404
submitted 2 months ago by rimu@piefed.social to c/fediverse@lemmy.world

We had a really interesting discussion yesterday about voting on Lemmy/PieFed/Mbin and whether they should be private or not, whether they are already public and to what degree, if another way was possible. There was a widely held belief that votes should be private yet it was repeatedly pointed out that a quick visit to an Mbin instance was enough to see all the upvotes and that Lemmy admins already have a quick and easy UI for upvotes and downvotes (with predictable results ). Some thought that using ActivityPub automatically means any privacy is impossible (spoiler: it doesn't).

As a response, I’m trying this out: PieFed accounts now have two profiles within them - one used for posting content and another (with no name, profile photo or bio, etc) for voting. PieFed federates content using the main profile most of the time but when sending votes to Mbin and Lemmy it uses the anonymous profile. The anonymous profile cannot be associated with its controlling account by anyone other than your PieFed instance admin(s). There is one and only one anonymous profile per account so it will still be possible to analyze voting patterns for abuse or manipulation.

ActivityPub geeks: the anonymous profile is a separate Actor with a different url. The Activity for the vote has its “actor” field set to the anonymous Actor url instead of the main Actor. PieFed provides all the usual url endpoints, WebFinger, etc for both actors but only provides user-provided PII for the main one.

That’s all it is. Pretty simple, really.

To enable the anonymous profile, go to https://piefed.social/user/settings and tick the ‘Vote privately’ checkbox. If you make a new account now it will have this ticked already.

This will be a bit controversial, for some. I’ll be listening to your feedback and here to answer any questions. Remember this is just an experiment which could be removed if it turns out to make things worse rather than better. I've done my best to think through the implications and side-effects but there could be things I missed. Let's see how it goes.

you are viewing a single comment's thread
view the rest of the comments
[-] ada@lemmy.blahaj.zone 16 points 2 months ago* (last edited 2 months ago)

I use people upvoting bigoted and transphobic content to help locate other bigoted and transphobic accounts so I can instance ban them before they post hate in to our communities.

This takes away a tool that can help protect vulnerable communities, whilst doing nothing to protect them.

It's a step backwards

[-] smeg@feddit.uk 29 points 2 months ago

whilst doing nothing to protect them

Well it also takes away a tool that harassers can use for their harassing of individuals, right? This does highlight the often-requested issue of Lemmy needs better/more moderation tools though.

[-] maegul@lemmy.ml 10 points 2 months ago

If public voting data becomes a thing across the threadiverse, as some lemmy people want.

Which is why I think the appropriate balance is private votes visible to admins/mods.

[-] doctortran@lemm.ee 14 points 2 months ago* (last edited 2 months ago)

Admins only. Letting mods see it just invites them to share it on a discord channel or some shit. The point is the number of people that can actually see the votes needs to be very small and trusted, and preferably tied to a internal standard for when those things need acted upon.

The inherent issue is public votes allow countless methods of interpreting that information, which can be acted on with impunity by bad actors of all kinds, from outside and within. Either by harassment or undue bans. It's especially bad for the instances that fuck with vote counts. Both are problems.

[-] maegul@lemmy.ml 2 points 2 months ago

I can see this argument, at least in general. As for community mods, I feel like it'd be generally fruitful and useful for them to be and feel empowered to create their own spaces. While I totally hear your argument about the size of the "mod" layer being too large to be trustworthy, I feel like some other mitigating mechanisms might be helpful. Maybe the idea of a "senior" mod, of which any community can only have one? Maybe "earning" seniority through being on the platform for a long time or something, not sure. But generally, I think enabling mods to moderate effectively is a generally good idea.

[-] rimu@piefed.social 16 points 2 months ago

I'm going to have to come up with set criteria for when to de-anonomize, aren't I. Dammit.

In the meantime, get in touch if you spot any bigot upvotes coming from PieFed.social and we'll sort something out.

[-] ada@lemmy.blahaj.zone 6 points 2 months ago

The problem is, it's more than just the upvote. I don't ban people for a single upvote, even on something bigoted, because it could be a misclick. What I normally do is have a look at the profiles of people who upvote dogwhistle transphobia, stuff that many cis admins wouldn't always recognise. And those upvotes point me at people's profiles, and if their profile is full of dog whistles, then they get pre-emptively instance banned.

[-] rimu@piefed.social 11 points 2 months ago

Ahh, right, got it.

Let's keep an eye on this. I am hopeful that with PieFed being unusually strong on moderation in other respects that we don't harbor many people like that for long.

[-] Blaze@sopuli.xyz 3 points 2 months ago
[-] Socsa@sh.itjust.works 3 points 2 months ago

So you can still ban the voting agent. Worst case scenario you have to wait for a single rule breaking comment to ban the user. That seems like a small price to pay for a massive privacy enhancement.

[-] Socsa@sh.itjust.works 3 points 2 months ago

I don't think you do. Admins can just ban the voting agent for bad voting behavior and the user for bad posting behavior. All of this conflict is imagined.

[-] maegul@lemmy.ml 6 points 2 months ago

Yea, which is why I think the obvious solution to the whole vote visibility question is to have private votes that are visible to admins and mods for moderation purposes. It seems like the right balance.

[-] rimu@piefed.social 9 points 2 months ago

It will be difficult to get the devs of Lemmy, Mbin, Sublinks, FutureProject, SomeOtherProject, etc to all agree to show and hide according to similar criteria. Different projects will make different decisions based on their values and priorities.

[-] amju_wolf@pawb.social 4 points 2 months ago

...and it still doesn't solve the issue that literally anyone can run their own instance and just capture the data.

[-] fuzzzerd@programming.dev 3 points 2 months ago

The OP discusses exactly a solution to the anyone setting up an instance to capture the data, because the users home instance federates their votes anonymously.

There maybe flaws in it, not that's exactly what it aims to solve.

[-] Max_P@lemmy.max-p.me -1 points 2 months ago

Plus, if you know your votes are public, maybe it'll incentivise some people to maybe skip upvoting that kind of content. People use anonymity to say and promote absolute vile things that would never dare say or support openly otherwise.

this post was submitted on 19 Aug 2024
404 points (97.9% liked)

Fediverse

28381 readers
158 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 1 year ago
MODERATORS