Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • @ChaosAD
    link
    English
    01 year ago

    You can’t make your profile entirely private like one would do on Twitter or any of Meta’s products.

    Even those are not private.