I wonder how much of this is rendered moot by enabling authorized_fetch (https://docs.joinmastodon.org/admin/config/#authorized_fetch) or the fedi service equivalent?
Or more use of locked accounts and follower-only posts? (For those who are most concerned.)
I enabled authorized_fetch here a couple of months back, and haven’t noticed any issues.
@neil #AuthorizedFetch does nothing to protect from the dissemination of personal data in at least two very common cases:
https://github.com/mastodon/mastodon/issues/22620#issuecomment-1363670888
https://github.com/mastodon/mastodon/issues/21674
#MastoMeta #MastoDev