Email or username:


Forgot your password?
22 posts total
Kevin Beaumont

Boring Mastodon security thing - make sure you enable MFA, that all your instance administrators and mods have MFA and that they’re on the latest version (4.0.2).

Why? If you or an admin/mod deletes your account, it’s instant and gone. Even if the entire instance was restored from backup (unlikely 🤣) your account would still be hosed as every other instance would flag it deleted.

For transparency #cyberplace admin is MFA’d with hardware token.

Kevin Beaumont

There's definitely some fun Mastodon security issues which will appear at some point, e.g. if anybody gets admin at an instance you can bulk select every user and delete them - even if you restore the instance from backup, every other instance has wiped them = no followers etc.

The first admin account on every instance has no MFA by default.

Kevin Beaumont

I’m still pissed at Elon for two things:

1) making me learn how to spell Mastodon
2) that he didn’t buy and ruin LinkedIn instead

Go Up