Live data from Hacker News

Private and Public Mastodon

tbray.org

161–170 of 191 posts

Re: Private and Public Mastodon

#161
post #155

Only architecture astronauts care about the fediverse, and by extension how search works on Mastodon. Normal people just wanted a Twitter clone when Twitter started to feel icky or doomed. It doesn’t speak to the platform’s long term growth if basic functionality like this is controversial, especially if it leads to fragmentation. There’s obviously some value to conservatism here - I suspect for most people, Twitter…

Mastodon isn't a public company or a VC-funded startup. It doesn't need perpetual user growth, nor, I suspect, do many of its current users or developers particularly want that. At most it just needs a critical mass of people who are interested in what it has to offer so that it doesn't die as a project/community. I don't use Mastodon (or Twitter) but it seems to me like Mastodon was never really intended to be a pur…

I don't use Twitter or Mastodon either, I'm happy spewing my terrible opinions here. But for those that remain, you're absolutely right it needs that critical mass of high quality content (for myriad definitions of quality), positive interactions, and reach. I'm just saying that from a purely utilitarian point of view, the sum total of disappointment will be higher for users if Mastodon's momentum disappears, compared to that of people who have ideological objections to Mastodon having a functional search engine. If nobody cares about that, well, then welcome to the fediverse I guess.

Re: Private and Public Mastodon

#162
post #83

Earlier quoted context omitted.

> there are good reasons to use them What is one of them?

The medium is better for expressing thoughts (you can write a decent-sized blog post in a single Mastodon post). It has most of the effective bits of Twitter, and many of the effective bits of the peak, RSS-soaked blogosphere. If the tooling gets better, I can see it being better than the golden age of Google Reader. It also makes sense that you can stand up your own Mastodon, in the same sense as you could stand up…

> and the notion of a single "decentralized social network" is not.

I've been running my own Pleroma instance for a month or so and I'm firmly of the opinion that a single network is actually a Bad Idea. The fact that ActivityPub is federated means that it's also prone to abuse from other nodes similar to email spam, which is just about as simple to execute in the fediverse right now as rolling a new domain name. Small-time casual admins like myself won't be able to keep up with a global abuse firehose which hasn't really happened yet to my knowledge but will sooner or later.

The solution in my mind (and what I've already done) is to use a node whitelist instead of relying on blacklisting, which means smaller networks based foremost on interpersonal trust. Which means a constellation of much smaller but also stronger social networks that reflect actual communities as opposed to just the internet at large. This is super easy to do with ActivityPub servers and my prediction is this is the way forward although I expect people will also try to write clever abuse filters and fall into that perpetual cat-and-mouse game since that's what happened with email.

Re: Private and Public Mastodon

#163
post #129
post #93

Earlier quoted context omitted.

Yes: there are reasons ordinary users might prefer Mastodon to Twitter; as I said: * You can write full posts in Mastodon * You can own your own data, run your own service, or select from a variety of hosted options * The ecosystem encourages good third-party clients and tooling The tooling isn't there, but then, I don't think anybody expected the events of the last few months, so I'm inclined to give it a quarter or…

What about the inherent bubble-y nature of Mastodon? Do you see it as beneficial to have a series of large groups of balkanized servers optionally interconnected rather than a general public network everyone contributes to. I hate the label of "public square", because Twitter should already be opt-in in terms of which content you see based on who you follow, even though it's one big network (ignoring the @jack era AI…

> A key difference in Twitter vs Mastodon UX is that users would have to make different accounts for each "Balkan country" server they join.

Sure, but this is functionally no different from the days of forums when you'd have an account on many different forums to discuss the topics of interest to those forums. Just like forums, they may all be running the same two or three codebases, but the communities are different. The cool new thing federation adds on top of this is that communities can organically merge and split while retaining a basic level of cohesion.

And since they're all running the same protocol, it's straightforward for clients like Fedilab to make multi-account use easy.

Re: Private and Public Mastodon

#164

> People should be able to converse without their every word landing on a permanent global un-erasable indexed public record. Call me crazy. Sure, and they should use Signal instead of publishing their conversations and then getting mad when they turn out to be publicly available.

I think the future of social actually looks more like Signal and Whatsapp groups (maybe Discord too?) than it does Twitter and Facebook. People seem to appreciate and value private discussion more than they used to.

I certainly spend more time interacting with people in small group chats than I do on Facebook now.

Re: Private and Public Mastodon

#165
post #61

I don't trust any "private" settings in any public social networks, for anything remotely serious. Anything I publish on any social network I'd be also comfortable seeing posted on every wall in foot-tall letters, with my real name attached to it. Were I not be comfortable with that, I won't post it. I consider all "private" or "limited" posting provisions on all social networks as paper walls at best, one small devo…

> Anything I publish on any social network I'd be also comfortable seeing posted on every wall in foot-tall letters, with my real name attached to it.

You misunderstand. It's layered defense / minimizing exposure. Nobody is suggesting it can't be done, but it not going to be normalized in the current Fediverse, and most potential attackers do not care enough to build throw own search engine.

The main reason is quite clearly stated in the article, and I'm not sure if you didn't see it or just don't care because you're not affected.

> And, if you’re vulnerable, attack you, shame you, doxx you, SWAT you, try to kill you.

A lot of people that are being targeted by the likes of KF or Libs of Tik Tok find nice comfortable corners on the Fedivserse because they're not immediately discoverable by someone typing their name into Google.

Re: Private and Public Mastodon

#166
post #140

Earlier quoted context omitted.

When you speak in public, anyone can hear you. What specifically do you feel is different?

If you say embarassing shit or shout obscenities in public then don't be surprised if someone pulls out their phone and starts recording it. It's completely different if someone sneaks into your home and leaves microphones there.

Yes — and we’re asking about the case of a quiet conversation in a bar, where someone surreptitiously records using specialize equipment.

I think it’s very telling you made a strawman rather than respond to that point.

Re: Private and Public Mastodon

#167
> A server should deliver posts only to people logged into the instance, or to other instances it is federated with.

This feels like maybe not an unreasonable _default_, but I certainly don't think it should be mandatory. If a user wants to publish something on the internet, it's reasonable for them to be able to do that.

Re: Private and Public Mastodon

#168

Earlier quoted context omitted.

No — I’m tired of saying all of society needs to walk on eggshells due to anti-social people like OP. If you go around a bar with a tape recorder and directional microphone capturing conversations from unsuspecting people and then use those private moments to launch protracted harassment campaigns, you’re an asshole. No matter how much you say “they didn’t have an expectation of privacy!”

Posting on Twitter or Mastodon is the equivalent of shouting on a public street. If you don't want to face the consequences of what you say, don't say it publicly (or at least don't do it with your real name).

No — the expectation was never that people would creepily record every corner of the public sphere.

That’s anti-social behavior and it’s okay to call it such.

Re: Private and Public Mastodon

#169
post #165
post #61

I don't trust any "private" settings in any public social networks, for anything remotely serious. Anything I publish on any social network I'd be also comfortable seeing posted on every wall in foot-tall letters, with my real name attached to it. Were I not be comfortable with that, I won't post it. I consider all "private" or "limited" posting provisions on all social networks as paper walls at best, one small devo…

> Anything I publish on any social network I'd be also comfortable seeing posted on every wall in foot-tall letters, with my real name attached to it. You misunderstand. It's layered defense / minimizing exposure. Nobody is suggesting it can't be done, but it not going to be normalized in the current Fediverse, and most potential attackers do not care enough to build throw own search engine. The main reason is quite…

Sorry, I do understand. I think that the particular fortress of highly private communication on a network designed for publishing and dissemination cannot be defended efficiently. I'd be glad to be proven wrong, but my last 25 years of experience with social networks of all sorts, from early IRC and web chats to what we have today tells me to keep my current security stance. Anything on a social network has a very high chance of a public exposure, one way or another.

For the defense in depth / layered defense to work, the initial assumptions should be different. They should be like Signal's, not like Mastodon's. The whole approach should be paranoid about not letting things seep through by any chance at all. I don't think that such an approach would be seen as productive by most users and developers. So, I view various access control settings in networks like Mastodon as a convenience filter, not as a security mechanism.

> not immediately discoverable

This is actually both important and achievable! If you never post your public identity, and things which easily link you to your public identity, it's pretty hard to doxx you and harass you IRL, even if everything you publish were publicly accessible. If you don't advertise your presence where everybody is looking, you have a good chance of not being harassed online, because the harassers won't try hard enough to infiltrate remote corners of the internet.

A reliable pseudonymous identity is a great mechanism, if you maintain reasonable opsec. I just won't expect a great level of insulation of your content from fellow pseudonymous users, and occasionally even from general public.

Re: Private and Public Mastodon

#170
post #61

I don't trust any "private" settings in any public social networks, for anything remotely serious. Anything I publish on any social network I'd be also comfortable seeing posted on every wall in foot-tall letters, with my real name attached to it. Were I not be comfortable with that, I won't post it. I consider all "private" or "limited" posting provisions on all social networks as paper walls at best, one small devo…

Yes. I would even argue that Privacy expectations should be much weaker than for the big centralized platforms.

Mastodon's instances admins have blanket read access to every post and message, even the "private ones", yet they are not under scrutiny of RGPD regulators like for example Twitter. Are you sure those admins take good security measures, like storing backups encrypted, keeping their tech stack minimal and up to date, using safe configs? Do you trust them for not reading and sharing your conversations?

Regarding the Fediverse search, it's even worse as you're supposed to trust the rest of the world for not abusing it and indexing the entire network. Well, that's not how things works. With this kind of large scale systems you should know that if there is the possibility of an event, that event will happen very soon if not already. Either you impose restrictions or you accept the tradeoffs.

Post reply on HN