• arotrios@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    7 hours ago

    Thanks for the list. Unfortunately, they list “Fediverse” which likely means they’re scraping ActivityPub. They’re also going after your Steam account, Twitch, YouTube, and porn.

    In other words, this is so much worse than the headline makes it out to be.

    Surprisingly, Reddit is NOT on the list.

    Here’s the full list of names:

    4chan Archives

    Discord Archives

    21Buttons

    500px

    about.me

    AllMyLinks

    AllTrails

    Amazon

    Ameba

    Amino

    AnimePlanet

    Apple Music

    Artists&Clients

    Asciinema

    AudioJungle

    AudiUSA

    BabyCenter

    Baidu

    BeReal

    Bigo Live

    Bing

    Biolink

    BitChute

    BlackPlanet

    Blogger

    Bluesky

    Bodybuilding

    BookCrossing

    Breaches

    BuyMeACoffee

    Cash App

    CastingCall Club

    Chaturbate

    Chess.com

    Cigar Dojo

    CityXGuide

    CloutHub

    Cocolog

    Companies House

    Cozy.tv

    Cracked

    Creema

    Dailymotion

    Danbooru

    Dark Web

    DeepL

    DeviantArt

    Disqus

    DLive

    Dot.cards

    Douyin

    Drum

    DuckDuckGo

    Duolingo

    E621

    eBay

    Eporner

    Etsy

    Facebook

    Fansly

    FastPeopleSearch

    Fediverse (likely ActivityPub - possibly DMs between servers)

    FetLife

    Fiverr

    Flickr

    FlightAware

    Foursquare

    FriendFinder

    FurAffinity

    Gab

    Gaia Online

    GameFAQs

    Gelbooru

    GeneralMotors

    Geocaching

    GeoEstimation

    Gettr

    Giphy

    GitHub

    Glassdoor

    GoFundMe

    Goo

    Google

    Goodreads

    Gravatar

    Guancha

    GunBroker

    Habbo

    Hackaday

    Hatena

    Honda

    Hubski

    ILoveGrowingMarijuana

    ImageShack

    Imgur

    IMVU

    Indeed

    Instagram

    Instructables

    JudyRecords

    Jugem

    JustForFans

    Keybase

    Kick

    Kik

    Last.fm

    LibraryThing

    Lichess

    Likee

    Line

    LinkedIn

    Linktree

    LiveIn

    LiveJournal

    Lobsters

    Mail.ru

    Malgari

    MapMyTracks

    Marshmallow

    MarTech

    Massage Anywhere

    Medium

    MeetMe

    Mercari Jp

    MeWe

    Minds

    Minecraft

    Mix

    Mixlr

    ModDB

    Mughosts

    MyFitnessPal

    Myspace

    MySubaru

    Naijapals

    Nextdoor

    NissanUSA

    Odysee

    OFAC Sanctions List

    OkCupid

    OK.ru

    OnlyFans

    Pandia

    Pandora

    Passes

    Pastebin

    Patreon

    PayPal

    PCGamer

    Peloton

    PGP

    Pinterest

    Plurk

    Poal

    Popl

    Pornhub

    Poshmark

    Product Hunt

    ProtonMail

    PSNProfiles

    Reblogme

    Reddit

    RedGifs

    Replit

    ReverbNation

    Roblox

    Rule34.xxx

    Rumble

    Rutube

    ScoutWiki

    Seesaa

    Seneporno

    Signal

    SkipTheGames

    Skype

    SlideShare

    Snapchat

    Sogou

    SoundCloud

    SourceForge

    Spiceworks

    Spotify

    Sprashivai

    Steam (fuck off you fucking fucks)

    StellantisEU

    StellantisUSA

    Strava

    Stripchat

    Substack

    TechNet

    Telegram

    Tellows

    Tesseract OCR

    Threads

    TikTok

    Tinder

    TinEye

    ToyotaUSA

    Trakt

    Triller

    TripAdvisor

    TrueCaller

    TruthSocial

    Tumblr

    Twilio

    Twitch

    Twitter

    Untappd

    Venmo

    VidLii

    Vimeo

    Vine

    VirusTotal

    VK

    Volkswagen

    VSCO

    WatchMeMore

    Weibo

    WhatsApp

    Wire

    Wordfeud

    Xbox

    xHamster

    XING

    XVideos

    Yahoo

    Yandex

    Yappy

    YCombinator

    Yelp

    YouTube

    Zhihu

    Zillow

    ZoneH

    • EveryMuffinIsNowEncrypted
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      3 hours ago

      Proton

      Signal

      What are they gonna do? Download gibberish?! Lol, it’s all end-to-end encrypted with the decryption keys stored locally.

    • EveryMuffinIsNowEncrypted
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      4 hours ago

      Aww man seriously DuckDuckGo is on the list? Ugh… Welp, does anyone know of any good alternatives? (I hear Ecosia’s not half-bad…)

    • dubyakay@lemmy.ca
      link
      fedilink
      arrow-up
      4
      ·
      6 hours ago

      Reddit is right there in your list.

      Also:

      Gaia Online

      Thanks. Brings back memories.

    • davel [he/him]@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 hours ago

      Surprisingly, Reddit is NOT on the list.

      If they’re slurping all these other sites, I highly doubt they’re not slurping Reddit, too, even if it’s not on the list.

      Fediverse (likely ActivityPub - possibly DMs between servers)

      They would have to hack the individual servers to get at the DMs, because they’re encrypted in transit. All the public stuff is trivial to scrape.

      • arotrios@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 hours ago

        They would have to hack the individual servers to get at the DMs, because they’re encrypted in transit. All the public stuff is trivial to scrape.

        Nope, ActivityPub DMs are not encrypted between servers - if it’s on the feed, it’s public- or at least it was as of six months ago. I found this out when I attached a Wordpress site to a Mastodon instance and suddenly found i could read anyone’s DMs to users on other servers. Totally unencrypted. I actually paused development and working with ActivityPub because of it.

        This doesn’t mean that messages to users on the same server are necessarily exposed, but the potential is there if you don’t have a filter for local publishing only engaged on your Mastodon instance.

        • davel [he/him]@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          ActivityPub DMs are not encrypted between servers

          It is insofar as TLS/SSL/HTTPS encryption is used in transit. That’s what I mean by encrypted in transit.

          i could read anyone’s DMs to users on other servers

          If you’re an administrator for (WordPress) ActivityPub server A, you can see all the DMs coming to and leaving from your server, yes. And they’re not encrypted at rest, so you can read them any time. But how would you see DMs going between server B and server C, when your server isn’t involved in the transaction?