The Kolektiva raid reminds us that itโ€™s important to stand with your users in the #fediverse too.
https://www.eff.org/deeplinks/2023/07/fbi-seizure-mastodon-server-wakeup-call-fediverse-users-and-hosts-protect-their
FBI Seizure of Mastodon Server Data is a Wakeup Call to Fediverse Users and Hosts to Protect their Users

Weโ€™re in an exciting time for users who want to take back control from major platforms like Twitter and Facebook. However, this new environment comes with challenges and risks for user privacy, so we need to get it right and make sure networks like the Fediverse and Bluesky are mindful of past...

Electronic Frontier Foundation
@eff Is there any guide of best practices for single-user instance operators wanting to avoid unnecessary legal liability?
@kmeisthax @eff Yes - create tools for admins on fedi platforms to view media that is uploaded to the server.
@eff I missed this when it happened. I'm sharing the original announcement for anyone else who wants to read it too. https://kolektiva.social/@admin/110637031574056150
admin :heart_cyber: (@[email protected])

๐Ÿšจ Kolektiva.social SECURITY ALERT ๐Ÿšจ This is an alert for Kolektiva.social users. Please read this post in its entirety! In mid-May 2023, the home of one of Kolektiva.social's admins was raided, and all their electronics were seized by the FBI. The raid was part of an investigation into a local protest. Kolektiva was neither a subject nor target of this investigation. Today, that admin was charged in relation to their alleged participation in this protest. Unfortunately, at the time of the raid, our admin was troubleshooting an issue and working with a backup copy of the Kolektiva.social database. This backup, dated from the first week of May 2023, was in an *unencrypted* state when the raid occurred and it was seized, along with everything else. The database is the heart of a Mastodon server. A database copy such as the one seized may include any of the following user data, in this case up to date as of early May 2023: - User account information like the e-mail address associated with your account, your followers and follows, etc. - All your posts: public, unlisted, followers-only, *and direct ("DMs")*. - Possibly IP addresses associated with your account - IP addresses on Kolektiva.social are logged for 3 days and then deleted, so IP addresses from any logins in the 3 days prior to the database backup date would be included. - A hashed ("encrypted") version of your password. ๐Ÿšจ ๐Ÿ‘‰ As a precaution we highly recommend that all users on Kolektiva.social *change their password immediately* to a new, unique, and strong password. We sincerely apologize to all our users and regret this breach. In hindsight, it was obviously a mistake to leave a copy of the database in an unencrypted state. Unfortunately, what would otherwise have been a small mistake happened to coincide with a raid, due to bad luck and spectacularly bad timing. We understand that our users and other people on the Fediverse will have a lot of questions. We will try to answer them as best we can, but please be patient and bear in mind that we may be overwhelmed with messages, and may be delayed in responding or unable to provide answers to certain questions for legal or technical reasons. As a security culture reminder, it can be extremely harmful to the individuals charged and to our community to openly speculate on the Internet about alleged criminal activity or about what law enforcement may be able to do with seized data. Our present awareness is that the seized Kolektiva data is unrelated to the federal investigation and prosecution and we are exploring legal avenues to have the seized data returned and copies destroyed. Thank you for your understanding and solidarity :black_sparkling_heart: ๐Ÿ‘‡ Please see our replies to this post for additional information (1/?) ๐Ÿ‘‡

kolektiva.social
@eff Do not underestimate this CSAM matter. As the recent attention from Facebook/Threads illustrates, big tech is starting to wake up to the danger the Fediverse represents to their regime of surveillance capitalism. The ostensible justification for attacking the Fediverse in the name of "rooting out child pornography" is a threat we need to take seriously.
@mastodonmigration @eff This can't be boosted enough.
@mastodonmigration @eff You read my mind, MM.
@KoHoSo @eff It's coming. Would not be at all surprised if Meta's next move is to say they have determined not federate because they need to protect their users. These guys punch hard.
@mastodonmigration @eff Yes we need to take this seriously, but not in the way that big-korpo would like to push on us - that is, connecting to their API , which will scan all our images.
Since such APIs for scanning #CSAM will never be open and free (so that criminals can not "test" materials before publication) then the only option is a decent #moderation #fediverse. But decent means actually manually reviewing all photo/video material published on the servers. And this, in turn, indicates that instances should be no more than real moderation capabilities. Such manual moderation does not seem realistic on instances with tens-hundreds of thousands of accounts.
@miklo @eff You have nicely summarized the problem. One of the most often proffered "solutions" is to hook up to Microsoft PhotoDNA. Which is... from Microsoft.

@mastodonmigration @eff Bittorrent was a nice protocol โ€“ until some people used it to distribute copyrighted material. These days, the Bittorrent protocol is blocked in many places.

This would work against ActivityPub as well: Claim there are "too many" people using it for an illegal purpose, and encourage/require ISPs to block it.

"No one controls how ActivityPub is used! We can't prevent abuse! We must block it!" Unfortunately, this kind of argument works against any decentralized setup.

@eschnett @eff Yup. Combine that with what appears to be a sophisticated information campaign to paint the Fediverse as a hotbed of CSAM. This is not a new tactic. Already getting side eye: "Don't you do stuff on Mastodon? Heard it is full of child porn..."
@mastodonmigration @eschnett @eff Washington Post made an entire article about Mastodon being solely for child exploitation. It's unreal. If you're seeing that material, fucking report it. I'm guessing you had to go looking for it though.

And that article was used by Senator Dick Durbin to push the STOP CSAM Act (which doesn't actually stop CSAM -- but it weakens encryption)

Here's the article @eff did yesterday on why the Stop CSAM bill is so bad

https://www.eff.org/deeplinks/2023/07/ndaa-no-place-sweeping-internet-legislation-stop-csam-act

And, here's an action from EFF to contact your Congresspeople and ask them to oppose STOP CSAM

https://act.eff.org/action/tell-congress-don-t-outlaw-encrypted-applications

@speculater @mastodonmigration @eschnett

The NDAA is No Place for Sweeping Internet Legislation Like the STOP CSAM Act

The STOP CSAM Act of 2023 would undermine services offering end-to-end encryption and incentivize internet companies to take down lawful user speech. This dangerous bill would threaten security and free speech on the internetโ€”but incredibly, it may pass Congress without even being seriously debated...

Electronic Frontier Foundation
@jdp23 @eff @speculater @eschnett Remember when Dick Durbin aced out Sheldon Whitehouse for Judiciary Chairman even though he was already Whip. Sad day for the country.
@mastodonmigration F---ing Dems. Don't get me started, it's almost midnight here, I need to get some sleep! ๐Ÿ˜‚
@jdp23 OK, sleep well. The world will still need saving tomorrow.

Also STOP CSAM is only one of the bad internet bills they're potentially trying to sneak through this week. EARN IT also weakens encryption. KOSA is especially harmful to LGBTQ+ people. Cooper Davis Act turns tech companies into DEA informants.

EFF's got actions on all of them in this thread. https://mastodon.social/@eff/110775891238303192

@eff @speculater @mastodonmigration @eschnett

@speculater @mastodonmigration @eschnett @eff
There needs to be an effort by the community to defend against such allegations.

But how do you defend yourself against a major new source? Especially of they print any 'we're sorry' message about a previous article on page N+1?

@speculater @mastodonmigration @eschnett @eff
Such things fall into a similar camp to 'parents sue social Media companies for damaging their children'.

What is the damage? Being socially and pro-LGBTQ+ for conservative parents? What?

The entire 'Think Of The Children' narrative is a figleaf for suppressing stuff you don't like through the backdoor.

It's never about children, water fountains, bathrooms, condoms or abortions.

@MeiLin @speculater @eschnett @eff On the right they seem to accuse anyone they don't like of being a 'pedo' sooner or later. This is nothing new.

@MeiLin @speculater @eschnett @eff Good question. Corporations have marketing communications departments with PR professionals who specialize in "crisis management". All we have is us. Think we will do just fine.

Already posts like this one are asking questions. We are not stupid, and we are not powerless. If this is a 'hit job,' we will figure it out. If we need to shore up our defenses, we will do that too. Its our network, and we are not going to let anyone mess with it.

@mastodonmigration @speculater @eschnett @eff
Don't we have a few marketing and PR professionals stacked in some Mastodon server somewhere?

Sic them on this kind of narrative.

@MeiLin @speculater @eschnett @eff Yeah, there must be. Think it's already happening. One of the great things about an open social media collective like the Fediverse, is that everyone has agency and can act independently in what they see as the interest of the whole. People bring their respective skills to bear. It's somewhat chaotic, but very effective.
@eff come and raid my server FBI! i dare you! you can claw my furries posts out of my cold dead hands
ุฃุฑุฌูˆ ู…ู† ุงุฏุงุฑุฉ ู…ู†ุตุฉ ุจุณุงู… ุงู„ุชู†ุจู‡ ู„ู‡ุฐุง ุงู„ู…ู‚ุงู„
@ahmad @saleh
@eff My girlfriend Leila was one of the first employees in Mitch and Mike's Cambridge office back in the day.
Not sure it was a paid position, but she got a job recommendation letter from Mitch Kapor, which is nice.
One of the best investments I ever made. Too bad the girlfriend thing did not work out...
@eff Under civil forfeiture, American cops are incentivised to steal as much valuable electronics as they can. Untill there's reform of the civil forfeiture rules, overly broad seizures of potentially fenceable property are unlikely to decline.
@eff I don't think it says in the article, but somewhere else someone mentioned that the important thing is: don't be an activist and run a server....