soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #security

[?]PrivacyDigest » 🌐
@PrivacyDigest@mas.to

Retailers Secretively Using to Spot “Persons of Interest” — Including For the Government

The grocery store chain , among other retailers, is using face recognition on its customers — and scanning their faces for resemblance not only to accused but also to people whose photos have been submitted to the company by law enforcement.

aclu.org/news/privacy-technolo

    [?]#FreeSchool <---> Hashtag » 🌐
    @freeschool@qoto.org

    Fediverse = lack of anyone dedicating to #caring for it's users more personally - we're too #alone and I'm not proud to be a #pioneer like this!... [SENSITIVE CONTENT]

    Uhff = Seeing your old post in #2026 - almost a year to the day from lack of anyone else dedicating to for it's users more personally - we're too and I'm not proud to be a like this!...

    Only providing one-way mass spaces with no-one personally driving their instance and space,...
    urghhh... dry...

    Thanks I guess - - a tech instance is not enough, we need humans answering / pushing / educating / warming up with the others ! Captains / people driving the ship forward socially else we just stay drifting with no pioneering / much less discovery / progress / just tech which gets rug pulled...

    Humans hold their and can share them better than cold !

    We can't stay humanly cold / unlearned / just in text-modes...
    Ouch .

    My post I'm referring to is about Browsing the web and being watched / activities logged...

    qoto.org/@freeschool/113811427

    (that post a bit unrelated to this post 💬

    But I guess I'll see this post soon enough a year from now.... so here's the last! (also without human comment, or interaction from / @molly0xfff )

    People are doing good work but more-personally we're not building OUR MASS - just a few specialists talking to the who are far from able to even reply sometimes...

    ⬅️ needed ?

    and some

      [?]Freezenet » 🌐
      @freezenet@noc.social

      Proton VPN Warns of the Dangers of Michigan’s VPN Ban Bill

      Age verification laws have become more dangerous to civilians as VPNs become increasingly targeted. Michigan is one example.

      freezenet.ca/proton-vpn-warns-

        [?]Igor Sovcik » 🌐
        @igisho@rockosbasilisk.com

        I’m exploring a post-crypto/post-ledger direction for Proof-of-Interaction:
        no identity, no global consensus, trust grounded in physical causality and local state, not signatures or blockchains.

        Looking for a crypto / protocol nerd who enjoys questioning first principles and would be up for a deep technical/philosophical consult.

        Not a pitch. Not a startup grind. Just serious thinking.

          [?]ResearchBuzz: Firehose » 🌐
          @researchbuzz_firehose@rbfirehose.com

          Coywolf: Starlink updates Privacy Policy to allow AI model training with personal data. “The Elon Musk-owned (SpaceX) satellite internet company Starlink just updated its Privacy Policy to allow the use of customers’ personal information to train [its] machine learning or artificial intelligence models, including for third parties. The change in its policy is opt-in by default.”

          https://rbfirehose.com/2026/01/18/coywolf-starlink-updates-privacy-policy-to-allow-ai-model-training-with-personal-data/

          [?]John-Mark Gurney [he/they] » 🌐
          @encthenet@flyovercountry.social

          Does anyone have good resources on [personal] key management? That is latest blog posts or books on the topic?

          This is things like secure management and backup (SSS?), off-line/dedicated devices, managing many keys due to rotation, etc.

          e.g. If you encrypt old/past keys, even with a secure key, and that key leaks, you need to know where all the encrypted data is to destroy/rewrite it with a new key, so you can't just keep tons of backups.

            [?]Miami Tech Enthusiast Club 📎 » 🌐
            @mtec@mastodon.social

            RE: mastodon.social/@eff/115907269

            It is AI integrations like these that have us concerned about the future of Florida, where a bill is being considered to require age verification for using a chatbot.

            It is possible that Google could require you to verify your identity to use any Google service because of Gemini being there.

            miamitech.club/oppose-sb-482/

            [?]Electronic Frontier Foundation » 🌐
            @eff@mastodon.social

            “It’s a reminder to people that email should be treated almost not quite public,” EFF’s Thorin Klosowski told The New York Times. Consider the company that runs it and law enforcement's access to it: "The more you put it in it, the more they’ll have access to.”
            nytimes.com/2026/01/15/technol

              [?]ResearchBuzz: Firehose » 🌐
              @researchbuzz_firehose@rbfirehose.com

              Gizmodo: Signal’s Founder Turns His Attention to AI’s Privacy Problem. “The founder of Signal has been quietly working on a fully end-to-end encrypted, open-source AI chatbot designed to keep users’ conversations secret. In a series of blog posts, Moxie Marlinspike makes clear that while he is a fan of large language models, he’s uneasy about how little privacy most AI platforms […]

              https://rbfirehose.com/2026/01/16/gizmodo-signals-founder-turns-his-attention-to-ais-privacy-problem/

              [?]PrivacyDigest » 🌐
              @PrivacyDigest@mas.to

              So, You’ve Hit an Gate. What Now?

              This blog also appears in our Resource Hub: our one-stop shop for users seeking to understand what age-gating laws actually do, what’s at stake, how to protect yourself, and why @eff opposes all forms of age verification mandates. Head to EFF.org/Age to explore our resources and join us in the fight for a free, open, private, and yes—safe—internet.

              eff.org/deeplinks/2026/01/so-y

                [?]windowsCult » 🌐
                @windowscult@flipboard.social

                Do you know how much data Google Chrome quietly collects about you? From your browsing history to device details, everything is logged. Here is how to lock your Chrome privacy settings in a few minutes. windowspost.com/chrome-privacy

                what data chrome collects for google and how to block it in 2026

                Alt...what data chrome collects for google and how to block it in 2026

                  screwlisp boosted

                  [?]Aral Balkan » 🌐
                  @aral@mastodon.ar.al

                  🥳 Auto-Encrypt Localhost version 9.0.0 released

                  Bye bye, Windows.

                  • Windows is no longer supported as Microsoft is complicit in Israel’s genocide of the Palestinian people¹ and Small Technology Foundation² stands in solidarity with the Boycott, Divestment, and Sanctions (BDS) movement³. Windows is an ad-infested and surveillance-ridden dumpster fire of an operating system and, alongside supporting genocide, you are putting both yourself and others at risk by using it.

                  Enjoy!

                  💕

                  About Auto-Encrypt Localhost:

                  codeberg.org/small-tech/auto-e

                  Auto Encrypt Localhost is similar to the Go utility [mkcert](github.com/FiloSottile/mkcert/) but with the following important differences:

                  1. It’s written in pure JavaScript for Node.js.

                  2. It does not require certutil to be installed.

                  3. It uses a different technique to install its certificate authority in the system trust store of macOS.

                  4. It uses enterprise policies on all platforms to get Firefox to include its certificate authority from the system trust store.

                  5. In addition to its Command-Line Interface, it can be used programmatically to automatically handle local development certificate provisioning while creating your server.

                  Auto-Encrypt Localhost is licensed under AGPL version 3.0.

                  ¹ bdsmovement.net/microsoft
                  ² small-tech.org/
                  ³ bdsmovement.net/

                    [?]Marcus "MajorLinux" Summers » 🌐
                    @majorlinux@toot.majorshouse.com

                    Are you being tracked by the police?

                    Police Unmask Millions of Surveillance Targets Because of Flock Redaction Error

                    404media.co/police-unmask-mill

                      [?]knoppix » 🌐
                      @knoppix95@mastodon.social

                      Arti 1.9.0 released with SOCKS proxy dynamic port support, relay circuit data handling, and directory authority key certificates for Tor's Rust implementation. 🛠️
                      Progress on relays and onion services advances next-gen privacy infrastructure, though still experimental for production use. 🔒

                      @torproject

                      🔗 blog.torproject.org/arti_1_9_0

                        [?]knoppix » 🌐
                        @knoppix95@mastodon.social

                        pcTattletale spyware founder Bryan Fleming pleads guilty to federal hacking and illegal surveillance software charges after HSI probe. 📱
                        The case highlights how stalkerware operators openly market non-consensual tracking, raising accountability gaps despite known privacy risks. ⚖️

                        🔗 techcrunch.com/2026/01/06/foun

                          [?]knoppix » 🌐
                          @knoppix95@mastodon.social

                          California's DROP platform took effect Jan 1, letting residents submit one deletion request to 500+ registered data brokers. 🗑️
                          The Delete Act streamlines prior per-broker opt-outs, but brokers still keep first-party/public data amid privacy advocates' mixed reception. ⚖️

                          🔗 arstechnica.com/tech-policy/20

                            [?]knoppix » 🌐
                            @knoppix95@mastodon.social

                            Telegram adds passkey support for secure, phishing-resistant logins across devices, replacing SMS verification codes. 🔐
                            Phone number requirement persists, raising ongoing privacy concerns around KYC compliance and account linking. 📱

                            🔗 privacyguides.org/news/2026/01

                              [?]ResearchBuzz: Firehose » 🌐
                              @researchbuzz_firehose@rbfirehose.com

                              MakeUseOf: I turned off these Google settings to improve privacy. “I use Google for almost everything. Search, email, maps, videos, documents, even my calendar. The biggest advantage here is convenience. I don’t have to create dozens of accounts and manage them separately. But it also means I’m giving way too much data to a single company. That’s not exactly a smart thing to do if you […]

                              https://rbfirehose.com/2026/01/13/makeuseof-i-turned-off-these-google-settings-to-improve-privacy/

                              [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                              @nemo@mas.to

                              🚨 Alarming update: ICE gains ability to spy on every phone in neighborhoods via advanced surveillance tools, tracking devices block by block. Privacy at risk? Read more: wired.com/story/security-news-

                                [?]ResearchBuzz: Firehose » 🌐
                                @researchbuzz_firehose@rbfirehose.com

                                The Register: How hackers are fighting back against ICE surveillance tech . “Clever hackers and digital privacy advocates are fighting back against the snooping activities of Kristi Noem’s masked agents. The Electronic Frontier Foundation (EFF) has rounded up several of these counter surveillance projects, and perhaps unsurprisingly many of these have to do with Flock, best known for its […]

                                https://rbfirehose.com/2026/01/12/the-register-how-hackers-are-fighting-back-against-ice-surveillance-tech/

                                [?]Tuta » 🌐
                                @Tutanota@mastodon.social

                                In 2025, the German launched the Year of recommending Tuta Mail.🇩🇪 ❤️

                                In 2026, we call for a year on end-to-end encryption in email - so they stop recommending Gmail & Co as well. 🔒

                                Screenshot from the BSI website recommending Tuta - and stating that end-to-end encryption is important - but still recommending Gmail & Co...

                                Alt...Screenshot from the BSI website recommending Tuta - and stating that end-to-end encryption is important - but still recommending Gmail & Co...

                                  [?]Jupiter Rowland » 🌐
                                  @jupiter_rowland@hub.netzgemeinde.eu

                                  @Jasper Burns

                                  Permissions meet groups


                                  It gets really interesting when the permissions system is applied to groups. As the owner of a Hubzilla forum, you have the following options:
                                  • You can control who can see the profile of the forum, i.e. what it is all about. For example, you can only allow confirmed members to see it. Or, in fact, you can only allow certain members to see it by assigning a specific contact role to them. Or you could make it Fediverse-specific: Only those who can be recognised as logged-in Fediverse users can see the profile. Or you can hide it altogether.
                                  • You can control who can see the contacts, i.e. the forum members, all the same. Like, for example, only a chosen inner circle may be allowed to see the list of forum members, but Joe Average Forum Member is not.
                                  • Likewise, you can control who can see what has already happened in the forum when visiting the group profile.
                                  • You can choose to hide the whole forum from the directory, the place where people go to find new contacts (the mastodon.social equivalent is https://mastodon.social/directory), to keep the forum secret altogether by keeping people from finding it accidentally or by searching.

                                  (streams) and Forte have four different types of group channels instead:
                                  • Normal: public, group members may upload media to the group's file storage
                                  • Limited: public, but group members may not upload media to the group's file storage
                                  • Moderated: like Limited, but by default, posts and comments by new group members have to be approved by the admins; members may have their permissions upgraded and post and comment without approval once they've proven themselves worthy
                                  • Restricted: private, profile is only visible to group members, stream of posts and comments is only visible to group members, posts and comments are only sent to group members, but group members may upload media to the group's file storage
                                  Whether or not a group is visible in the directory is a separate switch.

                                  As I've already said, you can grant individual permissions to your contacts on your personal channel. But you can grant individual permissions to forum users on a forum channel just the same. You can have regular users. You can have users with certain extra privileges. You can use the permissions system to silence users without kicking and blocking them.

                                  And you can use the permissions system to appoint extra forum admins/mods. You can grant contacts permission to administer your forum. Now, this requires for your channel to recognise visitors and their identities to see what permissions they shall have and to grant them these permissions. And this requires OpenWebAuth. So right now, you can only make forum members from Hubzilla, (streams), Forte, Friendica, Mitra and Tootik additional admins/mods. But you can.

                                  (9/9)

                                  #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Fediverse #Hubzilla #Streams #(streams) #Forte #Privacy #Security #Permission #Permissions #Groups #FediGroups #FediverseGroups #PrivateGroups

                                    [?]Jupiter Rowland » 🌐
                                    @jupiter_rowland@hub.netzgemeinde.eu

                                    @Jasper Burns

                                    Permissions, part 3: At post level


                                    As I've already said, whenever you write a post to start a new thread, you also define the permissions of this post. Of this post and of all replies.

                                    Let's translate this to Mastodon again.

                                    You know the toot visibility button, I guess. Let's assume it looks and works somewhat different. Especially the visibility options.

                                    "Public" still exists. It does what it says on the button: It makes your toot public. Oh, and now, it also makes all replies public. There's no replying to your toot with a DM.

                                    The other three don't exist.

                                    Instead, as the second option, you have "Only me".

                                    Right below, all your lists are listed up. You can pick one of them. You can send your toot to everyone on one specific list of yours and to only those on that list, all without having to mention them. Better yet: Only those on that list are permitted to see your toot. And only those on that list are permitted to see any reply to your toot. Killer feature: They can see each other's replies, and they can reply to each other.

                                    Below that, all groups that you follow are listed up. Again, you can pick one of them. This will have the effect that your toot will go to the group, and it will be forwarded by the group to all its members, but it will not go to your followers unless they're also in that group.

                                    Below that, there's "Custom selection". This opens another window with each one of your lists and each one of your followed accounts, each with a green "Allow" button and a red "Don't allow" button. Here, you can put together a choice of lists and single accounts whom to send your toot to and a choice of lists and single accounts whom not to send your toot to. Again, only those who receive the toot are also permitted to see it, and only them are permitted to see any of the replies, and no-one can ever change these permissions.

                                    What sense this makes?

                                    Imagine you have a list with a certain group of friends in it. One of them will soon celebrate their birthday, and you want to organise a birthday surprise for them. So you send a toot to that list with everyone in it, but without that person who'll soon celebrate their birthday so you won't ruin the surprise for them.

                                    Or: Imagine you have lists according to which languages people speak. Like, you have a German list, and you have an English list. Then you can put together an audience for a German toot from lists and single followed users, but exclude the English list so that those who don't understand German anyway won't receive that toot.

                                    By the way: This also covers DMs. And this means that DMs are actually private.

                                    As Mastodon is right now, you can DM Alice, you can have a conversation with Alice, but Alice could mention Bob and pull him into the conversation. This also gives Bob the opportunity to read the whole thread because he has access to it now. Mastodon only defines to whom a message is sent, but not who is allowed to see it.

                                    In this version of Mastodon, when you DM Alice, you only grant Alice permission to see your toot and everything else in the thread. Now, Alice can mention Bob all she wants, but she can't pull him into the thread. Bob won't even receive the toot with his mention in it. He is not permitted to see it. You have not granted him permission to see the start toot, and thus, you have not granted him permission to see any of the replies, including the one in which Alice mentions him. Alice cannot change any permissions in the thread. Neither can you, by the way. The moment you send the start toot, all permissions are permanently set in stone for the whole thread.

                                    This also makes dogpiling by extra mentions in DMs impossible.

                                    Also, this provides for very effective quote-post control. It isn't allowed to boost posts that aren't public, including replies. It isn't allowed either to Mastodon-style-quote, as in quote-post, posts that aren't public, including replies.

                                    These DMs have another advantage of DMs on Mastodon-as-it-is-now: If you send a DM to Alice and Bob, Bob receives Alice's replies, and Alice receives Bob's replies, and the two can reply to one another.

                                    Oh, by the way, there's another nifty button. A speech bubble. With this button, you can allow or disallow replies to your post. Mind you, again, this only works when you start a thread. You cannot allow or disallow replies to a reply that you post.

                                    Now, how does Mastodon-as-it-is-now handle DMs from Hubzilla, (streams) and Forte? It sees them as Mastodon DMs, and it treats them like Mastodon DMs. The downside is, if I send a restricted-permission post to Alice on Mastodon and Bob on Mastodon, both perceive it as a Mastodon DM. Both can only reply to and converse with me. They can't see each other's replies, and they can't reply to each other.

                                    (8/9)

                                    #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Fediverse #Hubzilla #Streams #(streams) #Forte #Privacy #Security #Permission #Permissions #ReplyControl

                                      [?]Jupiter Rowland » 🌐
                                      @jupiter_rowland@hub.netzgemeinde.eu

                                      @Jasper Burns

                                      Permissions, part 3: At contact level


                                      Let's go one level further down. The second level of Hubzilla's permission system is per contact. On Mastodon, that'd be those whom you follow.

                                      If Mastodon was like Hubzilla, you'd have the possibility to create permission templates which you can then assign to those whom you follow. (Hubzilla calls them "contact roles", by the way.)

                                      Like, you could make one template for those whom you really trust. You grant all permissions in that template.

                                      Then you could make one that's more privacy-oriented. You only grant permission to send you toots, fave and reply to your toots and send you DMs.

                                      In theory, you could also make one for those whom you absolutely must follow, but whose toots you don't want. In this one, you only grant permission to fave and reply to your toots and send you DMs. This, however, only makes sense on something that works like Facebook, something like Hubzilla, where you can only confirm follow requests by also following back because connections are always mutual by default.

                                      Then you could go to your list of followed accounts. And you could edit and configure them, one by one. You could choose which of these permission templates is assigned to them and thereby what you allow them to do. While you're already there, you could also, for example, add them to lists or remove them from lists.

                                      There's one catch, though: If you grant a permission for your whole account, you automatically grant it to everyone whom you follow. You cannot forbid one of your followed something your account generally allows. So if you want to be able to choose whether someone is allowed to do something or not, you must not allow it for your whole account, and instead, you must allow it followed by followed.

                                      (streams) and Forte make things a great deal easier than Hubzilla, by the way: They don't require such templates anymore. Instead, when you go edit a contact, you'll see one on-off switch for each permission, and you can turn each permission on or off right there, right then (provided it isn't inherited from the channel). You still have such templates, but they only serve to grant the same set of permissions to a whole lot of contacts without having to click single permissions on or off for all of them.

                                      (7/9)

                                      #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Fediverse #Hubzilla #Streams #(streams) #Forte #Privacy #Security #Permission #Permissions

                                        [?]Jupiter Rowland » 🌐
                                        @jupiter_rowland@hub.netzgemeinde.eu

                                        @Jasper Burns

                                        Permissions, part 2: At channel level


                                        The top level of Hubzilla's permissions system is the whole channel. On Mastodon, that'd be your account and everything that happens on it.

                                        Translated to Mastodon again, for each of the above permissions, your account would have seven or eight choices whom to grant the corresponding permission:

                                        • Anyone on the internet (only available where this makes sense, it's mostly viewing permissions, but it also includes "Can fave and reply to your toots")
                                        • Anyone in the Fediverse
                                        • Either anyone on Mastodon or anyone using ActivityPub*
                                        • Anyone on the same server as you (mastodon.social in your case)
                                        • Anyone who follows you**
                                        • Any mutual followers
                                        • Only those of your mutual followers whom you've explicitly granted that permission
                                        • Nobody but you yourself

                                        *It's unclear what exactly this option means. See, Hubzilla is not based on ActivityPub. It is based on its own protocol, Zot. When it was created, it was the only server software that used Zot, so limiting permissions to Hubzilla and limiting permissions to whatever uses Zot had the same effect, seeing as Hubzilla could and still can also connect to a whole lot of other things using a whole lot of other protocols. So nowadays, "Anybody in this network" may mean anybody using Zot which means anybody on Hubzilla or (streams), or it may mean anybody on Hubzilla which means just that, excluding (streams).

                                        **This translates to Mastodon badly. Basically, Friendica, Hubzilla, (streams) and Forte know three states of connection. Either a Mastodon follow request, that's a "contact". Or a mutual follower, that's a "confirmed contact" because it's listed on your connections page, and you have control over that connection. Or only you follow someone, that's a "confirmed contact", too, because, again, because it's listed on your connections page, and you have control over that connection. The concept of confirmed follower doesn't exist because confirming a connection request will automatically make it a mutual connection. Remember we aren't talking about Twitter followers and Twitter followed, but about Faceboook friends.

                                        The choices on (streams) and Forte, translated to Mastodon, are:

                                        • Anyone on the internet (only available where this makes sense, it's mostly viewing permissions, but it also includes "Can fave and reply to your toots")
                                        • Anyone in the Fediverse
                                        • Any mutual followers
                                        • Only you and those of your mutual followers whom you've explicitly granted that permission

                                        To stick with Mastodon equivalents, there are a few more settings on Hubzilla (as for (streams) and Forte, I've covered them in the previous comment already).

                                        I guess you already know the switch that hides your account from Google and other search engines and the switch that makes your account automatically accept follow requests.

                                        You know that you can mention anyone out of the blue on Mastodon, regardless of whether they follow you or you follow them or not, and they're always notified? Imagine this being notified is optional. And off by default. On Hubzilla, both is the case.

                                        Okay, so, next, you don't allow anyone on the internet to reply to your toots. But there's an option that "half-allows" this: Anyone on the internet can send replies to your toots, even if they don't have any Fediverse account at all. Now it comes: You have to approve these replies. You have a green button that you can click, and the reply becomes visible, and it's added to the thread to which it belongs. Before then, nobody can see the reply but you. You also have a red button, and when you click it, the reply is rejected and deleted.

                                        There are two clear use-cases for this. One is when you want absolute control over who replies what to you. Then you don't allow anyone to reply to your toots, but you activate this option. When someone does reply, you can choose whether to let the reply through or delete it.

                                        The other one is a use-case that doesn't work on Mastodon, namely when you want to run a Hubzilla channel as a fully public long-form blog with a target audience that isn't limited to the Fediverse, and you want everyone to be able to comment on your posts, even without having some Fediverse account and following you first, but you want to keep spam out.

                                        Lastly, there's the option that if you don't allow everyone to see your images and other media at https://mastodon.social/@jasperb/media, these images and other media can still be seen attached to toots by those who are allowed to see the toots that they're attached to.

                                        (6/9)

                                        #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Fediverse #Friendica #Hubzilla #Streams #(streams) #Forte #Privacy #Security #Permission #Permissions

                                          [?]Jupiter Rowland » 🌐
                                          @jupiter_rowland@hub.netzgemeinde.eu

                                          @Jasper Burns

                                          Permissions, part 1: Introduction


                                          Now allow me to explain Hubzilla's permissions system to you. From a Mastodon point of view again.

                                          Hubzilla's permission system works on three levels. In Mastospeak, the first level is your entire account.

                                          The second level is everyone whom you follow, individually. Like, you can go to your list of followed accounts and click on them and configure them. Among other things, you can assign to them a set of permissions that, usually, you'll first define. You'll probably have multiple such sets of permissions.

                                          (Yes, this completely leaves out those who only follow you, and whom you don't follow back. Such a thing does not exist on Friendica, Hubzilla, (streams) and Forte. That is, it does, but you don't have a list of these, and you can't configure these, because they can't do much anyway as long as you don't follow them.)

                                          And the third level is each toot that is not a reply, and then that toot forces its own permissions hard upon all toots that reply to it. If you reply to someone else's toot, your toot will have the same permissions as the start toot with no way for you to change them.

                                          Translated to Mastodon, Hubzilla offers the following permissions:

                                          • Can see your toots when visiting your Mastodon account at https://mastodon.social/@jasperb
                                          • Can send their toots onto your timeline (I'm being serious here, you can literally follow someone and forbid them to send you their toots)
                                          • Can see your profile
                                          • Can see your lists of followers and followed when visiting your Mastodon account at https://mastodon.social/@jasperb
                                          • Can see both the images and other media in your toots and the images and other media you've tooted at https://mastodon.social/@jasperb/media
                                          • Can fave and reply to your toots (those of your toots that aren't replies)
                                          • Can send you DMs

                                          In addition, there are more permissions that don't translate to Mastodon because they cover features that Mastodon doesn't have:
                                          • Can upload images and other files and modify existing files at https://mastodon.social/@jasperb/media
                                            (because https://mastodon.social/@jasperb/media is not a managed cloud file storage, and the only way to add images or other media there is by you tooting them)
                                          • Can see the webpages you've built on your account
                                            (because Mastodon doesn't have webpages)
                                          • Can see the pages in the wikis you've built on your account
                                            (because Mastodon doesn't have wikis)
                                          • Can edit the webpages you've built on your account
                                            (because Mastodon doesn't have webpages)
                                          • Can edit the pages in the wikis you've built on your account
                                            (because Mastodon doesn't have wikis)
                                          • Can send you a toot by visiting your Mastodon account at https://mastodon.social/@jasperb and using the toot editor that's present there to send a toot straight to your "wall"
                                            (because Mastodon doesn't have a wall, Mastodon doesn't have a toot editor on your account page for people who aren't you, and Mastodon doesn't have this entire feature)
                                          • Can like or dislike any element in your profile at https://mastodon.social/@jasperb
                                            (because liking or disliking things in profiles is not possible on Mastodon)
                                          • Can chat with me
                                            (because Mastodon doesn't have a chat)
                                          • Can automatically repost my toots through their account
                                            (because Mastodon doesn't have this feature either)
                                          • Can do absolutely anything on my account that I can, just by visiting https://mastodon.social/@jasperb
                                            (not possible for a whole lot of reasons)

                                          Translated to Mastodon again, (streams) and Forte offer the following permission settings, some of which are yes/no switches, some are numbers or text fields:
                                          • Automatically confirm follow requests (yes/no)
                                          • Allow replies on your start toots from
                                          • Manually allow disallowed replies (yes/no)
                                          • Only allow replies on your start toots for so many days (number)
                                          • Allow DMs from
                                          • Allow to see your followers and followed
                                          • Allow to full-text search your account
                                          • Allow non-followed-non-followers to fave your toots (yes/no)
                                          • Be notified about non-followed mentioning you (yes/no)
                                          • Not if at least so many accounts are mentioned (number) (this is spam prevention)
                                          • Receive toots from non-followed if they contain any of these hashtags (same as following hashtags, only that this is one text field and not a bunch of followed "accounts")
                                          • Not if at least so many hashtags are in the toot (number) (again, this is spam prevention)
                                          • Don't allow replies to replies from non-followed (yes/no) (reply guy filter)
                                          • Show a timeline of your own toots (yes/no)
                                          • Add your account to the directory (yes/no)
                                          • Hide your account from Google and other search engines (yes/no)
                                          • Delete toots and their replies from your timeline if you haven't interacted with them after so many days (number)
                                          • Allow toots from your followed accounts that are replies in threads starting with toots from accounts that you don't follow

                                          Again, there are permissions that don't translate well to Mastodon:
                                          [list]
                                        • Manually allow toots from those who request to follow you
                                          (Doesn't make sense on Mastodon because if someone wants to follow you, you do not have to follow them back; on (streams) and Forte, confirming a follow request does make you follow them back)
                                        • Show links to all clones of your account in your profile
                                          (Mastodon doesn't have nomadic identity)
                                        • Don't show whether you're online
                                          (Mastodon doesn't show whether you're online anyway, it doesn't even have this feature)[/list

                                          That said, some of these permissions don't make sense from a Mastodon point of view, namely those that handle what people can see when visiting your profile at https://mastodon.social/@jasperb. There would have be some way to identify them to grant them the permissions you've given them.

                                          Hubzilla has such a way, as do (streams) and Forte. It's OpenWebAuth, a "magic sign-on" system created by the creator of these four for a Hubzilla fork that was backported to Hubzilla and inherited by (streams) and Forte. These three can recognise logins to grant guest permissions, and their logins can be recognised. There are a few more Fediverse applications whose logins can be recognised. This was actually also developed for Mastodon and ready to be merged in, but the patch was actually silently rejected.

                                          (5/9)

                                          #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Fediverse #Friendica #Hubzilla #Streams #(streams) #Forte #Privacy #Security #Permission #Permissions

                                          • [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                            @nemo@mas.to

                                            (1/3) I have the greatest sympathy and empathy in regards to one; he is correct about the compartmentalization aspect — always compartmentalize. Always diversify your portfolio of security and privacy tools. Yet his assumption and suggestive tone bother me quite a lot in this video, and all e-mail providers have the metadata issue because e-mail as a protocol is flawed garbage from the past, and Soatok has many times called it out — can't be made secure.

                                              [?]knoppix » 🌐
                                              @knoppix95@mastodon.social

                                              Hackers are developing open-source tools like OUI-SPY and crowdsourced maps (deflock.me, alpr.watch) to detect and counter ICE's automated license plate readers and surveillance cameras. 🔍
                                              These counter-surveillance efforts aim to protect communities from mass tracking, though legal risks remain. ⚖️

                                              @eff

                                              🔗 eff.org/deeplinks/2026/01/how-

                                                [?]knoppix » 🌐
                                                @knoppix95@mastodon.social

                                                EFF warns new online age‑verification mandates risk expanding surveillance, censorship, and exclusion for adults and kids alike. 🪪
                                                They’ve launched a resource hub to track these laws and defend privacy, anonymity, and free expression online. 📚

                                                @eff

                                                🔗 eff.org/deeplinks/2026/01/effe

                                                  [?]knoppix » 🌐
                                                  @knoppix95@mastodon.social

                                                  Wegmans is now scanning shoppers’ faces, eyes, and voices in NYC stores—with no opt‑out or clear data deletion policy. 🛒
                                                  The grocery chain cites “security,” but privacy groups warn of lasting biometric risks and disproportionate impacts. ⚠️

                                                  🔗 gadgetreview.com/theres-no-opt

                                                    [?]knoppix » 🌐
                                                    @knoppix95@mastodon.social

                                                    Ireland plans to lead an EU push for ID‑verified social media accounts under Tánaiste Simon Harris. 🇮🇪
                                                    The proposal aims to curb online abuse, bots, and disinformation—but may test privacy norms, anonymity rights, and platform accountability. ⚖️

                                                    🔗 extra.ie/2025/12/28/news/simon

                                                      [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                                                      @wired.com@web.brid.gy

                                                      How to Protest Safely in the Age of Surveillance

                                                      Law enforcement has more tools than ever to track your movements and access your communications. Here’s how to protect your privacy if you plan to protest.

                                                      How to Protest Safely in the Age of Surveillance

                                                      Alt...How to Protest Safely in the Age of Surveillance

                                                      [?]Linux Security Summit 🐧 » 🌐
                                                      @LinuxSecSummit@social.kernel.org

                                                      Day 2 of LSS-EU kicking off with Casey Schaufler on the state of LSM stacking, now approaching its 15th anniversary.

                                                      https://static.sched.com/hosted_files/lssna2025/33/2025-06-LSSNA-Stacking.pdf

                                                      #linux #linuxsecuritysummit #infosec #kernel #security

                                                        [?]gtbarry » 🌐
                                                        @gtbarry@mastodon.social

                                                        Age verification changed the internet in 2025 – here's what it means for your privacy in 2026

                                                        Digital rights groups say that age verification measures compromise privacy, weaken data security, and invite unprecedented levels of censorship

                                                        techradar.com/vpn/vpn-privacy-

                                                          [?]Hacker News » 🤖 🌐
                                                          @h4ckernews@mastodon.social

                                                          [?]Monique Barrow » 🌐
                                                          @moniquebarrow_@mastodon.social

                                                          New posts for 2026 will start next Wednesday. In the meantime, catch up on the latest newsletter from The Privacy Cloud 🔐☁️.

                                                          theprivacycloud.substack.com/p

                                                            [?]Nonilex » 🌐
                                                            @Nonilex@masto.ai

                                                            “It’s approaching a full-on existential crisis,” said Mujtaba Rahman, managing director for at political risk consultancy Group. “It could be far greater than invading because Russia is an adversary. Now, it’s the guarantor of European undermining European security.”

                                                              Back to top - More...