this post was submitted on 19 Aug 2024
410 points (100.0% liked)

Fediverse

33337 readers
400 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to [email protected]!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)

founded 2 years ago
MODERATORS
 

We had a really interesting discussion yesterday about voting on Lemmy/PieFed/Mbin and whether they should be private or not, whether they are already public and to what degree, if another way was possible. There was a widely held belief that votes should be private yet it was repeatedly pointed out that a quick visit to an Mbin instance was enough to see all the upvotes and that Lemmy admins already have a quick and easy UI for upvotes and downvotes (with predictable results ). Some thought that using ActivityPub automatically means any privacy is impossible (spoiler: it doesn't).

As a response, I’m trying this out: PieFed accounts now have two profiles within them - one used for posting content and another (with no name, profile photo or bio, etc) for voting. PieFed federates content using the main profile most of the time but when sending votes to Mbin and Lemmy it uses the anonymous profile. The anonymous profile cannot be associated with its controlling account by anyone other than your PieFed instance admin(s). There is one and only one anonymous profile per account so it will still be possible to analyze voting patterns for abuse or manipulation.

ActivityPub geeks: the anonymous profile is a separate Actor with a different url. The Activity for the vote has its “actor” field set to the anonymous Actor url instead of the main Actor. PieFed provides all the usual url endpoints, WebFinger, etc for both actors but only provides user-provided PII for the main one.

That’s all it is. Pretty simple, really.

To enable the anonymous profile, go to https://piefed.social/user/settings and tick the ‘Vote privately’ checkbox. If you make a new account now it will have this ticked already.

This will be a bit controversial, for some. I’ll be listening to your feedback and here to answer any questions. Remember this is just an experiment which could be removed if it turns out to make things worse rather than better. I've done my best to think through the implications and side-effects but there could be things I missed. Let's see how it goes.

(page 2) 50 comments
sorted by: hot top controversial new old
[–] [email protected] 7 points 8 months ago (3 children)

How does this work with moderation? I.e. what happens if I ban the real user from a Lemmy instance? What if I ban the alternate user?

Also, what happens if on Piefed, a user votes for something, then they change the setting and then they vote for the same thing again? How would a Lemmy instance know if it should count the vote or not, since the original user didn't actually vote from Lemmy's point of view?

load more comments (3 replies)
[–] [email protected] 6 points 8 months ago

Interesting solution 👍 Curious to see how this plays out!

[–] [email protected] 6 points 8 months ago* (last edited 8 months ago) (6 children)

This is excellent.

I'm curious about piefed now. Is it free of any explicit agenda?

load more comments (6 replies)
[–] [email protected] 5 points 8 months ago
[–] [email protected] 4 points 8 months ago (1 children)

Is it possible to double vote this way (once on each account)? On second thought, would it even matter? A malicious actor could have multiple accounts.

[–] [email protected] 6 points 8 months ago

No, the other account isn't something you can log into or interact with. PieFed knows whether I've already voted on something, so it won't let me vote again by changing the 'vote privately' setting.

[–] [email protected] 4 points 8 months ago

Cool solution!

[–] [email protected] 4 points 8 months ago* (last edited 8 months ago) (5 children)

Regarding the voting account having no name, does that mean it will be a random string of letters and numbers? I get that it will still be possible to discover vote manipulation or mass downvoting with that, but I suspect it would be more difficult to detect initially or without some deeper analysis, since it's harder to recognize or remember a random string compared to a human made username.

[–] [email protected] 3 points 8 months ago (1 children)
[–] [email protected] 6 points 8 months ago

Ah, that's unfortunate. As an alternative, I have seen some online games name their bots with a random name generator that's designed to sound somewhat real, like AnnoyingPidgen or WrecklessRaptor. If the voting account naming system was more like that, it would be easier to notice voting patterns/manipulation while still being anonymous.

load more comments (4 replies)
[–] [email protected] 4 points 8 months ago (3 children)

@rimu is there a forum style ap implementation that can talk to lemmy communities (I'm assuming that piefed can) without voting?

[–] [email protected] 3 points 8 months ago

Not that I know of.

You could achieve this by installing a Lemmy, PieFed or Mbin instance (whichever you find easiest to install and customise), in the admin area set the sorting options to a sensible default ("New", or "Active", perhaps) and then add a small snippet of CSS that hides the voting information.

load more comments (2 replies)
load more comments
view more: ‹ prev next ›