this post was submitted on 17 Feb 2025
354 points (95.4% liked)

Fediverse

30278 readers
960 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to [email protected]!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 2 years ago
MODERATORS
 

Upvotes seem to just federate as likes and dislikes.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 23 points 3 days ago (2 children)

Yes, but then you can have malicious servers sending fake numbers without other server operators being able to check whether this is at all plausible.

(It's still possible for malicious servers to send fake votes, but server operators can see which users they are stated to originate from, then block that server if that looks like it's doing that. At least that is my understanding.)

[–] [email protected] 3 points 3 days ago (1 children)

What do you mean "send fake votes"?
Or rather, who do you think should be responsible for identifying and blocking fraudulent votes?

And how do you reconcile votes that come from servers that you've defederated with? Should everyone have the same view of the post, or should people only see votes from servers that their server is federated with? What about votes from users you've personally blocked? Etc

I personally kinda think that the responsibility is on the server hosting the post, and that everyone should see the same (but anonymous) vote count, of which the hosting server is the single source of truth.

[–] [email protected] 7 points 3 days ago (2 children)

A malicious hosting server could use fake points to blast any message to the top of everyone's feeds until manually banned or defederated

[–] [email protected] 4 points 3 days ago (1 children)

I'm not sure how giving every server access to the votes solves that.
The malicious server can make fake users to pump up votes. your server admin has to notice, then check the vote logs, then see what's happening and defederate them. That's pretty much what you described in your scenario, anyways.

[–] [email protected] 4 points 3 days ago (1 children)

It's way easier to notice and defed when you can see these fake usernames

[–] [email protected] 1 points 3 days ago

But it also has to be defended separately by the admin of every server that has a user subbed to that community. Seems like a large burden to put on small-mid instance admins.

I'd be surprised if my server admin was really paying attention that closely to votes on communities I'm subbed to, right?
I have to admit I don't know the view that admins get of how their server intersects the fediverse.

[–] [email protected] 2 points 3 days ago

Yes, that's happened before. They were sending a very large number of votes, so it was immediately obvious. Even a couple dozen from an unknown instance will be noticed, when an admin sees it and says "huh I haven't heard of that instance" and when they look there's nothing there.

[–] [email protected] 2 points 3 days ago

It's only fake numbers for posts on the instance.

Not the first malicious instance, wont be the last.