Some of the application processes are super invasive Some are hosted in hostile jurisdictions Some are ran by well meaning but incompetent admins Some log everything
Are there any that take privacy and security seriously?
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
much thanks to @gary_host_laptop for the logo design :)
Its a federated service. Anyone can track all your posts, comments, votes, etc.
There is no such thing as a “privacy respecting” lemmy instance. The admin can promise you that they wont log your IP but thats not worth anything at all, ever, anywhere on the internet.
This is mostly true.
However, it’s worth noting that your home instance is uniquely positioned: it can see not only everything you send out into the fediverse, but also everything you read or subscribe to, so its privacy practices can still matter.
With that in mind, I suggest avoiding instances that run behind Cloudflare, which can see (and even change) every interaction you have with the instance.
You might also want to disable off-site images in your web browser (if you use Lemmy’s web interface) and prefer an instance with a large image cache, because loading images that are hosted on other instances will leak your reading habits to those instances.
Lemmy is inherently bad at privacy. You can gain a little bit by running your own instance. Using anyone else’s instance discloses TMI.
You are posting on a public fora… What sort of privacy are you expecting?
No
What exactly are you worried about? The instance logging your IP, device info? I’m not sure I really see a large privacy or security risk if you’re logging in from a VPN and if you’re using a unique password. And what do you mean by some of the application processes being invasive?
I feel like accessing your Lemmy is pretty much like accessing any other website, but your instance really doesn’t know much about you in comparison to others. I don’t know much about deep privacy and security risks though.
This. A silo’d account. Speaking of which, ALL of your accounts online need to be silo’d. Each need it’s own username, password (preferably a generated one from Bitwarden or equal), it’s own avatar, and it’s own unique identity, especially any social media such as Lemmy. The latter is the hardest because it requires you to think about how you type in responses into social media forums. What kind of spelling errors you normally make. What kind of words and phrases you use. What kind of cultural references or cultural jargon you use. All of these things can be distilled down to track you. As mentioned, VPNs and other obfuscation techniques should be engaged as well.
Not saying anyone here is an active shooter, but if you’ve ever watched one develop on national TV, in the first 15 minutes of the airing, the news outlets know the person’s entire life story. Your life should not be that easily accessible to anyone.
Why not run your own?
Unironically this, if you couldn’t possibly trust any Lemmy admin with your data. Host your own single user Lemmy/mbin/Piefed instance and you set the rules. If you can trust a cloud VPS provider then use that, but if even that is too risky in your view, then self-host. Note it costs money and you will have to put a lot of effort to safeguard yourself from spam attacks and info-stealing.
Using someone else’s server means ultimately entrusting your information for safekeeping with the admin. I’m not that paranoid but it all depends on the tradeoffs you want to pay for.