Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • spaduf@slrpnk.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    6 months ago

    Totally. I’m just trying to bring it up whenever I see folks having this discussion because some people don’t seem to make the distinction. Worries me that some are so willing to cede that big social will illegally hoover up our data and there’s nothing we can do about it.