edit:
just wanted to share a great observation that was made by UlrikHD in our admin channel:
"So if a company wanted to demand the ip of every member on a piracy community, they would have to contact every instance federated with that community then
good to know"
I believe the rules wouldn't apply. Usually when a company is asked to provide data and they refuse they are forced to shut down. But since Lemmy is decentralized, I believe if the cops were to ask someone to provide the IP of a user, they can just say no and shut down the server at least temporarily, and then possibly bring it back up under a new domain and ip.
IANAL but withholding evidence from a court order can hold you in contempt of court. I remember hearing a story of a person who was accused of having CSAM on an encrypted hard drive, and refused to decrypt it, and is in jail until he decrypts it. Just because you're a person doesn't mean you can ignore a warrant.
information itself is a liability. best to have a policy of 'we keep no IPs in logs, so are happy to hand over whatever'.. dump data the moment you dont require it
yeah, this sounds like a much more sustainable solution. Do it the way signal does it. Collect as little as necessary, and delete it as soon as you dont need it.
I looked into that guy somewhat recently, he was in jail for something like five years then eventually released. Kind of a sickening situation all around.
With the federation does that also mean that the ip records are replicated? Because that would be a lot of parties that can be threatened, with only one required to give in...
As long you don't do the "known illegal" stuff you don't need a VPN.
However if you upload copyrighted material a vpn is one of very many steps to ensure that the police won't get you. A VPN alone does not provide any security. It delays at best the police