A word of warning to anyone upgrading to Mastodon 1.3(.1)!!!

Starting with 1.3(.1) Private posts will federate! But they don't do so securely! Warnings are built in but be aware that if you have followers on GNU Social, Friendica, or postActiv then they will **NOT** know that your post is marked private/followers-only!! And they **will** be able to boost it!! Once they do so, it becomes a public post

This is not opt-in, it just happens post-update

If this worries you, go audit your followers

@shel this is such an unfortunate implantation...

@lambadalambda OK but like the worst thing is like

remember how in my write-up Solution A, proposed by Hoodie, was to make it OPT IN and you have to read a warning explaining it first??? And we agreed this worked under that circumstance??

And like rather than any of those options we get like, weird A-1 which removes the main component that would make Solution A acceptable

@shel wait, it just happens now? Without confirmation?

@lambadalambda the moment your instance upgrades to 1.3 or higher it Just Happens and nothing tells you that it's different

and to a new user who isn't here in This Moment then they'll have no idea until they get rly confused by their followers-only post getting boosted when it's not supposed to be

@shel 👍👍👍👍 10/10 would federate again.