this post was submitted on 07 Jul 2023
82 points (96.6% liked)
Technology
69947 readers
3064 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Is this really a big deal though? Most of the data they'll have is publicly available data from other federated instances. The few users that are local might have some data on the server, but that's literally just login details and maybe an email address or Matrix user ID.
Meanwhile, Meta and Twitter try to scrape every bit of info they can from you, from all across the web.
Edit: after actually reading the article I see it includes DM content as well. This could maybe be an issue, but again if you want privacy you shouldn't be communicating on that platform.
DMs, emails, logins, and IPs, which they can use to pinpoint individual users
It's really only the DMs that have some level of concern. IPs and email addresses might give the FBI a lead, however only if you aren't covering yourself properly. Eg one of the darkweb marketplaces sent a welcome email to new users with a reply to email for the admin's personal gmail - this was used to identify him as he used the same email on LinkedIn.
What happened here isn't great, but with federated social media it should be immediately obvious that things are not private nor massively secure, and users should take that in account when registering for and using the service. This article doesn't prove any new faults with federated services that weren't already a given.
Yeah I haven't used dms here but mastodon at least makes it pretty clear that it isn't encrypted. If you want something secure use matrix or something like that.