Live data from Hacker News

Mastodon: Add end-to-end encryption API

github.com

91–100 of 188 posts

Re: Mastodon: Add end-to-end encryption API

#91
post #73

Earlier quoted context omitted.

> There was a block-list circulating around, and if you do not block every instance on the list, your instance is misogynist, pedophile and far-right. I must have missed the memo, because I run a medium-sized instance, don't follow any blocklist, and no one ever complained about it.

Are you blocking instances, and on what conditions? I wonder how often you get complaints about wanting an instance blocked, and how you manage them.

> Are you blocking instances, and on what conditions?

I block instances when they either flood or I find I don't want to have anything to do with them (I do tolerate opinions I disagree with, of course; but not patent bigotry).

And only based on evidence I gather myself, I don't trust screenshots or copy-pastes (but I understand some mod teams do, and that's ok if that's what their users want).

> I wonder how often you get complaints about wanting an instance blocked, and how you manage them.

As I said, I never got complaints. I also never got instance requests personnally; although I do sometimes see other instance admins saying they blocked a given instance. When it happens, I take a look at that instance's public pages. Usually, that's enough to make my mind, eg. because their public timeline is overrun by literal nazis and/or lolicon.

(I was looking for examples as I was writing this, and it turns out most of the nazi instances I blocked don't exist anymore. Oh well.)

The hardest part is dealing with big instances with many "well-behaved" users, but also a very lax moderation policy that tolerates trolls. So far I only banned individual trolls in this case, but it requires work, and I understand not all moderators want to spend so much time.

Re: Mastodon: Add end-to-end encryption API

#92

Earlier quoted context omitted.

Then I move instance (probably well before my instance is declared not safe, tbh). It's a feature in Mastodon, assuming my moderation team hasn't decided to disable it - basically, I send a protocol message to my followers saying "I'm over here" and they automatically follow me over there. In a future p2p protocol that's designed by people who actually realise that people exist who don't want everyone on the internet…

I had no idea account migration landed. Your description actually sounds quite reasonable. I guess I was too shocked and burnt by the instance blocking incident. Maybe I should give Mastodon another try. Just need to find an instance that doesn't block...

Finding an instance that doesn't block other instances, but also actually moderates its users and thus doesn't get blocked, is going to be pretty hard - and also a rather harassment-filled experience unless you fit in with the Gab crowd, I imagine. You could always run your own instance.

Note that the majority of instances that are "blocked" are actually soft-blocked by most instances, meaning you can still talk to people on them if you follow them, you're just not going to find posts from their users otherwise.

Re: Mastodon: Add end-to-end encryption API

#93
post #84

Earlier quoted context omitted.

That's simply untrue, speaking as the admin of a smaller instance. There are blocklists but they are entirely up to yourself to implement. I myself only implement rules to completely block far-right instances or "free speech" instances, those tend to cover almost 99% of content that would be frankly illegal for me to federate. The rest is a few japanese and sex-positive instances, which are only media-blocked, so the…

Sounds reasonable. It just feel very weird to me that the word "fediverse" is thrown around like a universe, except it is a balance of not getting thrown out by not being the norm. Perhaps it is just me that has this fantasy of everyone being in one place, at least on the Internet, but jerks are jerks. String phone in one hand, scissors in another.

The Fediverse is simply a term for all of the instances. It's not entirely fragmented, there is certainly shared hosts between bubbles in the fediverse. Though I don't think this is an issue really; our own universe functions on the bubble principle as well and it makes fediverse a place that you can find an instance to be on without having to worry that your instance moderator will allow nazis to vent their garbage into your feed.

Re: Mastodon: Add end-to-end encryption API

#94
post #71
post #58

Earlier quoted context omitted.

The idea of preemptive banning of federating with other instances is extremely common in Mastodon-land. This means that unilateral actions by admins, invisible to their userbase, restrict what their users can read, or who can read their users. It would be fine if the users opted into this, but it happens silently and arbitrarily by admins, oftentimes based on speculation or gossip, not even real abuse. It’s all of th…

Why does anyone have a requirement to talk to your instance? What if, due to your ideological stance on issues, I don't trust that your server won't decide that mine is distasteful in some way, and that you'd cause your server to disrupt mine in some way by flooding it with messages, for instance? I have legitimately had this happen and it nearly brought down my instance. Some script-kiddie decided to fuck around and…

> Why does it matter if any instance decides they don't want to associate with you? It doesn't affect your ability to use the service beyond not being able to interact with folks who probably don't want to talk to you anyway.

It prevents people on that instance who explicitly want to follow me from doing so.

It also prevents me from following people on that server from my primary account on my homeserver, even if those people explicitly want the whole world to be able to read their public messages.

Both of those are undesirable interference between mutually-desired communication by Alice and Bob, by Mallory.

Re: Mastodon: Add end-to-end encryption API

#95
post #88
post #79

>An additional layer on top of it is so-called message franking, which allows encrypted messages to be reported to content moderators without compromising keys or message contents ahead of time while also preventing fake reports. That sounds like the encryption isn't deniable. Personally I would prefer deniable encryption to ability to report wrongthink.

What about spam and legitimate abuse? Do you think these things should be allowed to run rampant just because you believe that an admin's decision to not communicate with you is that terrible?

>What about spam and legitimate abuse?

You can block the spammer yourself. I'm not sure if the feature is about only private communication between two users or in channel, but if it's in channel, there can be bot logging messages. That way the bot's owner still knows who posted what and can ban/moderate as needed.

>Do you think these things should be allowed to run rampant just because you believe that an admin's decision to not communicate with you is that terrible?

I have no idea what are you talking about. Are you reacting to what I wrote or to your own projections about my beliefs?

Re: Mastodon: Add end-to-end encryption API

#96
post #86
post #58

Earlier quoted context omitted.

The idea of preemptive banning of federating with other instances is extremely common in Mastodon-land. This means that unilateral actions by admins, invisible to their userbase, restrict what their users can read, or who can read their users. It would be fine if the users opted into this, but it happens silently and arbitrarily by admins, oftentimes based on speculation or gossip, not even real abuse. It’s all of th…

You can't force user's eyeballs to read the bytes you ship to their computers unless you want to go full Clockwork Orange. Some people want to exercise the rights over their computers (pick any ideology, FOSS included) and don't want certain bytes shipped to their computers. Who cares the reason. Some people don't have the time, energy, money, and technical experience to exercise their rights of byte-shipping in a co…

It isn't contradictory or incompatible to say that people shouldn't be forced to do anything, and also simultaneously believe that censorship, especially the silent or invisible kind, is bad.

Would a web host performing MITM on an HTTP connection to alter or redact your blog posts be bad? After all, it's their hardware...

Re: Mastodon: Add end-to-end encryption API

#97
post #95
post #88

Earlier quoted context omitted.

What about spam and legitimate abuse? Do you think these things should be allowed to run rampant just because you believe that an admin's decision to not communicate with you is that terrible?

> What about spam and legitimate abuse? You can block the spammer yourself. I'm not sure if the feature is about only private communication between two users or in channel, but if it's in channel, there can be bot logging messages. That way the bot's owner still knows who posted what and can ban/moderate as needed. > Do you think these things should be allowed to run rampant just because you believe that an admin's d…

If the spammer spams thousands of people, it's a better use of everyone's time if an admin bans it once and for all.

Re: Mastodon: Add end-to-end encryption API

#98
This work-in-progress feature is meant to replace the current DM system. The Olm library is being used in production by Matrix, although I believe app developers could use the libsignal library in their apps all the same. Please mind that neither Olm nor libsignal are actually included in the PR or used server-side in any way. The API is just key exchange and passing encrypted blobs.

Message franking is a technique used by Facebook in their own E2EE chats that allows them to trust user reports about E2EE messages, otherwise someone could claim they received something abusive and there would be no way to know it's true. Believe it or not, "just block the sender" is not a sufficient solution because while it works for the individual, when a spammer is allowed to run rampant and thousands of users receive spam messages from different spammers regularly it brings the quality of user experience for the whole platform down significantly.

Re: Mastodon: Add end-to-end encryption API

#99
post #89

Earlier quoted context omitted.

Yes, I forgot about this feature (is this opt-in or default on by the instance owner?) This addresses my last point. But admins can still choose to block instances in the future that I might have interest interacting with. It is like a gamble choosing an instance. Making an instance is tedious, and once someone in charge finds out who you hangout with, your domain name gets blocked. Such is socializing.

> But admins can still choose to block instances in the future that I might have interest interacting with. It is like a gamble choosing an instance. Then have multiple accounts and abide by each instances' rules. > Making an instance is tedious, and once someone in charge finds out who you hangout with, your domain name gets blocked. Such is socializing. You can still hang out with the folks you were hanging out wit…

Please don't put words in my mouth, personally I don't have anything worthy of being heard.

I really wanted Mastodon to be where I can find everyone. To be free of censorship, ads and algorithm-induced bubbles. I am lucky to have the "right" mentality (in regard to the tech industry), so I am not often suppressed, but everyone is different.

I don't want to impose on someone a "correct, healthy community". Blocking an instance seems to do so.

Re: Mastodon: Add end-to-end encryption API

#100
post #96
post #86

Earlier quoted context omitted.

You can't force user's eyeballs to read the bytes you ship to their computers unless you want to go full Clockwork Orange. Some people want to exercise the rights over their computers (pick any ideology, FOSS included) and don't want certain bytes shipped to their computers. Who cares the reason. Some people don't have the time, energy, money, and technical experience to exercise their rights of byte-shipping in a co…

It isn't contradictory or incompatible to say that people shouldn't be forced to do anything, and also simultaneously believe that censorship, especially the silent or invisible kind, is bad. Would a web host performing MITM on an HTTP connection to alter or redact your blog posts be bad? After all, it's their hardware...

[deleted]
Post reply on HN