and while we're at it, i think we need to have a discussion about Tootdon
Pleroma will soon begin blocking Tootdon from authenticating to the instance, using a configurable application blocklist. https://git.pleroma.social/pleroma/pleroma/issues/944 is the tracking bug for this, if you're interested.
Application blocklist (#944) · Issues · Pleroma / pleroma

We need to refuse to grant application credentials as well as retroactively revoke access to apps on a configurable blocklist. This is intended for blocking broken apps or apps which...

one may wonder why Pleroma is planning to block Tootdon, the answer is that Tootdon sends a copy of every post it sees to Tootdon's corporate servers.
needless to say, this is not something we believe should be happening (which is why we plan to block Tootdon). access credentials will be retroactively revoked for Tootdon, and any user who attempts to acquire new credentials will be advised that the application has been blocked for security reasons and will recommend uninstalling the app. we're working on the language for that still.
Pleroma (and Mastodon) are platforms. as developers of fediverse platforms, it is our responsibility to use this position to safeguard the security of the overall ecosystem whenever possible. I encourage Mastodon to join us in blocking Tootdon, giving admins the ability to block specific applications, and default-blocking any other apps found to be playing fast and loose with data.
@kaniini damn tootdon is real fuckin shady