814
submitted 3 months ago* (last edited 3 months ago) by rimu@piefed.social to c/fediverse@lemmy.world

Probably better to post in the github issue rather than replying here.

https://github.com/LemmyNet/lemmy/issues/4967

you are viewing a single comment's thread
view the rest of the comments
[-] 9point6@lemmy.world 508 points 3 months ago

Hard no from me

I don't want some nutjob with too much time stalking me because I upvoted something about climate change or downvoted some bigoted shit. We all know those fuckos are out there

Voting on Reddit-like platforms is soft moderation by a community, and if you disincentive that, the whole model kinda falls apart IMO

[-] mozz@mbin.grits.dev 126 points 3 months ago

Your votes are already public. It’s a matter of (a) do we want to make it slightly easier for the people who aren’t technically inclined to see them too (b) do we want people acting with the awareness that they’re public.

(a) doesn’t have a clear answer to me. The answer to (b), though, is clearly yes.

[-] rimu@piefed.social 150 points 3 months ago

Your votes are already public.

People say this all the time, but it's not really the case.

I don't think privacy is a binary thing that one either has or does not - there are degrees of privacy. Currently what we have is mostly private, requiring either technical skill or admin access to circumvent. This is a pretty high bar which 99% of people would not be able to reach. You're proposing removing the bar entirely because it is not high enough.

[-] rglullis@communick.news 44 points 3 months ago

requiring either technical skill or admin access to circumvent.

What if some troll sets up a website that indexes/publishes this data? What technical skill would be required then?

The data is public and ignorance is not bliss. People need to be made aware of this. If this will lead to people being more careful about what they post online or how they interact with a public social media service, then all the better.

[-] rimu@piefed.social 15 points 3 months ago* (last edited 3 months ago)
[-] rglullis@communick.news 37 points 3 months ago
  1. You don't need to be federated to read people's activities...
  2. Even if there was some type of "authorized fetch" involved, one could bypass it easily by writing a bot on LW to get the data. Then what?
[-] rimu@piefed.social 17 points 3 months ago

Ok, yeah, theoretically.

But we're talking about putting voting info into the UI for anyone to see. Not highly motivated and skilled bad actors.

[-] rglullis@communick.news 17 points 3 months ago

And the "we should not make it available for the public at large because it will lead to abuse" is also theoretical.

Anyway, I'm already on record saying that I don't like the voting system and that we should get rid of it altogether. Voting on content used to be about collective curation, not a constant popularity contest.

I'm also on record saying that we need to stop relying on systems that only give us the illusion of privacy and depend on the software developers for culture shaping.

If making the vote public gets people to be exposed to these fundamental issues of the current design, and leads us to search for better solutions, then I'm all for it.

[-] ericjmorey@fedia.io 6 points 3 months ago

It's not theoretical to se how people consistently behave when there's less friction for toxic behavior. You should look into it if you're not already aware of the very predictable negative outcomes that stem from removing those frictions.

[-] rglullis@communick.news 3 points 3 months ago* (last edited 3 months ago)

I mean in the specific case of "giving vote visibility to everyone will cause more harassment based on who-voted-on-what". It's theoretical because this has not been implemented yet.

[-] ericjmorey@fedia.io 1 points 3 months ago

Except that it plainly obvious that it's a reduction in friction for doing so and therefore will increase the behavior.

[-] rglullis@communick.news 1 points 3 months ago

I've addressed this in another comment. At first, it's quite likely that we'd see an increase in behavior. But the way to correct this would be by reporting "serial downvoters" and brigaders to moderators, which could then be empowered to enforce "don't downvote just because you disagree" guidelines.

Hackernews, for all its faults, does this very well. Their moderation team is quite small, yet it rarely falls into screaming matches between users. Their guidelines are clear and let people understand what is/is not acceptable. Mods are rarely seen threatening to ban someone, but often calling out bad behavior and simply asking people to stop doing whatever they are doing before it escalates further.

[-] Iceblade02@lemmy.world 2 points 3 months ago

We've already seen that kind of harrasment on major platforms including X and those owned by Meta.

[-] rglullis@communick.news 2 points 3 months ago* (last edited 3 months ago)

This feels a bit of a conversation-shutting argument. Lots of things (good and bad) will happen on a platform that has billions of users. The real question is to about many of those instances happened solely due to the data being (easily) available to the public.

In any case, I really don't think that the solution to the problem of targeted harassment is by providing quote-unquote-privacy. Today, people want to obfuscate votes. Tomorrow it will be subscription lists and later it will be even posts/comments. By then it will be better to just use a closed network or just go full darknet. I'd rather we spent more time educating the people on how to use actually secure and private communications platform instead of sacrificing Transparency and Accountability for the sake of a vocal minority who will keep trying to turn the "Open Social Web" (which is meant to be open and public) into their exclusive, cocooned service.

[-] Iceblade02@lemmy.world 2 points 3 months ago* (last edited 3 months ago)

That's because it's supposed to be. I was on Reddit for a decade until their management shit the bed, and these kinds of problems weren't a thing there despite the much larger userbase.

For the record, to me it's less about privacy and more about setting expectations. I'm not anonymous online, I'm pseudonymous, I've had this handle for a long time. I am my online identity, and when I post and vote I don't feel anonymous, even if I'm relatively protected from someone knocking on my door or messaging my boss about a statement.

If voting "ledgers" aren't presented in the discussion, that's because they aren't intended to be part of the discussion. This reduces the value of influential individuals votes (ooh Bill Gates liked X, Kamala Harris disliked Y etc.) and shifts focus to how the community values of the content. It’s the same reason that we follow communities rather than individuals. We get an internet "hive mind" of sorts without cult of personality.

[-] rglullis@communick.news 2 points 3 months ago

These specific kinds of things were not a problem, yet it didn't stop the mob from doxxing people "by mistake", getting the police breaking into people homes based on false allegations or getting people fired over something stupid that was said years ago...

If this is about "expectations" of privacy, then it would be better to just expect the worst always and only write/post/share things when you are 100% sure you don't mind them being ever attributed to you.

[-] Iceblade02@lemmy.world 2 points 3 months ago* (last edited 3 months ago)

Expectations of what is part of the discussion, not expectations of privacy.

As for doxxing, that's a problem with all social media - but possibly worse on the "regular" ones (people having mobs attacking their houses, being arrested in countries with censorship laws etc.)

[-] rglullis@communick.news 1 points 3 months ago* (last edited 3 months ago)

shifts focus to how the community values of the content.

Ok, I think I get your point, but I can tell you that in my experience is the exact opposite:

  • The hivemind effect is strong, and a lot perfectly-acceptable content gets up/downvoted by people just because the score is already high/low.

  • I have been posting quite a bit since I joined Lemmy in the different niche communities from the instances that I run. Invariably I see downvotes from people who are not subscribers. I've sent DMs to some of them asking what was wrong with the post, and the answer was simply "this is not interesting to me". I replied saying "Look, this isn't Reddit. There is no algorithm. If you are not interested in the content from this community either block it or don't browse by all". Their response was a basic "how dare you tell me how to browse Lemmy?!" Unsurprisingly, when I tried to bring this up for general discussion, I was mass downvoted for the majority that thinks that "downvotes-as-disagreement" is okay..

So, yeah... In my view, for better or worse votes are part of the conversation. If people were using votes as a valid filter for content quality, I'd totally agree with you. If there is a mass of people downvoting a comment or post that seems to be aligned with the community's values, I feel like I should know why about the comment is deserving of the downvotes. At the very least, I think it's important to know who is downvoting for legitimate reasons and who is downvoting just because they are a whiny brat that should be ignored/muted/blocked.

[-] Iceblade02@lemmy.world 1 points 3 months ago

I agree that it would be better if people used votes as a marker of quality, but strongly disagree on moderation action based on voting.

Personally, there's three scenarios when I use downvotes w/o commenting:

  • Someone has already voiced the reason

  • I don't have time/energy to comment

  • The target is a censored echo-chamber that will ban anyone who disagrees (can't vote/show disapproval if you're banned) - example would be .ml communities having moments about how stalinist USSR did nothing wrong.

Anyway, once a post from a community rises sufficiently to pop up on all, it becomes a part of the larger discussion, and voting will shift towards the opinions of the larger fediverse. This is also usually when communities get discovered by more people. If a community doesn't want the engagement of the wider user-base, a closed blog may be more suitable as a forum, or alternatively have an instance w/o downvoting.

When browsing all or new I do so both to break out of my bubble and to vote on content (usually stuff I find interesting).

[-] rglullis@communick.news 2 points 3 months ago

Yeah, unfortunately it seems that I am in the minority when it comes to how this "should" be used. I genuinely believe that one of the reasons that open platforms are better is because it's not designed to constantly get me engaged. If they are not meant to keep me constantly engaged, then I shouldn't be repeating/missing the behaviors that were learned when using the more addictive platforms. This means:

  • Browsing by all is a fundamental mistake. No sane person should be trying to drink from the firehose. It doesn't matter that the firehose is "small" compared to the larger networks. If this network is out of interesting content, then either go elsewhere (and maybe share what you find here) or just close the app and move on.
  • If a community/instance/person is not open to a healthy discussion, it's better to just block/mute/defederate and move on.
  • If I don't have "time/energy to comment", then just take a break and move on.

This is why you'll never see me commenting on stuff like politics/news. Not only I find these discussions boring beyond belief, I feel like they are completely pointless. These places serve only as a "two minutes hate" type of thing. No amount of voting/commenting/arguing will ever change anyone's minds.

[-] kux@lemm.ee 1 points 3 months ago

the illusion of privacy

i am from the post usenet and pre facebook internet generation (i hope that is vague enough) so using my real name on the internet or signing up for accounts with my real name email acount is strictly verboten by indoctrination, so my opinion may be out of date or invalid somehow, but i can not see how your lemmy account's up or down voting history violates privacy in any meaningful way

[-] Feathercrown@lemmy.world 7 points 3 months ago
[-] Redjard@lemmy.dbzer0.com 3 points 3 months ago

So the technical-skill-bar is transforming a lemmy link into the equivalent on an mbin instance? That is huge.

[-] mozz@mbin.grits.dev 6 points 3 months ago

It's not quite that simple. As far as I'm aware, it's difficult to fetch from another instance "after the fact" what all the votes are for a particular user or comment; you have to be signed up to receive updates on it, and then after the fact you can go hunting around in your own instance's DB and see what all the votes were (or your UI can do it, if it's supported).

But, yes, there are instance softwares that will do it, and no one's defederating from every one of those instances (nor I think should they). Someone posted a link to an mbin instance breaking down the votes for this post. Votes are not private.

[-] rglullis@communick.news 16 points 3 months ago

I ran curl "https://mbin.grits.dev/u/mozz/outbox?page=1" -H 'accept: application/activity+json' and I could see your outbox. Apparently mbin does not put Like/Dislike activities in there, only your comments/posts/notes.

In a world where ActivityPub is only used in server-to-server, this would be fine. If we ever get to a (IMNSHO, better) scenario where we have more clients talking AP directly, then this will not work, and mbin will have to add those as well.

All of this to say:

  • the debate about "what Lemmy devs are doing" vs "what mbin is doing" vs "what PieFed is doing" should be seen as tremendous conflict with the idea that "The good thing about the Fediverse is that we can all talk with each other, regardless of where we are".
  • There is no sane way to square this peg into a round hole. Privacy and "Social Media" are inherently incompatible. The advice about not putting anything online that you are not willing to ever be made public is evergreen, and anyone that does not follow it will eventually have to learn it the hard way.
[-] mozz@mbin.grits.dev 3 points 3 months ago

Apparently mbin does not put Like/Dislike activities in there

Yes. That's what I said. I'm actually not 100% sure about it; for all I know there's some way to get it, but AFAIK all the existing softwares don't publish votes "after the fact", only at the time to current subscribers. But then, of course, it's kind of a moot point because you can just grab it from any mbin instance's DB through the UI without needing to do anything special or any particular knowledge.

In a world where ActivityPub is only used in server-to-server, this would be fine. If we ever get to a (IMNSHO, better) scenario where we have more clients talking AP directly, then this will not work, and mbin will have to add those as well.

Not really. You can have your client talking to all the servers and grabbing votes for whatever you're subscribed to, and losing votes for anything you're not subscribed to. It works basically exactly that way for one-user instances already.

There is no sane way to square this peg into a round hole. Privacy and "Social Media" are inherently incompatible. The advice about not putting anything online that you are not willing to ever be made public is evergreen, and anyone that does not follow it will eventually have to learn it the hard way.

Tru dat. 100% agreed. It seems like there are all these people in this thread arguing that their votes need to be private. Their votes are not private, and will never be private, for as long as ActivityPub is what they're using. I can see some value, maybe, to making it slightly difficult to extract the information instead of just giving it for free to everyone, but holding onto the idea of your votes being private is a gateway to unhappiness and only unhappiness.

[-] rglullis@communick.news 2 points 3 months ago

You can have your client talking to all the servers and grabbing votes for whatever you’re subscribed to, and losing votes for anything you’re not subscribed to. It works basically exactly that way for one-user instances already.

It works like that for servers because servers are assumed to have high uptime, so (in theory) push-based communication should be enough. However, we see that this is not true even for servers (e.g, medium-sized instances getting out of sync with LW because they can not keep up with all the data being sent to them) and this will be specially true in the case of a network with tens/hundreds of thousands of separate clients. No server will be willing to push activities to all those inboxes, so we will need to have some pull-based form of communication as well.

[-] mozz@mbin.grits.dev 4 points 3 months ago* (last edited 3 months ago)

Oh, yeah, at that point it'll be a scalability clusterfuck. No idea what the solution is. Maybe something with persistent caches run by third parties or something? That actually would be fine, since all the actions are signed with the private key of the actor, I think.

ActivityPub is not to me a real great designed protocol but it's whatever. Usually the key part for social networks is the "social" part of it; the protocol or the web site can be pure shite and if people like interacting with the other people there then it's fine. But yes, you are correct that beyond a certain point of scalability there are some dragons lurking that don't have obvious weak spots.

[-] rglullis@communick.news 3 points 3 months ago* (last edited 3 months ago)

The problem is not with ActivityPub, but the implementations. No one ever claimed that it should be only a push-based system, but it seems that everyone working on AP software can only think in terms of server-to-server interactions to get the data and then reinvent the wheel by developing their ad-hoc API.

AP is fine if we treat it as a messaging protocol and use it to power offline-first applications. The devices do not need to have all the network's data, just the one that the user has actively interacted with.

[-] dandroid@sh.itjust.works 2 points 3 months ago

How do you know who you're defederating with? When I set up my instance, the list of federated instances was thousands. How do you know which one is scraping the data?

[-] intensely_human@lemm.ee 8 points 3 months ago

How is the data public? I’m asking in the most technical sense?

This informs an issue I’ve had lately with a group of three people or bots following along my comment chain (All my comments, for a while, were dropping consistently to -2 score in all contexts).

It’s my understanding that votes are not public. Am I wrong?

[-] rglullis@communick.news 21 points 3 months ago

Every comment/post/vote made in a community is sent as an activity to the community's subscribers.

[-] adam@doomscroll.n8e.dev 14 points 3 months ago

All votes are public, they're literally broadcast to the Fediverse writ large. You vote on something on your server, your server then tells the server owning the thing you voted on and that server then tells anyone who is interested (subscribers on other servers). That way everyone knows that this comment was voted on, but that information is indelibly tied to you - an entity on the Fediverse.

Lemmy devs just chose not to a) show that information in a UI (plenty of other software out there does) and b) not inform people that was the case. Which leads to the whole point of the thread, hiding this from users merely gives a false sense of security.

[-] systemglitch@lemmy.world 4 points 3 months ago

Your idea of a nice world and mine are very different.

[-] rglullis@communick.news 2 points 3 months ago

Yeah, I do my best to avoid cliched references, but this is 100% a "blue pill/red pill" dilemma. The majority of people seem to prefer to live a comfortable lie than face the harsh truth.

[-] Redjard@lemmy.dbzer0.com 1 points 3 months ago

Your world does not correspond to reality given that mbin already shows individual votes.

Head over to your comment on fedia.io and see who voted on your own comment.

Do you want to only vote on instances that defederate all mbin instances, and commit to keep doing so in the future?

[-] systemglitch@lemmy.world 3 points 3 months ago* (last edited 3 months ago)

Just because people can go out of their way to find this information, doesn't mean we should remove all restrictions. That's a real twisted way of thinking.

What we have in place is already egregious imo, and a major flaw with the system in place.

[-] Redjard@lemmy.dbzer0.com 3 points 3 months ago

That isn't really going out of your way, it is the base mode of how the fediverse works. Looking at something on a different instance.
Plenty of people just use mbin and see this, without any action at all.
The point is that as it stands right now, there are already basically no restrictions. The only thing perhaps missing is the knowledge that you can simply copy paste a link into fedia or another mbin instance to view upvotes.

You can open an issue on mbin about it, to restore a semblance of restriction. But currently as it stands, all restrictions are about as fallen as they could be.

You can ofc argue that we shouldn't open another equivalent hole in lemmys webui and api, so that you can in the future remove the ability from mbin.

I would in turn argue that this system has always been egregious, and that in the same sense as banning encryption you never hit those you want to hit using incomplete restrictions. Regular users are led to believe their votes are private, while the worst dataminers or trolls will always have their instances to query all of that info.
And how could you inform people that their votes are public without at the same time telling them how to get access to that info?

If mbin removes the info, you will get another fediverse software showing it. You will get fediverse activity pub log info pages, specific vote info pages, it will never end.
Has reddit ever managed to kill the 200ᵗʰ removeddit clone?

Please instead put your effort into changing the way lemmy federates, the only way to fix this is to make vote details private, between only a select few instances. An mbin dev in the other thread mentioned PeerTube as an example implementation where you could remove vote details like that.

[-] SteveFromMySpace@lemmy.blahaj.zone 3 points 3 months ago* (last edited 3 months ago)

They already can. This information is not locked away.

load more comments (48 replies)
load more comments (57 replies)
load more comments (83 replies)
this post was submitted on 18 Aug 2024
814 points (97.9% liked)

Fediverse

28493 readers
446 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 2 years ago
MODERATORS