So with the revelation that the owner of a big Fedi server is a target of a lawsuit, and that if things go badly the server may find itself seized—
I realize that that users on that instance follow users on my instance, so there are going to be semiprivate posts of mine that may fall into the hands of people—law enforcement, data brokers—who are not beholden to any Fedi Admin Code of Honour.
(I already do not post about my crimes on Fedi, if I were the kind to do crimes.)
Server seizure is just not a part of the ActivityPub threat model. What if it was? How would it change the protocol to protect data at rest, or perhaps not even keep it at rest on a server but defer to the originating server?
End-to-end encryption [user-to-user, not server-to-server] could be part of the answer, but it need not be the whole answer.
I welcome considered thoughts, so any response I see within an hour of my posting this will be ignored.