Like even if they have nothing else they could just leak IP is there any law against it ? Or any technical aspect stopping them ?

  • @[email protected]
    link
    fedilink
    784 months ago

    Ethically it’d be shitty and people don’t want to be part of an instance with shitty admins so people would migrate away. Technically, nothing unless you’re using a VPN. Welcome to the internet, the same is true for every website

    • @[email protected]
      link
      fedilink
      English
      354 months ago

      Also there’s the aspect of just… not caring. As someone who technically could read the email, browse the files, or track the apps installed and used on the phone of nearly any person where I work, any small bit of idle curiousity died before I was done my first day.

      Even if I was nosy, 99% of people are just not that fucking interesting. What would even be the point of abusing my access?

      I’ve seen someone put it like this: male gynecologists don’t get excited looking at lady bits at work.

      • @[email protected]
        link
        fedilink
        84 months ago

        I was able to do that for years. For me to give a shit what’s in your email you have to be more interesting than the rest of the internet, which pretty much means you’d have to be doing something at least borderline illegal and have it brought to my attention by someone who noticed it over your shoulder.

  • @[email protected]
    link
    fedilink
    English
    31
    edit-2
    4 months ago

    An IP address by itself isn’t going to let you dox users unless you have access to the databases that map these to the subscriber accounts. Typically, you would need to be an ISP or law enforcement to do this, but you can also purchase this information from a data broker if you know what you’re doing.

    With that said, there is absolutely nothing stopping the instance operator from getting your IP address. You’re connecting to his or her computer which they own, so they can easily see where you’re connecting from.

    • BombOmOm
      link
      fedilink
      English
      21
      edit-2
      4 months ago

      A notable way to protect against this is to use a VPN. Then the operator only knows you use a VPN.

      Also need to be careful of what you write in comments (this is a public forum!). People sometimes write a surprising amount of detail about their life and it makes it much easier to narrow you down to a single individual the more you do it.

  • frozen
    link
    fedilink
    224 months ago

    I run an instance. I promise, I have literally 0 care about who you are. I have much more productive things to do with my time.

      • frozen
        link
        fedilink
        12
        edit-2
        4 months ago

        I’m sorry I didn’t call out every exception to the rule. Obviously, if you do illegal things on my instance, I will care. I kind of thought that was a given, to be honest.

        • @[email protected]
          link
          fedilink
          -44 months ago

          Because it’s the most important reason we have admins, and they have a responsibility to not “not care” about it

          • @[email protected]
            link
            fedilink
            24 months ago

            Except they don’t though. They have 0 reason or incentive to care. You are hoping they are good people and care, but they don’t have to.

            • @[email protected]
              link
              fedilink
              14 months ago

              In the case of CSAM they really have to care, if they want to or not. Otherwise the instance gets shut down pretty fast and the police will have a not so nice chat with the admin.

  • southsamurai
    link
    fedilink
    224 months ago

    Serious answer: nothing except their own lack of access to anything except the ip address and whatever you give them.

    But that’s easy to counter with a VPN and a bit of common sense.

  • @[email protected]
    link
    fedilink
    134 months ago

    Oh my… This whole thread is literally the best of ‘Do you have something to hide?’, ‘Why should they use it?’, ‘What could happen?’, ‘That’s paranoid’ and so on.

    Really disappointing.

  • @[email protected]
    link
    fedilink
    124 months ago

    Technical measures are impossible in this particular case. However, I would say that the complete lack of benefits or incentives makes it very unlikely. Doing so could be illegal and collecting data which is otherwise useless is only a liability and a waste of resources. Basically the admin own self-interest I would say is what’s stopping them. That said, if someone is individually afraid due to a bad relationship with an admin, then personal motives could void the above, in which case, they should change instance probably or use a VPN at least.

  • @[email protected]
    link
    fedilink
    English
    10
    edit-2
    4 months ago

    You’re connecting to their servers. They’re going to get your IP. This is unavoidable.

    They can even * [gasp] * read the messages and things you willingly post onto their servers.

  • @[email protected]
    link
    fedilink
    94 months ago

    There’s not much to prevent it from happening. They could lose standing in the community. They could be given legal trouble, and they could be attacked in return by people who knew which server owner was responsible. But that’s pretty much it.

    There’s also a much lower bar for entry when it comes to running a server. All you need to “be” is technically competent. You don’t need to be very good at security, and you don’t need the temperament of a reasonable person.

    And when that’s the case, data might be leaked even indirectly.

    Two Mastodon examples come to mind.

    • One administrator shut down their servers after being accused of transphobia. They could have done anything after having a bit of a public meltdown, so that was the best case scenario.
    • Another server administrator was raided by police, and all the contents on the server were made accessible to them.
  • poVoq
    link
    fedilink
    74 months ago

    They have no business incentive for it, contrary to most other websites that are funded by targeted advertisement which basically means doxxing their users to advertisement companies.

  • arran 🇦🇺
    link
    fedilink
    64 months ago

    Don’t let your guard down but at some point trust and risk consideration is required for most systems to work. If you’re after solutions; you could run your own node in the cloud and federate it.

    • The wild cardOP
      link
      fedilink
      34 months ago

      Was thinkin about it and read some docs which brought me to the conclusion that its too much work for me

  • ɐɥO
    link
    fedilink
    54 months ago

    Nobody cares about ips. This is mine: 193.81.127.151 . Try to find out anything about me exept my approximate location.

  • @[email protected]
    link
    fedilink
    4
    edit-2
    4 months ago

    Yes, there are laws against doxxing in several countries.

    There is no technical aspect stopping it. Every website has your IP, sometimes also the people you chat with or write emails to, as this might (or might not) be part of the meta-information.

    An IP address is a boring piece of information. Usually you can just infer the country and which internet service provider someone uses. You’d need to sue the ISP or get a court order to get the name and address of who’s using that IP number.

    Running these services is a lot of work and requires some skill, at least to do it sustainably. Usually it’s certain people who are dedicated enough and willing to put in the effort… They are motivated to build something or help people. That’s what drives them. It’s somewhat unlikely but not impossible that they participate in malicious behaviour. Sometimes internet drama happens. But users aren’t stupid either.

    (But people who want to destroy and troll, rarely have the character traits to succeed at something like this. You’d pass on easier methods to wreak more havoc, to instead spend time learning webhosting, Linux, build up a community and maintain the server… You wouldn’t do all of that unless it were worth it. I can only imagine that happening in a targeted attack that pays a good amount of money. Or a really good amount of internet fame because you doxxed a high-profile celebrity or something like that.)

    • The wild cardOP
      link
      fedilink
      04 months ago

      So your whole argument is based of the kindness of admins ? I get that you are trying to see the good but still

      • Troy
        link
        fedilink
        54 months ago

        The kindness of admins is a requirement of pretty much all internet infrastructure. Email servers are the same, no? And it gets even harder with proprietary networks – if the admins are being unkind, you can just switch discord servers or whatever. Anyway, I digress.

      • @[email protected]
        link
        fedilink
        4
        edit-2
        4 months ago

        What’s your question? I mean different types of services exist. You’re currently on a platform powered by volunteers. If you don’t like it, there is alternatives like Reddit which is a commercial / for-profit company.

        We have projects like Lemmy, Linux and the whole Free Software which somewhat relies on kindness and giving. It’s the same for charity, your schools extracurricular club where parents and teachers volunteer their time and energy. Or bring cake to a special day.

        And with the “trust”: I think it’s more nuanced. You also rely on other peoples kindness to stop at the red light at a traffic junction and not crash into you at full speed. Theoretically nothing is stopping them. It’s the same concept, you’re forced to cooperate sometimes and rely on other people to abide by the law and also cooperate. It regularly works fine. Just make a good choice whom you trust and why.

        You don’t need to worry about your IP. It’s really not a big deal if people know it… I’d have a look at who’s running a service once I upload private documents with my finances etc, photos of me… More than random ramblings. And experience shows also the services that don’t rely on volunteering aren’t a safe bet. Most of the big companies and platforms have been hacked. https://haveibeenpwned.com/ lists my email AND password has been lost at least 3 times by the big players.

        And regarding you specifically… I already know enough about you by reading your public posts. You’re probably from the USA. At least I didn’t find comments in other languages, and statistics tell me people here are either american or german. You use Android, know what FOSS is, seem to like it and play things like Supertuxkart. You like to waste some of your time in meme communities and casual conversation and just created this account yesterday. And you talk a certain way which makes me think this isn’t your first time on the internet. What else am I supposed to deduct by knowing your IP?

        You’re right asking the question “should I trust you with my data”. That is why I don’t use Facebook, Microsoft, bonus cards, TEMU…

        • The wild cardOP
          link
          fedilink
          0
          edit-2
          4 months ago

          Woah you were close

          like it and play things like Supertuxkart.

          Wrong . I hate playing any and all games.

          just created this account yesterday.

          And you talk a certain way which makes me think this isn’t your first time on the internet.

          There was a post about me moving my account on casual conversation.

          Other than these two mistake you mostly nailed it

          • @[email protected]
            link
            fedilink
            1
            edit-2
            4 months ago

            Hehe, we seem to share a few things…

            I mean we’re often predctable, and while Lemmy is somewhat diverse, most people I meet here are either American or German and males from, lets say 20-40. And there are certain types prevalent. Like the Meme-Lord, the casual Linux expert, the normal guy or the agitated opposer. Some people fulfill multiple categories or like being a bit schizophrenic on the internet. But I’ve also met people with crazy niche interests, or trying new things, so there is that.

            And I can’t really tell: Playing devil’s advocate, participating in memes and internet culture and having multiple sock-puppet accounts for different use-cases are fairly common and make it difficult to judge a person. And my own behaviour is also very different in real-life than what I do here.

            • The wild cardOP
              link
              fedilink
              0
              edit-2
              4 months ago

              Huh never knew germans where the other popular category here i guessed that usa would be one of course. You learn somethin everyday i guess.

              • @[email protected]
                link
                fedilink
                1
                edit-2
                4 months ago

                It’s been the same on Reddit, so I think with lots of people coming from there, it’s just the logical consequence that we get the same demographics here. My perspective might be a bit skewed on that… I’ve also talked to some British and Canadian people here. There’s some server statistics (on Fediverse observer or something) that reflect a similar thing with the origin of the servers. Ultimately I like platforms like this for connecting people all across the world.

                • The wild cardOP
                  link
                  fedilink
                  24 months ago

                  Yea i thought uk or canada maybe the other popular one as i don’t even see much german focused instances

      • @[email protected]
        link
        fedilink
        English
        34 months ago

        Their comment started with mentioning laws. That’s more than betting on only kindness.