Blocking Threads won't be enough to protect privacy once they join the Fediverse
privacy.thenexus.today
privacy.thenexus.today
Defederating from Meta as a solution is stupid - Meta can (and will if they actually care enough) just rejoin undercover.
Furthermore, when it comes to the fediverse, Meta is actually one of the more trusted actors compared to whatever else is on there - at least they're a known legal entity instead of some random.
Finally, the fact that publishing private information publicly on the fediverse wasn't considered an issue before Meta came along shows just how irrelevant the whole thing is - the data has been public all this time, but the network is so irrelevant that not even bad actors cared enough to actually scrape it (or at least do anything with it).
Copyright cannot restrict who can view a work you created once you transfer or license that work to somebody else (e.g. by releasing it publicly on the fediverse). You don't get to say "here's my post but if you show it to Meta then that's illegal". We don't even have a common legal framework for dealing with content distribution that isn't copying (we got "lucky" that you have to copy content to view it digitally so copyright can be poorly jammed onto the digital content distribution model and everything doesn't burn down).
Where the heck did people get the idea that they get to dictate how culture spreads and evolves?
After all how else would you describe someone allowing Netflix to stream your content?
You can't restream Netflix and Netflix is restricted on how it can stream to you. Both rooted in the original Copyright protection and the licenses to content given out by intermediaries.
Most posting platforms give themselves very broad rights with what they can do in a transitive fashion.
But that is "companies don't want to get sued for user uploaded content and are lazy" not "you don't have any rights over things that are published".
If you want to place downstream restrictions on your content then you have to license it (and get someone to agree to your license). You have rights over how you license content. Yes. And users may agree that they're only "viewing" a copy and don't in fact own it when engaging with your licensed content, sure. But my main point was that you don't get to publish content to the public domain and then say oh wait no I didn't want Meta to see that oops #privacy #cancelmeta. And further that it's kinda silly to imagine a world where everyone licenses every little toot they make. At some point we're in a public forum and we just all need to understand what that means, including that someone you don't like might be listening.
Anyway, I don't think licensing content is a positive thing for society. It may benefit media conglomerates, but not individuals. Arguably, creators shouldn't be allowed to say "Netflix you can stream this content to users but not in Brazil". I don't think it's a sealed deal that downstream restrictions on content distribution are healthy or in any way in the public interest. Charging a royalty for a views/streams of some show is one thing. Saying "only on Tuesdays and not in Brazil" gives too much control to creators to dictate how their art should be interpreted. And nobody can prevent you from using Netflix to stream a show to your Brazilian friend on the couch next to you... nor should they ever be able to. That would be really really bad technology, were it to exist.
So short of attaching licenses to every post you make, no, there's not a socially healthy, let alone even viable, strategy to control content distribution in the "fediverse".
I think you have this backwards. Full copyright protection is the default for all content not licensed otherwise. Publishing does not put content into a "public domain" status. Social media platforms already have strong legal terms around every piece of content. If you violate that license, platforms may choose to fuck you up. E.g.: https://www.malwarebytes.com/blog/news/2023/01/untraceable-s...
It would be easy enough for particular Mastodon servers and/or accounts to be explicit about their downstream licensing.
That's not how copyright works like... at all. HN needs a license to display your comment right now (see here: https://www.ycombinator.com/legal/#tou). Copyright works by default (in the US) of being the most restricted. The first sale doctrine applies but online when you distribute something you're not making 1 copy.
The license associated with physical media does have restrictions. You can't mount a public display of the work without acquiring a separate license. E.g., you can't buy a DVD of a movie and then screen it for a group (outside of what's permitted under fair use). If you sell tickets to that screening or intersperse ads, thereby infringing copyright for commercial gain, you're in even hotter water.
Do you feel the same way about restrictive open source software licenses like GPL3?
Not to mention the millions of derivative works where the definition gets fuzzy: I applied a filter to someone else photo and put an emoji over it, is still the same work? Should FB algorithm be smart enough to classify it as a copyright violation? It would be unsustainable economically to run that algorithm against the millions of posts, and even if they told the user "stop! that is copyrighted!" a huge chunk of users would just edit their post a bit and just try again.
A fair point, and one that's not really new either.
Don't want something to be public? Don't post it publicly. As I recall, when my employer at the time (mid 1990s) "federated" their email with the rest of the world, they sent out a memo which stated, in part, "don't put anything in an email that you wouldn't want to see on the front page of your local newspaper."
That was back when local newspapers were a thing, but I imagine you can see the parallels.
That said, I do get to control who sees my content -- by not making it public (i.e., I don't federate my AP instances and curate who can create accounts on them).
If you want something to be private, don't post it publicly. I'm not sure why that's such a foreign idea to some folks since, as I mentioned, it's not even close to being a new idea.
I was responding to the idea that if you post something publicly, whether that's on a Mastodon instance, a bulletin board at the library, in a Craigslist ad or any other public forum, it's unreasonable to attempt to limit access to the information contained therein. That's intuitively obvious, no?
If you only want specific people to see that information, only give it to those folks. And if they're trustworthy, they won't share it with others but that's not guaranteed.`
How does the old saw go? "Three can keep a secret, if two are dead."
Don't want something to be public? Don't post it in a public forum. Full stop.
I am unfamiliar with the example you mention and its potential privacy impacts. But even if (and maybe especially if) there are the risks/issues you allude to, that doesn't obviate (and perhaps even strengthens) my point.
I think the only way to guarantee this control in a federated system, is to encrypt everything that's not completely public. If everybody has a public key, you can use that to encrypt the secret key. It's a hassle, but I think this would work.
Diapora has something similar, but considering it's federated, I'm not sure if you can really guarantee it.
Exactly, this level of access requires a hegemon. Who will be the hegemon?
In the end, every private, highly encrypted message can always be made public by the recipient. That doesn't mean encryption is worthless for privacy.
If I explicitly deny Meta to use my work, then that is my wish and I can sue them.
As has been explained multiple times, that's now how it works. If you sell me a copy of your work, you do not have any authority after that to dictate how I use your work.
They also don't appreciate that the "come one and all" nature of the internet back then led to many people crossing the fences and experiencing viewpoints they'd never seen or heard before. This is an atmosphere we desperately need to return to.
Present day censorship, "gotcha" moderation, and algorithmic manipulation of emotion have led to hyper polarization. We should 1) deescalate the intrusion of these systems and remove them from our day-to-day experience and 2) reinforce the fundamental rights we all deserve.
Social media networks with over 100,000,000 daily active users should not be considered as "private companies with a right to free speech through censorship". They are effectively public squares that we have all elected and chosen to share. Right and left alike.
Public companies tend to censor to protect profits, but small individuals (such as Reddit moderators and Fediverse instance maintainers) do it from either a position of laziness or political retribution. The latter is a form of disgust and hatred for fellow humans and should be called out as such, even if the other party is guilty of the same.
I've seen the free speech argument twisted into "right wing figures trying to force their views into everyone's feed", but that need not be the case. There are tools for individuals to block. And if we'd finally divorce ourselves from platforms and federation and escape to true p2p social networking, we'd all have maximum individual control: we could institute any blocking, boosting, ingestion, sharing, and ranking criteria we wanted. Many amongst the left obsesses over what the right is doing (and vice versa), which tells me people enjoy rubbernecking rather than tuning out. It's a game of "neener-neener" high school football rivalry.
But back to the core point - you shouldn't get to choose who people talk to if you're not a first party in that conversation. You shouldn't get to choose who can publish openly or who can read public broadcasts. If you want to keep your words private, share them in private. Your choices should be limited to blocking what you personally dislike at your own consumption level, and it should be that way for everyone. Because that's fair.
The pendulums of politics will swing. One day liberals will need the free speech refuge again. Preserve it now even if you want to get rid of it. Question yourself if you find yourself wanting to mute or persecute others. If you're angry with my words right now, please ask yourself why you want the other party to shut up.
I want to emphasize that I do not agree with the far right. But I will fight with my last breath to preserve the right to free speech for us all. If we lose it, we will slide into tyrannical oppression from those in power.
I wish we could all just get along. I know that's not going to happen in my lifetime, but we should make best attempts at deescalation and maintaining open communication with one another. Conversation can be a bridge.
Shouldn't this also apply to TV channels? Chat apps like iMessage? Popular newspapers, blogs, and email newsletters? And indeed, why stop at 100M DAUs - why not 10M, or 1M? The problem I expect is this path leads to the death of freedom of the press.
Like a shopping mall, the classic US example of a privately owned public square
They shouldn't get carte blanche to claim wild conspiracy theories and to turn people into figurative monsters and then claim 1st amendment rights to protect them from the consequences of their public agitating slander.
On the other hand, reviewing and moderating anything other than their current carte blanche status quo would be an inhuman ordeal, so it's not like I have a more perfect idea to replace it with, just an understanding that there are bad actors using the rules of our American Social Contract as a weapon against the fundamental rights of "life, liberty, and the pursuit of happiness" that the self-same social contract they are exploiting has promised us for our abidance.
I live in a country with less than that number of people in total.
Which country gets treat the corporation as if the corporation was an arm of the government? Can't really be the servant of two masters.
And if the advertisers don't like what they see, should the government(s) subsidise the sites to make up the difference? That kinda already happens a bit with TV licences in some countries.
I don't think algorithmic manipulation is really that big of a problem. Look at HN during the Reddit blackout. Tens of overemotional posts, lots of low quality pithy responses, and not an algorithm in sight. Flame wars are at least as old as Usenet itself. I think the truth is humans online, without the context of body language and the consequences of long term relationships, are just emotionally attracted to rage and strong emotions. Algorithms may exacerbate the forum but plain old upvote behavior is plenty to surface it.
pithy means the opposite of low quality, concise and meaningful
The problem with true P2P social networking is that I don't want to have to make individual moderation decisions based on each identity that happens to try and send me a message. That is makework best delegated to someone at least marginally trustworthy so that I can spend my time actually using the network as intended. Moderation is a necessary precondition to any kind of online forum actually, y'know, working as a forum.
In order to actually have effective moderation, you need scarcity of identity. In a completely P2P network, you can just make new identities to spam people with, so blocking them has no effect. Centralized platforms have a certain magic to them in that they can make identities cost money without actually charging people for them. That's why everything wants a phone number now - because phone numbers cost money, and they can limit sign-ups to a few per number per year. The closest Mastodon has to this is domain names, which is why defederation is the first thing instance operators run to when dealing with rule breakers. It forces you to at least burn a domain name to continue harassing someone.
> Many amongst the left obsesses over what the right is doing (and vice versa), which tells me people enjoy rubbernecking rather than tuning out. It's a game of "neener-neener" high school football rivalry.
No, this is just Twitter. Twitter is structured to encourage clout-chasing and toxic behavior.
[0] Or spammers. Actually I don't get why people who call for extreme free speech aren't also calling for getting rid of spam filters. Spam filters are censorship, but it's censorship we tolerate in exchange for a functional e-mail system.
The political censorship on current social media goes far beyond “we don't want people advocating for mass censorship here”. Ironically, they do like advocating for mass censorship, as long as it's censorship of the “correct” side.
Your solution to private companies not broadcasting what you want is for the government to take the companies over and then dictate what they broadcast? Then what? Anything goes? There are plenty of sites that show you what happens when there is no form of moderation at all and they turn into complete cesspools.
Well, that's precisely because there's only a few of them. If the only site with free speech is some obscure forum, then all people with extremist opinions are going to concentrate there. If all popular social networks have free speech, extremist content is going to be diluted in normal content.
You mean like rolling back Roe v. Wade?[1]
You mean like trying to overthrow an election?[2]
Denying access to gender-affirming care for adults?[3]
What exactly do you think people are being unfairly obsessed over? Because there's a reason people follow politics: it's because politics, and because we're in a democracy - public opinion and discourse - has direct, kinetic effects on people's lives.
This is a real cheap opinion to have provided you're never weighed down with having to engage with the content and stick to vague insinuation. The fiction of "both sides".
[1] https://www.npr.org/2022/06/24/1102305878/supreme-court-abor...
[2] https://en.wikipedia.org/wiki/January_6_United_States_Capito...
[3] https://www.washingtonpost.com/nation/2023/02/28/anti-trans-...
I agree with the rest of your post but I suspect that in this instance Meta, a large public company, that might leery about doing something that potentially embarassing.
But your basic point remains true. A wide variety of companies, many bad actor, are going to be scraping, processing and connecting any data anyone makes puts online and that will happen whether Meta joins the fediverse or not. If Meta wanted fediverse data bad, they'd likely just buy it.
Indeed, all the hand wringing about Meta in particular in the article and here seems deeply confused - of course Meta isn't the only problematic actor out there. Indeed, the anonymity-problem of all the walled-gardens is that they explicitly attempt to stop online anonymity in various overt ways. But everywhere entities are trying to deanonymize covertly and these can be at least as bad.
The main thing is that anyone wanting anonymity needs to take active measures to achieve it. And these measures vary on how visible you are and effectively how much your enemies are capable and interested in you. Those talking anonymity would do best educating people in this.
I wouldn't say that the company directly responsible for the state of online discourse today as being leery of doing anything.
https://www.theguardian.com/technology/2014/jun/29/facebook-...
It has published details of a vast experiment in which it manipulated information posted on 689,000 users' home pages and found it could make people feel more positive or negative through a process of "emotional contagion".
...
One test reduced users' exposure to their friends' "positive emotional content", resulting in fewer positive posts of their own. Another test reduced exposure to "negative emotional content" and the opposite happened.The company, huh? Not Twitter, not "us", not the properties of online discourse, the polarization of American and world political ideologies...
Anyway, this "hating on" FB doesn't change the situation.
"Of course, Meta's far from the only threat out there, but as I discuss in 'Threat modeling Meta, the fediverse, and privacy', looking at Meta-related threats also points to solutions that increase privacy and safety in the fediverse more generally."
Here's a link to the longer post (still a draft). https://privacy.thenexus.today/fediverse-threat-modeling-pri...
And agreed, it doesn't scale for Meta to infiltrate people into every single fediverse instance -- although threat actors who are targeting specific people or communities might well do this, so it's also something to take into account.
I don’t know, they did depend on Onavo analytics for a while: https://en.m.wikipedia.org/wiki/Onavo
Using a protocol designed to distribute content with the expectation that you remain in control of it is asinine. If you really want to control it, either allow list federate with only instances you know are in the same circle (IE make your own smaller fediverse), or move to a private forum.
I argued with the Fediverse about this several months ago, and raised all of the same problems in the article with them. Only to be shouted at, doxed, abused, insulted and attacked. I still think that what I experienced would be enough to drive some people to self harm. The level of toxic interactions on the fedivese was the worst I have ever experienced on the internet.
As such I find the fact that there is a freakout over what has been predicted multiple times hilarious. I welcome Meta joining. The sooner people on the fedivese grow up and realize the reality of what is coming the better.
I really like ActivityPub. I really like the fedivese idea. However when you visit you rapidly discover its full of the really annoying people from twitter, and people with "ex tumblr poster" in their bios.
Forget where this came from but it sums it up perfectly.
Fediverse: We are open for federation and you to join!
Meta: Ok here is what we are doing with instagram.
Fediverse: Not that kind of open!One question I've had for fediverse people is how you prevent a federated system from centralizing. I am legitimately curious. Email is often given as an example, but imo that a perfect example of a decentralized system BECOMING centralized. Sure, other players exist but the vast majority of people are on gmail, apple, or outlook (which is much smaller than the other two). Things tend to follow power distributions due to the momentum force being critical. In network systems (e.g. twitter,facebook,HN,email,ISPs,Walmark,etc) the utility/value is not linearly proportional to the userbase, but super-linear (this was one of the big problems with cryptocurrencies too. "Gotta have money to make money"). In these systems resources are "attractive."
So with this in mind, how is a decentralized paradigm any different than an attempt to just reshuffle the top players? (i.e. re-centralize but with a different group at the top) I just don't see the mechanism that prevents centralization.
https://heat-shield.space/mastodon_two_camps.html looks at tensions between people who just want a "better twitter" (which tends to lead to centralization) and people who focus more on small communities (a more decentralized solution).
You need urbit or something like it to fix it, the problems are deeper.
https://martiancomputing.substack.com/p/tlon-urbit-computing...
It needs to be a lot easier still (particularly the mobile experience isn't there yet without a fully formed app), but if it's been a while it's worth checking out again: https://tlon.io/
It'll be insanely hard to actually pull off, but it's the only attempt in this space that I think has a legitimate chance of a successful outcome. The others are dead on arrival because they don't actually fix the underlying issues. (Success being widespread adoption of software the users actually own and control.)
I personally self-host mine which has also gotten a lot easier too: https://martiancomputing.substack.com/p/product-review-nativ...
The UX needs to be just as good as a centralized service - I think urbit is the only design where that's really plausible (without recentralizing).
What do apple email addresses look like? I genuinely don't know anybody that uses an address that says to me "provided by Apple"... I do know a lot of people that use their corporate/organisational addresses for personal email though, which always surprised me.
Edit: just read that "me.com" email addresses are apple-provided - I have at least seen them used occasionally, though nowhere near as much as gmail and hotmail/live.com (outlook).
Still I agree -- decentralized paradigms that are successful seem like they'd end up with big players like you describe eventually. Still better than actually centralized like slack or something.
A pure monopoly (a single story) is rather uncommon and usually associated with government direction. Generally these don't exist without government intervention because if anyone is able to create a company, in any form, and sell the same product/service (in any form/price) then it's technically not pure. So doesn't happen unless it's illegal or some other factor. Whereas an effective monopoly refers to dominance in market share.
The reason a practical monopoly is used is because we need to look at the reason to why we discuss monopolies in the first place. Usually it is because they are bad (but they aren't always). The reason they can be bad is because abuse of power: they are able to dictate the market and force prices that are unreasonable.
So with this understanding, we usually call things like Coke+Pepsi a duopoly despite a combined market share of 68% (48% + 20.5%). Or we talk about oil despite OPEC not even being 40% (followed by Persian gulf, oapec, then US), and all of these are multiple players. Similarly we say the same about ISPs. The problem with these isn't that it's single player control, but rather significant market share and the leverage that comes with that, which includes the ability to reduce competition and effectively cornering the market.
I want to give this explanation so we can discuss on the same page and understand what each other means. Because when I'm referring to email (context clues should tell you I don't mean pure -- I mentioned multiple players) I'm referring to these companies abilities to force aspects onto others. Maybe a more clear example is browsers because Chrome's pressure is frequently discussed here and Explorer's previous history also shows similar influence.
I'm not saying decentralized services will become 100% centralized by a single player (it would be incredibly naïve to interpret my words to mean that), but that people will collect into a small set of servers (likely seeing a power distribution) who then have a clear ability to use their leverage and dictate the format of smaller servers. Effectively this is not too different than the power that Salesforce has over Slack. While not absolute power, it is closer to that end of the spectrum than a fully decentralized system. If you make the mistake of creating two bins -- centralized vs decentralized -- you are missing the entire point of decentralized systems. At least the point that is philosophically argued.
Try to realize that when people are talking they have different priors than you. Language is messy and communication is about the exchange of ideas. So even if you disagree with my definitions (neither of ours are objective) you can still argue my points. Just claiming semantics is problematic because it derails the conversation or creates artificial contention. See 5.11 of the Simple Sabotage Field Manual.
Since you mentioned email, there is also a large risk that filtering unwanted content and impersonators from appearing on your instance becomes so expensive and/or time-consuming that only a few instances have the resources to do it, just like happened with email.
I suspect that the above along with the cost is why it hasn’t happened. Although you do miss a lot of what’s going on by not being on one of the larger instances.
Jikes. Hadn't considered that. Certainly seems plausible, not just via technical means but also content. I've got a reddit profile that I try very hard to keep "clean and anonymous" yet I've had people from halfway around the world message me say "Hey you're Jack from X". Post sufficient volume and it becomes identifiable no matter how hard one tries.
Meta appears to be publicizing account associations that were previously difficult to confirm, in a way that defeats any previous efforts to maintain deniability.
But someone who uses a completely different site hasn't consented to the Threads terms of service, and if Threads randomly decided to dox people and alter their posts to add real names (or perhaps deadnames for trans folks), that's a very different matter, and I'm sure that their lawyers are going to tell them not to do that (or risk legal consequences). Since non-users haven't agreed to any terms of service Meta face real court, none of that binding arbitration stuff, and possibly class action if they do it a lot.
Person has been doxxed, the content is entirely on Threads or Instagram , they agreed to the TOS, and it seems very plausible Meta would do something like this.
Aren't there laws against that? are there even allow to build internal links between FB/IG accounts without user consent?
Instagram used to have different rules, but they seem to be trying to integrate everything.
Law is a weak form of mitigation for risk of harm. If it can be done and there is motive to do it, expect that it will be done.
Any rights that they are allowed to strip from you are gone as part of the ToS.
Unless there is a law saying what you said explicitly, then 100% for certain Meta gives themselves permission to do it when you sign up for either service.
This is false, there's been frequent discussion around how indexing and search should be performed in a privacy preserving way. Meta is just the latest concern.
[1] https://www.anildash.com/2023/01/16/a-fediverse-search/
[2] https://blog.joinmastodon.org/2018/07/cage-the-mastodon/
But they're a known entity with a long track record, which is how I know they can't be trusted.
Personally, while I certainly don't trust a random stranger, I trust Facebook even less.
Not that any of this matters, really. My opinion affects nothing.
I trust my grandma to make a good cake, but I do not trust my dad to do the same. But I trust my dad to be there when I call him, whereas I wouldn't of my grandma.
And that level of trust nuance comes from a long track record. To me, there is no other source of trust.
That's not the only alternative. Another is, literally, me, someone I know very well, with a lifetime track record that I'm intimately familiar with, known motives and the skillset to keep my information secure.
It's called "hosting your own instance."
And it doesn't stop me from following users on other instances, nor does it require me to accept the TOS of other instances either.
That said, I'm not interested in juicing my "follower" count or building/enhancing my "brand," nor am I interested in doing so for others.
That's the alternative. And when someone comes up with an AP hub that can interact with other AP instances like an email client (my Thunderbird[0] can talk smtp, pop3, IMap, xmpp, Matrix, nntp and more) that's a viable alternative for the hoi polloi. Until then, more technical folks like myself can just roll their own.
I don't really care what most other people say anyway, including (well, especially) "influencers", celebrities, politicians, advertisers and other scum of the earth.
So I'll just follow whoever I want to follow from my own AP instance. Or not, if I choose not to federate with other instances.
[0] https://www.thunderbird.net/
Edit: Added the missing link.
However, I do see the point of considering ways for instances to somehow distance themselves from Meta's instance. If another instance/admin was publicly known to comparably engage in pervasive user tracking (both on and off their own websites) and algorithmic attention monopolization, would we not expect many other actors in the fediverse to defederate or otherwise distance themselves from those practices/that instance? Obviously, several instances have decided to do so by premptively saying they will defederate. I'm just saying that I think it makes sense to at least consider it. E.g., compare the labels the data collected by the Threads Android app (https://play.google.com/store/apps/datasafety?id=com.instagr...) to those of the Mastodon one (https://play.google.com/store/apps/details?id=org.joinmastod...), and I at least see the contrast.
But perhaps this is just me being naively unaware of rampant community-sanctioned indiscriminate collection of user data in the fediverse (I'm not part of it, just curiously observing Meta's entry).
Yes they can go out and spider ActivityPub content already, though they probably don't currently bother. But what they will gain by being part of the fediverse is the ability to associate your interest in their content back to your identity and learn out a graph about you. Boost/like/share something off Threads, and you've helped them build a model about you in a way that they can't currently do with all the free content out there already.
I'm not sure why other people aren't making this connection. Again, the threat is that Meta could extend its abilities to build a model on how users from outside its own user database interact with its content and users. They're known to already do this in the form of tracking pixels on 3rd party sites already, but this is a richer source of information.
That said, I also think the Fediverse is so tiny that this particular market isn't of much interest to Meta in reality. I suspect this feature will never launch.
MeWe was nice though, really great communities on there back in the day
you seem to not even have read the first paragraph, or not understood what it imples
the whole point of this article is that meta has a precendence of aggregating and combining data from all kind of sources. This includes data which is not supposed to be public, but e.g. was sold without your knowledge, awareness or explicit consent. A situation you could argue the huge majority of people on the internet is in.
For example consider this hypothetical scenario:
So they might take the supposed to be public data of e.g. your anonymous political activism (lets say anti corruption in a very corrupt country).
Then take a public profile you created e.g. in your teens, which you never linked or used the same email address with as you politic profile and should have no connection at all (you acted carefully).
But then meta is like, oh see through the data we bought/own we know that that profile was using that (non public) email address and through other data we brought we know that that email is belived to be owned by the same person as that other email (e.g. you used is for forwarding or account recovery, also non public) so we conclude they are the same and publish *to the whole world trivially accessible that the anonymous political activists is you*.
Or another scenario: They used AI body/face recognition to make the link even through you never posted the face in you anonymous account without appropriate masking or at all.
Or another scenario: Metadata of locations leaked through the usage of social media created the link.
Or another scenario: Someone marks you on a image they took without your consent (and/or knowledge), doesn't matter if they later delete it or make it only visible to their frinds followers.
Or in other words as long as you don't live as a complete hermit and have far above average tech knowledge and also treat absurdly careful to a point where it causing major annoyance in your life stuff like that can totally happen to you.
This is why the GDPR was created to make it illegal to aggregate information about third parties without their consent in surprising ways. But it's also where it failed the hardest to archive it's goals you could say (but thats a different discussion altogether).
Mastodon and Fediverse however explicitly offers your data to them.
Mastodon and the fediverse explicitly offer public posts to everyone. Some sites use robots.txt to block search engines and web crawlers that follow the conventions. Others don't.
Embrace, Extend, Extinguish. Owning the vast majority of the fediverse userbase will cause them to have a large amount of power to compel users or servers to do whatever they want. What do you do when Facebook implements a new feature and all of your followers complain that your using a Mastodon server instead of joining Threads that has this feature they want? You either go against your entire community or let Meta takeover your account.
As such, the resolution is to not let anyone have this much power. It being Meta makes it easier to hate on them, but no single server should own the vast majority of the network, let alone (100M / (100M + 2M + 1M)) = 97% of it [1].
[1] Threads has 100M users and is rising fast, Mastodon was recently stated to have 2M active users, the rest of the fediverse can be estimated to be, say, 1M. As such, Threads has about 97% of the userbase.
The fediverse has somewhere around 10-13m total users, about 8-10m of those are on the main Mastodon network, and around 2-4m MAU. It's hard to pin these down precisely because different counters disagree (it's hard), but if you're going to take the most optimistic number from Meta (the only one you'll ever see), you should take the most optimistic from the other "side" as well.
Threads doesn't have an MAU yet because it hasn't existed for a month, but it will not be anywhere near 100%. Most people I've seen on it seem to have bounced day one and user growth has stalled a lot (roughly halving every day).
Sources for fediverse/mastodon numbers:
- fedidb.org
- the-federation.info (includes some things that aren't activitypub based)
- https://mastodon.social/@mastodonusercount
Threads numbers (only total users, pulled from badges on Instagram)
Google all but killed XMPP by using it in GTalk/GChat/Gmail/whatever it's called now. They probably had no ill intent from the beginning, but their very presence gave everyone the need to quickly be if not bug- then quirk-compatible.
By the time everyone came around they suddenly de-federated everyone and with vague references to spam, which everyone knew was bunk. But the damage was done.
Mastodon already did this to ActivityPub. Extending open protocols is important else people will stop using them in order to accomplish building what they want.
That's not a resolution, that's a wish. But how could it be achieved though? In 6 months Threads could well have hundreds of millions of active users, the vast majority of whom probably won't care about the fediverse.
> What do you do when Facebook implements a new feature and all of your followers complain that your using a Mastodon server instead of joining Threads that has this feature they want?
Mastodon (and others) either have to compete or their users will be like the people reading email in emacs or vi (no offence intended)
Take a look at Threads.net and Mastodon.social and tell me these two projects have anything in common. Everything is open on Mastodon.social (I can even use the search box) and everything is purposefully closed on Threads.net (I can't even see the basic metadata). It's all dark patterns since day 1. Meta is not givin up a sliver of control that's for sure.
Meta scraping your name and doing other shenanigans is a different subject and obviously bad, but the rest is like complaining joining a public torrent tracker and being mad about leaking your ip address to its peers.
Systemic data collection and casual access aren’t equal.
That said, on these protocols you can’t control it anyway, so it’s not like you can stop it.
They could have been scraping it for years (if they cared) and you’d never know.
Federating won’t give them anything new except DMs to their users since those aren’t encrypted.
All the existing stuff you’ve posted publicly is already public.
If being separated from the mainstream internet is the reasoning then yeah sure, go ahead, but you also can't complain why no one besides fanatics is using alternatives when the alternatives are not worth using for the mainstream audience.
I see the situation as similar
It is anti-privacy by design.
Once you've posted something to it, you have absolutely no control over who has that data and what they do with it. That's the fundamental design of the system.
Complaining about meta potentially ingesting all data from the fediverse comes off as a bit naive. Meta is the least of the privacy concerns on the fediverse. You at least know who they are and have legal recourse against them. Huge numbers of other consumers are not even known. Just look at the thousands of instances that have popped up. Many of which are just in joe bob's closet and god only knows how they protect the data.
Welcome to the Internet. It’s always been like that.
but if I'm posting to facebook/twitter, I have privacy settings that they legally have to adhere to. Of course this doesn't prevent all scraping/copying/whatnot/whathaveyou, but it's a lot harder to scrape a private profile than something on the fediverse. Most of these sites have a vested interest in preventing scraping and the like. I have some control even if it's not great.
Fediverse I don't even have an idea off where my data is much less what their security/privacy practices are.
I think we might need to be better about communicating this to new users: once something leaves the server, it is out of control.
ActivityPub, and Mastodon in particular, is very public-oriented though yeah. The feature-set and discovery stuff is pretty much inherently un-protectable.
It’s just Mastodon movement or whatever it calls itself don’t want to be associated with shady corners of lower classes or the human society, despite there shouldn’t be such classes and hidden areas in the first place, as in not trying to stigmatize, deny and nullify the fact that we’re dirty animals, but in constructively removing negative aspects of life.
Please ignore the people who die and are harmed in the process.
If you post incriminating content on a Mastodon server it is still out there whether Facebook can officially connect to it or not. It is archived forever out of your control. The server owner can be subpoenaed. Anyone can scrape the website, take a screenshot, or share it in a hundred different ways. Regardless of what pseudonym you use it can be tied to your real identity with 5 minutes of internet sleuthing.
"Private" online social media is an oxymoron. If you put something out there in the world you don't get to control whose eyeballs land on it. Facebook isn't the problem, your expectations are.
A "friend" may make a photo of you as part of a social/work event and directly post it publicly.
Even with no participation on your behalf, your real name, phone number, address and photo are out there.
If I don’t want other people to see something or to know about it, I don’t post it online. Or I don’t post it in a way that could be traced back to me. There’s absolutely no link from my HN account, for instance, back to me IRL.
Why open yourself up to the risk? What do you get in exchange?
I really believed that discoverability is king, and I should just be able to search a global graph of user profiles and read everything that everyone has ever said, but you're right, there's a lot of conversations that don't happen in public, and not everyone wants to be "discoverable".
So I think there's a case to embrace the balkanization of social media, and go back to having separate identities to be a part of each phpbb we signed up to. Going to different domains to talk to different groups of people makes sense, and we can have the modicum of privacy offered by a semi-private chat server like discord, so that your messages don't get indexed by google and archived forever. (Obviously discord retains all the message logs, DMs included, but at least its not publically searchable)
And global social media is always going to suffer eternal september. Smaller, unfederated chat communities is a probably a much healthier approach to social media than whatever it is we've been doing the last decade of meta-gramming
There's just no way to get enough moderation in place and get people to behave respectfully, and then it just gets ugly.
I remember BBSes back in the 80s degrading to uncomfortable useless places simply because of a few bad trolls or assholes getting in the mix. Now it's just ridiculous.
Small, comfortable social networks and a feed that I can fully control, that's what I want. Facebook and Twitter began their misdeeds the moment they rolled out algorithmic suggested content that I did not explicitly subscribe to.
I've mostly just retreated into a few discord channels for family and friends at this point, with forays into Mastodon here and there. Oh, and way too much time on this orange site.
this is the real problem. Mastodon and lemmy share way more information than they actually need to (like lemmy shares a list of usernames who upvoted or downvoted a post, not just a count), and if you're using one of those services you should expect that all your data and interactions are public. that's the actual threat here, not the possibility that facebook might suck up that data. Blocking Threads from federating is just a short-term patch over mastodon's bad privacy controls.
(I'm trying to play around with ways around this, like using a bot to instead publish aggregation events and making votes private, but it's an ongoing exploration.)
lemmy does not make it in any way clear that upvotes and downvotes are public information.
It's not a patch at all. Facebook (and literally anyone else) can still scrape or otherwise access that data in a hundred different ways. Blocking Threads is simply some server admins making an anti-Facebook statement, nothing more.
>A Nebraska woman has pleaded guilty to helping her daughter have a medication abortion last year. The legal proceeding against her hinged on Facebook's decision to provide authorities with private messages between that mother and her 17-year-old daughter discussing the latter's plans to terminate her pregnancy.
If you have information you don't want others to know, then don't tell your secrets to a multi-billion dollar pseudo-governmental organization that has even less data collection protections than the governments it serves. There's more you should do, but that's a big one.
People on Mastodon make this mistake quite often, tagging someone they're talking about, or realising that the person they tagged now receives a copy of their conversation.
This is a massive issue on top of the lack of end to end encryption. Both servers receive plaintext copies of the messages exchanged. I'm sure mastohub.ai is a safe server, but how can you be sure they'll never be bought out or hacked?
If you want to federate and share secrets, try something like Matrix or XMPP. They make it significantly more difficult to read your messages.
https://privacy.thenexus.today/fediverse-threat-modeling-pri...
that's such a naive egoistic apathetic world view it baffles me
sometimes I wonder if posting stuff like that just don't understand how humans and societies work, or just don't care because "they know better".
[1] https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extingu...
Personally I think it's more an "embrace, extend, and exploit" approach; a decentralized model could work well for Meta, for example if they do revenue-sharing on ads hosted by other instances (think Disney or LA Lakers).
Update: here's another good article looking at how Meta could embrace and extend -- again, not extinguish. https://darnell.day/heavy-meta-four-business-reasons-why-ins...
It's not like Google had "extinguished" anything, it's more like the "largest server went uncooperative and removed themselves". Sucked for people who were able to chat before and got separated, but I disagree with painting this as some sort of fatal blow.
I don't think there's some statistics on reasons why people stopped using XMPP, but I don't believe Google is the reason for it. I'd speculate that it just coincided with the beginning of the smartphone era and this whole "Google killed XMPP" is a convenient myth.
And the comparison is not fair. XMPP was meant to be extended, so complaining about the second "E" in "EEE" is IMHO questionable. Google left a bunch of useful XEPs and even a Free Software codebase (libjingle) that others still use to the day, and I don't see anything wrong with this (and I'm surely no fond of Google, but that's not something I'd bash them for). This is feels very different from what may possibly happen in the whole Meta/Threads/Fediverse/ActivityPub situation - I mean, it's not likely Meta starts contributing to Mastodon project or something. In my understanding, EEE is more applicable to Microsoft and IE (where it surely happened, and a lot) than to Google and XMPP.
IMHO the article is a good read to at the very least be familiar with the events and understand the argument - but personally I find myself disagreeing with the presented arguments, thinking it's quite a stretch. Of course, that's my own, purely subjective opinion.
AcitivityPub's also meant to be extended, there are FEPs, and it's likely that the working group will come up with a new version as well. That said there certainly are differences between XMPP and ActivityPub, most people say the ActivityPub ecosystem is significantly farther along than XMPP was.
I could imagine Meta doing an open-source AP server (and with a fresh start it would be cleaner base than Mastodon). I also wouldn't be surprised if the release a app building toolkit / framework / whatever ... there isn't a good one now, they do that stuff well, and as they introduce proprietary AP extensions then they toolkit is a good way to get people to adopt them. But it's very hard to know at this point, it's also possible it's just PR spin and they won't really invest in it. We shall see.
Anyhow, good discussion, thanks much!
- ActivityPub is an open protocol. If Meta goes all-in on it, they'll be implementing a transparent spec everyone knows. Modifying that would send obvious shockwaves through the network and signal their non-cooperation. There isn't a covert way for them to really try this.
- Mastodon itself is AGPL licensed, meaning any Meta fork (for whatever reason) would be subject to "provide the source code of the modified version running there to the users of that server. Therefore, public use of a modified version, on a publicly accessible server, gives the public access to the source code of the modified version."[0]
- Meta has no reason to. If they decide the app is sufficiently popular without ActivityPub integration, then things return to the status-quo for Mastodon. Meta loses what little control they had over the direction of the standard/protocol/applications and nothing really changes.
I've been thinking about this in terms of Lemmy (also built on ActivityPub), which I understand isn't currently on the table for interop (but if Facebook is after Twitter's lunch, why shouldn't they be after Reddit's). It could even be the same application - Kbin is another AP service which has separate tabs for "link aggregation" and "microblogging" (Reddit and Twitter, respectively).
With Lemmy, the way a large corp could come in and push it around is by simply creating it's own version of the top 100 (or N, whatever) communities, and automatically subscribing users into them based on their interests (already known, due to existing accounts/profiles elsewhere). c/linux on lemmy.ml has ~6k subscribers, and is the largest Linux community on Lemmy, afaict. It's not unreasonable to think a large corp willing to pull in its existing userbase couldn't increase that by an order of magnitude in very short order. Overnight, those communities become the place where conversations are happening on those topics (maybe even with some pre-seeded content) and the existing lemmy communities stagnate.
Fast forward a while and one day BigCorp decides to pull the plug. Existing non-BigCorp Lemmy users are now separated from the communities they've been in and need to create BigCorp accounts. You could argue that those non-BigCorp Lemmy users are no worse off than they are pre-BigCorp-federation, but they're effectively migrating their communities all over again.
As far as why, I think it's pretty invaluable for Facebook to:
1) appear to be "playing ball" from a regulatory aspect 2) eat a competitor's lunch 3) control a (potentially!) up and coming federated service
I assume they will do the same with the ActivityPub compatibility. I don't see it as a permanent plan.
The real risk here in my opinion is the influence that Threads could have over the Fediverse indirectly. What if they become an integral part of it and threaten to leave, or just leave? What if they become the defacto censor of what instances you can federate with, by virtue of cutting off anyone that doesn't defederate certain instances? Etc, etc.
The privacy concerns, while they hold some validity, are a little bit moot for people who weren't going to consider using Threads in the first place. Google hoovers up all of this data already if only indirectly, and nobody seems to bat an eye.
Meta has zero interest in ActivityPub or the Fediverse, a tiny speckle of users hostile to them. In less than a week, they've created an "instance" 50 times the size of all of Mastodon and the rest of the fediverse combined. The projection/goal is to grow towards 1B MAU, which would make it 500 times larger than all of the rest of the fediverse.
Why would Meta possibly care about this tiny group of misfits? The only reason I can think of is to give legislators the idea that they are "doing good".
Say it is done, and we have this Threads cosmos-sized instance. Tiny vocal Mastodon instances will defederate out of principle, and nobody cares. Because they are anti-growth anyway, they object to anything.
Larger Mastodon instances will consider federating but will then find out Threads will only do this under conditions. You have to serve ads, have to comply with a moderation policy, treat user data in a certain way. You effectively work for Meta now, but unpaid.
Then you turn the thing on and the flood gates open. The first thing you'll notice is your bankruptcy as your few tens of thousands of users now having follow access to a billion users, including very active and popular ones, spiking your infra. 10x? 100x? Who knows? And what about storage? Yesterday I've read how a mid-sized Mastodon instance (few thousand users) was adding 1GB of media storage every 15 mins. Do that times a 100 (or 1,000) as well. Your moderation inbox...well, good luck.
This entire thing isn't going to work, at all.
Also worth consideration: They could federate your Facebook feed in the future too.
It may not be so much supporting the protocol from the outside as its worth doing from the "inside".
EDIT: I'm not talking about full blown customization here, just enough that allows creators to make their direct profile feed look different from the standard app, maybe have targeted links or a special background color etc. Simple but differentiating things.
Ultimately I think their play here is they want to build their social graph and interaction model around users that are not on their network right now. Every time you boost or share something that came out of Threads, they'll learn something about you -- a non-Meta user -- that they couldn't get just from mining public content. But I think they'll find they're actually not interested much in that data, that its value isn't high enough to justify the hassle.
I just think it's a tempest in a teacup and by the autumn when it's rumoured to be supposedly launching, we'll just stop hearing about it. Or there'll be a trial for a bit and then it'll just get unceremoniously dropped.
If you want true privacy, make a centralized self-hosted service where people have to be allowed in explicitly.
Don't see what the problem is in the OP, they are kind of expressing displeasure that a service that technically can be scraped by almost anyone is... you know, scheduled for scraping and exposed. And at the same time nobody actually bothered to prevent the scenario from happening.
And this also looks very much like the early internet: people didn't think others are malicious so security was minimal.
This kind of naivete really needs to get clubbed to death. We can't afford being as naive nowadays.
The issues in the article are related to how ActivityPub/Mastadon work, if you are concerned by privacy issues, don't use Meta.
Meta is guaranteed to erode your privacy, being outside doesn't come with a guarantee of being bullied.
I'm quite convinced that Meta actually does have the real name of most of us as well as the ability to link it to other accounts. But the idea that Meta would willingly reveal this without the user's consent means a planet-scale doxxing event. It could lead to actual deaths in the real world, and they would be legally crushed.
What is far more likely to have happened is that the user had an Instagram account with their real name and used that to log in/sign up to Threads. There is no stand-alone account on Threads currently.
Meta is not known for being a good citizen, but unlike sending fake notifications or tracking which helps them achieve a business goal, updating user profiles without consent achieves nothing of that sort.
It could lead to actual deaths in the real world
They've already been there, just it wasn't white people.Myanmar https://www.nytimes.com/2018/10/15/technology/myanmar-facebo... https://edition.cnn.com/2021/12/07/tech/facebook-myanmar-roh... and Dutertes drug war in the Philippines https://www.buzzfeednews.com/article/daveyalba/facebook-phil...
I don't use Fediverse nor Meta/Threads, but I write stuff that is public and anyone can view it, or private which only the recipient should read, like anything else, whether I post on Hacker News, or on Usenet, or on a public IRC channel, or whatever else it might be. (Some people don't like public IRC logs, but if it is a public channel then I would prefer that it does have logs; fortunately some IRC channels do.)
Meta has the scale and scope to make it scary, but the point of the Fediverse is that it is federated, which implies some openness. If you're federated, you are publishing content to other people that they might do whatever they want with. That includes crawling it, storing it, indexing it, and building mass profiles. You can certainly protect yourself by blocking bad actors, but since the network is, well, a network, an aggressor that wants your published data need only find access to a node you do want to share with and copy from there.
So you either default-close your data and choose very, very carefully who you federate your node to or... You don't put that data in the fediverse at all.
(Contrasting to a walled garden, where monolithic control of the data storage and transfer means a single entity is responsible for where the data goes and can constrain at will. If someone's kicked off Facebook, they're off Facebook; they have a single attack surface they have to reenter to get to that data, not O(nodes) they could make an account on to reach the data of someone who'd rather not share it with them).
You can't have perfect privacy in a system that has the exact opposite goal: federation. It means your data spreads by design and enforcement of any privacy-preserving feature is optional per instance.
The very loud minority on Mastodon that obsesses over safety has picked the wrong software. They should have just created a Telegram group.
It's my understanding that Libs of Tik Tok simply reposts public videos. Say you manage to find a way to block them specifically from seeing your content what's to stop another account springing up and doing the same thing. The only option is to keep your content among friends. But then you have another trust model where your friend could be the next Libs of Tik Tok.
It does look like something idealistically-minded early techies would justifiably find really cool.
It may indeed be desirable for, say, Dutch government (and perhaps any government that wants to be transparent).
However, I’d argue it may be from suboptimal to harmful for regular people.
Regular people may have to worry about future governments, which may or may not end up less transparent to hostile towards them, as well as other powerful adversaries. Regular people may want to be careful and value features like transience, privacy, and plausible deniability.
Perhaps we can do better and come up with a protocol that combines openness and those values. Whether Facebook enters the Fediverse with its new product or not, ActivityPub in its current shape and implementation seems to be a liability.
And "I want random people to see my social stuff (cos I yearn for attention) but not that particular person/corporation" is unsolvable problem
If fully precluding public and private intelligence is infeasible, that does not mean we should be using a protocol that in many ways is optimised for public and private intelligence.
Privacy, like many things, is a spectrum.
I absolutely disagree if you want to keep the data public but make it "harder to scrape", i.e. remove all APIs bury it in some annoying HTML/Javascript mess.
That would absolutely punish the wrong players: Having an API which allows easy access to structured data allows all kinds of desirable usecases, such as being able to use whatever client you like.
In contrast, the big players who are interested in tracking the entire userbase already have enough experience in building robust scrapers - they won't be deterred by a closed-down API.
I understand the Meta hate, but joining a very explicitly public and intentionally republishable service and then being unhappy that your data is public and intentionally republishable is bizarre to me.
The irony to me is that any chance of relevance for a protocol is obviously going to need big players like meta to sign up (and that's a good thing for the protocol).
A weird set of circumstances might have aligned where meta sees an advantage in being part of a federated protocol to commoditize a threat to themselves (twitter, bluesky, etc.) and still hold a dominant position in quality of the end user clients (which is the only thing 99% of users care about).
It's a little funny a lot of the mastodon hosts are up in arms about this, but not that surprising when considering what they're actually getting out of being part of it (the identity stuff that comes along with being a mastodon user).
I'd guess similar stuff was said during the eternal september era of the web itself - simply being an internet user was no longer an identity that meant something culturally specific.
Example: download the supposedly privacy-focused app pCloud on your iPhone, start it up, and check what IPs it's hitting. That's right, it's hitting facebook tracking servers.
This is not a tribal ingroup club thing. It's a "fuck off, megacorps" thing.
I thought "mastodon.social" was based in Germany, heart of GDPR country but there is no consent theater, no harassment by cookie popups, certainly no controls over data.
I really don't mind, but there is some serious cognitive dissonance there.
Comparing the sheer amount of data that Meta/Facebook vacuums up to the privacy practices of similar apps is instructive.
https://www.wired.com/story/meta-twitter-threads-bluesky-spi...
In practical terms, Facebook is actually quite tame compared to any other malicious actor who can get the same data. FB just wants it for ads and processes it in aggregate (most is never seen by a human), while other malicious actors might actually target you personally.
The main issue is that you shouldn't post anything on a public, unauthenticated network that you wouldn't want random, potentially-hostile actors to see.
It's the same effect as any platform that tries "free speech" invariably becomes a nazi echo chamber, because the only people who WANT to use the less popular system are those that CAN'T or REALLY REALLY REALLY cling to their ideology.
The working group was closed after browser implementers failed to express interest. As I recall, Microsoft Internet Explorer was the only browser participating. https://learn.microsoft.com/en-us/openspecs/ie_standards/ms-...
I could be mistaken/mislead about the purpose here. But this idea of having the data be able to advocate for itself what rights other people have seems semi-obvious. It won't prevent abuse, but the age of ultra-Legalistic DMCA corporate hawkishness seems largely to have won above almost all others, in most arenas, and this idea of sticking a "you can't do that" label on stuff thus seems like a pretty obvious first level defense. One that big data warehouses & big companies in particular probably couldn't violate & keep under-wraps.
2 Said well elsewhere but its daft to want to hide public info from a subset of users on a protocol designed to distribute public data.
Who gave FB permission to conflate two different identities?
The law says they don't need permission to do something like that, regardless of any morality or decency issues that causes. The law is often not aligned with morality.
Most people seem to not really get this, even when they objectively know it, or are otherwise unable to imagine what could go wrong, because doing so basically requires you to be the unhealthy kind of imaginative and paranoid. "What if facebook doxxes me and changes my display name" SEEMS like it should be an insane paranoia, because the human brain isn't equipped to handle extremes of scale and bureaucracy like this.
Meta would have no more (extra) access to Fedi posts than an large Mastodon instance like Mastodon.social would have.
I'm not sure I agree, privacy can be achieved via anonymity. Use a VPN, block cookies, change usernames, etc
And guess what happens when Meta refuses those DMCAs? You go to the networks they peer with. You don't screw with tier 1 transit providers, not even Facebook has some magical power here.
This isn't, and was never, about privacy. It is 100% about Meta stealing data and displaying it so they can pretend people are using their product, so it looks active, and then they can tell their shareholders it was a successful launch. Nobody in the Fediverse wants to help Zuck profit from people's hard work that they didn't donate to him (ie, post on Facegram and thus license it to him).
The flip side of this is also, how will they moderate data that isn't theirs? They will have to unfederate from certain servers and users, thus solving the problem.... and if you've seen the fediverse, its 20% trans catgirls who code in rust, are part of a polycule, wear programmers socks, and have spicy opinions about niche Linux distros, all of which are persona non-grata on the Instabook platform.
The catgirls are going to save us from Zuck slathering the Internet in Sweet Baby Rays. This wasn't the future I was expecting.
They have done the opposite of a moat... they built a bridge across the moat that is around the prison island everyone is trapped in.
Meta's moat will be that they will be the largest home domain. They'll have the most user data and they'll have a secured user base even if the fediverse collapses.
But privacy is not the issue with Threads. The issue with Threads is that they're going to attempt to destroy the Fediverse through standard Embrace, Extend, Destroy tactics.
You see this with Bluesky as well. The point is to interoperate when it's in your interests and then break interoperability when you have enough of the audience. Thus, thereby capturing the lion's share of the audience.
Just wait. Threads will soon have a 'new feature' that only works with Threads and that does not work on other Fediverse nodes. Then they'll try and poison the standards bodies working on ActivityPub. They could increase the velocity of new 'features' to ActivityPub so fast that unpaid OSS developers couldn't keep up. Like Google and that cartel do with browsers. Eventually Meta and maybe a couple other large players will control the standards, or atleast make it obtuse enough to prevent new entrants. This playbook is tried and true.
For sure Meta cannot be trusted to be up to anything kosher especially since social media tech is close to the money spinning core of the Death Star.
But what "stolen" audience are you worried about? The existing million or so fediverse users that will be lured back into the lethal embrace of the move-fast-and-break-things brigade? Future fediverse users that cant tell whether they are joining a surveillance apparatus or, e.g. their local community instance? Threads is currently cannibalising Instagram in the hope, pressumably, of grabbing some pieces from the decaying corpse of Twitter. All quite morbid affairs that dont have overlap with the migrants escaping to build a new life in the fediverse.
The issue of subverting the fediverse standards is more serious - in principle. But the tangible threat is not clear (to me at least). E.g., the protocols are low level, minimum interop standard, they specify nothing about how server platforms can (ab)use their users. This is all down to implementations.
In any case if you dont want corporate control of a standard make sure you dont take any corporate money and if they insist to join the fediverse party give them one vote like every other solo fediverse pioneer.
The fediverse is being noticed. Thats a good thing. Savvy PR by fediversians could spin Meta's "interest" in the project to open doors that they could not dream of. Granted PR and marketing is not the fediverse's strong point. Its better this way even if it makes the job of adoption harder. But lets not get scared by shadows.
This will make Mastodon pretty much useless if it can just block networks..
1 - I mean on the US where Meta really cares about. It's probably one on most countries where Meta has revenue, but that won't send anybody to jail.
It's a crime to obtain public data published on a public network built on a public protocol explicitly designed to share data? Isn't that the whole raison-d'être of mastodon?
That's not what I said, and not what is on the article.
There are various processes at Meta that do require identification to be submitted and in some cases that information will be published. For example, to be verified on Instagram you must have your name be published. Likewise, certain Facebook pages must publish their operators identities.
Most likely the person in question submitted their identity documents to Facebook (perhaps their account got locked) and they didn’t realise they were agreeing to that information being put on their profile.
The concern is valid — Facebook has information users might not want public — but the cause isn’t nefarious. Facebook is not finding an anonymous sex workers identity and then intentionally outing them.
They are?
Collecting personal information is central to Facebook's business model. Facebook's policies mandate legal names.
> Most likely the person in question submitted their identity documents to Facebook
Most likely this person would remember that.
> The concern is valid — Facebook has information users might not want public — but the cause isn’t nefarious.
Surveillance capitalism and legal names policies are nefarious.
It's hard to take the post seriously when they make statements like that, From the linked article:
> Fuentes, who claims to have been banned from Meta's platforms, announced in a livestream on July 6, “I signed up for it last night. I made a fake Instagram. I got on a fake Thread.”
I'd guess of the 100M users that have signed up lots of people that are banned, or post content that gets banned on FB and Instagram have managed to make accounts too. But I'm sure the same content moderation policies on FB/IG will apply once they start posting, some will get through, but that is far from being welcomed.
Amazing, eh?
Also ActivityPub as I understand it has two separate forms -- a client mode, and a server to server federation mode. When/if they do implement ActivityPub, it will likely be the latter that gets implemented not the former.
Sigh.
https://qz.com/333313/milliions-of-facebook-users-have-no-id...
https://en.wikipedia.org/wiki/Internet.org
https://www.wired.com/2016/01/facebook-zuckerberg-internet-o...
I'm glad I just routinely obfuscate my online presence by lying on every different platform.
Blocking threads? Do we need a mutex here? Faster I/O?
What would they gain?
Things you post publicly are public.
What does that have to do with anything? Mastodon is explicitly setup to allow all user data to be harvested. What Threads supports or doesn't support in the end has no bearing on Mastodon having all user data public.
If you want to control distribution of your data, don't join a federation designed to distribute data. Trying to blacklist nodes in a graph that you don't control is not a solution.
Information wants to be free, if you post something to a social graph assume everyone in the graph can see it forever.
To me that still seems fairplay on a platform that's designed to be open and heralded that way. Not a opinion I hold strongly though.
"Even if I only make followers-only posts, which aren't public and can't be boosted, if somebody who's following me replies, any of their followers on Threads will see my account name and instance" and also "If somebody on another instance who follows me boosts one of my public or unlisted posts, people on Threads who are following them may be able to see everything I've said in the post"