Title says it. Apparently lemmy devs are not concerned with such worldly matters as privacy, or respecting international privacy laws.

  • kglitch@kglitch.social
    link
    fedilink
    arrow-up
    7
    ·
    3 years ago

    OP is simply incorrect.

    I’m coding a Lemmy alternative right now and have been testing this functionality out extensively. Deletes of posts and comments certainly federate, I’ve seen the AP traffic to make it happen. Also, the docs: https://join-lemmy.org/docs/contributors/05-federation.html#delete-post-or-comment

    I haven’t tested what happens when the ‘delete account’ button is clicked… Mastodon solves this by sending a ‘delete this user’ Activity to every fediverse instance so there’s nothing about ActivityPub that makes removing an account and all it’s posts in one go impossible.

  • 0xtero@kbin.social
    link
    fedilink
    arrow-up
    2
    ·
    3 years ago

    Effect of ActivityPub, not Lemmy. All federating systems function similarly, because it’s a feature of the protocol.
    If instances want, they can ignore delete requests and your content stays in their cache forever (remember Pleroma nazis from couple of years ago?) - now, that is an instance problem that might be a GDPR issue, but good luck reporting it to anyone who cares. At best you can block and defederate, but that doesn’t mean your posts are removed.

    The fediverse has no privacy, it’s “public Internet”. Probably a good idea to treat it as such.

  • Jears@social.jears.at
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 years ago

    Well it is pretty much impossible to delete any thing on any federated service. It is technically just not possible without opening a whole other world of problems.

    I always like to think of the fediverse in some way like emails. If you send an E-Mail, the moment it leaves your mail providers server it is pretty much impossible to stop.

    Basically think before you post. The internet never forgets, the fediverse especially so.

  • lily33@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 years ago

    I don’t know where this myth came from, but you don’t have a right to erase your public posts from there internet under GDPR. See, for example, https://law.stackexchange.com/questions/32361/does-a-user-have-the-right-to-request-their-forum-posts-deleted

    If anything, you might have such rights under copyright law, if your posts cover the threshold for copyright. In that case, you can ask server admins to delete them, and they will have to comply. But the request has to reach them (if they’re defederated, the delete button won’t teach them, and you’ll have to contact them separately).

  • XYZinferno@lemmy.basedcount.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 years ago

    To my knowledge, these privacy laws prevent corporations from holding onto your data after you have requested to delete it. Lemmy is not a corporation, and there is no single entity that holds onto all of your data. That’s just a tradeoff of being decentralized.

  • burgersc12@sh.itjust.worksdeleted by creator
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 years ago

    Oh no, that’s not even the half of it. The admin for your instance has access to literally anything on their server, including passwords afaik. If you want privacy, this ain’t it chief.

    • Russ@bitforged.space
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 years ago

      They have access to your password hash, effectively the “infrastructure” admin(s) as I’ll call it (not admins of the site - they need to have access to the actual system that is running the instance) have access to the same things that infrastructure admins of another site would have.

    • kpw@kbin.social
      link
      fedilink
      arrow-up
      0
      ·
      3 years ago

      Every website has access to the password you use on that website. ALWAYS use unique and randomly generated passwords for every service.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 years ago

      including passwords afaik

      Nobody has access to passwords. They have access to password hashes, which are not the same thing. It would be the absolute most half baked of solutions to still be saving passwords in cleartext.

      • acausal_masochist@awful.systems
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 years ago

        Which isn’t to say it doesn’t happen. I still occasionally get my password emailed back to me from small handbuilt websites. Which is part of why you should at the very least never use the same password twice.

  • originalucifer@moist.catsweat.com
    link
    fedilink
    arrow-up
    2
    arrow-down
    2
    ·
    3 years ago

    seems weird this expectation of privacy on public sites built for public consumption of public content posted by people publicly.

    i mean, i get wanting to control your data. the software i use allows for this ( the 'bins offer a user-level purge).

    but privacy? seems weird

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      3 years ago

      I mean, to have a Lemmy account you already decided to put your trust in total strangers with questionable security credentials.

        • Snot Flickerman@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 years ago

          Mastadon works the same way, all ActivityPub services work the same way.

          By being Federated that means data is being sent to remote servers. Sometimes that data doesn’t always make it, like a delete request. So someone on their own home-server deletes their post, but on some remote server where that post they made is cached, it’s not deleted, because the delete request never federated. For example, say you made a post on your own box, which you clearly have, and you delete a post, but it doesn’t get deleted over on say, Lemmy.world. That’s not purposeful, that’s something they’re also trying to fix.

          This is literally a consequence of how federation works. It’s not a purposeful violation of GDPR.

  • JustMy2c@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    3 years ago

    Very bad indeed! This is the beginning of the end for lemmy.

    Ps for those who don’t know, copying a deleted comment makes it appear in your pastbin

  • maegul (he/they)@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 years ago

    All your posts on the fediverse are effectively a public blog of your thoughts that will be scraped and stored in servers you have no control over.

    If you care about privacy, which I understand, you probably want to leave quickly.

    Here’s a rundown from someone who got fed up with the fediverse and kinda rage quit: https://blog.bloonface.com/2023/07/04/the-fediverse-is-a-privacy-nightmare/

    Another example of this is that it’s not just about lemmy. One way in which lemmy actually federated well worth microblogs like mastodon is that users can be followed from mastodon etc.

    So any number of servers running a number of open source easy to run platforms could be taking up everything you specifically post.

    • YarrMatey(she/her) @lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 years ago

      Thank you for posting that link. I’m not fed up (completely?) yet I suppose but it was eye-opening. I’ll have to be a lot more careful about posting, possibly not post again.

  • YarrMatey(she/her) @lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 years ago

    This is definitely a con of Lemmy for me. I like to be more privacy focused but Lemmy gives you 0 privacy on whatever you do on the website. Anyone who wants more privacy on Lemmy is told you have no right to privacy, don’t expect any privacy, everything you do is public on the internet, etc. A massive boner killer for me. I think basic things like deleting your own post or comments should actually get removed from all servers, PMs should not be viewable by anyone except the recipients, and what you vote on or subscribe to should be private. Lemmy doesn’t sell your data but that’s because anyone can take the data for free. I thought this stuff was because Lemmy is still new and will get to it eventually but the push back seems to say this was a choice or is not broken. I ended up exploring different social media alternatives but I like the style of Lemmy better since it is more reddit-like with an active user base plus has different android clients. I don’t like kbin because it shows who upvoted or downvoted something to everyone - it’s not accountability when it erodes your privacy.

    I used to comment on Lemmy more but then I ran into this problem when juggling multiple accounts, Liftoff sucks ass at letting you know which account you are logged into (I use Summit now and it is better at it) so I ended up getting my accounts’ wires crossed when I thought using the drop down on your accounts changed your account but no you have to go to manage instances to switch which was not intuitive. I ended up abandoning the accounts when I couldn’t figure out how to actually delete the post from the server.