers everywhere, and deleting those is not as easy as for a centralised server. Whatever I post on any sharing type service, I consider to be public.

load more comments (4 replies)
[-] ZILtoid1991@kbin.social 10 points 1 year ago

I think an option for full data deletion would be nice for those who want it, otherwise people should also expect others recording their data, which can be published later on.

load more comments (6 replies)
[-] AllonzeeLV@vlemmy.net 9 points 1 year ago

I wasn't planning on doing any banking through Lemmy.

[-] slartibartfast42@beehaw.org 9 points 1 year ago

I would encourage you to stay as far away from Raddle as possible. It has an incredibly toxic site-wide culture, and some serious security problems.

load more comments (1 replies)
[-] exoteefs@kbin.social 8 points 1 year ago

I'm not sure what this has to do with mastodon all I see are some salty idiots on raddle moaning.

[-] ellabella@beehaw.org 8 points 1 year ago

If I wanted privacy, I wouldn't be browsing online.

load more comments (1 replies)
[-] VexCatalyst@lemmy.fmhy.ml 8 points 1 year ago* (last edited 1 year ago)

In both services you are basically shouting into a giant megaphone. What’s so private about it? If you don’t want say it in public, don’t say it there.

If you need privacy there are much better tools available such as pgp encrypted email or encrypted Matrix DMs (a nonfederated Matrix sever would be even more secure but rather overkill).

Edit: specified encrypting Matrix DMs. I forgot for a moment that you can send unencrypted DMs over Matrix.

[-] MoshBit@beehaw.org 7 points 1 year ago

As a life long anarchist, I personally find raddle to be a fucking embarrassment. The elitist bullshit is right up there with other political anarchist sites like anarchistnews.net, they're all a fucking shit show and shows why anarchists will never accomplish anything.

load more comments (3 replies)
[-] trent@kbin.social 6 points 1 year ago

The stuff listed in OP doesn't really seem like much concern. "What you put on the internet is there forever!" is completely true, and things like this should only make it more concrete that you can't rely on your service provider to delete information somebody else already archived.
With that being said, default privacy settings - at least on Kbin - seem pretty bad.

load more comments
view more: ‹ prev next ›
this post was submitted on 19 Jun 2023
167 points (100.0% liked)

Technology

37716 readers
379 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS