The more people use Fedecan services, the more Fedecan will attract bots.

Which means Fedecan will have to do something for users to prove that they are human. When I joined, you guys had a registration prompt with manual review, but I imagine the prompts you gave could be automatically bypassed by an LLM fairly easily.

The naive solution is to do something like collecting government IDs like Facebook tried at one point. But that’ll just drive people away who don’t trust Fedecan with that info.

What would be your thoughts (admin thoughts, and community thoughts) to implement some ‘proof of unique personhood’ process with something like Canada Post Identity+? Basically, Canada Post verifies that users are human and is responsible for taking care of PII, and Fedecan just trusts Canada Post to not let the same user register multiple times. If done well, I think ‘Canada Post proves that every user account on this site is a unique human’ could be a real selling point for lemmy.ca and pixelfed.ca

Full disclosure, I heard about it in a Reddit thread of people complaining about bugs in it while they try to vote in the Liberal party election. But I bet this is just early adopter bugs, and the Liberal party clearly trusts it with their leadership elections.

Regardless, I think proof of unique personhood is a problem Fedecan will have to solve, and a solution through something as Canadian as the post office just seems more elegant than having the Fedecan admins reinvent the wheel.

I realize you guys (admins) are probably quite busy with IRL work and the Pixelfed launch, so if there was interest in this but no admin capacity to investigate further, I could volunteer to reach out to Canada Post and see what they could offer for non-profit use, including what it would cost Fedecan.

Thoughts?

EDIT: for people concerned about “but then CSIS knows which account is mine”, an anonymous credential system like U-Prove could be used to prove “1 lemmy.ca user = 1 unique real person”, while cryptographically guaranteeing it is impossible to link any particular lemmy.ca user to any particular human identity.

  • Whooping_Seal
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    8 hours ago

    I think it isn’t the most useful spam reduction method as lemmy.ca and I’m assuming Pixelfed.ca federate with a block list rather than an allowlist. Bad actors can always run a new instance to bypas bans etc., even positioning the instances as valid moderated instances for a while before launching bot attacks.

    I also think part of the joy of using a platform like lemmy is the pseudo-anonymous nature of the platform. That type of government identity verification begins to compromise that a bit, but maybe I have a more extreme view on the option of pseudo-anonymity being a paragon of the free internet.

    Edit: Just to note I am not a lemmy.ca account, but I am a Canadian (which is in part why I picked sh.itjust.works, another Canadian owned instance)