@ur_faec

43 Followers
31 Following
100 Posts
triangle husbandry. gayer than an x-wing pilot. trans.
i make pretty pictures of abstruse math:
http://faec.me
i make songs:
http://beadysea.bandcamp.com
heads up, this account may be going away soon so if you haven't yet followed @[email protected] this is a good time
@noelle i'd prefer it just didn't send that stuff at all to instances that don't implement the privacy features, though i don't know how technically feasible that is. it does seem like a potential forcing issue for a lot of instances in whether mastodon can federate with non...

@noelle ahh -- so it's not all federation, just non-masto federation?

ok, that's still somewhat concerning but much less bad.

@noelle like, (1) i'm glad followers on other instances will be able to see my selfies, but (2) i don't want them looking like public posts and being easily reshared
@noelle that is nice, but i don't use Direct much. most posts on my personal account are Private, and apparently those will now federate to followers looking like public posts :-/
i know security in federated stuff is shaky and imperfect and vulnerable to malicious actors, but making it hard for people to respect each other's explicit privacy preferences even if they WANT to is. disappointing?
"a UI to audit your followers" is kind of a stunning non-solution. i do check out my followers but if they can't even tell a post is non-public then lack of malice isn't going to help anything.

umm... so it's the intended behavior that private posts get federated as non-private, with no barriers to resharing?

that's... a serious problem.

A word of warning to anyone upgrading to Mastodon 1.3(.1)!!!

Starting with 1.3(.1) Private posts will federate! But they don't do so securely! Warnings are built in but be aware that if you have followers on GNU Social, Friendica, or postActiv then they will **NOT** know that your post is marked private/followers-only!! And they **will** be able to boost it!! Once they do so, it becomes a public post

This is not opt-in, it just happens post-update

If this worries you, go audit your followers

i might post on this account more now that amaroq supports multiple accounts XD but reminder that the personal stuff is all at @[email protected] now