Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)G
Posts
93
Comments
1020
Joined
3 yr. ago

  • Maybe look up the story behind Tornado Cash.

    EU law has liability exemption for hosters if they remove illegal content once notified (DSA Article 6). I think we still have to wait for more case law to know how that works with encryption. National law may still cause problems.

  • You have full control over a server on which you chose to run certain Software. But you feel you don't have to comply with takedown requests because that's just how the software works? That may work on indulgent parents but not in court. If you're too technically inept to know how to comply, then you're just not complying. End of story.

  • Holy shit. I can't believe that 65 people upvoted this. Do you really believe that's how the world works? Are you actually adults?

  • That's why the protests started.

  • The imposition of the ban was discussed in this community. I agree that this is barely on topic but that's precisely why it should be available here. So that people who are interested in social media bans but not in world news, can find the info in the same channels and put the FO to the FA.

  • It was signed by a number of people, including OG ActivityPub contributors. I guess you'd have to know what goes on in the mailing list.

    Looking around here, there's a lot of ignorant hostility. I am always surprised by how tech-illiterate fediverse fans are. People who feel that that's their peer group probably have a hard time ignoring that background toxicity.

  • The statement has been... uh... updated. The URL now reads:

    A statement was originally published here, however, we have since received an objections to its publication citing that proper processes were not followed, and therefore it has been taken down and republished on Emelia's website instead, whilst we seek community group consensus. When Emelia merged the pull request, she had been granted permission to do so by the co-chair of the Social Web CG, and given the number of signatories with various significant contributions to ActivityPub and ActivityStreams, Emelia believed that there was enough agreement to publish.

  • To boldly come where no man has come before.

    • Zafran Cockrain
  • I assume it proves that there is a public key associated with each vote.

    It doesn't sound like cryptography is able to add anything worthwhile. You have to trust the instance to police itself. Self-hosted instances still don't vote anonymously.

    A group of users has to cooperate to hide their votes from others and each other. Only the tally is known, but you have to trust the group. On the Fediverse, such a group will be the users of an instance. The more users the instance has, the more anonymous the individual becomes.

    You have to trust the instance admins to weed out bots and sock puppets, which is extra hard when they don't see the votes either. Presumably, compensating by collecting and keeping other data, such as IPs, for longer is undesirable. You have to believe that admins, volunteers all, are willing to do the extra work and that they don't actually favor manipulation for ideological reasons.

    The only way to uncover untrustworthy instances is to look at aggregated data. I guess you'd have to get/scrape data for some community and then analyze by instance if the number of posters is out of whack with the number of voters. I wonder if anyone's ever done such a thing. It's certainly more challenging than looking at oddities among voters who brigade some topic.

    Admins of large instances could get away with having many sock voters among the real users, if they wanted to manipulate discussions for, say, ideological reasons.

  • You could also make it prove each vote comes from one real account and that no account voted twice.

    How would it prove that the account is real? I suspect that the meaning of "real account" is not the opposite of bot or sockpuppet.

  • But accounts are already pseudonymous?

    Here's where I am at:

    I can check if my votes are federated correctly by checking if any of my votes are suppressed or votes in my name are made up. If my instance sends a different random token with each vote, I can still do that, as long as I know which tokens are assigned to my votes.

    But vote tallies can also be manipulated by making up new votes through fake/bot accounts. If a vote can be connected to posts, this can be checked to some degree. Say, if an instance has a lot of voters that never post, that indicates a problem.

    I don't see how the second thing with E2EE.

  • Wait. What is the relation to vote federation?

  • It’s doable with E2E encryption,

    How?

  • Federation requires openness and that goes badly with secrecy. You can argue that one has to trust instance owners anyway, but knowing the users and not just the tallies makes uncovering manipulation easier.

  • That's not how it works.

  • How do you algorithmically manipulate those 12M people with Mastodon?

    The usual way, whatever that is. What would Mastodon do about it? How do you manipulate Bluesky?

    BTW, Bluesky has almost 40M users.

    It's the number in OP, so I ran with that. The fediverse number apparently excludes Gab and Truth Social. Makes sense, since those aren't federated with the rest, but that also shows an issue.

  • Alternate history: Bluesky never happens. Instead, some company opens up a Mastodon instance as a Twitter replacement. So instead of Bluesky with 12M+ users, there's a Mastodon instance with 12M+ users. Now what?