24 ms·
Blocking Threads won't be enough to protect privacy once they join the Fediverse
- soligern 3y agoWhat an asinine concern. Don’t want your data on threads? Don’t use threads.
- ajmurmann 3y agoIsn't the exact concern here that people avoid Meta properties and for that reason chose Mastodon, but now Meta is sucking that data in? To me that still seems fairplay on a platform that's designed to be open and heralded that way. Not a opinion I hold strongly though.
- deleted 3y ago[deleted]
- ollien 3y agoEven if you don't use Threads, when they eventually add ActivityPub support, Mastodon users' data will inevitably be harvested. Instance admins have been signing a pact[1] to defederate with Meta for this reason, in addition to the fact that they don't trust Meta to moderate their instance well enough for it to be safe to federate with. [1] https://fedipact.online/ https://fedipact.online/
- smoldesu 3y agoWhat stops them from harvesting Mastodon users' data after they're defederated?
- ollien 3y agoI mean, I guess nothing, they could absolutely still scrape data, but that's much more likely to be noticed (rather than sucking in data as part of product functionality), and is a higher barrier to entry.
- robrtsql 3y agoThanks. I was going to point out that this was an existing problem in the Fediverse (there are instances that are 'unsafe' because they are either explicitly _for_ hate speech or just don't do enough to moderate it) and that the standard approach is to not federate with those instances, nor with any instance that chooses to federate with them. It's not universally popular (some people don't like the idea of 'guilt by federation') but it's necessary if your goal is to prevent your users from coming into contact with nazis.
- PaulHoule 3y agoI find it hard to believe they are really going to join the Fedi. With 100 million users on Threads and maybe 2 million on the Fedi, how could Meta possibly benefit? Federating could bring them trouble but no benefit.
- notatoad 3y agoThe EU digital markets act will require "gatekeepers" like meta to provide some form of interoperability or open access. Supporting activitypub would be a way to satisfy that requirement.
- PaulHoule 3y agoBut Mastodon can't possibly comply with GDPR the way it is organized. I mean Heavens you can use it without clicking on a cookie popup, they probably owe $70 billion dollars just for all the people who haven't seen a cookie popup already.
- notatoad 3y agoI'm assuming this is the point. Facebook can get around things like requests for deletion under the GDPR by sending that data out to the fediverse, and then reading it back in from the fediverse after they've deleted it. and when the EU complains, they get to throw their hands in the air and say "yeah, you made us do it"
- countrpt 3y agoIt doesn’t need a cookie popup because they aren’t using cookies for non-essential reasons, similar to how it complies with GDPR because they aren’t collecting any data beyond what is necessary for the service’s stated purpose.
- ollien 3y agoI could definitely see a benefit for them from a legislative perspective. By federating with other networks, they're able to signal to lawmakers that they're not _really_ a monopoly, they're willing to pay-ball with others. Also, isn't the 100M user figure disputed, because it's counting existing Instagram users or some such?
- tick_tock_tick 3y ago> when they eventually add ActivityPub support What does that have to do with anything? Mastodon is explicitly setup to allow all user data to be harvested. What Threads supports or doesn't support in the end has no bearing on Mastodon having all user data public.
- kazinator 3y agoJust like digital entertainment is set up to allow all movies and music to be downloaded for free! If you don't like it, just don't make movies or music.
- smoldesu 3y agoThis, but unironically. If you are uncomfortable with the idea of a zero-marginal-utility medium distributing your content without your consent, you probably shouldn't make and share digital copies of your work.
- ollien 3y agoI think you would agree that harvesting that information is far easier if it's being literally POST'd to your servers (which ActivityPub does) than if you're going out to scrape them, no? It's the same principle with defederation; either they're going to scrape all the data, or the data is going to be literally sent to their platform. The point is, the idea that "don't use threads" solves the problem being presented (your data being harvested), is wrong.
- zimpenfish 3y agoSpecifically addressed in the article. "Even if I only make followers-only posts, which aren't public and can't be boosted, if somebody who's following me replies, any of their followers on Threads will see my account name and instance" and also "If somebody on another instance who follows me boosts one of my public or unlisted posts, people on Threads who are following them may be able to see everything I've said in the post"
- nickthegreek 3y agoIsnt this a core way that ActivityPub works though? Like this isn't a Meta issue. It is the technical functionality of the protocol these federated services are built on. If you transmit data using the AP protocol, your content isnt private.
- boyter 3y agoCorrect. A lot of the protections in ActivityPub are listed in the spec as "should" not "must". For example edits and deletes. I think it should be assumed that when you publish content over activitypub it is now public. Any exception that it is private is asinine since you are literally publishing it to other servers.
- zimpenfish 3y ago> Isnt this a core way that ActivityPub works though? Yep but it counters the "If you don't want your data on Threads, don't use Threads" argument since you can be two hops away from Threads and still have your data appearing on Threads.
- andybak 3y agoI know replying with "did you actually read the article?" is explicitly forbidden on HN but is there an exception for cases where the person who didn't read the article uses a word like "asinine" in their dismissive reply?
- deleted 3y ago[deleted]
- Falell 3y agoThe article shows that federation delivers data to Meta even if you personally don't use Threads, but I agree with your point. If you want to control distribution of your data, don't join a federation designed to distribute data. Trying to blacklist nodes in a graph that you don't control is not a solution. Information wants to be free, if you post something to a social graph assume everyone in the graph can see it forever.
- jdp23 3y agoDid you even read the article? This is about data going to Threads from people who aren't on Threads.
- linusg789 3y ago"Privacy" and "fediverse" are like water and oil: they don't mix. Meta would have no more (extra) access to Fedi posts than an large Mastodon instance like Mastodon.social would have.
- bhdlr 3y ago> "Privacy" and "fediverse" are like water and oil: they don't mix. I'm not sure I agree, privacy can be achieved via anonymity. Use a VPN, block cookies, change usernames, etc
- crooked-v 3y ago"Decentralized access for everyone, unless it gets popular enough that somebody actually wants to interop with it" I understand the Meta hate, but joining a very explicitly public and intentionally republishable service and then being unhappy that your data is public and intentionally republishable is bizarre to me.
- turnsout 3y agoYeah, this article reads more like a critique of the way ActivityPub and Mastodon work. None of this is particular to Meta.
- PaulHoule 3y agoThe odd thing is that even the biggest fedi promoters don't seem to get it. I thought "mastodon.social" was based in Germany, heart of GDPR country but there is no consent theater, no harassment by cookie popups, certainly no controls over data. I really don't mind, but there is some serious cognitive dissonance there.
- Finnucane 3y agoThere's no consent theatre because mastodon isn't doing anything that requires consent under the GDPR.
- sunbum 3y agoBecause almost none of that is actually required if you are not collecting data outside of the actual usage of the application.
- PaulHoule 3y agoPeople are documenting their own personal lives without any protections. You can delete your account and the system will circulate a polite notification that other servers should delete that information. If you are a "sexworker" (sic) and you doxx yourself tough luck. If you reveal your mental illness through the things you write about and the language patterns you use tough luck. (Pro tip: machine learning algorithms can read your social media posts and psychodiagnose you better than the psychiatric nurse practitioner you'll struggle to get an appointment with.) People get these spams inviting them to play games where they ask questions trying to gather their answers to break into their bank account such as "What was the name of your first pet?" Even if you didn't have a tendency to be paranoid maybe you should.
- marcosdumay 3y agoHunting down your personal details and publishing them is a crime¹, isn't it? 1 - I mean on the US where Meta really cares about. It's probably one on most countries where Meta has revenue, but that won't send anybody to jail.
- tredre3 3y ago> Hunting down your personal details and publishing them is a crime¹, isn't it? It's a crime to obtain public data published on a public network built on a public protocol explicitly designed to share data? Isn't that the whole raison-d'être of mastodon?
- jeffbee 3y ago[dead]
- marcosdumay 3y ago> obtain public data That's not what I said, and not what is on the article.
- oldtownroad 3y agoThe story is almost certainly untrue or a misunderstanding. Facebook has no reason to scrape individuals personal information and then forcefully update their Facebook profile. There are various processes at Meta that do require identification to be submitted and in some cases that information will be published. For example, to be verified on Instagram you must have your name be published. Likewise, certain Facebook pages must publish their operators identities. Most likely the person in question submitted their identity documents to Facebook (perhaps their account got locked) and they didn’t realise they were agreeing to that information being put on their profile. The concern is valid — Facebook has information users might not want public — but the cause isn’t nefarious. Facebook is not finding an anonymous sex workers identity and then intentionally outing them.
- 1970-01-01 3y ago>Facebook is not finding an anonymous sex workers identity and then intentionally outing them. They are? https://www.thewrap.com/facebook-sex-workers-outed/ https://www.thewrap.com/facebook-sex-workers-outed/
- 1970-01-01 3y agoThe best way to handle it is to make a "minimum viable" account and do absolutely nothing with it, ever, except login and logout annually. Set up a spam filter to trash every single notice from the company.
- nemacol 3y agoCan you help me understand why this is preferable to never joining in the first place? What is the goal? Controlling the entry for my email/auth of choice?
- 1970-01-01 3y agoIt is a mitigation for identity theft and slander. https://news.ycombinator.com/item?id=26931894 https://news.ycombinator.com/item?id=26931894
- nemacol 3y agoInteresting. Thank you for the link.
- justincredible 3y ago[dead]
- bobobob420 3y agonot a problem for 99.99 percent of people.
- seattle_spring 3y agoSo... Still a problem for 700,000 people. Got it
- bobobob420 3y agothe only problem is lack of critical thinking and victimization. You're joining a centralized netowrk its pretty obvious.
- andybak 3y agoIsn't ActivityPub specifically about decentralisation?
- bobobob420 3y agoprotocol to centralize decenteralized activity. The blog starts with an issue on facebooks centralization and then goes into issue on centralization on this decentralized network. It's all very stupid imo. Edit sorry for my spelling
- deleted 3y ago[deleted]
- Dma54rhs 3y agoWhat's the point of joining a decentralized federated platform if you don't want other instances or people to see what you post? Meta scraping your name and doing other shenanigans is a different subject and obviously bad, but the rest is like complaining joining a public torrent tracker and being mad about leaking your ip address to its peers.
- kazinator 3y agoWhat's the point of joining a decentralized, open-source federated platform if you don't want Facebook to collect information about you and track you online, even though you aren't a Facebook user?
- blitzar 3y agoThreads doesnt need to exist for facebook to capture every post in the fediverse.
- fsflover 3y agoThis is not a problem specific to Federation/ActivityPub/Mastodon.
- rcmjr 3y agoWhy do you think they aren't doing that now? Meta could easily do it.
- w0m 3y agoSo you want the information to be free! But not free to those guys over there. Ever so slightly hypocritical.
- klabb3 3y agoThat’s a bit of an overstatement. I can want an open neighborhood but still be creeped out when a neighbor puts up a camera facing my house. Systemic data collection and casual access aren’t equal. That said, on these protocols you can’t control it anyway, so it’s not like you can stop it.
- Aaronstotle 3y agoDon't have public accounts on a platform if you are concerned about privacy. Don't use threads, don't use Mastadon.
- kazinator 3y agoDon't go outside if you're concerned about bullies.
- Aaronstotle 3y agoMeta makes their money through advertising, they do everything in their power to profile and track you so they can serve up relevant ads. The issues in the article are related to how ActivityPub/Mastadon work, if you are concerned by privacy issues, don't use Meta. Meta is guaranteed to erode your privacy, being outside doesn't come with a guarantee of being bullied.
- foderking 3y agounironically
- Nextgrid 3y agoIf you have personal information you do not wish bad actors to see, do not publish it using an open protocol explicitly designed to allow anyone to read said information. Defederating from Meta as a solution is stupid - Meta can (and will if they actually care enough) just rejoin undercover. Furthermore, when it comes to the fediverse, Meta is actually one of the more trusted actors compared to whatever else is on there - at least they're a known legal entity instead of some random. Finally, the fact that publishing private information publicly on the fediverse wasn't considered an issue before Meta came along shows just how irrelevant the whole thing is - the data has been public all this time, but the network is so irrelevant that not even bad actors cared enough to actually scrape it (or at least do anything with it).
- zzzeek 3y agoI think the point they're making is that Meta is in a special place, where by using their unusually vast amounts of personal data and photos, they are somehow (?) going to dox anonymous users by publishing their real names, based on matching their profiles in some way. At least that is the implication based on the quoted tweet right at the top of the post (which is lacking any real detail how exactly Meta got this person's real name matched up with an online alias).
- chc 3y agoThe only entity that could realistically tell us how Meta linked the profile to that person's real name is Meta, and they aren't likely to share that information — so it's not exactly surprising that the tweet lacks detail on the matter.
- Tempest1981 3y agoPhone numbers and recovery email addresses?
- deleted 3y ago[deleted]
- cdot2 3y ago[flagged]
- howinteresting 3y ago[flagged]
- cubefox 3y ago[flagged]
- howinteresting 3y ago[flagged]
- cubefox 3y ago[flagged]
- ndlan 3y ago[flagged]
- howinteresting 3y agoJust convince other people about the falsehood of the opinion.
- zzzeek 3y agowhat an ignorant take. Social media promotion of "hated" groups can be plausibly blamed for mass murder, including a literal genocide for which Facebook is now being sued for £150bn right now: https://en.wikipedia.org/wiki/Facebook_content_management_controversies#Incitement_of_human_rights_abuses_in_Myanmar https://en.wikipedia.org/wiki/Facebook_content_management_co... https://www.nytimes.com/2018/10/15/technology/myanmar-facebook-genocide.html https://www.nytimes.com/2018/10/15/technology/myanmar-facebo... https://www.theguardian.com/technology/2021/dec/06/rohingya-sue-facebook-myanmar-genocide-us-uk-legal-action-social-media-violence https://www.theguardian.com/technology/2021/dec/06/rohingya-...
- notatoad 3y ago>Mastodon (and most other fediverse software) wasn't designed with privacy and user safety in mind this is the real problem. Mastodon and lemmy share way more information than they actually need to (like lemmy shares a list of usernames who upvoted or downvoted a post, not just a count), and if you're using one of those services you should expect that all your data and interactions are public. that's the actual threat here, not the possibility that facebook might suck up that data. Blocking Threads from federating is just a short-term patch over mastodon's bad privacy controls.
- kazinator 3y agoIf ActivityPub and Mastodon were designed with privacy in mind, Facebook/Meta wouldn't touch it with ten foot pole.
- chc 3y agoTo be clear, Twitter also shares the list of users who like a post, and people generally seem to view this as a good feature rather than an invasive one, so it makes sense that Mastodon implemented it as well.
- notatoad 3y agotwitter shares that while making it immediately clear that the information is public. when you like a post you know your name is going to show up on the list of people who liked it, because the "like" button and the list are right beside each other. that's consent. lemmy does not make it in any way clear that upvotes and downvotes are public information.
- FireInsight 3y agothat's an UX problem more than a protocol problem. anonymous voting would be more easily gameable.
- Karrot_Kream 3y agoNot justifying the design decision (which is bad IMO), but the reason upvotes and downvotes are shared is the nature of sending discrete events. I've been working on a Reddit like thing on top of Matrix and likewise I have to send upvote and downvote events, which means other clients that fetch events will fetch each upvote and downvote event and a malicious client can then track what individuals upvote and downvote. (I'm trying to play around with ways around this, like using a bot to instead publish aggregation events and making votes private, but it's an ongoing exploration.)
- strogonoff 3y agoActivityPub has a problem of laying all data out, nicely structured, just waiting to be scraped and mined and machine-processed, in perpetuity by default, as if it was something people inherently need when communicating. Is it, though? It does look like something idealistically-minded early techies would justifiably find really cool. It may indeed be desirable for, say, Dutch government (and perhaps any government that wants to be transparent). However, I’d argue it may be from suboptimal to harmful for regular people. Regular people may have to worry about future governments, which may or may not end up less transparent to hostile towards them, as well as other powerful adversaries. Regular people may want to be careful and value features like transience, privacy, and plausible deniability. Perhaps we can do better and come up with a protocol that combines openness and those values. Whether Facebook enters the Fediverse with its new product or not, ActivityPub in its current shape and implementation seems to be a liability.
- ilyt 3y agoshrug not having API didn't stop anyone before that. And "I want random people to see my social stuff (cos I yearn for attention) but not that particular person/corporation" is unsolvable problem
- strogonoff 3y agoBug-free software is unsolvable, but it does not mean we should stop trying to avoid bugs, that’d be just silly. If fully precluding public and private intelligence is infeasible, that does not mean we should be using a protocol that in many ways is optimised for public and private intelligence. Privacy, like many things, is a spectrum.
- xg15 3y agoI'm with you if you want to keep the API but put them behind stronger authorisation requirements, i.e. what "authorized fetch" seems to be for. I absolutely disagree if you want to keep the data public but make it "harder to scrape", i.e. remove all APIs bury it in some annoying HTML/Javascript mess. That would absolutely punish the wrong players: Having an API which allows easy access to structured data allows all kinds of desirable usecases, such as being able to use whatever client you like. In contrast, the big players who are interested in tracking the entire userbase already have enough experience in building robust scrapers - they won't be deterred by a closed-down API.
- dabedee 3y agoThis reminds me of the "embrace, extend, extinguish" strategies Microsoft used extensively with Linux and open source software in the 90s. From [1]: "a phrase that the U.S. Department of Justice found that was used internally by Microsoft to describe its strategy for entering product categories involving widely used standards, extending those standards with proprietary capabilities, and then using those differences in order to strongly disadvantage its competitors." [1] https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extinguish https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extingu...
- jdp23 3y agoThere's a lot of discussion about that! Here's a very good article on the EEE threat. https://ploum.net/2023-06-23-how-to-kill-decentralised-networks.html https://ploum.net/2023-06-23-how-to-kill-decentralised-netwo... Personally I think it's more an "embrace, extend, and exploit" approach; a decentralized model could work well for Meta, for example if they do revenue-sharing on ads hosted by other instances (think Disney or LA Lakers). Update: here's another good article looking at how Meta could embrace and extend -- again, not extinguish. https://darnell.day/heavy-meta-four-business-reasons-why-instagram-is-using-threads-to-embrace-the https://darnell.day/heavy-meta-four-business-reasons-why-ins...
- drdaeman 3y agoIn my personal (subjective) opinion, XMPP died because of entirely different primary reason: it, by design, had trouble working on mobile devices. Keeping the connection was either battery-expensive or outright impossible, and using OS native push notifications had significant barriers. At the very least, that's why I stopped. It's not like Google had "extinguished" anything, it's more like the "largest server went uncooperative and removed themselves". Sucked for people who were able to chat before and got separated, but I disagree with painting this as some sort of fatal blow. I don't think there's some statistics on reasons why people stopped using XMPP, but I don't believe Google is the reason for it. I'd speculate that it just coincided with the beginning of the smartphone era and this whole "Google killed XMPP" is a convenient myth.
- Modified3019 3y agohttps://news.yahoo.com/teen-mom-plead-guilty-abortion-230802922.html https://news.yahoo.com/teen-mom-plead-guilty-abortion-230802... >A Nebraska woman has pleaded guilty to helping her daughter have a medication abortion last year. The legal proceeding against her hinged on Facebook's decision to provide authorities with private messages between that mother and her 17-year-old daughter discussing the latter's plans to terminate her pregnancy. If you have information you don't want others to know, then don't tell your secrets to a multi-billion dollar pseudo-governmental organization that has even less data collection protections than the governments it serves. There's more you should do, but that's a big one.
- jeroenhd 3y agoIf you have secrets at all, don't send them through any ActivityPub conversation. People on Mastodon make this mistake quite often, tagging someone they're talking about, or realising that the person they tagged now receives a copy of their conversation. This is a massive issue on top of the lack of end to end encryption. Both servers receive plaintext copies of the messages exchanged. I'm sure mastohub.ai is a safe server, but how can you be sure they'll never be bought out or hacked? If you want to federate and share secrets, try something like Matrix or XMPP. They make it significantly more difficult to read your messages.
- jdp23 3y agoThat's true -- and my more detailed threat modeling post has a big public service announcement saying "don't share information on the fediverse that you want to keep secret" -- but there's a lot of information that's not "secret" that people do want to share on social networks. https://privacy.thenexus.today/fediverse-threat-modeling-privacy-and-meta/ https://privacy.thenexus.today/fediverse-threat-modeling-pri...
- em-bee 3y agothis is also what always bothered me about twitter. some friends of mine has absolutely private conversations on their public twitter feeds (nothing sensitive but stuff like sharing shopping lists). my fear always was that if i join twitter they would use it for private conversations with me insteads of using email or something else that isn't public for everyone.
- AndyMcConachie 3y agoIn theory it shouldn't be hard to block Threads. If they're only using one domain for all their users it's trivial to block it. But privacy is not the issue with Threads. The issue with Threads is that they're going to attempt to destroy the Fediverse through standard Embrace, Extend, Destroy tactics. You see this with Bluesky as well. The point is to interoperate when it's in your interests and then break interoperability when you have enough of the audience. Thus, thereby capturing the lion's share of the audience. Just wait. Threads will soon have a 'new feature' that only works with Threads and that does not work on other Fediverse nodes. Then they'll try and poison the standards bodies working on ActivityPub. They could increase the velocity of new 'features' to ActivityPub so fast that unpaid OSS developers couldn't keep up. Like Google and that cartel do with browsers. Eventually Meta and maybe a couple other large players will control the standards, or atleast make it obtuse enough to prevent new entrants. This playbook is tried and true.
- nologic01 3y agoThis feels like irrational fear. The subversion of the original Web took decades to happen, a lot of complacency, lack of reflexes and the moral degeneration that allowed surveillance capitalism to become hugely profitable. For sure Meta cannot be trusted to be up to anything kosher especially since social media tech is close to the money spinning core of the Death Star. But what "stolen" audience are you worried about? The existing million or so fediverse users that will be lured back into the lethal embrace of the move-fast-and-break-things brigade? Future fediverse users that cant tell whether they are joining a surveillance apparatus or, e.g. their local community instance? Threads is currently cannibalising Instagram in the hope, pressumably, of grabbing some pieces from the decaying corpse of Twitter. All quite morbid affairs that dont have overlap with the migrants escaping to build a new life in the fediverse. The issue of subverting the fediverse standards is more serious - in principle. But the tangible threat is not clear (to me at least). E.g., the protocols are low level, minimum interop standard, they specify nothing about how server platforms can (ab)use their users. This is all down to implementations. In any case if you dont want corporate control of a standard make sure you dont take any corporate money and if they insist to join the fediverse party give them one vote like every other solo fediverse pioneer. The fediverse is being noticed. Thats a good thing. Savvy PR by fediversians could spin Meta's "interest" in the project to open doors that they could not dream of. Granted PR and marketing is not the fediverse's strong point. Its better this way even if it makes the job of adoption harder. But lets not get scared by shadows.
- vinceguidry 3y agoEvery single comment on this story qualifies to be in "Shit HNer's say."
- nottorp 3y ago'I had a FB account as Mistress Matisse, but FB scraped my legal name from somewhere else and then changed my displayed NAME on my account without notice/consent.' Who gave FB permission to conflate two different identities?
- gidam 3y agoprobably in their TOS, where they give themself right to do anything.
- mrguyorama 3y agoThe legal right for a private entity to do most things to its private property. The law says they don't need permission to do something like that, regardless of any morality or decency issues that causes. The law is often not aligned with morality. Most people seem to not really get this, even when they objectively know it, or are otherwise unable to imagine what could go wrong, because doing so basically requires you to be the unhealthy kind of imaginative and paranoid. "What if facebook doxxes me and changes my display name" SEEMS like it should be an insane paranoia, because the human brain isn't equipped to handle extremes of scale and bureaucracy like this.
- nottorp 3y agoI didn't ask if it's legal.
- jahewson 3y agoClaiming control over information that you’ve made publicly available is nothing but claiming control over other people.
- FollowingTheDao 3y agoMy hope is that people will give up on all social media.
- kgwxd 3y agoMeh, I'm posting on a public forum, I don't consider any of it private. Anyway, they're not going to do the Fediverse, I'm 100% positive at this point. There is no benefit to them anymore. Nobody wants them there, and their target user doesn't want the complications inherent to the system. I love Mastodon and Lemmy specifically for these reasons. Go there. Forget this nonsense. It's a beautiful place to be.
- Pxtl 3y agotl;dr: Things you post publicly are public.
- chrisnight 3y agoThe problem I see with Threads isn't what Meta will do with fediverse data, it's the power they have with owning 97% of the entire fediverse network [1]. Embrace, Extend, Extinguish. Owning the vast majority of the fediverse userbase will cause them to have a large amount of power to compel users or servers to do whatever they want. What do you do when Facebook implements a new feature and all of your followers complain that your using a Mastodon server instead of joining Threads that has this feature they want? You either go against your entire community or let Meta takeover your account. As such, the resolution is to not let anyone have this much power. It being Meta makes it easier to hate on them, but no single server should own the vast majority of the network, let alone (100M / (100M + 2M + 1M)) = 97% of it [1]. [1] Threads has 100M users and is rising fast, Mastodon was recently stated to have 2M active users, the rest of the fediverse can be estimated to be, say, 1M. As such, Threads has about 97% of the userbase.
- ajross 3y agoThreads is still way behind Twitter, though, which doesn't even federate with Mastodon and never did. If that's your complaint, why wasn't it doubly or triply so with the last corporate overlord? "Don't use that silly Mastodon thing, everyone is on Twitter" is, in fact, the way the world has worked for the whole lifetime of Mastodon.
- chrisnight 3y ago> If that's your complaint, why wasn't it doubly or triply so with the last corporate overlord? I'll interpret this to mean "If the problem is that Threads owns the majority of the userbase, why didn't you complain about Twitter owning the majority of the userbase?" I'll reply to that as: Mastodon users did. That's why they used Mastodon in the first place, because they felt too much power was controlled in a single entity, so they complained and moved. In terms of actions to take, what power was there with Twitter that Mastodon users did not exert? With Threads, Mastodon server owners have the power to defederate and block Threads trying to intermingle with their userbase. With Twitter, Mastodon users were the ones with the power to publicly disclose their Mastodon account and tell users to follow them on there. In each instance, Mastodon users are doing what they can to reduce corporate overlords from having power over as many people as possible. Even if Threads is more centralized because of other instances defederating with it, the overall reach of Meta is reduced.
- 56kbps_capsLOCK 3y ago[dead]
- jchw 3y agoI wonder if all of this hoopla over Meta joining the Fediverse is even justified. If Meta wanted to suck up all of that data right now, they could do that without creating an entire social network to do so, by literally grabbing it from the source, where it is publicly available, and they can do this with basically no fear of ever getting called on it. By merely federating with and supporting ActivityPub, all they do is make it reciprocal, and opt-in, at least from our PoV. The real risk here in my opinion is the influence that Threads could have over the Fediverse indirectly. What if they become an integral part of it and threaten to leave, or just leave? What if they become the defacto censor of what instances you can federate with, by virtue of cutting off anyone that doesn't defederate certain instances? Etc, etc. The privacy concerns, while they hold some validity, are a little bit moot for people who weren't going to consider using Threads in the first place. Google hoovers up all of this data already if only indirectly, and nobody seems to bat an eye.
- sureglymop 3y agoI want it to be blocked for a different reason. The fediverse has always been small enough that the content is "underground" and interesting. Some of the people on there are weird or completely different than me and that's what makes them so interesting. That's not the case on something like Twitter and Instagram. Good and actually interesting content is drowned out between your average tweets and posts about nothing at all. Or all the content sucks and is there for the sake of exposure, likes, clicks etc. But I don't want mastodon to be overrun by 100M users' uninteresting content! I don't even want them in the replies of posts. Mastodon has consistently been great before this while Twitter fiasco. I wish it never happened, I don't want the space I have liked for years to change and be ruined. Maybe an apt analogy would be the difference between Marginalia and Google as search engines. Why would one want the interesting underground search engine to be filled with SEO spam and ads?
- sanderjd 3y agoI think this privacy thing is incomprehensible, but this makes total sense to me.
- jazzyjackson 3y agoYou know what, you've convinced me. I've been rooting for some kind of society-at-large network to succeed at federation (I was so optimistic I tried bitclout, and more recently bluesky. Both want to be a single global database to send money or to index hashtags and blocklists globally) I really believed that discoverability is king, and I should just be able to search a global graph of user profiles and read everything that everyone has ever said, but you're right, there's a lot of conversations that don't happen in public, and not everyone wants to be "discoverable". So I think there's a case to embrace the balkanization of social media, and go back to having separate identities to be a part of each phpbb we signed up to. Going to different domains to talk to different groups of people makes sense, and we can have the modicum of privacy offered by a semi-private chat server like discord, so that your messages don't get indexed by google and archived forever. (Obviously discord retains all the message logs, DMs included, but at least its not publically searchable) And global social media is always going to suffer eternal september. Smaller, unfederated chat communities is a probably a much healthier approach to social media than whatever it is we've been doing the last decade of meta-gramming
- raymondgh 3y agoI’m surprised that a followers-only post’s author’s information would be available to followers of original author’s followers. I would think that a non-public discussion started by one account should be nonexistent to anyone without access to follow that account.
- shadowgovt 3y agoThe unfortunate thing about the Fediverse, relative to a (hypothetical) walled garden, is that this sort of information leaking is inevitable. Meta has the scale and scope to make it scary, but the point of the Fediverse is that it is federated, which implies some openness. If you're federated, you are publishing content to other people that they might do whatever they want with. That includes crawling it, storing it, indexing it, and building mass profiles. You can certainly protect yourself by blocking bad actors, but since the network is, well, a network, an aggressor that wants your published data need only find access to a node you do want to share with and copy from there. So you either default-close your data and choose very, very carefully who you federate your node to or... You don't put that data in the fediverse at all. (Contrasting to a walled garden, where monolithic control of the data storage and transfer means a single entity is responsible for where the data goes and can constrain at will. If someone's kicked off Facebook, they're off Facebook; they have a single attack surface they have to reenter to get to that data, not O(nodes) they could make an account on to reach the data of someone who'd rather not share it with them).
- giancarlostoro 3y agoI know the main image in the article claims Meta scraped their posts and updated their profile, but is it not feasible they used the same email address or phone number they use on IG / FB and Meta just filled in the missing blanks using information they have already? Which mind you, Facebook buying IG was under the premise that they would NOT merge IG and FB, but they've been doing that for a while now, they are arguably already merged to the hip.
- paxys 3y agoA lot of privacy problems (including every single one raised in that article) will be solved by just not posting your personal business on social media, but people are somehow unwilling or unable to accept it. If you post incriminating content on a Mastodon server it is still out there whether Facebook can officially connect to it or not. It is archived forever out of your control. The server owner can be subpoenaed. Anyone can scrape the website, take a screenshot, or share it in a hundred different ways. Regardless of what pseudonym you use it can be tied to your real identity with 5 minutes of internet sleuthing. "Private" online social media is an oxymoron. If you put something out there in the world you don't get to control whose eyeballs land on it. Facebook isn't the problem, your expectations are.
- dahwolf 3y agoIt's even worse when you consider that others will put something about you out there. They willingly give up their contacts list (with you in it), when joining a network. A "friend" may make a photo of you as part of a social/work event and directly post it publicly. Even with no participation on your behalf, your real name, phone number, address and photo are out there.
- mock-possum 3y agoYeah I feel like maybe this is old fashioned of me but If I don’t want other people to see something or to know about it, I don’t post it online. Or I don’t post it in a way that could be traced back to me. There’s absolutely no link from my HN account, for instance, back to me IRL. Why open yourself up to the risk? What do you get in exchange?
- dahwolf 3y agoThe sex worker real name reveal has to be bullshit. I'm quite convinced that Meta actually does have the real name of most of us as well as the ability to link it to other accounts. But the idea that Meta would willingly reveal this without the user's consent means a planet-scale doxxing event. It could lead to actual deaths in the real world, and they would be legally crushed. What is far more likely to have happened is that the user had an Instagram account with their real name and used that to log in/sign up to Threads. There is no stand-alone account on Threads currently.
- charcircuit 3y agoMy guess is that she was breaking Facebook's real name policy by using a fake name on her main profile. It seems plausible that Facebook would update someone's main profile to their real name.
- supriyo-biswas 3y agoThey usually just suspend the account silently instead of updating your profile in the claimed way. Meta is not known for being a good citizen, but unlike sending fake notifications or tracking which helps them achieve a business goal, updating user profiles without consent achieves nothing of that sort.
- totetsu 3y agoIt could lead to actual deaths in the real world They've already been there, just it wasn't white people. Myanmar https://www.nytimes.com/2018/10/15/technology/myanmar-facebook-genocide.html https://www.nytimes.com/2018/10/15/technology/myanmar-facebo... https://edition.cnn.com/2021/12/07/tech/facebook-myanmar-rohingya-muslims-intl-hnk/index.html https://edition.cnn.com/2021/12/07/tech/facebook-myanmar-roh... and Dutertes drug war in the Philippines https://www.buzzfeednews.com/article/daveyalba/facebook-philippines-dutertes-drug-war https://www.buzzfeednews.com/article/daveyalba/facebook-phil...
- dahwolf 3y agoAs the crypto industry discovered: the paradox of decentralization is that every downside it has can only be solved in a centralized way. You can't have perfect privacy in a system that has the exact opposite goal: federation. It means your data spreads by design and enforcement of any privacy-preserving feature is optional per instance. The very loud minority on Mastodon that obsesses over safety has picked the wrong software. They should have just created a Telegram group.
- dahwolf 3y agoMy prediction on how this goes down... Meta has zero interest in ActivityPub or the Fediverse, a tiny speckle of users hostile to them. In less than a week, they've created an "instance" 50 times the size of all of Mastodon and the rest of the fediverse combined. The projection/goal is to grow towards 1B MAU, which would make it 500 times larger than all of the rest of the fediverse. Why would Meta possibly care about this tiny group of misfits? The only reason I can think of is to give legislators the idea that they are "doing good". Say it is done, and we have this Threads cosmos-sized instance. Tiny vocal Mastodon instances will defederate out of principle, and nobody cares. Because they are anti-growth anyway, they object to anything. Larger Mastodon instances will consider federating but will then find out Threads will only do this under conditions. You have to serve ads, have to comply with a moderation policy, treat user data in a certain way. You effectively work for Meta now, but unpaid. Then you turn the thing on and the flood gates open. The first thing you'll notice is your bankruptcy as your few tens of thousands of users now having follow access to a billion users, including very active and popular ones, spiking your infra. 10x? 100x? Who knows? And what about storage? Yesterday I've read how a mid-sized Mastodon instance (few thousand users) was adding 1GB of media storage every 15 mins. Do that times a 100 (or 1,000) as well. Your moderation inbox...well, good luck. This entire thing isn't going to work, at all.
- no_wizard 3y agoI wonder if they'll surprise us all a little and allow people to create - tightly controlled mind you - personalized fedi instances for things like "fan experience", but from the Threads app perspective it allows you to jump "portal to portal" if you will, without leaving the app, so it feels seamless. This would open other monetization verticals for Meta via platform creators etc. It'd also give you data carve outs that let Meta see what the most popular verticals are and they can sell specialized targeted ads against that, which would likely fetch a bigger premium and provide more useful analytics. Also worth consideration: They could federate your Facebook feed in the future too. It may not be so much supporting the protocol from the outside as its worth doing from the "inside". EDIT: I'm not talking about full blown customization here, just enough that allows creators to make their direct profile feed look different from the standard app, maybe have targeted links or a special background color etc. Simple but differentiating things.
- dsr_ 3y agoI don't think Meta is ever going to federate in the first place. What would they gain?
- deleted 3y ago[deleted]
- foobarbecue 3y agoSo I was going to try threads but can't figure out how. I'm not interested in using a phone. I'm on a computer. Is there no web version?
- cmrdporcupine 3y agoThere is no web version. Threads can be viewed at a URL, but you can't join, post, or browse via web. Amazing, eh?
- foobarbecue 3y agoWow. And this is supposed to liberate us from twitter. Oh, my poor internet, what have they done to you?
- cmrdporcupine 3y ago"Website? e-mail? What's that? If you want to get in touch with me, or find out what school events are coming up or whether your kids bus is late, or whether there's a tornado that touched down near by, or whether your local ski hill is open ... use [Facebook|Twitter|Threads]" Sigh. https://qz.com/333313/milliions-of-facebook-users-have-no-idea-theyre-using-the-internet https://qz.com/333313/milliions-of-facebook-users-have-no-id... https://en.wikipedia.org/wiki/Internet.org https://en.wikipedia.org/wiki/Internet.org https://www.wired.com/2016/01/facebook-zuckerberg-internet-org/ https://www.wired.com/2016/01/facebook-zuckerberg-internet-o...
- zzo38computer 3y agoIf it uses the ActivityPub protocol, then couldn't you use any ActivityPub client to send/receive messages with it (or else, to deal with the JSON data directly)?
- cmrdporcupine 3y agoIt doesn't use ActivityPub yet. (Or maybe ever) Also ActivityPub as I understand it has two separate forms -- a client mode, and a server to server federation mode. When/if they do implement ActivityPub, it will likely be the latter that gets implemented not the former.
- kelseyfrog 3y agoBeyond copyright, why wouldn't restrictive licensing fill that need? ex: by accessing content on this server, you agree to the terms of service..blah blah ?
- xupybd 3y ago>Trans people at risk of being targeted by groups like Libs of Tik Tok It's my understanding that Libs of Tik Tok simply reposts public videos. Say you manage to find a way to block them specifically from seeing your content what's to stop another account springing up and doing the same thing. The only option is to keep your content among friends. But then you have another trust model where your friend could be the next Libs of Tik Tok.
- pdimitar 3y agoThis is very akin the dilemma of getting yourself a very secretive and secured email: all the privacy and security stops the matter the moment you send an email to somebody with a GMail; the entire thread is visible below (through a chain of quote blocks) and it's game over. If you want true privacy, make a centralized self-hosted service where people have to be allowed in explicitly. Don't see what the problem is in the OP, they are kind of expressing displeasure that a service that technically can be scraped by almost anyone is... you know, scheduled for scraping and exposed. And at the same time nobody actually bothered to prevent the scenario from happening. And this also looks very much like the early internet: people didn't think others are malicious so security was minimal. This kind of naivete really needs to get clubbed to death. We can't afford being as naive nowadays.
- est 3y agoYou can't exactly keep privacy if you choose to broadcast your message with a "loud speaker"
- technick 3y agoWhoever wrote this needs to be flogged. So melodramatic...
- goodoldneon 3y agoMeta should use an event loop to avoid blocking Threads
- jauntywundrkind 3y agoA million years ago there was P3P, Platform For Privacy Preferences, which pages/resources could use to declare what kind of sharing/privacy rights surrounded a document. https://www.w3.org/P3P/ https://www.w3.org/P3P/ The working group was closed after browser implementers failed to express interest. As I recall, Microsoft Internet Explorer was the only browser participating. https://learn.microsoft.com/en-us/openspecs/ie_standards/ms-p3p/a4defcb3-2504-4a73-abb5-954a8b1b1adc https://learn.microsoft.com/en-us/openspecs/ie_standards/ms-... I could be mistaken/mislead about the purpose here. But this idea of having the data be able to advocate for itself what rights other people have seems semi-obvious. It won't prevent abuse, but the age of ultra-Legalistic DMCA corporate hawkishness seems largely to have won above almost all others, in most arenas, and this idea of sticking a "you can't do that" label on stuff thus seems like a pretty obvious first level defense. One that big data warehouses & big companies in particular probably couldn't violate & keep under-wraps.
- protocolture 3y ago1. The renaming thing happened to me, and it wasnt that Facebook had scraped something and made some super AI decision, its that one of the things you can report people for on the platform is using an alias, because its against T's and C's, and that form (last I checked) let you identify the actual user. 2 Said well elsewhere but its daft to want to hide public info from a subset of users on a protocol designed to distribute public data.
- smeagull 3y agoHow would meta know tyhey were the same person though? I'm glad I just routinely obfuscate my online presence by lying on every different platform.
- NoZebra120vClip 3y agoNow that I know the term "garden path sentence" I can accurately spot them. Blocking threads? Do we need a mutex here? Faster I/O?
- DiabloD3 3y agoI don't see why people think this is the issue it is: the community, at large, will refuse to federate with Threads, and then anything that Meta steals is just a simple DMCA away. And guess what happens when Meta refuses those DMCAs? You go to the networks they peer with. You don't screw with tier 1 transit providers, not even Facebook has some magical power here. This isn't, and was never, about privacy. It is 100% about Meta stealing data and displaying it so they can pretend people are using their product, so it looks active, and then they can tell their shareholders it was a successful launch. Nobody in the Fediverse wants to help Zuck profit from people's hard work that they didn't donate to him (ie, post on Facegram and thus license it to him). The flip side of this is also, how will they moderate data that isn't theirs? They will have to unfederate from certain servers and users, thus solving the problem.... and if you've seen the fediverse, its 20% trans catgirls who code in rust, are part of a polycule, wear programmers socks, and have spicy opinions about niche Linux distros, all of which are persona non-grata on the Instabook platform. The catgirls are going to save us from Zuck slathering the Internet in Sweet Baby Rays. This wasn't the future I was expecting.
- jayd16 3y agoI think you're right that DMCA will be effective but my guess is that meta will actually be able to federate just fine. As for moderation, they're already the best at it. They can simply allow or block federated content as they choose, just as easily as their own content.
- DiabloD3 3y agoBut the content doesn't cease to exist... its just going to tell people "hey, join this better non-Meta branded Fedverse server, and look at all the banned content you want! And now Meta cant ban you for having opinions about things!" They have done the opposite of a moat... they built a bridge across the moat that is around the prison island everyone is trapped in.
- jayd16 3y agoIt's like suggesting gmail would fail because they have spam filters. People actually want moderation. As long as it's mostly good or at least consistent, I expect Meta to find success. I also expect a wide variety of more lax/niche aggregators to also find success. Meta's moat will be that they will be the largest home domain. They'll have the most user data and they'll have a secured user base even if the fediverse collapses.
- dustedcodes 3y agoI stopped reading the article as soon as it criticised LibsOfTikTok, arguably one of the best and funniest social media accounts.
- Vaslo 3y agoSame - when they start comparing accounts like that to Nazis, I know the article is trash.
- helsinkiandrew 3y ago> Threads has rolled out the welcome mat to Nazi supporters, anti-LGBTQ extremists, and white supremacists, including groups like Libs of TikTok that harass trans people. It's hard to take the post seriously when they make statements like that, From the linked article: > Fuentes, who claims to have been banned from Meta's platforms, announced in a livestream on July 6, “I signed up for it last night. I made a fake Instagram. I got on a fake Thread.” I'd guess of the 100M users that have signed up lots of people that are banned, or post content that gets banned on FB and Instagram have managed to make accounts too. But I'm sure the same content moderation policies on FB/IG will apply once they start posting, some will get through, but that is far from being welcomed.
- dncornholio 3y agoIf Mastodon block Threads, I don't know what to think anymore. Mastodon should be open to all. That's the whole unique selling point, no federation from US companies etc. This will make Mastodon pretty much useless if it can just block networks..
- liotier 3y agoLooks like some Mastodon users wanted an interpersonal communication channel and didn't realize they were using a publishing platform.
- zzo38computer 3y agoIf a message is public then I shouldn't care if Meta has access to it or not; they can access it if they want to do. However, if I wish to send a private message to someone, even on a different server, it should not have to go through Meta to do so (unless the recipient is on Meta, although then the sender should be made aware of that before sending the message). I don't use Fediverse nor Meta/Threads, but I write stuff that is public and anyone can view it, or private which only the recipient should read, like anything else, whether I post on Hacker News, or on Usenet, or on a public IRC channel, or whatever else it might be. (Some people don't like public IRC logs, but if it is a public channel then I would prefer that it does have logs; fortunately some IRC channels do.)
- FireInsight 3y agoIME the problem with Meta in the fediverse aside from the privacy issues is that fedi is largely built by and run by people who want a community separate from the mainstream of social media, with their own rules and goals, without corporations, for them specifically and not for profits.
- zzo38computer 3y agoWell, it will be a problem if people are forced to use Meta even those who do not wish to do so.