The FBI raided one of the admins of Kolektiva and a full copy of the website's database, dated early-may, was among the data seized. Full details in the linked URL.

Kolektiva.social is a Mastodon instance focused on radical politics and activism, with about 6.6K active users. One of the largest open-signup instances of its kind.

  • Cadende [they/them]
    ·
    edit-2
    1 year ago

    Scary stuff

    Take this as a reminder: Do not dox yourself in DMs on social media. Treat them as if they were public, at least in terms of opsec.

    If you want your communications to be properly private, use Matrix or something. This includes hexbear

    Emails and other signup info too. If you have any reason to think you could be targeted by feds, other steps like using a VPN or Tor might be next. But the above advice is true for most social media users, celeb DMs leak all the time, for example. There's always a way.

    • JuneFall [none/use name]
      ·
      edit-2
      1 year ago

      Yes, DMs are pretty much never deleted, the kollektiva instance leaked the IP adresses of users within a 3 day range in the past, as an unencrypted db image was currently worked at.

      This means that you have to use VPNs/TOR and dynamic IPs to stay secure (or go the public varying internet cafe route).

      • blobjim [he/him]
        ·
        1 year ago

        And Hexbear doesn't even try since it uses cloudflare lmao

        • Cadende [they/them]
          ·
          edit-2
          1 year ago

          outdated reference. cloudflare is no longer used (at least not their CDN functionality)

          • blobjim [he/him]
            ·
            1 year ago

            ooh thanks for the info! Do you know what they're doing now?

            • Cadende [they/them]
              ·
              edit-2
              1 year ago

              not really, just that cf was dropped in the migration. nobody ever really liked cloudflare as far as I know but it did make certain things a bit faster and safer from certain kinds of attack. At the expense of all traffic going through the servers of a US company, who could if they wanted to probably spy on contents of traffic

              • blobjim [he/him]
                ·
                1 year ago

                Yeah it made sense as a practical choice. Dealing with potential DDoSes is a much bigger priority for a silly online forum than attempting and failing to be opaque to the US government xD

    • blobjim [he/him]
      ·
      1 year ago

      also the US government can always get the data from any service that wants to do business in the US. A service being hosted elsewhere does not mean it will not comply with US laws, especially if you're paying for it with a credit card or something and it has a sizeable US userbase.

  • BoarAvoir [they/them]A
    ·
    1 year ago

    Our server going AWOL just hours after this announcement had me kinda paranoid at first ngl

  • HornyOnMain
    ·
    edit-2
    1 year ago

    nice to know that apparently the FBI now has my nudes saved in one of their computers because several kolektiva users followed me and boosted them so they were saved on kolektiva's servers apparently

  • RNAi [he/him]
    ·
    edit-2
    1 year ago

    Holy shit, lol

    I mean, the NSA can know the amount of hairs in your butt anyways, but still this is almost parody

  • PorkrollPosadist [he/him, they/them]
    hexagon
    ·
    1 year ago

    To quote a thread from somebody who did a good job explaining:

    For people who are not really up on how federation works regarding kolektiva.social's database news above, instances serve you content that has been federated to the server you're on. Which means for you to see it, your local server has downloaded a copy. So if you are on a third party server and have been boosted onto tls of people on kolektiva, share DMs or private posts with people on kolektiva, that content is stored on their servers too, not just yours.

    Private media, for example, is not just in the hands of your admin. It is in the hands of the admins of followers or people you dm on other servers etc

    And I know a lot of people who are familiar with mastodon software or have been here forever see this as a 'well duh', which I've seen come up a lot already from the usual suspects, but a lot of people don't know how this stuff works and with some things, like this, it can be really important.

    • blobjim [he/him]
      ·
      1 year ago

      It's really lame how a lot of these open source projects don't have a "privacy policy" that educates people on what types of communication are secure.

  • Frank [he/him, he/him]
    ·
    1 year ago

    Pffft. I kind of expect the fbi to kick my door down and accuse me of sedition any day now these days. I hope the Kolektiva kids are okay.

  • PorkrollPosadist [he/him, they/them]
    hexagon
    ·
    edit-2
    1 year ago

    The thing that really makes me scratch my head is that this raid happened near the start of May, and they are announcing it now, on the first of July. What the fuck is up with that? Were they gagged? Did they just not want to say anything in hopes the feds wouldn't realize what they got their hands on? It's a fucking shit show. Absolute disaster.

    • triplebean
      ·
      edit-2
      1 year ago

      deleted by creator

  • blobjim [he/him]
    ·
    1 year ago

    If someone is going to host a server like that, they need to encrypt the live data and every backup.

    • wopazoo [he/him]
      ·
      edit-2
      1 year ago

      Also maybe not hosting it in the USA or aligned countries (i.e. Canada, U.K., Germany)

  • HornyOnMain
    ·
    1 year ago

    incredibly common kolektiva L