Email or username:

Password:

Forgot your password?
Top-level
Michael

@PCOWandre you can be a moderator without being admin.

1 comment
Andre

@michael Yes, I know.

A purloined moderator account could be used to crush an instance very quickly. Scripts to report every post then take a moderator action on every post, as an example.

We're not seeing much in the way of real attacks on Mastodon yet because there's not enough in it. The stakes are still too low. That's going to change over time.

I'm old and cranky and think if we consider security first and convenience second we'll get a better long-term outcome. I don't want to see an instance incinerated because of a preventable condition; I also have no idea what happens when one restores a Masto database from backup in terms of resuming federated operations with a day of lost data. The whole thing sounds very messy.

@michael Yes, I know.

A purloined moderator account could be used to crush an instance very quickly. Scripts to report every post then take a moderator action on every post, as an example.

We're not seeing much in the way of real attacks on Mastodon yet because there's not enough in it. The stakes are still too low. That's going to change over time.

Go Up