Live data from Hacker News

Blocking Threads won't be enough to protect privacy once they join the Fediverse

privacy.thenexus.today

81–90 of 458 posts

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#81

Hunting down your personal details and publishing them is a crime¹, isn't it? 1 - I mean on the US where Meta really cares about. It's probably one on most countries where Meta has revenue, but that won't send anybody to jail.

The story is almost certainly untrue or a misunderstanding. Facebook has no reason to scrape individuals personal information and then forcefully update their Facebook profile. There are various processes at Meta that do require identification to be submitted and in some cases that information will be published. For example, to be verified on Instagram you must have your name be published. Likewise, certain Facebook…

> Facebook has no reason to scrape individuals personal information and then forcefully update their Facebook profile.

Collecting personal information is central to Facebook's business model. Facebook's policies mandate legal names.

> Most likely the person in question submitted their identity documents to Facebook

Most likely this person would remember that.

> The concern is valid — Facebook has information users might not want public — but the cause isn’t nefarious.

Surveillance capitalism and legal names policies are nefarious.

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#82

Earlier quoted context omitted.

> when they eventually add ActivityPub support What does that have to do with anything? Mastodon is explicitly setup to allow all user data to be harvested. What Threads supports or doesn't support in the end has no bearing on Mastodon having all user data public.

Just like digital entertainment is set up to allow all movies and music to be downloaded for free! If you don't like it, just don't make movies or music.

This, but unironically. If you are uncomfortable with the idea of a zero-marginal-utility medium distributing your content without your consent, you probably shouldn't make and share digital copies of your work.

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#83
post #49

If you have personal information you do not wish bad actors to see, do not publish it using an open protocol explicitly designed to allow anyone to read said information. Defederating from Meta as a solution is stupid - Meta can (and will if they actually care enough) just rejoin undercover. Furthermore, when it comes to the fediverse, Meta is actually one of the more trusted actors compared to whatever else is on th…

I think the point they're making is that Meta is in a special place, where by using their unusually vast amounts of personal data and photos, they are somehow (?) going to dox anonymous users by publishing their real names, based on matching their profiles in some way. At least that is the implication based on the quoted tweet right at the top of the post (which is lacking any real detail how exactly Meta got this pe…

The only entity that could realistically tell us how Meta linked the profile to that person's real name is Meta, and they aren't likely to share that information — so it's not exactly surprising that the tweet lacks detail on the matter.

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#84

https://news.yahoo.com/teen-mom-plead-guilty-abortion-230802... >A Nebraska woman has pleaded guilty to helping her daughter have a medication abortion last year. The legal proceeding against her hinged on Facebook's decision to provide authorities with private messages between that mother and her 17-year-old daughter discussing the latter's plans to terminate her pregnancy. If you have information you don't want oth…

If you have secrets at all, don't send them through any ActivityPub conversation. People on Mastodon make this mistake quite often, tagging someone they're talking about, or realising that the person they tagged now receives a copy of their conversation. This is a massive issue on top of the lack of end to end encryption. Both servers receive plaintext copies of the messages exchanged. I'm sure mastohub.ai is a safe…

That's true -- and my more detailed threat modeling post has a big public service announcement saying "don't share information on the fediverse that you want to keep secret" -- but there's a lot of information that's not "secret" that people do want to share on social networks.

https://privacy.thenexus.today/fediverse-threat-modeling-pri...

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#85

Earlier quoted context omitted.

The EU digital markets act will require "gatekeepers" like meta to provide some form of interoperability or open access. Supporting activitypub would be a way to satisfy that requirement.

But Mastodon can't possibly comply with GDPR the way it is organized. I mean Heavens you can use it without clicking on a cookie popup, they probably owe $70 billion dollars just for all the people who haven't seen a cookie popup already.

It doesn’t need a cookie popup because they aren’t using cookies for non-essential reasons, similar to how it complies with GDPR because they aren’t collecting any data beyond what is necessary for the service’s stated purpose.

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#87
post #46

Earlier quoted context omitted.

Because almost none of that is actually required if you are not collecting data outside of the actual usage of the application.

People are documenting their own personal lives without any protections. You can delete your account and the system will circulate a polite notification that other servers should delete that information. If you are a "sexworker" (sic) and you doxx yourself tough luck. If you reveal your mental illness through the things you write about and the language patterns you use tough luck. (Pro tip: machine learning algorithm…

What does any of what you just said have to do with GDPR requirements?

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#88

Earlier quoted context omitted.

They're not unhappy about their data being intentionally republishable. C'mon. On the contrary, they are saying that when the product gets successful, they will pull the rug. Like facebook did before, and like twitter did with the API and now again.

Even if this happens it won't make any difference to how these instances operate, will it? It'll just reduce traffic to them, right?

In the same sense that Google didn't largely kill off the RSS ecosystem with Google Reader and Microsoft didn't stagnate the browser ecosystem for a decade with Internet Explorer, sure.

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#89

>Mastodon (and most other fediverse software) wasn't designed with privacy and user safety in mind this is the real problem. Mastodon and lemmy share way more information than they actually need to (like lemmy shares a list of usernames who upvoted or downvoted a post, not just a count), and if you're using one of those services you should expect that all your data and interactions are public. that's the actual threa…

To be clear, Twitter also shares the list of users who like a post, and people generally seem to view this as a good feature rather than an invasive one, so it makes sense that Mastodon implemented it as well.

Re: Blocking Threads won't be enough to protect privacy once they join the Fediverse

#90
post #50

This reminds me of the "embrace, extend, extinguish" strategies Microsoft used extensively with Linux and open source software in the 90s. From [1]: "a phrase that the U.S. Department of Justice found that was used internally by Microsoft to describe its strategy for entering product categories involving widely used standards, extending those standards with proprietary capabilities, and then using those differences i…

There's a lot of discussion about that! Here's a very good article on the EEE threat. https://ploum.net/2023-06-23-how-to-kill-decentralised-netwo...

Personally I think it's more an "embrace, extend, and exploit" approach; a decentralized model could work well for Meta, for example if they do revenue-sharing on ads hosted by other instances (think Disney or LA Lakers).

Update: here's another good article looking at how Meta could embrace and extend -- again, not extinguish. https://darnell.day/heavy-meta-four-business-reasons-why-ins...

Post reply on HN