Reference. Privacy Policies on the Fediverse: A Case Study of Mastodon Instances

Free and open source social platform software has dramatically lowered the barrier to entry for anyone to set up and administer their own social network. This new population of social network administrators thus assume data management responsibilities for sociotechnical systems. Administrators have the power to customize this software, including data collection and data retention, potentially leading to radically different privacy policies. To better understand the characteristics — e.g., the variability, prohibitions, and permissions — of privacy policies on these new social networking platforms, we have conducted a case study of Mastodon. We performed a text analysis of 351 privacy policies and a survey of 104 Mastodon administrators. While most administrators used the default policy that ships with the Mastodon software, we observed that approximately ten percent of our sample tailored their privacy policies to their instances and that some administrators conflated codes of conduct with privacy policies. Our findings suggest the existing market-based individualistic frameworks for thinking about privacy policies do not adequately address this emerging community.

Cite

Cite as @tosch-2024-privacy (helia, typst) · \cite{tosch-2024-privacy} (LaTeX)
BibTeX
bibtex · 1 line
@article{tosch-2024-privacy, title={Privacy Policies on the Fediverse: A Case Study of Mastodon Instances}, volume={2024}, ISSN={2299-0984}, url={http://dx.doi.org/10.56553/popets-2024-0138}, DOI={10.56553/popets-2024-0138}, number={4}, journal={Proceedings on Privacy Enhancing Technologies}, publisher={Privacy Enhancing Technologies Symposium Advisory Board}, author={Tosch, Emma and Garcia, Luis and Li, Cynthia and Martens, Chris}, year={2024}, month=Oct, pages={700–733} }
hayagriva YAML (typst)
yaml · 20 lines
tosch-2024-privacy:
  type: article
  title: 'Privacy Policies on the Fediverse: A Case Study of Mastodon Instances'
  author:
  - Tosch, Emma
  - Garcia, Luis
  - Li, Cynthia
  - Martens, Chris
  date: 2024-10
  page-range: 700-733
  url: http://dx.doi.org/10.56553/popets-2024-0138
  serial-number:
    doi: 10.56553/popets-2024-0138
    issn: 2299-0984
  parent:
    type: periodical
    title: Proceedings on Privacy Enhancing Technologies
    publisher: Privacy Enhancing Technologies Symposium Advisory Board
    issue: 4
    volume: 2024
Cites 98 works (1 here)
With notes (1)

Exploring Consequences of Privacy Policies with Narrative Generation via Answer Set Programming dabral-2022-exploring

Informed consent has become increasingly salient for data privacy and its regulation. Entities from governments to for-profit companies have addressed concerns about data privacy with policies that enumerate the conditions for personal data storage and transfer. However, increased enumeration of and transparency in data privacy policies has not improved end-users’ comprehension of how their data might be used: not only are privacy policies written in legal language that users may struggle to understand, but elements of these policies may compose in such a way that the consequences of the policy are not immediately apparent. We present a framework that uses Answer Set Programming (ASP) – a type of logic programming – to formalize privacy policies. Privacy policies thus become constraints on a narrative planning space, allowing end-users to forward-simulate possible consequences of the policy in terms of actors having roles and taking actions in a domain. We demonstrate through the example of the Health Insurance Portability and Accountability Act (HIPAA) how to use the system in various ways, including asking questions about possibilities and identifying which clauses of the law are broken by a given sequence of events.
arXiv
External (97)
  • "Those things are written by lawyers, and programmers are reading that." Mapping the Communication Gap Between Software Developers and Privacy Experts (2024)
  • A Statistical Understanding of Disability in the LGBT Community (2023)
  • Section 230 and the Fediverse: The ‘Instances’ of Mastodon’s Immunity and Liability (2023)
  • Ethics of Decentralized Social Technologies: Lessons from Web3, the Fediverse, and Beyond (2023)
  • FBI Seizure of Mastodon Server Data is a Wakeup Call to Fediverse Users and Hosts to Protect their Users (2023)
  • An Empirical Study of Trust & Safety Engineering in Open-Source Social Media Platforms (2023)
  • Fleeing Elon Musk's X, the quest to re-create 'Black Twitter' (2023)
  • "We do not appreciate being experimented on": Developer and Researcher Views on the Ethics of Experiments on Open-Source Projects (2023)
  • Towards Intersectional Moderation: An Alternative Model of Moderation Built on Care and Power (2023)
  • Mastodon Fixes Critical "TootRoot" Vulnerability Allowing Node Hijacking (2023)
  • Flocking to mastodon: Tracking the great twitter migration (2023)
  • Whose Policy? Privacy Challenges of Decentralized Platforms (2023)
  • Less is Not More: Improving Findability and Actionability of Privacy Controls for Online Behavioral Advertising (2023)
  • Decentralizing Platform Power: A Design Space of Multi-level Governance in Online Social Platforms (2023)
  • Awareness, Intention,(In) Action: Individuals’ Reactions to Data Breaches (2023)
  • Researchers’ Experiences in Analyzing Privacy Policies: Challenges and Opportunities (2023)
  • Mastodon Rules: Characterizing Formal Rules on Popular Mastodon Instances (2023)
  • Moderating the fediverse: Content moderation on distributed social media (2023)
  • Decentralized Networks Growth Analysis: Instance Dynamics on Mastodon (2023)
  • Privacy Lost and Found: An Investigation at Scale of Web Privacy Policy Availability (2023)
  • Common Abuses on Mastodon: A Primer (2023)
  • For Bluesky to thrive, it needs sex workers and Black Twitter (2023)
  • Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by Websites (2023)
  • Emerging Forms of Sociotechnical Organisation: The Case of the Fediverse (2022)
  • The Whiteness of Mastodon (2022)
  • How we keep our online surveys from running too long (2022)
  • Adhesive Terms and Reasonable Notice (2022)
  • Network analysis of the information consumption-production dichotomy in mastodon user behaviors (2022)
  • Establishing Market and Monopoly Power in Tech Platform Antitrust Cases (2022)
  • How a University Got Itself Banned from the Linux Kernel (2021)
  • Do you Really Code? Designing and Evaluating Screening Questions for Online Surveys with Programmers (2021)
  • Validity and reliability of the scale internet users' information privacy concerns (IUIPC) (2021)
  • Disproportionate removals and differing content moderation experiences for conservative, transgender, and black social media users: Marginalization and moderation gray areas (2021)
  • Too Long; Didn’t Read: Finding Meaning in Platforms’ Terms of Service Agreements (2021)
  • Understanding the growth of the Fediverse through the lens of Mastodon (2021)
  • "Now I'm a bit angry:" Individuals' Awareness, Perception, and Responses to Data Breaches that Affected Them (2021)
  • A Large Publicly Available Corpus of Website Privacy Policies Based on DMOZ (2021)
  • Studying reddit: A systematic overview of disciplines, approaches, methods, and ethics (2021)
  • Defining Privacy: How Users Interpret Technical Terms in Privacy Policies (2021)
  • Mastodon is crumbing — and many blame its creator (2021)
  • "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion Choices (2020)
  • Seven theses on the fediverse and the becoming of FLOSS (2020)
  • An Open Letter from the Mastodon Community (2020)
  • Rethinking the “social” in “social media”: Insights into topology, abstraction, and scale on the Mastodon social network (2020)
  • Symposium: The Tech Giants, Monopoly Power, and Public Discourse (2019)
  • Your Speech, Their Rules: Meet the People Who Guard the Internet (2019)
  • "This Place Does What It Was Built For": Designing Digital Institutions for Participatory Change (2019)
  • Run Your Own Social (2019)
  • Setting up your new instance (2019)
  • "We Can't Live Without Them!" App Developers' Adoption of Ad Networks and Their Considerations of Consumer Risks (2019)
  • We Did it Right, but It was Still Wrong: Toward Assets-based Design (2019)
  • Challenges in the Decentralised Web: The mastodon case (2019)
  • The Effect of a Data Breach Announcement on Customer Behavior: Evidence from a Multichannel Retailer (2018)
  • Follow the “mastodon”: Structure and evolution of a decentralized online social network (2018)
  • Risk and Anxiety: A theory of Data-breach Harms (2017)
  • A Quick Guide to The Free Network (2017)
  • Consumer Attitudes toward Data Breach Notifications and Loss of Personal Information (2016)
  • The creation and analysis of a website privacy policy corpus (2016)
  • Understanding Malicious Behavior in Crowdsourcing Platforms: The case of online surveys (2015)
  • The case for alternative social media (2015)
  • Disagreeable Privacy Policies: Mismatches between Meaning and Users’ Understanding (2015)
  • A design space for effective privacy notices (2015)
  • Internet, phone, mail, and mixed-mode surveys: The tailored design method (2014)
  • The Growth of Diaspora — A Decentralized Online Social Network in the Wild (2012)
  • Necessary but not sufficient: Standardized mechanisms for privacy notice and choice (2012)
  • Expectation and purpose: understanding users’ mental models of mobile app privacy through crowdsourcing (2012)
  • The impact of context collapse and privacy on social network site disclosures (2012)
  • 4chan and /b/: An Analysis of Anonymity and Ephemerality in a Large Online Community (2011)
  • I tweet honestly, I tweet passionately: Twitter users, context collapse, and the imagined audience (2011)
  • Scikit-learn: Machine learning in Python (2011)
  • Information privacy research: an interdisciplinary review (2011)
  • Experiences in the logical specification of the HIPAA and GLBA privacy laws (2010)
  • Natural language processing with Python: analyzing text with the natural language toolkit (2009)
  • A defeasible logic for modelling policy-based intentions and motivational attitudes (2009)
  • A "nutrition label" for privacy (2009)
  • Examining usability of web privacy policies (2008)
  • The impact of reading a web site’s privacy statement on perceived control over privacy and perceived trust (2007)
  • What’s wrong with online privacy policies? (2007)
  • Structure and evolution of online social networks (2006)
  • How to Search a Social Network (2005)
  • Giving Notice: Why Privacy Policies and Security Breach Notifications aren’t Enough (2005)
  • Privacy practices of Internet users: Self-reports versus observed behavior (2005)
  • P3P: Making privacy policies more useful (2003)
  • The theoretical, historical, and practice roots of CBPR (2003)
  • Reply networks on a bulletin board system (2003)
  • Small-world phenomena and the dynamics of information (2001)
  • Navigation in a small world (2000)
  • On the modeling and analysis of regulations (1999)
  • Assets-based Community Development (1996)
  • Electronic bulletin boards and “public goods” explanations of collaborative mass media (1993)
  • Privacy policies and practices: Inside the organizational maze (1993)
  • Use of computer network bulletin board systems by disabled persons (1992)
  • Mapping the Margins: Intersectionality, Identity Politics, and Violence against Women of Color (1991)
  • Utilization of an Electronic Bulletin Board (1985)
  • The electronic bulletin board: A computer-driven mass medium (1984)
  • Cognitive structures in comprehension and memory of narrative discourse (1977)
  • Privacy and Freedom (1968)
tosch-2024-privacy reference entries/refs/tosch-2024-privacy/tosch-2024-privacy.hel