YSK: Your Lemmy activities (e.g. downvotes) are far from private - eviltoast

Edit: obligatory explanation (thanks mods for squaring me away)…

What you see via the UI isn’t “all that exists”. Unlike Reddit, where everything is a black box, there are a lot more eyeballs who can see “under the hood”. Any instance admin, proper or rogue, gets a ton of information that users won’t normally see. The attached example demonstrates that while users will only see upvote/downvote tallies, admins can see who actually performed those actions.

Edit: To clarify, not just YOUR instance admin gets this info. This is ANY instance admin across the Fediverse.

  • Vlyn@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    1 year ago

    But that has always been a thing. Just like Reddit mods banning you from their subreddit just because you posted in another subreddit they didn’t like. It sucks, but it’s nothing new.

    If either a server admin or a community mod doesn’t like you for what you’re doing, they can kick you out. It’s the same as if this was an old time forum and you pissed off the admin.

    With lemmy you have to watch two things:

    1. Trust the instance admin you sign up with, this is where your account data lives, the admin can read everything on your account. Hell, even your password if they manipulated the instance code, so use a random one

    2. Trust the moderators of the communities you interact with. If you interact with a community and the mods there don’t like you, they can just remove your posts for example. Same as with Reddit

    A random person outside of your instance or communities you interact with can’t do much. They can “steal” your posts and comment data and see your votes. But that’s it. They can’t block your account or kick you out of your favorite communities. They could obviously harass you (just your account, not your email), but then you can block them. Or ask the admin to block their entire instance.