this post was submitted on 13 Jan 2025
95 points (92.0% liked)
Fediverse
28976 readers
1104 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Because of the way the protocol works.
There is no way to accomplish this is a publicly federated network without trusting the portals people use and/or creating some sort of public key exchange on friend requests.
This results in privacy breaches being as simple as compromising one node, or writing some code to make a node hostile.
The key idea would be basically when you friend/follow someone you send them your public key, they keep a list of keys and encode/individually send followed messages to people. Very onerous.
Doesn't PixelFed allow marking accounts private though?
I don't know what mechanism they use, but I have a hunch that if you allowlist one user from an instance, the instance owner could potentially see the stuff. Not just your own instance owner.