I came here for the same reasons as most of you and chiefly among them was to escape the corporate embrace of common social media platforms.

But how much trust can we place into Lemmy, Mastodon, and/or other various integrated Fediverse platform instances?

I’m all for open-source and transparency which the devs seem to provide, although providing source code and routinely audited source code are entirely different concepts.

Similarly, the high availability of source code may lead to malicious instances, actors, and/or back-end modifications that would favor specific instances resounding consequence throughout the Fediverse.

So I ask simply: How much faith do you have? (Please provide supporting documentation links supporting your answer because I’m genuinely interested.)

EDIT: I literally removed a semi-colon character ‘:’

  • @Nibodhika
    link
    31 year ago

    First of all I never insulted you, I said you’re not on the level of paranoia to be using exclusively open source software on your phone, if you were you wouldn’t use open source as a negative term (btw I’m also not on that level, I’m writing this answer from a third party closed source client on a stock Android phone). I apologise for the misunderstanding and rereading my answer I can see why you would take it as an insult, but let me assure you it was not, I only meant to say you’re not too paranoid about other software that’s running on your phone so you shouldn’t be about this either.

    Availability of source code and actual auditing are entirely different.

    Indeed they are, but auditing is only possible on open source programs, therefore on the worst case scenario, i.e. no one ever audited the code, it should be at least just as safe as a closed source alternative. Plus I was answering to a point you made which specifically stated that code availability might lead to malicious instances, which is completely contrary to all historical information we have, which is why the most critical pieces of software for security (SSL, TLS, etc) are all (100%, no exceptions) open source.

    They very well can as a private platform. For the record, google does favor specific vendors through their Google Partnership program and similarly through search results as recently found through court proceedings.

    Yes, but I was specifically talking about emails, if gmail refused to send/receive emails from addresses @yahoo or @microsoft people would not use it. Remember that the fediverse is similar to email, where different servers talk to each other, if one server refuses to play nice and blocks content it’s by definition worse than the others that show you that content, therefore there’s no incentive to keep using that server and users would migrate away.

    It’s also managed by a single source of truth, ie. databases… correct?

    Noz it’s managed by multiple sources of truth, each server has their own database of the content they serve and/or have cached. Being worried about a server altering the data is like being worried Google will alter the content of the emails you send/receive, possible? Yes, but the moment someone discovered it (and it would be very simple to discover) no one else would trust that server and would instead use another.

    I’m not worried about anything. I asked a question to a forum which seemed to superficially accommodate questions, my bad.

    But your question was about how much trust to put in it, which implies you think there’s a reason to be worried and not put trust in it, and I’m trying to figure out what is your worry, what exactly is it that you think you shouldn’t trust.

    Counter question, how many straws are you grasping at here?

    As many as I could think, because honestly I can’t understand what is it that you have a problem with trusting, so I was bouncing ideas on things people might not trust (mods, malicious code, etc).

    Realize how many questions you levied and that I was actually kind enough to take the time to answer most of them even if possibly rhetorical.

    Yes, because I don’t understand what is it that you have a problem with trusting, content? Server code? Client code? There are many things you could have an issue with trusting, and I honestly want to understand which one is it.

    You insulted me and I’m okay with your opinions that I’m ignorant, “not on the level”, or whatever. I literally just asked a question.

    Again, I’m sorry for the miscommunication, it was never my intention to insult you.