Skip Navigation
0xtero 0xtero @kbin.social

First I drink the coffee, then I do the things.

Cybersecurity specialist. Perpetual blue team botherer and a glorified network janitor. SecurityFest Crew (https://securityfest.com/)

Trying to leave things better than I found them. Slow regard of silent things.

\#infosec #security #cybersecurity #dfir #coffee #climate #sustainability #solarpunk

About Me: https://0xtero.hanninen.eu/ Mastodon: https://infosec.exchange/@0xtero

Posts 8
Comments 285
Warning: You cannot delete posts or comments on Lemmy. It stays up forever, and is in direct violation of GDPR and other national privacy laws.
  • In this case, the "lemmy devs" and the operators of lemmy.ml are the same people and it's hosted within EU.
    But - that's still a far cry from getting any kind of GDPR violation report going, much less getting it through the process to actual fines.
    People like to bring up GDPR violations as a some kind of super-moderator tool, but it isn't that easy and it definitely isn't automated.

  • Warning: You cannot delete posts or comments on Lemmy. It stays up forever, and is in direct violation of GDPR and other national privacy laws.
  • Effect of ActivityPub, not Lemmy. All federating systems function similarly, because it's a feature of the protocol.
    If instances want, they can ignore delete requests and your content stays in their cache forever (remember Pleroma nazis from couple of years ago?) - now, that is an instance problem that might be a GDPR issue, but good luck reporting it to anyone who cares. At best you can block and defederate, but that doesn't mean your posts are removed.

    The fediverse has no privacy, it's "public Internet". Probably a good idea to treat it as such.

  • Threads is blocking servers on the Fediverse. Here's how we unblocked ourselves. | Soapbox
  • It's also a matter of scale. FB has 3 billion users and it's all centralized. They are able to police that. Their Trust and Safety team is large (which has its own problems, because they outsource that - but that's another story). The fedi is somewhere around 11M (according to fedidb.org).
    The federated model doesn't really "remove" anything, it just segregates the network to "moderated, good instances" and "others".

    I don't think most fedi admins are actually following the law by reporting CSAM to the police (because that kind of thing requires a lot resources), they just remove it from their servers and defederate. Bottom line is that the protocols and tools built to combat CSAM don't work too well in the context of federated networks - we need new tools and new reporting protocols.

    Reading the Stanford Internet Observatory report on fedi CSAM gives a pretty good picture of the current situation, it is fairly fresh:
    https://cyber.fsi.stanford.edu/io/news/addressing-child-exploitation-federated-social-media

  • Threads is blocking servers on the Fediverse. Here's how we unblocked ourselves. | Soapbox
  • I find it interesting that Meta Platforms, Inc., a company known for harvesting user data, is blocking some servers from fetching its public posts. They decided to implement a feature Mastodon calls Authorized fetch.

    This was always going to happen. They will block agressively, because they can't have their precious advertising money mixed with CSAM, nazis and other illegal content. And the fedi is full of that.

  • What distros have you tried and thought, "Nope, this one's not for me"?
  • I've been using Debian since 1.3. Haven't really ever needed anything else.
    I did "experiment" a bit when the decision to go with systemd was taken, but in the end, most distros went with it and it really isn't that big deal for me.

    So it's just Debian. I need a computer that works.

  • Top 50 Drivers of 2023 | Autosport.com
  • How is Lando higher than Rovanperä? WTF? What championship did he win? Or better.. did he actually win anything at all this year?

  • Which microblogging platform should i ideally host?
  • Pleroma in that case I guess

  • Mystery Solved - Bill Gates murdered CPM's Gary Kildall over DOS
  • Gates is probably just as bad and evil as the global 0.1%:er billionaire cabal members come, but that site gave me a crackpot conspiracy brainrot.

  • Why is kbin so full of empty stuff?
  • As is the case normally with these "exodus" things, most people went back to Reddit after the first month here.

  • *Permanently Deleted*
  • Somehow I don't think many instance admins have resources or knowhow to drive legal processes against Meta?

    And while a disclaimer on the instance page might have some effect, the Federation protocol makes it hard to avoid getting a copy of the said content in your cache.

  • *Permanently Deleted*
  • How do we accomplish that?

  • *Permanently Deleted*
  • I bet he does. You can block/mute influencers pretty easily and you can block the whole domain if you so wish.
    He's talking about some kind of nefarious ad injection into ActivityPub objects as part of server to server activities.

  • *Permanently Deleted*
  • I think he's talking about people on his own instance.
    He's Fosstodon admin, so pretty sure he knows how federation works.

  • *Permanently Deleted*
  • doesn’t mean we have to hand it to them on a silverplatter and allow them to scrape it legally

    They could have just set up a simple Pleroma on Raspberry Pi and it would have been just as "legal" as any other instance. You'd need to turn on AUTHORIZED_FETCH and set up authentication on the Mastodon API, otherwise everything is public and unauthenticated (even if the instance is suspended/defederated).

    But if enough instances say no, that means they are not welcome. Democracy and all

    mastodon.social has already said yes. So have all the other big instances. Most of them have said "we'll wait and see". So democracy served I guess

    And the last point is the dumbest: Threads will just include a revenue sharing model like Youtube does

    Yeah, maybe. Who knows. I'll deal with it when it happens rather than knee-jerk years in advance. Threads has a long way to go, it's missing a lot of features to put it on par with their other commercial competitors, so I think they're going to be busy doing other things.

  • *Permanently Deleted*
  • Yeah, that's pretty much my take as well.

    All the "but muh datas" pearl clutching is just annoying and frankly, ridiculous. If they wanted to mine us, they already would have. They're probably doing it as we speak. They didn't have to create a multi-million social network for it. A raspberry pi on someones desk would have sufficed. Fedi doesn't have any (/very much) privacy.

    They're doing this to escape the wrath of EU privacy watchdogs. They were already fined for $1.3bn and more is coming. Running their Twitter killer on interoperable protocol is nice, because it's free and they get to point at W3C and say they're LIKE TOTALLY supporting data portability. Why would they "extend and extinguish" that? It's their alibi.

    I don't like Meta. It's a shit company ran by shit people. I hope they burn in hell.
    But I can't really get my panties in a twist about threads.net existing.

    I'll get angry if they somehow figure out to push ads to my face.

    But for now. Maybe I'll block it. Maybe I won't. We'll see.

  • www.theguardian.com Army of fake social media accounts defend UAE presidency of climate summit

    Sultan Al Jaber – Cop28 president and CEO of state oil firm – is ‘ally the climate movement needs’, posts say

    An army of fake social media accounts on Twitter and the blogging site Medium have been promoting and defending the controversial hosting of a UN climate summit by the United Arab Emirates.

    2

    Potential Erik Karlsson trade?

    Hello Detroit!

    Swedish hockeyfan coming in peace!

    Hockeymedia has been speculating about San Jose wanting to trade EK65 during the summer. He wants to go to a team that can make a run for the cup and compete - and that team will also have to have cap to take in his contract. Even if the Sharks retain salary, I'd guess he'd be around $8M.

    I've been thinking - maybe he could be a piece in Yzerplan? Does it make any sense to you guys?

    1
    www.wowhead.com World of Warcraft Subreddit to Return Private Indefinitely in Protest of API Pricing

    After participating in a 48-hour blackout protest against Reddit's decision to charge third-party developers for API access, moderators of the World of Warcraft subreddit have announced that the subreddit will be indefinitely returning to private mode in continued protest.

    6