892
submitted 1 year ago by Raisin8659 to c/technology@lemmy.world

Synopsis: The article discusses the FBI's seizure of the Mastodon server and emphasizes the need for privacy protection in decentralized platforms like the Fediverse. It calls for hosts to implement basic security measures, adopt policies to protect users, and notify them of law enforcement actions. Users are encouraged to evaluate server precautions and voice concerns. Developers should prioritize end-to-end encryption for direct messages. Overall, the Fediverse community must prioritize user privacy and security to create a safer environment for all.

Summary:

Introduction

  • We are in an exciting time for users wanting to regain control from major platforms like Twitter and Facebook.
  • However, decentralized platforms like the Fediverse and Bluesky must be mindful of user privacy challenges and risks.
  • Last May, the Mastodon server Kolektiva.social was compromised when the FBI seized all electronics, including a backup of the instance database, during an unrelated raid on one of the server's admins.
  • This incident serves as a reminder to protect user privacy on decentralized platforms.

A Fediverse Wake-up Call

  • The story of equipment seizure echoes past digital rights cases like Steve Jackson Games v. Secret Service, emphasizing the need for more focused seizures.
  • Law enforcement must improve its approach to seizing equipment and should only do so when relevant to an investigation.
  • Decentralized web hosts need to have their users' backs and protect their privacy.

Why Protecting the Fediverse Matters

  • The Fediverse serves marginalized communities targeted by law enforcement, making user privacy protection crucial.
  • The FBI's seizure of Kolektiva's database compromised personal information, posts, and interactions from thousands of users, affecting other instances as well.
  • Users' data collected by the government can be used for unrelated investigations, highlighting the importance of strong privacy measures.

What is a decentralized server host to do?

  • Basic security practices, such as firewalls and limited user access, should be implemented for servers exposed to the internet.
  • Limit data collection and storage to what is necessary and stay informed about security threats in the platform's code.
  • Adopt policies and practices to protect users, including transparency reports about law enforcement attempts and notification to users about any access to their information.

What can users do?

  • Evaluate a server's precautions before joining the Fediverse and raise privacy concerns with admins and users on the instance.
  • Encourage servers to include privacy commitments in their terms of service to resist law enforcement demands.
  • Users have the freedom to move to another instance if they are dissatisfied with the privacy measures.

What can developers do?

  • Implement end-to-end encryption of direct messages to protect sensitive content.
  • The Kolektiva raid highlights the need for all decentralized content hosts to prioritize privacy and follow EFF's recommendations.

Conclusion

  • Decentralized platforms offer opportunities for user control, but user privacy protection is vital.
  • Hosts, users, and developers must work together to build a more secure and privacy-focused Fediverse.
you are viewing a single comment's thread
view the rest of the comments
[-] Blackmist@feddit.uk 11 points 1 year ago

I like the idea of it, but you're right. It's not going to scale because at some point, somebody has to pay for it. And most users, myself included, seem unwilling to dip into our own pockets to satisfy our crippling addiction to cat pictures and world weary cynicism.

In the old days we had Usenet newsgroups, hosted by ISPs, just like most of them still do with email. It's the ideal place for hosting a fediverse, maybe not necessarily this one. They already scale their stuff with the number of users. We already pay them. And it decentralises power away from a handful of tech billionaires.

Would they do it? Who knows. They're certainly best placed for it, but would they want the unenviable job of identifying and blocking kiddy porn and cartel torture videos? I know I wouldn't want to be looking at that shit all day. The big networks obviously have a solution for that, but automated AI image recognition stuff only goes so far. At some point there's a poor minimum wage worker looking at it in a third world country.

[-] Rodeo@lemmy.ca 5 points 1 year ago

In the old days we had Usenet newsgroups, hosted by ISPs ... it decentralises power away from a handful of tech billionaires.

And into the hands of the ISPs, which are also owned by billionaires.

[-] Blackmist@feddit.uk 3 points 1 year ago

Depends where you are. In the US, probably. You don't even get a choice of ISP in some places, although there's probably more choice if you use a mobile. In the UK, there are a few dozen. Small ones all over most other countries. It's still an improvement over Facebook and Twitter.

And you wouldn't have to use your ISP's one. You could use any. But you will have to accept that it costs money. You'll be having to pay at some point, either with adverts, a subscription, or some Discord style nonsense waved in your face every day.

[-] nomadjoanne@lemmy.world 1 points 1 year ago

I'm a bit unconvinced that we would want to scale. Why is growth necessarily good? We'd end up looking much like mainstream social media by that point. A lot of regulatory compliance, a lot of normie BS on the platform, etc. There is still probably some room to grow before that becomes a reality though.

I think it's a fine line to walk, but being and staying a bit niche isn't such a bad thing.

[-] astral_avocado@programming.dev 5 points 1 year ago

Because otherwise Lemmy will die from lack of interest, it's too small at the moment.

this post was submitted on 25 Jul 2023
892 points (97.5% liked)

Technology

59648 readers
1516 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS