I’ve been grappling with a concern that I believe many of us share: the lack of privacy controls on Lemmy. As it stands, our profiles are public, and all our posts and comments are visible to anyone who cares to look. I don’t even care about privacy all that much, but this level of transparency feels to me akin to sharing my browser history with the world, a discomforting thought to say the least.

While the open nature of Lemmy can foster community and transparency, it also opens the door to potential misuse. Our post history can be scrutinized by creeps or stalkers, our opinions can be nitpicked based on past statements, and we can even become targets for mass downvoting. This lack of privacy control can deter users from actively participating in discussions and sharing their thoughts freely.

Even platforms like Twitter and Facebook, often criticized for their handling of user data, provide some level of access control. Users can choose who sees their timeline: friends/followers, the public or nobody. This flexibility allows users to control their online presence and decide who gets to see their content.

The current state of affairs on Lemmy forces us into a cycle of creating new accounts or deleting old posts to maintain some semblance of privacy. This is not only time-consuming but also detracts from the user experience. It’s high time we address this issue and discuss potential solutions.

One possible solution could be the introduction of profile privacy settings, similar to those found on other social media platforms. This would give users the flexibility to choose their level of privacy and control over their content without having to resort to manual deletion or account purging.

I believe that privacy is a fundamental right, and we should have the ability to control who sees our content. I’m interested in hearing your thoughts on this matter. How do you feel about the current privacy settings on Lemmy? What changes would you like to see? Let’s start a conversation and work towards making Lemmy a platform that respects and upholds our privacy.

  • Exocrinous@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 months ago

    The admin of Blahaj is openly interested in exposing trans people’s alt accounts and outing them on their mains. And somehow it’s the biggest trans instance. We need a community and admin reaction in favour of defederating people who do that.

  • Zerush@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    What irritates me many times when I enter Lemmy is that instead of my Nick at the top right, someone else’s Nickname appears for a moment, before changing it to mine. This is a sign of an open account sharing channel, which is quite serious and should be fixed quickly. Security at Lemmy is apparently non-existent.

  • solrize@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    8 months ago

    Lemmy has many privacy problems that have nothing to do with public comments you make. For example, the “hide posts that you have already read” option requires that the server track what posts you have read. There is no public activity involved in reading a post. So the Lemmy server should not track that info. If that feature is to exist at all, it should be implemented purely on the client. The same can be said about subscriptions, and for that matter about voting (server should discard voting info after a brief interval for abuse detection). The Lemmy software in many ways naive about this stuff.

  • Mr. Satan@monyet.cc
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    What you’re describing is an issue with all of social media. While your concerns are valid, I don’t see your arguments as privacy issue. I honestly prefer post and comment history being transparent and accessible. It’s much like Reddit and this format fits much better with an open forum style of platform.

    Don’t post private information and it’s a non-issue.

    Also, can’t you just delete posts and comments like on Reddit?

  • risencode@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    The only privacy setting I can encourage on any social media site is don’t share private stuff about yourself and never link to your account from other accounts

    • LemmyHead@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      8 months ago

      That is part of the problem though. Proper privacy allows you to express what you want to, without self censorship. The issue is not: don’t speak about x, but rather: speak about it and feel comfortable that you can do it in a safe environment. I fully agree with the account linking though

  • Creddit@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    When you have privacy settings, what you really have is a lie.

    It starts out with good intentions, like those in this post, but eventually everyone forgets that the platform still sees your posts and does not give a shit about selling them.

    I would rather acknowledge from the very beginning that this entire system is not private, so there is never such a misunderstanding.

    Everyone should post and comment with caution, just like you use caution with what you say in public places.

    • blackbrook@mander.xyz
      link
      fedilink
      arrow-up
      0
      ·
      8 months ago

      The way you use caution saying something in a public place that you don’t want everyone to hear is by keeping your voice down so that only certain people can hear it. Without privacy settings there is no equivalent to that.

    • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 months ago

      Sup. And all this data would still be federating, it has to be. That just means that some data-collecting company could make a fake instance and get everything together. Or someone could just fork it back.

  • MajorHavoc@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    8 months ago

    It gets weird fast, because before privacy controls in the Lemmy source code mean anything, we need trusted third party verification of a server’s patch level, and security controls.

    That can be done, and I think Lemmy has a shot at getting to that point, but it’ll be awhile.

    In the meantime, I suspect the Lemmy developers are hesitant to add and advertise features that you can’t be sure are actually correctly enabled on your instance.

    But yeah, let’s not let perfect be the enemy of moving toward better.

    Edit: Assuming you completely trust your instance admin, we could start adding some basic privacy to actions taken on your home instance.

    But as soon as the user starts interacting via federation, all bets are off - because the federated instance may he malicious.

    I think we might see one or more “trusted fediverse” groups emerge in the next few years, with instance admins making commitments to security controls, moderation, code of conduct, etc.

    So, in theory, the lemmy software could start implementing privacy controls that allow users to limit their visibility to whichever part of the fediverse their instance admin has marked as highly trusted.

    But even then, there’s risks from bad actors on highly trusted instances that still allow open signups.

    Anyway, I totally agree with you. It’s just a genuinely complex problem.

    • Salamander@mander.xyz
      link
      fedilink
      arrow-up
      0
      ·
      8 months ago

      I think we might see one or more “trusted fediverse” groups emerge in the next few years, with instance admins making commitments to security controls, moderation, code of conduct, etc.

      There is now at least one system in place for admins to vouch for other instances being non-malicious, and to report suspected instances. It is called the fediseer: https://gui.fediseer.com/

  • Eggyhead@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    While I think most of us forum users are, I get the impression that the biggest proponents of activity pub and the fediverse as a whole aren’t even seeing privacy as even relevant. It’s a lot of talk of businesses having their very own instances to interface with the public rather than needing to rely everything on the whims of Facebook, twitter, LinkedIn, etc. Nothing with regards to the implications for surveillance, identity theft, spam, privacy or security.

    Right now, we’re relatively under the radar because the fediverse hasn’t really hit the mainstream yet. But I think it will, and once it does, everything we’ve ever posted will just get slurped up by data trawlers and the flood of spam will be inevitable. We’ll be juggling social media accounts just like we do with emails.

    I don’t know if this is relevant, but I’d like to someday have my own kbin instance hosted on my own personal server exclusively for family. I imagine the instance being able to federate content from bigger instances, allowing members to follow people they like on microblogs or participate in federated forums from this privately maintained instance. But if anyone wanted a thread or magazine to be available to users from outside the instance, they would have to specifically opt-in to that option when creating it, and it would only apply to that one thread or magazine. Any other instance would just see our humble little family instance with only that one thing to federate. The rest of the instance would be an ecrypted enclave specifically for family accounts, and completely invisible to the fediverse.

  • Leraje@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 months ago

    To me, it’s an issue of personal responsibility.

    Lemmy is, like a lot of Fediverse platforms, about as private as it can be. There’s no trackers, you’re not forced to use real names or any other identifying information, no adverts follow you from site to site, no browser fingerprinting and no instance owners are trying to sell your data.

    Beyond that, what you choose to say on Lemmy is your responsibility and yours alone.

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    I have a feeling that you might be misunderstanding what the actual purpose of lemmy is. lemmy has taken quite a few design decisions from Reddit which is exactly the same way. Both platforms are public places where all content is shared. Anyone using them needs to be aware of that fact. Mastodon might be a better fit for you as it is more focused on individuals rather than public communities.

  • TexMexBazooka@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    Bruh what? If you’re repeatedly making new accounts because you don’t want people reading your post history you’re doing something wrong.

  • chicken@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    I remember a little while ago a thread with someone from kbin gloating that they could see what everyone was voting, and accusing the people upvoting comments they disagreed with of being bigots in a vaguely threatening way obviously intended to produce a chilling effect, and people found this surprising because that information is not public on most instances.

    I basically agree with the people saying open info is just the nature of posting on a public forum and of federation, but there could be improvements, even just in awareness of what is and isn’t private.

    • bamboo@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 months ago

      This is a great point because in the Lemmy UI, this information isn’t shown, and you can’t even list out all posts you’ve upvoted. As most of us coming from Reddit, we’re used to upvotes being private, and probably assume it’s the same. I understand the technical reasons for having the information public, but it is not clear from a user perspective that it’s public.

      • chicken@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        8 months ago

        What’s extra confusing is that I’ve seen people asking about how to get this information from the API, with the answer being that you can’t (I guess to protect privacy?). It’s only accessible to federated servers, but then those can do what they want with it including publishing it to everyone.

  • LWD@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    There’s a grim tragedy in how many people in this comment section have either succumbed to defeat or actively seek to advocate against privacy.

    The comments can mostly be boiled down to:

    • My data is online already, and I give up
    • Your data is online already, and you don’t deserve control over it
    • I have nothing to hide and nothing to fear (and you should too)

    You will find Fediverse types are far more cynical and antagonistic to privacy than people on other platforms.

    • Devorlon@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 months ago

      I’ve not seen any of these arguments. Though it may be all downvoted to hell and back.

      My main gripe with adding privacy features to Lemmy is that the whole point of Lemmy is that all data is already publicly available and for Lemmy to continue working the way it does it’ll need to remain that way. And because of that there’s nothing that can be done to stop bad actors setting up an instance and selling all the data they collect.

      At least in the EU (and UK to a lesser extent) no major corporation would be able to get away with selling that data, so the spent man hours on allowing privacy settings would be wasted time.

      • LemmyHead@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        8 months ago

        It doesn’t necessarily need to remain that way. For example,we should have the option to make our profiles private. We should also be able to create pseudonyms for content we submit. The content will still be federated, but not necessarily linked to one user ID

  • amanneedsamaid@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 months ago

    The way I see it, community-based social media is a public forum, where every post / comment is public (Obviously less applicable on an individualized platform like Instagram). Everyone has an inherent right to privacy, but not when they’re using a platform like Lemmy. Twitter and Facebook are fundamentally different platforms. You can’t expect privacy while using lemmy, so use a different platform to post private content.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      8 months ago

      These people should be looking into spinning up Matrix servers if they want a private club with real privacy so bad.

      It’s definitely a weird thing to constantly be upset about: “People can see what I posted in public when I post them publicly!”

      It’s like complaining about people being able to take photos with you in the background in public. It’s a public space, there is no expectation of privacy.

      If you want a private internet experience, you have to put some work in.