I recently learned that voting on lemmy is not anonymous. Anyone can get information about who has upvoted and downvoted a post or comment.
In combination with your IP, this is a massive privacy (maybe even physical security) risk. Also, people can target you for your votes.
Sadly, this is something where I would prefer Reddit over Lemmy. Big tech scrapes data from both places anyways, at least Reddit is safe.
whats the problem with it . you did not liked it you downvoted . its not like they can ban your account
at least Reddit is safe.
Lmao, what!? Reddit tries their best to know exactly who you are, where you live, your education, where you work, etc… And then they sell that data to anyone.
Yes, exactly! This is just what they hoard on iOS devices:
I try not to downvote without commenting so they should be aware
I’ll downvote everyone here if I damn well please it!!!
I want you to know
that you are skibidi sigma rizzler from ohio ?
?
They want you to know that they downvoted you
If you’re an instance admin, for any post, you can just click “view votes” and see everything tied to usernames, even outside your own instance. Moderators can too, but it’s restricted to the communities they moderate.
So if a bad actor wanted to get aces to vote data, they could setup and instance and have it federate with any instance they want to extract voting data from?
Yes, it’s very simple too. You don’t even need to extract anything from a database or do some complicated stuff. As an admin you have free access to all moderation tools no matter where the post is from, including the option to “view votes”.
The IP address thing is not real, though
Just choose a nickname that is random word+4 random digits and don’t reuse it on other services
This is the way. Randomise your usernames and use a password manager to keep track of them.
Sir, this is the Fediverse.
It is nowhere explicitly made clear to users that voting is public. It should be made clear if it is going to be
An EU resident could sue for emotional damages under the GDPR. Or maybe just complain to data protection authorities.
One day it will happen.
Why would it need to be made clear? Likes on Facebook are public, nowhere does it say “liking this photo will alert every friend you have that you just liked your stepdaughters’ friends’ bikini pic from 2 years ago.”
I like the public vote system. Anonymous systems have a much greater potential for abuse.
Accounts are easy enough to make that you can just burn your account every few months if you’re that worried.
It is made clear because there is an option to see all the votes right next to the like button. Similarly, many sites allow you to go through activity of people you follow.
You can see the number of votes here too. Why does your hand need to be held? It’s the fucking internet, guy.
I can see the number of votes but not who voted. This gives the impression that this information is not available publicly. However, it can be accessed by anyone on third party websites.
Then don’t vote? Nobody is forcing you to interact with the content and it’s kind of hilarious you’d consider it a security/privacy violation.
And then you put the cherry on top by saying “reddit is safe.”
It’s the other way around here: Everything is public except where it’s made clear that it won’t be (e.g. email address, password).
For what it’s worth, your instance of choice is particularly negligent in regard to informing its users. Compare lemmy.today/legal to lemmy.world/legal, or their respective signup pages for examples. There’s little that Lemmy itself or the community at large can do about that 😞
Are you sure about that? Reddit is a fucking cesspool.
In combination with your IP, this is a massive privacy (maybe even physical security) risk. Also, people can target you for your votes.
No.
It would be unusual to be able to exactly identify someone purely from their IP, but let’s say someone posted from their work IP in a small company. It would substantially lower the bar to dox them.
Let’s go further and ponder if an authoritarian regime setup an admin and started coorelating dissent ip’s collected from user when they did things like paying parking fines, or signing their online tax forms.
Let’s say that they collected all that and trained an LLM on it, then when you go to get a passport renewed or are stopped for a traffic violation and ask the LLM if you’re a dangerous person based on their criteria.
It’s not a direct problem, but it has slippery slope all over it.
Let’s just say you don’t understand how IP or llms work.
IP addresses are not something that can be pulled from just any instance. You would need to be the administrator, and even then you’d only get access to the ip address of just your own instance users. AFAIK, at least - maybe they’ve made efforts to mask ips, too, but im not even sure how that’d work.
Federated posts and comments are copied from server to server. When someone from .world is looking at a comment from .dbzer0, what they are seeing is information that was synced from the dbzer0 server address, not the user’s.
There was a brief moment when there was a vulnerability with linked images sent via DM that could route you to an external server and log your IP address, but that has been patched now by most instances.
As with anything on the internet: assume your activity is not private at all times, or take active precautions to mask your identity, or both. No opsec is perfect and often the only thing standing in the way of a hack or dox is the endurance and motivation of the bad actor.
Seems like a good thing to me. Should be a better known feature.
How would I go about seeing this information for myself?
Yeah, at worst it’s a necessary evil to prevent a rogue user on a second instance from mass downvoting. Your username is tied to your vote, because otherwise a rogue user could just spam downvotes at whatever they didn’t like.
Instance 1 has a post. Instance 2 has a user who disagrees with that post. User is able to spam downvotes, because instance 2 is not binding their username to the vote. So Instance 1 has no way of knowing if the votes are multiple different users, or all one user. The only real solution here is to disable external voting, but the entire point of the fediverse is cross-compatibility and self-hosting. By binding the username to the vote, instance 1 is able to detect repeat votes and disregard them.
Important to note here, too, is that ip addresses of users arent synced across instances.
This is only a problem for people who care about the reputation of their user account - which is something people should be rotating out anyway if they care about their privacy.
This always givea me a 404
Just tested your post here, your instance def opted out.
your instance may have opted out.
Or just buggy results.
this is why i vote at random, like two-face doing his quarter thing
You get 3 accounts. Say you want to upvote something. You downvote in 1 account (randomly selected), upvote on another, and upvote on the third. So it’s net +1 and the only way to see how you voted is to piece together all 3 of your accounts voting history. Need more privacy? No problem, just use 5 accounts instead of 3.
/s
wait, so what do i do with the first shell again?
I did this last night putting my son to bed, said heads you go to bed, tails we stay up. Jokes on him though, double heads. And he fell for it, what a sucker. Hope it works when he’s not four, or I at least don’t need to do it.
you’re raising a future supervillain
Russia really should just leave Ukraine, though. (Sorry, I just saw the context for this a few minutes ago and can’t help myself).
Dont care who knows but I too agree with this.
It is not the context for this post, people have made it the context. It is the reason for this post.
Maybe context is the wrong word.
E: how about catalyst.
I like piefed because it lets you see at a glance if someone is a serial downvoter. On each piefed user profile is a thing called “attitude” and it’s a ratio of your upvotes vs downvotes.
100% means the person doesn’t downvote people. 50% means they downvote and upvote equally. 0% is only downvotes.Edit: I saw someone today with negative % so it must be 100% is all upvotes. 0% is half upvotes half downvotes. -100% is all downvotes.It shows up for people outside piefed too so i see you too lemmy angry people.
This just sounds like Reddit account karma score all over again? But with a percentage displayed instead of total.
Reddit karma is how others feel about what you say. Piefed’s attitude is how you feel about what other people say.
Slightly different but i see your point.
oh no. I should upvote more. I’m really bad about voting at all 😓
Why would you let others police your behavior?
Others influence many things about my life. I don’t see it as policing if I’m trying to choose to bring more positivity to the table.
I would never downvote cereal.
Unless it was grape nuts. That shit is like eating gravel.
Here’s how you Grape Nut:
Pour a small pile (like a cup or so) in a bowl.
Take a spoonful of peanut butter and use the backside of the spoon to mix up the PB and GN. Smash it together for longer than you think until it’s well mixed.
Top with a drizzle of honey and then pour milk over it.
S-tier breakfast.
Raisin bran gang!
What is mine?
90%
Thanks! Cool feature.
Now do me, please.
Hang on, doing your mom.
Why are you saying IP addresses are publicly shown here and why is (almost) no one correcting you? That would’ve been an enormous privacy risk that would’ve required intentionally fucking users over. Just doesn’t even make sense to write what you did about IP addresses. Seems like you’re just hoping to cause some panic.
Admins can get them. It is not available to everyone.
Only admins of your instance.
Only the admin of your instance can see your IP address, it doesn’t get federated to other instances.
Who says that Reddit isn’t selling upvote/downvote and IP info? Or sharing with govts?
They 100% are
I am not worried about big tech because they scrape everything anyways. I am more worried about the witchhunt and potential admin abuse.
And even this does not happen, it should be made clear that votes are public
Why are you worried about admin abuse? If you are worried that your admin will abuse you, you should switch to an instance you trust more.
What?
Okay so then why fearmonger? You’re thinking that a handful of people in the world having your IP and also opinions is somehow more dangerous than anything else on the Internet?