• 1 Post
  • 71 Comments
Joined 3 years ago
cake
Cake day: December 18th, 2023

help-circle

    1. Yes, people are used to monopolistic social media. Doesn’t mean that there shouldn’t be an alternative. There simply are a lot of things that you cannot do without an authority that grants or denies access to data. If you want the advantages of openness, you have to accept the downsides.

    2. I don’t know how that is an argument for anything. If people are more comfortable voting and not posting, maybe we should make posting anonymous.

    3. Repeating a rejected assertion is not going to convince. You strip the username from data. Give me some reason why it would be easier when the data is short. People want their posts to be seen. That doesn’t mean they want their usernames seen.


    1. The problem with trad SoMe is that it is monopolistic. That’s because these companies “own” the data and gate-keep access. If you want open social media, you must not have a gate-keeper. Which means that you can’t have someone who controls access. That’s a fundamental trade-off.

    2. So what? Should posts be anonymous as long as they are short?

    3. No. It’s always data+owner. It doesn’t matter if the data is only a single bit.


  • Mastodon is built around individual posters. When you interact with a post, you interact with the author. Lemmy is built around “communities” (discussions forums) and individual threads/topics. Having multiple different servers handle the voting for a single thread makes much less sense.

    The obvious problem is that the author/their instance has a vested interest in up/down votes.

    To me votes are a way to signal to others if they should bother reading something. I’m not quite sure how that works on Mastodon. I don’t think likes influence visibility outside the home instance?

    The author is interested in getting their message out. Think about someone trying to sell stuff, for example. They would want to manipulate the visibility/apparent popularity of a post. Such a party would also be most interested in the identities of supporters/detractors.

    If you wanted to create psychological profiles, you could create bait messages and observe the reactions. That would be much more effort, but if that is a concern, then that probably isn’t good enough.


  • It’s not clear why voting should be private when posting is not. Your posts reveal much more about you than your votes. Voting only signals to other people that you believe the content is good/a waste of time. Eventually, the arguments for anonymous posting/voting are the same.

    It is a problem that it is obfuscated that votes are public. When people don’t know that, then they may be tricked into revealing things they might not otherwise.

    I believe there is a place for both anonymous and pseudonymous posting/voting, but not for half measures. Anonymous and pseudonymous posting shouldn’t be mixed. That just opens the floodgates for all sorts of manipulative practices.




  • GDPR-wise, this is the absolute nightmare scenario.

    Data about the political orientation is defined as especially sensitive (“special category data”). When people just straight post their ideological leanings, that’s one thing. But what’s described here is profiling. All the available data relating to a person is analyzed by “automatic means” and used to assess their leanings. This then is used to discriminate against them. It doesn’t get much worse.

    This might be legal in very specific circumstances. EG non-profit religious or political organizations are allowed to police their members and associates to some degree. That would involve quite some extra paperwork. But it doesn’t apply here anyway.

    Apparently that is on top of ordinary GDPR violations. The processing is done by a third party (OpenAI) without the necessary paperwork. You remember that billion Euro fine that Meta got? That was because they processed data outside the EU, in the US. And that wasn’t even “special” data.

    You know how those cookie banners in the EU look like? That’s for normal data. All the disclosure, all those settings are legally required. Some people on the Fediverse go apeshit over far smaller things.

    This may also be a problem for other instances. Your instance sends all your data (except e-mail and IP address) to anyone in the world who asks, with no strings attached. That may be okay as long as users understand that that’s exactly what they sign up for. Looking at comments here, it doesn’t seem like that is universally understood. That’s a problem. On top of that, we now have a situation where there are hints that the personal data is being abused.





  • There has always been a tension between GDPR and the Fediverse; more generally, between European laws and the Internet. That’s why Europe doesn’t have the Big Tech companies. Europe demands a lot of control over the sharing of data. That’s difficult to reconcile with the decentralized nature of the Fediverse, or the Internet as a whole. The Künast case is really only one example.



  • The EU has similar but generally harsher laws. The copyright lobby is extremely powerful. They literally control the media. In the US, this is slightly tempered by the traditional commitment to free speech.

    Europe demands that you follow their law if your service is available to them. You may have noticed the legal fight between the UK and 4chan? (BBC story)

    In the EU there is a lawsuit regarding the matter. The ECJ will soon decide. It’s about the diaries of Anne Frank, which are public domain in most countries, but not in the Netherlands. The Dutch Anne Frank Foundation offers a free edition on the net, but in deference to Dutch copyright they geoblock the Netherlands. The rights owner, the Swiss Anne Frank Fund, is suing them with the argument that geoblocks can be easily circumvented via VPNs. (Heise story)

    So that’s about where we’re at.






  • You don’t need age verification if you run it for your family and know everyone’s age.

    You could run your own family forum just fine. The problems start when you want to federate. Let me be crass to make the point. Say someone posts child porn and that gets federated to your instance. You think you can just declare that someone else’s problem to avoid legal complications?

    The way I expect this would work, is that instances would become responsible for who they federate with. If an instance allows your family instance to federate, they would allow your users to indirectly use their instance. We’ll have to wait what lawmakers or courts do, as you say. But I think, federation would only be by manual approval after some sort of check for compliance, or maybe even a legal contract similar to how it goes in GDPR. Actually, such GDPR contracts might be required anyway, but who cares.


  • I hadn’t considered if existing legislation might already require implementing an age verification when l posed the question. Now that you bring it up, I fear it does.

    The DSA has exceptions for small companies. But I would caution that there is no case law that supports your interpretation that users should be counted on a per-instance basis. Courts are often not very receptive to attempts to avoid rules through such formalities. Bear in mind that the DSA is supposed to protect the “fundamental rights” of Europeans, which may not include running an instance.

    Other laws do not have such exceptions. This app seems poised to become the required age verification mechanism, wherever age should be known. Either use the app or show you have something better.

    In January, a Berlin court ruled that TikTok was in violation of the GDPR for not doing enough age checking. It’s being appealed. It remains to be seen how much of that case will be applicable to the Fediverse. But there is a good chance, that even without new laws, age-gating will become mandatory through case law.