• @deegeese@sopuli.xyz
    link
    fedilink
    English
    42
    edit-2
    3 months ago

    Bit of a red herring to put GDPR in the title when the article is about Lemmy missing key admin functions, and only tangentially how this runs afoul of GDPR.

    TL;DR Lemmy hasn’t implemented image deletion for users or admins, so don’t upload your government ID.

    • @woelkchen@lemmy.world
      link
      fedilink
      English
      213 months ago

      Bit of a red herring to put GDPR in the title when the article is about Lemmy missing key admin functions, and only tangentially how this runs afoul of GDPR.

      I haven’t read the GDPR, yet, but it’s still a serious issue – GDPR or not. Imagine if Instagram did that. Everybody would seriously go bonkers and rightfully so.

      System administrators often aren’t software developers. Lemmy users need to trust Lemmy admins and Lemmy admins need to trust Lemmy developers. Maybe not letting users delete any uploaded media isn’t outright illegal, maybe it is. I’m in the camp of it being definitively not cool.

      • @deegeese@sopuli.xyz
        link
        fedilink
        English
        9
        edit-2
        3 months ago

        Inflicting lawyers on an open source project is a great way to drive off the developers.

        If I hear Lemmy has a GDPR problem I assume it’s lawyer BS only European instance admins have to worry about.

        If I hear Lemmy has bugs in basic CRUD functionality, that’s a real issue.

          • @kernelle@lemmy.world
            link
            fedilink
            English
            83 months ago

            Yet GDPR requires if you operate anywhere but allow European citizens to register, you have to be GDPR compliant as well, or risk being blocked by an entire continent.

        • @woelkchen@lemmy.world
          link
          fedilink
          English
          63 months ago

          If I hear Lemmy has bugs in basic CRUD functionality, that’s a real issue.

          Coincidentally I saw bug reports by that person and another person earlier that day (before the blog post was published), including one opened months ago with absolutely no reaction at all of even acknowledging that this is even an issue: https://github.com/LemmyNet/lemmy/issues/3973

          I’ve heard from time to time that Lemmy developers can be difficult to work with (I never worked with them, so I make it clear that this is hearsay) but I have the suspicion that there is some merit to that.

      • @morras@jlai.lu
        link
        fedilink
        English
        113 months ago

        No, Lemmy servers are not exempt from GDPR compliance. The household exemption (you are not subject to gdpr for private activities) only applies for purely personnal activities. As soon as a service is offered to someone else, the exemption is no more applicable.

        That’s one of the drawback about open-source projects, they are designed to fulfill a need (persistent storage & decentralised communication for Lemmy), and no one give a f*ck about legalities.

          • @morras@jlai.lu
            link
            fedilink
            English
            93 months ago

            I’m not so sure about the GDPR status for the Fediverse, I don’t think there’s the law is prepared for “Jerry runs this for people, just for fun”. It’s very much “official organisation” or “money grabbing business” oriented. Someone should fund an actual lawyer to look into this and lay down the real requirements.

            I’m working in the gdpr compiance field ;) Using a personnal device to monitor public space doesn’t fall under the household exception, this solution even pre-dates the GDPR (https://curia.europa.eu/jcms/upload/docs/application/pdf/2014-12/cp140175en.pdf).

            (the case-law is about camera fixed on a private house, but the logic easily translates in a private server grabbing public data).

            but when legal compliance comes up, everybody just sticks their fingers in their ears and pretends not to hear you.

            Just as you did ^^

              • @morras@jlai.lu
                link
                fedilink
                English
                22 months ago

                Article 3 GDPR is straightforward, gdpr will apply.

                The real question is how any kind of authority could enforce it ? Almost no chance that any law enforcement/regulator will bother a single-user instance purely on the ground of gdpr…

    • @deegeese@sopuli.xyz
      link
      fedilink
      English
      233 months ago

      Just another guy who thinks he’s Gods gift to open source because he found a bug, and thinks the volunteer developers fail to show proper gratitude by not dropping everything to work on your pet bug.

      • @Darrell_Winfield@lemmy.world
        link
        fedilink
        English
        213 months ago

        Interestingly, he was silent for 3 weeks after being assigned to the bug, then came back to post his blog post and nothing else. I’ve seen this blog post a few times today, looks like his self promoting strategy is working.

      • @bleistift2@feddit.de
        link
        fedilink
        English
        103 months ago

        To be fair, this is a bug that could be the end of lemmy. As soon as one malicious actor sues even a few instance admins, other will get scared and shut down their instances. As the reporter points out, this isn’t just a shiny feature that’s missing. Instance admins lack the ability to follow data protection requirements that their users have a right to. It’s a lawsuit waiting to happen.

        • @lambalicious@lemmy.sdf.org
          link
          fedilink
          English
          12 months ago

          To be fair, this is a bug that could be the end of lemmy.

          Then the reporter should have acted like it was, indeed, that important. Like, putting money or a PR into it.

          Just “someone, sometime, somewhere, might sue” does not suffice to fix things. Just like with physical products in the real world, if someone, somewhere, sometime, might sue, then you designate money, time and staff into your project to pre-corect the things to minimize the chance of that happening, or to buy whatever auditing / maintenance needed to check for issues.

          And, correctly enough, the devs are not saying “we won’t fix this”. They are saying, “fix this requires people to pour $X time and $y money into it. Care to chime in?”

          Unfortunately, the world of free software users is full of “couch coaches”.

    • Ricky Rigatoni
      link
      fedilink
      English
      12 months ago

      The lemmy devs are communist, isn’t doing free labor their whole thing?

    • @willya@lemmyf.uk
      link
      fedilink
      English
      143 months ago

      Yikes. Played it for shits and giggles and it leads off with saying the vaccines or even being around people who took the vaccine causes you to emit a Bluetooth MAC address lmfao.

  • freamon
    link
    fedilink
    English
    213 months ago

    I’m gonna find this guy’s image …

    https://monero.town/pictrs/image/00000000-0000-0000-0000-000000000000.jpeg … nope
    https://monero.town/pictrs/image/00000000-0000-0000-0000-000000000001.jpeg … nope
    https://monero.town/pictrs/image/00000000-0000-0000-0000-000000000002.jpeg … nope
    https://monero.town/pictrs/image/00000000-0000-0000-0000-000000000003.jpeg … nope

    Mmm, I’m sure it won’t take long. Just have to remember to do it all again for .jpg, .webp, and .png.

    Anyway, I’ll let you know when I get it.

      • freamon
        link
        fedilink
        English
        63 months ago

        Not quite, no. I know what it isn’t at least.

        I’ll keep going - I’m sure the article’s author is someone who genuinely uploaded some confidential info and then became really involved with privacy/GDPR etc, and not someone who was always been really involved with privacy/GDPR issues and now has a story to fit.

  • @rglullis@communick.news
    link
    fedilink
    English
    17
    edit-2
    3 months ago

    Not that I hold the Lemmy devs in particular high regard, but unless OP is cutting them a check every month enough to pay their full time salaries, I really don’t think that he should be expecting anything just because he faced an issue that was difficult, but (a) not specific to the developers but the admins of the instance and (b) ultimately solvable.

    I also think that this is not a reason to justify a whole fork or even a fully adversarial position. Yeah, tooling for moderation and instance management is lacking, but these can be built on top of the existing codebase. If my fediverser tool does that for user authentication and account management, it could also be extended for content moderation and provide granular access for staff.

    • @woelkchen@lemmy.world
      link
      fedilink
      English
      23 months ago

      a check every month enough to pay their full time salaries

      I would usually agree because often FOSS projects are used commercially but I don’t think this standard doesn’t apply here because the Lemmy instances are also non-commercial projects.

  • @dumpsterlid@lemmy.world
    link
    fedilink
    English
    3
    edit-2
    3 months ago

    I would actually consider using normal reddit a nightmare, lemmy like the rest of the fediverse softwares mostly just feels like a community theater play put on by people who really passionately care about what they are making but have zero budget and so long as you go into not expecting a blockbuster movie it is awesome.