I have a lot of questions about this. I assume our passwords aren’t hashed. I assume they log our IPs every connection. Every instance does seem to have their own rules. What is the general stored data? I assume they see to our bookmarks too, for example
Be safe. Assume everything is publicly visible and recorded.
you can read the entire sourcecode.
why would you assume passwords arent hashed?
The code being run by any instance could be changed? Just don’t use the same passwords anywhere else or share personal information and it doesn’t matter outside of that instance’s security.
I think OP is asking “In the worst case scenario of a malicious instance owner that is able to fork the Lemmy codebase (so could disable hashing) and intercept and record all communications going to and from their instance, what risk do I have as a user of that instance?”
The answer of course is yes, in theory a malicious instance owner could see the password you use and can see all your communications, votes, what you look at, etc. So use a unique password for that instance, and don’t use the instance for private communucations whose interception could seriously harm you.
It’s worth pointing out that, while Lemmy doesn’t make it easy to see another user’s votes, those votes are still public for anyone to see.
I’m also not so sure that any DMs sent from one instance to another are private.
I hope it isn’t hashed 👉👈
My Lemmy password is: IThinkMy$erverAdmin1sCute
My Lemmy password is: *************************
Looks like they hide passwords, would love to know what it is.
something something hunter2
Is that true? Here’s mine: NeverGonnaGiveYouUp
Is that true? Here’s mine: *******************
This is what comes up for me.
Passwords are definitely hashed unless it is a modified version of software, that does the opposite. Also, yes, IP and port number can be easily gathered from pretty much any https requests. Other than that it doesn’t seem that instances collect any other additional info unlike Reddit, that aggressively does browser fingerprinting.
You’re interacting with a server managed by someone else - everything that flows through it is ultimately under their control, and you’re trusting them with it. They could log everything, or nothing. Even if storing passwords hashed is the default, an admin can replace any part of the code they want, so they could grab and store raw passwords if they really wanted to, or take over your account and impersonate you, or any number of other unlikely but possible things.
So use a unique password, and only provide data (your real source ip, your saved posts, views, votes, etc) that you trust the admins of your server with.
FWIW, votes are actually public information and sent as activity pub events for the votes to be counted from different instances. For example these are the people who up/down voted this post: https://lemvotes.org/post/programming.dev/post/54017015
I guess with this info, don’t be horny on main and vote on stuff you wouldn’t be comfortable with others knowing about.
don’t be horny on main
Don’t tell me what to do. Instead, help me get these sweat soaked clothes off.
I assume you were downvoted because someone didn’t like hearing the truth.
As with any online service you are entrusting your safety to the owner of said service. Anything you put into Lemmy you should assume can be used in any way. Any assumption otherwise is simply carelessness.
Why would they see your bookmarks? Your browser should not be sharing bookmarks with sites.
Passwords are hashed and salted if I remember correctly and IPs are likely seen as that is how IP works, if the server didn’t see your IP how would it know who to respond to?
They probably didn’t mean browser bookmarks, but bookmarked/saved lemmy posts.
I had a problem on a Piefed instance—couldn’t downvote at all—and asked for help. An admin said they logged in as me and couldn’t reproduce the problem. 😬
I don’t put any trust into any account. I don’t share personal information. I use multiple accounts on different instances and software.
Fediverse is just news and random stuff dopamine hits for me. My comments are just venting and internal dialogue dumping when I don’t have IRL people to talk to.
FYI DMs aren’t encrypted, so they would be visible to admins (on both sides of the conversation). There is a warning about this when starting a DM, but is something to consider. I’m not sure how the delete function works, but best to go with the assumption that DMs are soft deleted (i.e. not removed from the DB, just not returned) and could be visible after being deleted.
They know what you did last Summer









