Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Why Kolektiva.social Is a Cautionary Tale for Activists Using Mastodon
FOSSForce ^ | 26 July 2023 | Christine Hall

Posted on 07/28/2023 6:49:00 AM PDT by ShadowAce

A Mastodon server that focuses on left-leaning political activists, recently had an unencrypted copy of its database confiscated by the FBI.

People riding elephantPeople riding elephantSource: Pixabay

The recent news that a copy of Kolektiva.social’s database was confiscated by the FBI as the result of a raid at the home of one of the organization’s administrators, should serve as a cautionary tale for activists taking advantage of Mastodon’s federated nature to form online communities. Specifically, you should should do some research into the security in place at an activist-focused server, as well as the servers privacy policies.

Actually, the same advice would hold even if you were joining a server for, say, people who like knitting, but if you’re a political activist it’s even more important because law enforcement loves to keep tabs on folks whose politics fall outside the mainstream.

I’m not alone in my thinking. In an article published yesterday on Electronic Frontier Foundation’s website, the organization’s executive director, Cindy Cohn, and its associate director of community organizing, Rory Mir, called the incident, “a wakeup call to fediverse users and hosts to protect their users.”

“Protecting user privacy is a vital priority for the fediverse,” they wrote. “Many fediverse instances, such as Kolektiva, are focused on serving marginalized communities who are disproportionately targeted by law enforcement. Many were built to serve as a safe haven for those who too often find themselves tracked and watched by the police. Yet this raid put the thousands of users this instance served into a terrible situation.”

According to EFF, it doesn’t matter that that the FBI wasn’t looking to gather information on Kolektiva’s users. Although the raid was connected to an investigation into a local protest having nothing to do with Kolektiva, and the admin’s computer was taken as part of the investigation of that protest and had nothing to do with Kolektiva, all of the information taken from the machine can be used by law enforcement, whether or not it pertains to the investigation that led to it falling into the FBI’s hands.

“Most users are unaware that, in general, once the government lawfully collects information, under various legal doctrines they can and do use it for investigating and prosecuting crimes that have nothing to do with the original purpose of the seizure,” Cohn and Mir explained. “The truth is, once the government has the information, they often use it and the law supports this all too often. Defendants in those prosecutions could challenge the use of this data outside the scope of the original warrant, but that’s often cold comfort.”

In this case, the fact that the database was on the computer at the raided home at all was a coincidence of timing. When the raid took place in mid-May, the admin happened to be doing maintenance work on an unencrypted copy of the database (which is encrypted on the server).

In a post, Kolektiva’s administrators said the confiscated database contained:

About Kolektiva Social

Unlike social platforms such as Facebook or Twitter, where all users sign onto the same monolithic architecture owned by a single corporation, federated platforms such as Mastodon are a collection of independently owned and operated servers (also called “instances”), which are tied together to form the fediverse. This means that users are actually members of the server where they opened their account, although they can interact with users on other servers seamlessly.

Some servers are huge and host a community of millions of users. Most are much smaller, with thousands or hundreds of users, with some servers hosting only a single user (perhaps with a few family members along of the ride). Each server has its own rules about what content is considered acceptable, and each has its own system for content moderation.

Kolektiva got started sometime after August 2020, which is when Facebook purged some anarchist news organizations and left-wing activists as part of a larger ongoing ban that had been targeting far-right extremists and QAnon conspiracy theorists. This prompted a group of self-proclaimed anarchists to join the Mastodon fediverse with their own social media server.

According to the folks who run the server, “Kolektiva is an anti-colonial anarchist collective that offers federated social media to anarchist collectives and individuals in the fediverse.”

Since the server went online and connected to the fediverse, it’s become something of a haven for left-leaning political activists of all stripes. For example, after Instagram suddenly disabled the account of the Pacific NorthWest Youth Liberation Front last October, the network of youth collectives opened an account on Kolektiva and encouraged people to find them there or on their website.

According to stats found on the instance’s server, Kolektiva currently has 36,463 users, with 8,100 of them being currently active.

Privacy and Security

Although Kolektiva administrators handled the recent incident with the FBI badly (the data confiscation happened in May, but members of the instance weren’t notified until July 1, for just one example), the membership seems to fully understand the extreme need for privacy protection on a site with a membership that publicly proclaims themselves “anarchists,” which automatically draws unwanted attention of law enforcement.

“Folks saw a need for a social media platform that was not rife with censorship, shadow banning, and data tracking,” Franklin Lopez, an “anarchist filmmaker” and Kolektiva member told the website Mic in November, 2020. “This would be a platform that belongs to us, that is ad free, where we don’t track users’ habits or keep any of their data except for what they publish themselves.”

In yesterday’s article, the EFF seemed to recognize that security and privacy issues like the one that Kolektiva is dealing with are to be expected at this stage of the fediverse’s evolution due to the learning curves involved. They recommend that users investigate a server before they sign up for an account, to determine the degree to which that server has privacy and security precautions in place.

“Once you’ve joined, you can take advantage of the smaller scale of community on the platform, and raise these issues directly with admin and other users on your instance,” they added.

EFF’s advice for developers?

“While it would not have protected all of the data seized by the FBI in this case, end-to-end encryption of direct messages is something that has been regrettably absent from Mastodon for years, and would at least have protected the most private content likely to have been on the Kolektiva server,” they said. “There have been some proposals to enable this functionality, and developers should prioritize finding a solution.”


TOPICS: Computers/Internet
KEYWORDS: confiscation; data; electronic; fbi; internet; privacy; security; social; socialmedia

1 posted on 07/28/2023 6:49:00 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; AFreeBird; ...

2 posted on 07/28/2023 6:49:12 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Actually, the same advice would hold even if you were joining a server for, say, people who like knitting, but if you’re a political activist it’s even more important because law enforcement loves to keep tabs on folks whose politics fall outside the mainstream.

EVERYONE on Free Republic...

3 posted on 07/28/2023 7:07:32 AM PDT by Alas Babylon! (Repeal the Patriot Act; Abolish the DHS; reform FBI top to bottom!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Alas Babylon!
EVERYONE on Free Republic...
4 posted on 07/28/2023 7:30:37 AM PDT by BraveMan
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

Been playing with a similar protocol using ZeroNet for a few months now. The difference is the only thing on the common servers is the anonymous ID system and temporary email holding. Everything else including any data is encrypted and held in your own machine rather than the common server.

Every peer is both client and server. I now see that this system can actually work without any “common” federated servers at all. You would just have to keep trying to send data until the peer on the other end hooks up to the net to receive it.

But we have dealt with that old school situation before. It would be just like trying to dial into a sever with limited modem lines or a FAX needing to retry until a line is available. A small sacrifice to bypass all the central servers and have optimum privacy and security.

https://zeronet.io/


5 posted on 07/28/2023 7:53:23 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

“While it would not have protected all of the data seized by the FBI in this case, end-to-end encryption of direct messages is something that has been regrettably absent from Mastodon for years, and would at least have protected the most private content likely to have been on the Kolektiva server,”

End to end encryption of EVERYTHING...


6 posted on 07/28/2023 8:23:37 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Alas Babylon!
EVERYONE on Free Republic...

But we've known for over twenty years that the Secret Service are actively watching us, with nothing to hide.   Antifa, couldn't happen to such nicer guys. /S

7 posted on 07/28/2023 10:46:22 AM PDT by higgmeister (In the Shadow of The Big Chicken!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Openurmind
End to end encryption of EVERYTHING...

Fifty years ago in the military we used link encryption for every bit of information regardless of its importance.   We even sent constant encrypted space holder streams of coded nothing so that an increase of traffic would not be noticed.

8 posted on 07/28/2023 11:03:47 AM PDT by higgmeister (In the Shadow of The Big Chicken!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: higgmeister

“Fifty years ago in the military we used link encryption for every bit of information regardless of its importance. We even sent constant encrypted space holder streams of coded nothing so that an increase of traffic would not be noticed. “

Absolutely, there is no reason why a P2P or federated network is not fully encrypted. I am having trouble understanding why Mastodon is not 100% encrypted? Because it is slightly slower? Impossible to have high security without some added latency.


9 posted on 07/28/2023 11:15:36 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 8 | View Replies]

To: higgmeister

I believe Antifa is the Deep State, or operatives thereof.


10 posted on 07/28/2023 1:18:38 PM PDT by Alas Babylon! (Repeal the Patriot Act; Abolish the DHS; reform FBI top to bottom!)
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson