you are viewing a single comment's thread
view the rest of the comments
[–] 38 points 2 years ago (5 children)

So how would that work with Lemmy? If a company demands the IP of users?

  • source
  • hideshow 10 child comments
  • [–] 18 points 2 years ago* (last edited 2 years ago)

    For our instance we've answered that here:

    Reddit might be forced to hand out IPs of users frequenting piracy subreddits: how does programming.dev compare?

    edit: just wanted to share a great observation that was made by UlrikHD in our admin channel:

    "So if a company wanted to demand the ip of every member on a piracy community, they would have to contact every instance federated with that community then
    good to know"

  • source
  • parent
  • [+] 9 points 2 years ago (2 children)
  • [–] 40 points 2 years ago (4 children)

    IANAL but withholding evidence from a court order can hold you in contempt of court. I remember hearing a story of a person who was accused of having CSAM on an encrypted hard drive, and refused to decrypt it, and is in jail until he decrypts it. Just because you're a person doesn't mean you can ignore a warrant.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 46 points 2 years ago (2 children)

    information itself is a liability. best to have a policy of 'we keep no IPs in logs, so are happy to hand over whatever'.. dump data the moment you dont require it

  • source
  • parent
  • hideshow 4 child comments
  • [–] 9 points 2 years ago (1 child)

    Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 2 years ago (1 child)

    Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 5 points 2 years ago*

    If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting.

    ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers.

  • source
  • parent
  • [–] 6 points 2 years ago* (2 children)

    Don’t browse lemmy with your naked IP. This isn’t the 90s. When using the Internet, wear a condom.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 12 points 2 years ago

    As long you don't do the "known illegal" stuff you don't need a VPN.

    However if you upload copyrighted material a vpn is one of very many steps to ensure that the police won't get you. A VPN alone does not provide any security. It delays at best the police

  • source
  • parent
  • [–] 11 points 2 years ago (2 children)

    Ah yes, give your browsing history to the shady VPN company instead.

    Although that would help in this situation.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 2 years ago (1 child)

    Shady? I only use VPNs from known companies, like Sony.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 2 years ago* (last edited 2 years ago)

    A VPN either:

    1. Logs access/usage so it can be given to authorities. (And/or sold/stolen etc)

    2. doesn't log usage data and willingly accepts that some disgusting stuff will be done using their service.

    1 might have to give browsing data if sued by a media company, 2 is ethnically bankrupt and shouldn't be trusted at all.

    Doesn't mean their not useful, just be aware of who you are giving your money to and the limitations of their protection.

  • source
  • parent