- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.
Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.
Thank you for explaining it, I think you’re right. Not sure why they wouldn’t explain it to me, I can’t read minds and that’s an interesting conversation.
Which is even more reason for all the big instances to not federate, but it’s their choice. All these smaller instance, weekend hobbyists are going to feel the pain. At least meta says they’re going to integrate slowly. We’ll see.
Don’t worry, it’ll sort itself out when it becomes truly painful.