Follower-only posts are not about hiding something from prying eyes, but about removing noise and clutter from those who don't care about certain topics.
Anyone thinking their post is only seen by their followers when they have federation turned on is grossly misinformed.
I think this is simply a social problem — when sending a post to your followers, you have to trust that they do not share your post. The same applies in private messaging. You have to trust the recipients.
I don't agree in this case where the system is designed to spread those posts. Fair enough if you don't want that to happen, in which case don't use a federated system where that is a design goal.
It's also possible to send messages to part of the followers as well, some instances like qoto.org support circles. You make circles from your followers and post to just them.
I wouldn't call these privacy features, but ability for sender to choose what it wants to say for certain group of followers.
This is pub/sub, it's not pull based, so every time you release something it is pushed to the subscribers, your followers servers.
I would like to have a bit of pull based things as well, but ActivityPub is not built for it.
Even though it's pushed to a server, doesn't mean it goes to everyone in that server.
Right, the issue being raised is that there's nothing preventing it from going to everyone on the server except the server being nice about it.
It's in the specs what servers should do if it receives a message. If someone sends a message addressed to just these people the server then delivers it to just these people?
Of course if you send something from foo@gmail.com to bar@yahoo.com the server at yahoo.com decides who gets it, hopefully just bar.
In fact email analogy in my mind is most apt and easiest to explain, including the fact that it's not E2E encrypted. It's totally up to servers who gets your messages when you send them.
Stuff you post will only be visible to the set of users you want it to be visible to. Writing software to present those posts in a suitable UI is left as an exercise to the reader. And it's a bit late to start now, but I really wish we'd been able to start our fediverse journey with something that's at least supposed to be secure, then opened up the stuff that's intended be open.
I don't want to start discussing what Fediverse should be, but I have had this discussion in past, few points:
- ActivityPub has two signatures: HTTP signatures, which are ephemeral, and more persistent JSON-LD object signatures. They are contentious. Some servers disable JSON-LD object signatures, because they allow to proof cryptographically that someone posted something, thus deleted posts become "liability".
- E2E encryption will have similar ramifications, because not all servers agree that crypto be used.
Currently only way to do "privacy" is to deliver messages to just the people you want, and hope servers won't send them to third parties, like in email. That's what Mastodon does.
E-mail has decent brand separation between the protocol and providers. People don’t talk about joining .social, they talk about Mastodon.
Sure. But users are cognizant they're using Gmail. And when something goes wrong, they're halfway decent at attributing it to their or the recipient's provider. Mastodon servers are eclipsed by Mastodon per se. It's closer to AOL than e-mail.
But for follower only posting, you are right, Activities go only to the recipients, theoretically to each individual inbox, practically to the instance's shared inbox.