I came here for the same reasons as most of you and chiefly among them was to escape the corporate embrace of common social media platforms.

But how much trust can we place into Lemmy, Mastodon, and/or other various integrated Fediverse platform instances?

I’m all for open-source and transparency which the devs seem to provide, although providing source code and routinely audited source code are entirely different concepts.

Similarly, the high availability of source code may lead to malicious instances, actors, and/or back-end modifications that would favor specific instances resounding consequence throughout the Fediverse.

So I ask simply: How much faith do you have? (Please provide supporting documentation links supporting your answer because I’m genuinely interested.)

EDIT: I literally removed a semi-colon character ‘:’

  • Nibodhika@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    11 months ago

    Similarly, the high availability of source code may lead to malicious instances, actors, and/or back-end modifications that would favor specific instances resounding consequence throughout the Fediverse.

    Historically availability of source code has prevented that sort of thing since forever. Plus you can’t favor a specific instance, that’s the beauty of the protocol. It’s like saying google can favourite a specific email provider, they can’t, if suddenly Gmail stops receiving or sending emails to random domains people would just switch boats because you can register on any of the other email providers that don’t do that. Gmail can collect your data and all, but all data on Lemmy is public, so there’s no need to mess with the source code to gather data.

    So what are you worried about? Mods moderating content in ways you don’t like? That will happen on any platform that allows moderation, and you don’t want to use one that doesn’t (plus it has nothing to do with the open source nature of the server, and you can jump to another community with different mods). Maybe you’re worried that malicious software will run on your phone? That’s more likely to happen with a closed source software, if you’re truly paranoid about these things you would have a full open source phone with a custom OS without google components flashed into it, I can see that you’re not on that level since you still don’t understand that open source is needed for transparency. Or maybe you’re worried the server itself will host malicious content? Any server can do that, servers that host things people write will always be able to host malicious content, it’s not hard to link to an external website or provide malicious scripts or files, just don’t click on random links or download random things from strangers online and you should be mostly fine.

    • Inept@lemmy.worldOP
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      edit-2
      11 months ago

      Historically availability of source code has prevented that sort of thing since forever. Plus you can’t favor a specific instance, that’s the beauty of the protocol.

      Availability of source code and actual auditing are entirely different.

      It’s like saying google can favourite a specific email provider, they can’t,

      They very well can as a private platform. For the record, google does favor specific vendors through their Google Partnership program and similarly through search results as recently found through court proceedings.

      but all data on Lemmy is public

      It’s also managed by a single source of truth, ie. databases… correct?

      So what are you worried about?

      I’m not worried about anything. I asked a question to a forum which seemed to superficially accommodate questions, my bad.

      Mods moderating content in ways you don’t like?

      I literally don’t care about moderated content, censorship, or whatever.

      Maybe you’re worried that malicious software will run on your phone?

      Nope.

      I can see that you’re not on that level since you still don’t understand that open source is needed for transparency.

      Yes, I’m lower than you. Teach me.

      Or maybe you’re worried the server itself will host malicious content?

      Counter question, how many straws are you grasping at here?

      Realize how many questions you levied and that I was actually kind enough to take the time to answer most of them even if possibly rhetorical.

      You insulted me and I’m okay with your opinions that I’m ignorant, “not on the level”, or whatever. I literally just asked a question.

      EDIT: I failed to proofread and had a redundancy collision.