

Security has been a hot topic for Lemmy recently and privacy is something that we all care about. Here's how we're set up to handle both.
Security
As a self-hosted Lemmy instance, we're actually in a slightly better position than many:
- The server is not remotely accessible from outside the local network (it doesn't need to be).
- The Lemmy admin interface is not remotely accessible from outside the local network (even if my Lemmy account ends up compromised through some exploit, the potential harm from that is greatly reduced).
We also have more generic network security measures in place:
- The server sits behind a hardware firewall.
- The Lemmy instance sits behind a reverse proxy.
- Internal networks are segregated from each other.
- IP whitelisting is used for all internal remote access.
Nothing on the Internet is unhackable and we're no exception. However, we're too small to be an attractive target and we're sufficiently hardened to avoid being a target of opportunity.
Privacy
Being self-hosted has a number of advantages here too. Lemdit does not use any 3rd party web services whatsoever:
- No cloud hosting of any kind
- No external e-mail service
- No CDN
- No DoS protection
- No analytics
- No ads
- You name it, we don't have it.
Privacy is important to me personally and all the trade-offs I have made have been in favour of privacy.
Lemdit runs an unmodified version of Lemmy available from its official GitHub repository.
What Lemdit knows about you:
- Standard NGINX access logs are kept for 2 weeks (IP address, time stamps, etc).
- The Lemmy database contains the e-mail address that you signed up with.
- The mail server has a record of e-mails that were sent to you by Lemdit.
This data is not available to anyone else and only legal/law enforcement action could compel us to share it.
Legal
Due to the nature of federated services, all of your engagement (your profile; posts; comments; messages; votes) on this platform should be considered public. We highly recommended that you do not share any information on Lemdit, or the Lemmy platform, that could in any way personally identify you.
Internet regulations are increasingly complex and country specific. To navigate this complexity, we rely on TermsFeed to define our Terms and Conditions, as well as our Privacy Policy. This post tries to describe some of the key points in plain English, but does not act as a substitute for these documents.
I'm not a lawyer nor do I have the time to try and prettend I'm one, so while I dislike long documents written in Legalese, that's what we have in place for now.
Version history
15 July 2023
- Initial release
19 July 2023
- Added Version history for transparency
:::
What kind of potato are we running on?
3y 16d ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comOpening a new community: Federated Ideas (Discussion for apps that should or could be federated, or existing projects)
2y 9mon ago by lemdit.com/u/Gnubyte in lemdit@lemdit.com from lemdit.comWe now require registration applications for new users
2y 9mon ago by lemdit.com/u/delendum in lemdit@lemdit.comOur mascot woke up today as an octopus
2y 9mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comHi I'm new here
2y 9mon ago by lemdit.com/u/PrettyBlackDress in lemdit@lemdit.comRegarding "Controversial Ideas" and a change in our mascot
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.comLemdit defederation tracker
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comLemdit has been updated to Lemmy 0.18.4
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.comWe're hosting Photon (alternative web client for Lemmy with the UI of Xylo) - Access it at https://p.lemdit.com
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comIntroducing lestat.org - Lemmy instance status monitor for all popular instances
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comDefederating from lemmy.comfysnug.space due to legal concerns and a note on "loli porn" instances in general
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.comWe're hosting Alexandrite (beautiful desktop-first alternative web UI) - Access it at https://a.lemdit.com
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comWe've upgraded to Lemmy 0.18.3 and other improvements
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.comLemdit was down for about 4 hours
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.comWe're hosting Mlmym (Lemmy UI that looks like old Reddit) - Access it at old.lemdit.com
2y 10mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comWhat are your thoughts on Lemmy and Lemdit so far?
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comLemdit Status page and backup Discord server
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comWe’re hosting Voyager (formerly wefwef)! - Access it at m.lemdit.com
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comUpdating to Lemmy 0.18.2 Release - Success
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comUpdating to Lemmy 0.18.2-rc.2 / UI 0.18.2-rc.2 - Success
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comDefederating from burggit.moe due to legal concerns
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comLemmy exploit update - open registration and community creation are re-enabled
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comLemmy exploit response - temporarily switching off open registration and the ability to create new communities
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comIs there a way to donate to Lemdit?
2y 11mon ago by lemdit.com/u/Caithe in lemdit@lemdit.comUpdating to Lemmy 0.18.1 Release - Success
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comKnown bugs in Lemmy UI 0.18.1-rc.9
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comUpdating to Lemmy 0.18.1-rc.9 / UI 0.18.1-rc.9 - Success
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comLemmy-ui misbehaving
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comUpdating to Lemmy 0.18.1-rc.4 / UI 0.18.1-rc.7 - Success
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comCautiously turning off requiring registration applications
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.comCautiously turning off requiring registration applications
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comOff-Lemdit Instances Subscribe + Block Buttons Broken UI
2y 11mon ago by lemdit.com/u/DriveWorld in lemdit@lemdit.comLemmy 0.18.0 quirks and requiring registration applications
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.comUpdating to Lemmy 0.18.0 - Success
2y 11mon ago by lemdit.com/u/delendum in lemdit@lemdit.com from lemdit.com













