this post was submitted on 07 Jul 2023
82 points (96.6% liked)

Technology

58036 readers
4341 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 1 year ago
  • DMs - this is an issue, but as I say you shouldn't be chatting on Mastadon if you want your conversations to be private. Move the conversation elsewhere.
  • Email addresses - might be an issue, but only if you're using an email you shouldn't be and linking accounts/online personas together when you want them separate.
  • Logins - publicly available. Passwords were secure.
  • IPs - always gonna be available to the instance or website you're using. If you don't want the instance to know your home IP, there are a number of things you could be doing to mask this.

It's really only the DMs that have some level of concern. IPs and email addresses might give the FBI a lead, however only if you aren't covering yourself properly. Eg one of the darkweb marketplaces sent a welcome email to new users with a reply to email for the admin's personal gmail - this was used to identify him as he used the same email on LinkedIn.

What happened here isn't great, but with federated social media it should be immediately obvious that things are not private nor massively secure, and users should take that in account when registering for and using the service. This article doesn't prove any new faults with federated services that weren't already a given.