this post was submitted on 18 Aug 2024
814 points (97.9% liked)
Fediverse
28789 readers
622 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Your votes are already public. It’s a matter of (a) do we want to make it slightly easier for the people who aren’t technically inclined to see them too (b) do we want people acting with the awareness that they’re public.
(a) doesn’t have a clear answer to me. The answer to (b), though, is clearly yes.
People say this all the time, but it's not really the case.
I don't think privacy is a binary thing that one either has or does not - there are degrees of privacy. Currently what we have is mostly private, requiring either technical skill or admin access to circumvent. This is a pretty high bar which 99% of people would not be able to reach. You're proposing removing the bar entirely because it is not high enough.
What if some troll sets up a website that indexes/publishes this data? What technical skill would be required then?
The data is public and ignorance is not bliss. People need to be made aware of this. If this will lead to people being more careful about what they post online or how they interact with a public social media service, then all the better.
They'd get defederated.
Ok, yeah, theoretically.
But we're talking about putting voting info into the UI for anyone to see. Not highly motivated and skilled bad actors.
And the "we should not make it available for the public at large because it will lead to abuse" is also theoretical.
Anyway, I'm already on record saying that I don't like the voting system and that we should get rid of it altogether. Voting on content used to be about collective curation, not a constant popularity contest.
I'm also on record saying that we need to stop relying on systems that only give us the illusion of privacy and depend on the software developers for culture shaping.
If making the vote public gets people to be exposed to these fundamental issues of the current design, and leads us to search for better solutions, then I'm all for it.
It's not theoretical to se how people consistently behave when there's less friction for toxic behavior. You should look into it if you're not already aware of the very predictable negative outcomes that stem from removing those frictions.
I mean in the specific case of "giving vote visibility to everyone will cause more harassment based on who-voted-on-what". It's theoretical because this has not been implemented yet.
We've already seen that kind of harrasment on major platforms including X and those owned by Meta.
This feels a bit of a conversation-shutting argument. Lots of things (good and bad) will happen on a platform that has billions of users. The real question is to about many of those instances happened solely due to the data being (easily) available to the public.
In any case, I really don't think that the solution to the problem of targeted harassment is by providing quote-unquote-privacy. Today, people want to obfuscate votes. Tomorrow it will be subscription lists and later it will be even posts/comments. By then it will be better to just use a closed network or just go full darknet. I'd rather we spent more time educating the people on how to use actually secure and private communications platform instead of sacrificing Transparency and Accountability for the sake of a vocal minority who will keep trying to turn the "Open Social Web" (which is meant to be open and public) into their exclusive, cocooned service.
That's because it's supposed to be. I was on Reddit for a decade until their management shit the bed, and these kinds of problems weren't a thing there despite the much larger userbase.
For the record, to me it's less about privacy and more about setting expectations. I'm not anonymous online, I'm pseudonymous, I've had this handle for a long time. I am my online identity, and when I post and vote I don't feel anonymous, even if I'm relatively protected from someone knocking on my door or messaging my boss about a statement.
If voting "ledgers" aren't presented in the discussion, that's because they aren't intended to be part of the discussion. This reduces the value of influential individuals votes (ooh Bill Gates liked X, Kamala Harris disliked Y etc.) and shifts focus to how the community values of the content. It’s the same reason that we follow communities rather than individuals. We get an internet "hive mind" of sorts without cult of personality.
These specific kinds of things were not a problem, yet it didn't stop the mob from doxxing people "by mistake", getting the police breaking into people homes based on false allegations or getting people fired over something stupid that was said years ago...
If this is about "expectations" of privacy, then it would be better to just expect the worst always and only write/post/share things when you are 100% sure you don't mind them being ever attributed to you.
Expectations of what is part of the discussion, not expectations of privacy.
As for doxxing, that's a problem with all social media - but possibly worse on the "regular" ones (people having mobs attacking their houses, being arrested in countries with censorship laws etc.)
It's in the mbin ui already
So the technical-skill-bar is transforming a lemmy link into the equivalent on an mbin instance? That is huge.
It's not quite that simple. As far as I'm aware, it's difficult to fetch from another instance "after the fact" what all the votes are for a particular user or comment; you have to be signed up to receive updates on it, and then after the fact you can go hunting around in your own instance's DB and see what all the votes were (or your UI can do it, if it's supported).
But, yes, there are instance softwares that will do it, and no one's defederating from every one of those instances (nor I think should they). Someone posted a link to an mbin instance breaking down the votes for this post. Votes are not private.
I ran
curl "https://mbin.grits.dev/u/mozz/outbox?page=1" -H 'accept: application/activity+json'
and I could see your outbox. Apparently mbin does not put Like/Dislike activities in there, only your comments/posts/notes.In a world where ActivityPub is only used in server-to-server, this would be fine. If we ever get to a (IMNSHO, better) scenario where we have more clients talking AP directly, then this will not work, and mbin will have to add those as well.
All of this to say:
Yes. That's what I said. I'm actually not 100% sure about it; for all I know there's some way to get it, but AFAIK all the existing softwares don't publish votes "after the fact", only at the time to current subscribers. But then, of course, it's kind of a moot point because you can just grab it from any mbin instance's DB through the UI without needing to do anything special or any particular knowledge.
Not really. You can have your client talking to all the servers and grabbing votes for whatever you're subscribed to, and losing votes for anything you're not subscribed to. It works basically exactly that way for one-user instances already.
Tru dat. 100% agreed. It seems like there are all these people in this thread arguing that their votes need to be private. Their votes are not private, and will never be private, for as long as ActivityPub is what they're using. I can see some value, maybe, to making it slightly difficult to extract the information instead of just giving it for free to everyone, but holding onto the idea of your votes being private is a gateway to unhappiness and only unhappiness.
It works like that for servers because servers are assumed to have high uptime, so (in theory) push-based communication should be enough. However, we see that this is not true even for servers (e.g, medium-sized instances getting out of sync with LW because they can not keep up with all the data being sent to them) and this will be specially true in the case of a network with tens/hundreds of thousands of separate clients. No server will be willing to push activities to all those inboxes, so we will need to have some pull-based form of communication as well.
Oh, yeah, at that point it'll be a scalability clusterfuck. No idea what the solution is. Maybe something with persistent caches run by third parties or something? That actually would be fine, since all the actions are signed with the private key of the actor, I think.
ActivityPub is not to me a real great designed protocol but it's whatever. Usually the key part for social networks is the "social" part of it; the protocol or the web site can be pure shite and if people like interacting with the other people there then it's fine. But yes, you are correct that beyond a certain point of scalability there are some dragons lurking that don't have obvious weak spots.
The problem is not with ActivityPub, but the implementations. No one ever claimed that it should be only a push-based system, but it seems that everyone working on AP software can only think in terms of server-to-server interactions to get the data and then reinvent the wheel by developing their ad-hoc API.
AP is fine if we treat it as a messaging protocol and use it to power offline-first applications. The devices do not need to have all the network's data, just the one that the user has actively interacted with.
How do you know who you're defederating with? When I set up my instance, the list of federated instances was thousands. How do you know which one is scraping the data?
How is the data public? I’m asking in the most technical sense?
This informs an issue I’ve had lately with a group of three people or bots following along my comment chain (All my comments, for a while, were dropping consistently to -2 score in all contexts).
It’s my understanding that votes are not public. Am I wrong?
Every comment/post/vote made in a community is sent as an activity to the community's subscribers.
All votes are public, they're literally broadcast to the Fediverse writ large. You vote on something on your server, your server then tells the server owning the thing you voted on and that server then tells anyone who is interested (subscribers on other servers). That way everyone knows that this comment was voted on, but that information is indelibly tied to you - an entity on the Fediverse.
Lemmy devs just chose not to a) show that information in a UI (plenty of other software out there does) and b) not inform people that was the case. Which leads to the whole point of the thread, hiding this from users merely gives a false sense of security.
Your idea of a nice world and mine are very different.
Yeah, I do my best to avoid cliched references, but this is 100% a "blue pill/red pill" dilemma. The majority of people seem to prefer to live a comfortable lie than face the harsh truth.
Incorrect. I said that I see no obvious answer as to whether to remove the bar -- that's the (a) part. What I'm proposing to do is definitely to educate people about the existence of the bar and the fact that they shouldn't be voting on porn, or contentious political topics from an account with their real name, or etc etc like that.
More than 1% of the currently active Lemmy users are actively running a server (it's 1.4%, 649 active instances out of 45k MAU), so I think the number is definitely less than 99% of people who wouldn't know how to do it in the first place (or find an mbin or Friendica server or etc).
The broader point about it being fairly difficult / fairly rare to have the knowledge, I can agree with, but I wasn't saying necessarily that we should make it easier for the 98.6% of people to do; just that everyone should be aware that it's possible so they can make their voting decisions with that knowledge in mind.
You say that, but you simply have to be using something that isn't Lemmy and that information is there (doubly so if you're an admin on any of these systems)
Except that it is, people with the skills already bridged that gap for everyone.
https://kbin.earth/m/fediverse@lemmy.world/t/267356/Lemmy-devs-are-considering-making-all-votes-public-have-your/favourites
Hmmm I see a bunch of my friends have not upvoted my post. I will contact them to ask why not and ensure that they do.
Yeah, just like rglullis actually dragged downvoters into the public on a few occasions, to pressure them to explain their downvotes.
Ach, well, a known method to create a nice discussion
I agree with the general point that privacy isn't a binary thing, but I don't think the bar is nearly so high, as it simply takes opening the post in the right kbin(/mbin?) instance. This requires neither technical skill nor admin privileges.
piefed is already extremely redditty maintaining behind-the-scenes 'karma' and 'attitude' for users whether they signed up for it or not. why shouldn't this info be public instead of in the hands of admins only?
https://join.piefed.social/2024/06/22/piefed-features-for-growing-healthy-communities/
Oof, I'd rather just stick to Lemmy and let people see my votes rather than deal with karma.
Summed up my whole sense of humor in half a throwaway sentence ;-)
Seriously though, interesting read, thank you kux… you can really feel the author’s frustration and yet I can’t help but feel that they are interested in a certain kind of idealistic online community. Reddit but with a really restrictive HOA where everyone has the exact same color mailbox.
the author almost certainly has more experience in managing online communities than me (i have none) but it seems counterintuitive to see a dumb take, downvote and bother to leave an argumentative reply rather than just downvote and scroll past. downvotes in this case would defuse potential arguments rather than start them, but i'll defer to the author and assume that's not what happens
That was my take on it too. The vague sense that you’re just going to end up with nothing but circle-jerks if you implement all these suggestions. I could also just be whooshing an attempt a levity, something obvious to a seasoned community moderator.
Hopefully my shitty attempts at socratic method rate a bit better then trolling, but I often doubt it :-)
Admin access means nothing if you can set up your own instance in an afternoon, federate with everything, then get all the votes copied to your database. I have done this just to prove it could be done, btw.
(b) will just lead to fewer up and down votes, i.e. less engagement. That in turn could lead to slowly bleeding out.
I would like a (c) where my instances collects all the votes on the post, and then transmits an anonymized aggregate.
That would require a major change to the ActivityPub standard, which is not easy or trivial. This is at worst infeasible to impossible, at best something that is 5+ years away.