The Mastodon "Remote follow" feature could be so easily used to phish the average Mastodon user into signing into a fake instance.

⚠️ Important security reminder: Always make sure the URL shows your "home instance" when logging in.

@fj this is what password managers excel at. They won't fill in a password on a different instance (or any phishing site) and you can't enter a password because you don't know it.