31

Another dust-up with Dansup lol...

cross-posted from: https://lemmy.crimedad.work/post/903768

The author of the article characterizes their findings as a vulnerability in Pixelfed, that it was treating all follow requests as approved. An update has already been released to make Pixelfed honor that setting, but the vulnerability still exists with ActivityPub in the feature itself. It gives users a false expectation of privacy, which is not safe.

top 10 comments
sorted by: hot top controversial new old
[-] Rentlar@lemmy.ca 22 points 1 week ago

The Mastodon folk that have an expectation that publishing stuff on the Fediverse could be private, makes no sense to my silly little Lemmibrain.

That said it is a bug, it is worth being disclosed, it has been fixed, it wasn't a malicious omission as far as I can tell. So chill. Dan is doing his best. Awareness is fine but constantly needing to make everything about him drama is unnecessary imo.

[-] Irelephant@lemm.ee 6 points 1 week ago

They can be private, if the instances you're sending the post to co-operate. For example, all my followers on mastodon are on mastodon, sharkey, wafrn and gotosocial, these all comply and hide private posts, so if i set my posts to followers only, only they will get the post.

[-] PhilipTheBucket@ponder.cat 11 points 1 week ago

Lemmy DMs can be private, if all the people who have the ability to look at them all agree not to. That’s not how it works, so Lemmy does the right thing and warns you that they are not private.

Privacy systems that depend on broadcasting information and then requesting that everyone who isn’t supposed to receive it should not pay attention are fine, for some things, but they are not good privacy systems.

[-] Irelephant@lemm.ee 2 points 1 week ago* (last edited 1 day ago)

The same can be said about email, which is arguably private.

The privacy warning is because instance admins can see dms, not because random servers can.

[-] PhilipTheBucket@ponder.cat 8 points 1 week ago

Email is not private. I think we're running into a difference of definitions.

Stuff that random unauthorized people can read if they want to, even if the number of people is small, is not private. To me. Other people might have different definitions, but that's the one I am using when I say "private."

[-] Irelephant@lemm.ee 4 points 1 week ago

I agree, like you said in an earlier comment, they should be encrypted.

[-] CrimeDad@lemmy.crimedad.work 7 points 1 week ago

Maybe I misunderstood, but I thought the issue was with the follower approval feature. Apparently on Mastodon, users have the option to review all prospective followers. With this setting enabled, no one is supposed to be able to just follow your account with a click. You have to approve each one. Pixelfed wasn't honoring this setting. I think it's a bad feature that gives anyone who uses it a false sense of security.

[-] PhilipTheBucket@ponder.cat 7 points 1 week ago

While we're on the subject, all your votes on Lemmy are public, and Lemmy takes the same approach of "every software needs to agree to keep it a secret, and the ones that do not, don't count, and the information is private because I say it's supposed to be even if in practice it is not." This should be more widely known.

[-] CrimeDad@lemmy.crimedad.work 1 points 6 days ago

I didn't even consider that, but yes if votes can't be private then it's bad to pretend that they are. It looks like there's been some debate on the topic, but the decision was apparently to keep pretending.

[-] Irelephant@lemm.ee 2 points 1 week ago* (last edited 1 day ago)

Well, I was responding to the person who said private posts weren't possible.

AP is push based, meaning servers recieve posts, rather than servers pulling posts. When you make a post its sent to your followers inbox. If its public, anyone can see the post, it can be "boosted" into people's timelines and it can be fetched with the url of the post. If its followers only, it will be sent to your followers inboxs, but it cannot be boosted, and the url will fail for anyone not authenticated.

The followers thing seems to be that the post was sent to pixelfed.social, but it wasn't made private. If I have no followers on pixelfed, and I don't let anyone on pixelfed view my posts, then pixelfed.social will have no record of my post, and thus it cannot expose it.

Consider email, a faulty, negliegent or malicious server could start publicly exposing emails, but if you don't send to emails to that server, the server cannot expose them.

this post was submitted on 26 Mar 2025
31 points (97.0% liked)

FediLore + Fedidrama

2159 readers
23 users here now

Rules

  1. Any drama must be posted as an observer, you cannot post drama that you are involved with.
  2. When posting screenshots of drama, you must obscure the identity of all the participants.
  3. The poster must have a credible post and comment history before submitting a piece of history. This is to avoid sock-puppetry and witch hunts.

The usual instance-wide rules also apply.


Chronicle the life and tale of the fediverse (+ matrix)

Largely a sublemmy about capturing drama, from fediverse spanning drama to just lemmy drama.

Includes lore like how a instance got it's name, how an instance got defederated, how an admin got doxxed, fedihistory etc

(New) This sub's intentions is to an archive/newspaper, as in preferably don't get into fights with each other or the ppl featured in the drama

Tags: fediverse news, lemmy news, lemmyverse

Partners:

founded 2 years ago
MODERATORS