Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • @ttmrichter
    link
    English
    -11 year ago

    Clear sign every post using a third-party application. Make your public keys known far and wide. Authenticity solved.

    • Natanael
      link
      fedilink
      English
      51 year ago

      And now we’re dealing with key management instead

      • @ttmrichter
        link
        21 year ago

        You always need key management if you have decentralized authentication.

      • @ttmrichter
        link
        01 year ago

        You always need key management if you have decentralized authentication.