Mastodon, privacy flaws, account deletion 1/4 

From a masto admin perspective, I recently noticed that accounts don't ever get fully deleted.
I repeat:

Accounts never get fully deleted from a Masto instance

TL;DR: Choose your mastodon instance wisely.
Never use your legal name as your nickname and associated email addresses.
VPN is advised too.

Mastodon, privacy flaws, account deletion 2/4 

There are two cases of account "removal":

1. If the user manually deletes their account. The nickname will still show up in the admin panel but the associated IP addresses and emails will be removed. This cannot be reverted, but I assume the nickname cannot be recycled for any new account.

2. The other case is when an account is suspended from an instance. The IP and email addresses are still associated with it. And it's impossible for the former owner of the account to sign in to remove the said account unless an admin lifts the suspension.

Mastodon, privacy flaws, account deletion 3/4 

So basically, your username will stay forever on the instance's userlist.
If you get suspended, no matter if the suspension is justified or not, your email and IP addresses will be saved forever on the userinfo in the admin panel.

The admins won't even be able to delete a suspended account except if they reset the account password, unsuspend it, login with it and then proceed to a removal.
(Note that we don't do this)

Mastodon, privacy flaws, account deletion 4/4 

Imagine a worst case scenario where cops seize a large instance, suspend everyone and then collect all the user's info without them being able to make an emergency account deletion.

Sounds bad, heh?

Mastodon, privacy flaws, account deletion 4/4 

@iantila yep... You can manually remove the user from the database, but it's a huge faff and not everyone has direct access to their dB or knows how to do it. From what I remember, mastodon keeps the entry in order to not mess up federation by creating another user with the same name/id. But I would hope there'd be a way around that...

Mastodon, privacy flaws, account deletion 4/4 

@dumpsterqueer @iantila keeping a hash of the account name would be plenty to avoid someone reusing the name. And regarding federation, serving 404's should be handled perfectly well by any decent federating server.

re: Mastodon, privacy flaws, account deletion 4/4 

@iantila i do not understand that worst case scenario
what would cops gain by suspending everyone? if they have seized the instance, they already have the data

ip addresses of accounts who have not logged in within a year (suspended or otherwise) are automatically deleted

before that, they are kept in order to detect people registering multiple accounts with the same address, etc.

currently, i believe emails to be kept forever, indeed

usernames are indeed kept to avoid someone “stealing” a username

re: Mastodon, privacy flaws, account deletion 2/4 

@iantila If an email is changed does the old email still show up or is it replaced with the new one?

re: Mastodon, privacy flaws, account deletion 2/4 

It will be replaced by the new one in the panel.

But keep in mind that if your sign-up had to be manually confirmed, the mod team received an email notification containing the email address you signed up with.

re: Mastodon, privacy flaws, account deletion 2/4 


Thank you for your answer :)

I use aliases anyway, so I can just delete the email address forever and still have the main hidden address.

I was just curious as to what happened if I or others changed them.

Mastodon, privacy flaws, account deletion 1/4 

@iantila from a masto admin perspective, as storage has a cost, how can I claim back the storage space occupied by deleted account wiping them for good?

Mastodon, privacy flaws, account deletion 1/4 

When accounts are suspended/deleted, all the data the account created is cleaned (toots, medias etc.).

The persisting remnants of the accounts that I mentioned earlier are probably no larger than a couple of kilobytes.

