The Mastodon "Remote follow" feature could be so easily used to phish the average Mastodon user into signing into a fake instance.

⚠️ Important security reminder: Always make sure the URL shows your "home instance" when logging in.

@fj and turn on 2FA
@szbalint @fj It won't save you if your 2FA code get phished as well