————
Suspended sneak.berlin
TEK 9 MAR 2020 • 1 MIN READ
The sneak.berlin instance is a small or single-user instance operated by a software author who writes hostile instance-scraping bots. On the web page for that software, in the ironically named "ethics statement", he writes:
“Publishing your toots/messages on a server without marking them private or requiring authentication and thus making them available to the web is an act of affirmative consent to allowing others to download those toots/messages (usually by viewing them in a browser on your profile page). If you don’t want your toots downloaded by remote/unauthenticated users on the web, do not publish them to the web.
If you publish them to the whole web (and your home instance serves them to all comers), do not be surprised or feel violated when people download (and optionally save) them, as your home instance permits them to.“
This is an interesting take on online privacy, to be sure: "because you have not physically restricted me from harvesting your information, you are affirmatively consenting to it". This is much the same argument as "you shouldn't have let me hit you" and carries about the same moral weight with me.
By choosing not to talk to this instance, I hope we make clear that the Free Radical community does not wish to interact with the author or his software.
I'd rather compare it to not locking your bicycle and then complaining someone stole it. It may be illegal but you're a bit naive for expecting otherwise.
Also, in this instance the users were able to notice the data collection. What about the instances where they aren't, because the scraper just keeps to themselves? And then maybe they start getting very well-targeted spam or phishing, and maybe never find out how they were able to do that?
In a way, this scraper is a service to awareness.
If one were to run it, it does not violate anyone’s privacy because it only indexes information from the public, unauthenticated web.
It’s a bit of a stretch to claim that I myself am collecting anyone’s data. I write software. As a point of fact, I have actually never spidered or indexed the Fediverse (yet).
The software I wrote sends requests to webservers, which are in no way obligated to reply to those requests with any information. This is how the web works, and the tool I wrote is no different than any other web spider/indexer from an ethical perspective.
ActivityPub users seem have interesting concepts of what it means to have “published”.
That’s why I have a bit of a hard time taking your complaints about Def Con seriously.
Quite the contrary, I wish for the things I publish to be read and understood as widely as possible.
That's how the web works: if your webserver (or web host, or mastodon instance, or whatever) receives a request for a webpage, and then it says "yes, sure, here's the webpage", and sends it to the requesting user, there's no ethical or moral framework which at that point says that the webserver has been wronged by the requesting user having that content. It literally sent it to them voluntarily.
If you (or your server, or your host) hands out data to all comers, it is not reasonable to then say that those other people should not have access to that data. You (or your server, or your host) provided it to them.