So. I thought about the potential of bad actors sniffing on lemmy data. In theory, you’ld have to trust your lemmy-instance hosted to not be a bad actor and every single server they federated with. That means, it should be really - REALLY - easy for a bad actor of even a nation state actor to set up an instance and just wait for the data of users to pour in.

Theoretically they could see all the posts you ever made, and, every post you upvoted. Which also gives clues on: When are you active, what region are you from, what you like and dislike (obviously), political views, etc.

I mean - Maybe I’m too suspicious but tbh the more I read into this, the more I get a bad feeling about this…

  • Overeater@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    Since lemmy instance can be deployed and federated by anyone it’s fair to assume that some bad actors are already doing it. With some scripting or machine learning you could determine user habits and subscribed feeds. Based on other posts the subscription information (activitypub) have also upvotes and downvotes which could be used to gauge one sentiment/political affiliations. I think the only way to circumvent this is to have disposable accounts maybe with some script to to rest scribe to topics of interest every time you have new account. Then don’t use moderator account for anything other than moderating specific sub.

    • NicestDicerest@lemmy.worldOP
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      Yes! It gives me the chills that everyone can easily snack all of our data. From criminals, to stalkers to governments to companies (Example would be Meta right now). I think we should be very careful what we post and like/dislike on this platform. Gives me the chills.

      I could literally go and get your data in less than 10 Minutes. And potentially thousands ofdifferentt users too.

    • NicestDicerest@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Yes. That is exactly what I wanted to say. Thank you!

      I have a bad feeling about this. Companies can sneak in easily (As Meta is doing now), Governments can sneak in easily, Stalkers, Criminals, everyone.

      I could literally go, setup and instance and get most of you data in an blink of an eye. I don’t know. This gives me the chills

    • NicestDicerest@lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Yes. That is exactly what I wanted to say. Thank you!

      I have a bad feeling about this. Companies can sneak in easily (As Meta is doing now), Governments can sneak in easily, Stalkers, Criminals, everyone.

      I could literally go, setup and instance and get most of you data in an blink of an eye. I don’t know. This gives me the chills