New Privacy Guides tutorial mastodon
by me:

This article is now a series of two articles on Privacy and Security on Mastodon.

This tutorial is a step-by-step guide
to help Mastodon users make the most of the privacy and security features the platform offers.

The first article of this series was divided to better segment the information for readers who might prefer to read or share each part independently.

How To Improve Your Privacy and Security on Mastodon

#PrivacyGuides#Mastodon#Privacy#Security#Tutorial#Fediverse#TinyMastodonTip

@Em0nM4stodon wonderfully written, and extremely approachable! A few comments:

- under the sections for blocking a user and instance, it'd be nice to call out that people should report accounts that are harassing or abusing them.
- In reporting section, a big privacy consideration is choosing where to send your report (just to your moderators or to the remote server's moderators too (which may include the user you are reporting))
- when moving accounts, only relationships are moved, existing posts and other interactions are not moved, this is noted much later on though
- when moving, the accounts you follow may receive follow requests from your new account which they can approve or deny.
- On E2EE, your mastodon server admins may still be able to access significant metadata about your conversations, via the interactions with your server that are required to both send a message and initiate an E2EE conversation, this metadata may include when, how often and potentially to whom your communicating with. For full privacy, using an E2EE messaging app like Signal would still be recommended.
- whilst currently admins and moderators cannot see "mentioned only" or "followers only" posts without either a report for a specific post, they can still see these posts by looking at the database. Future versions of Mastodon may allow moderators to view these posts as part of an investigation into a report (details are still TBD, but there'd likely be some form of automatic notice N days after your account's less public data was accessed for moderation purposes. This is a change folks are pushing for to better combat mentioned-only and followers-only spam and harassment.
- When deleting content, keep in mind that soft-deletions may be used, where the post is retained for some time in order to assist moderation teams with investigating reports, but deleted afterwards.
- If your account is suspended, or perhaps otherwise frozen, you may be prohibited from deleting your account, this is to ensure moderators can investigate reports fully. You will receive a notification if such a hold is placed on your account.

1/2

@Em0nM4stodon continued:

- For "followers only" posts, keep in mind that this is only as good as the software of the servers where you have followers, there has been a security incident (that's still partially unresolved) where Pixelfed allowed non-approved followers to see your followers only posts, other software may have similar bugs where post visibility and follow requests are not correctly implemented.
- Followers only posts also tend to be retroactive, in many cases, so someone who recently followed you will be able to see followers only posts made before they followed you.

2/2