I have a lot of questions about this. I assume our passwords aren’t hashed. I assume they log our IPs every connection. Every instance does seem to have their own rules. What is the general stored data? I assume they see to our bookmarks too, for example

    • Rhaedas@fedia.io
      link
      fedilink
      arrow-up
      0
      ·
      3 个月前

      The code being run by any instance could be changed? Just don’t use the same passwords anywhere else or share personal information and it doesn’t matter outside of that instance’s security.

    • festus@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 个月前

      I think OP is asking “In the worst case scenario of a malicious instance owner that is able to fork the Lemmy codebase (so could disable hashing) and intercept and record all communications going to and from their instance, what risk do I have as a user of that instance?”

      The answer of course is yes, in theory a malicious instance owner could see the password you use and can see all your communications, votes, what you look at, etc. So use a unique password for that instance, and don’t use the instance for private communucations whose interception could seriously harm you.

      • QuadratureSurfer@piefed.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 个月前

        It’s worth pointing out that, while Lemmy doesn’t make it easy to see another user’s votes, those votes are still public for anyone to see.

        I’m also not so sure that any DMs sent from one instance to another are private.

    • Vanth@reddthat.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 个月前

      I hope it isn’t hashed 👉👈

      My Lemmy password is: IThinkMy$erverAdmin1sCute

  • AlteE@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    3 个月前

    Passwords are definitely hashed unless it is a modified version of software, that does the opposite. Also, yes, IP and port number can be easily gathered from pretty much any https requests. Other than that it doesn’t seem that instances collect any other additional info unlike Reddit, that aggressively does browser fingerprinting.

  • mlfh@lm.mlfh.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 个月前

    You’re interacting with a server managed by someone else - everything that flows through it is ultimately under their control, and you’re trusting them with it. They could log everything, or nothing. Even if storing passwords hashed is the default, an admin can replace any part of the code they want, so they could grab and store raw passwords if they really wanted to, or take over your account and impersonate you, or any number of other unlikely but possible things.

    So use a unique password, and only provide data (your real source ip, your saved posts, views, votes, etc) that you trust the admins of your server with.

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 个月前

      I assume you were downvoted because someone didn’t like hearing the truth.

      As with any online service you are entrusting your safety to the owner of said service. Anything you put into Lemmy you should assume can be used in any way. Any assumption otherwise is simply carelessness.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 个月前

    Why would they see your bookmarks? Your browser should not be sharing bookmarks with sites.

    Passwords are hashed and salted if I remember correctly and IPs are likely seen as that is how IP works, if the server didn’t see your IP how would it know who to respond to?

  • LordMayor@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 个月前

    I had a problem on a Piefed instance—couldn’t downvote at all—and asked for help. An admin said they logged in as me and couldn’t reproduce the problem. 😬

    I don’t put any trust into any account. I don’t share personal information. I use multiple accounts on different instances and software.

    Fediverse is just news and random stuff dopamine hits for me. My comments are just venting and internal dialogue dumping when I don’t have IRL people to talk to.

  • bamboo@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 个月前

    FYI DMs aren’t encrypted, so they would be visible to admins (on both sides of the conversation). There is a warning about this when starting a DM, but is something to consider. I’m not sure how the delete function works, but best to go with the assumption that DMs are soft deleted (i.e. not removed from the DB, just not returned) and could be visible after being deleted.