Mastodon's decentralized social network has a major CSAM problem | Engadget

SELECTstarFROMreddit@sh.itjust.works to Technology@lemmy.world – 24 points –
Mastodon's decentralized social network has a major CSAM problem | Engadget
engadget.com
31

You are viewing a single comment

Given new commercial entrants into the Fediverse such as WordPress, Tumblr and Threads, we suggest collaboration among these parties to help bring the trust and safety benefits currently enjoyed by centralized platforms to the wider Fediverse ecosystem

In such a system, the server on which a post originates would submit imagery to PhotoDNA for analysis

This same technique could also be applied to other hosted media analysis mechanisms (e.g. Google’s SafeSearch or Microsoft’s Analyze Image API40

While large social media providers utilize signals such as browser User-Agent, TLS fingerprint,8 IP and many other mechanisms to determine whether a previously suspended bad actor is attempting to re-create an account, Mastodon admins have little to work with apart from a user’s IP and e-mail address, both of which are easily fungible.

So basically people might have joined the fediverse in large due to privacy reasons but if fediverse is to be "ethical" it should share your images with big tech as well as track you better.

He also laments Tor and E2E messaging.

Anyone who's on Lemmy for "privacy reasons" is probably not looking very closely at the technology. Everything you do here, including votes and DMs, is effectively public. All of it can be scraped, ingested, processed, etc. by absolutely anyone.

Votes are federated. They are tied to account names. Only your instance can tie them to your IP.

DMs are insecure in that admin instances can read them. Most instances tell you not to use them.

Scraping is more resource intensive than using an API to have data submitted to you. Since you are now offering a service you can set terms on what you can legally do with that data while scraping can lead to legal issues. PR issues as well.

In general using a corporate social media will allow companies to track you (or buy the tracking data from the social media company) far more thoroughly than scraping lemmy.