Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • froggersEnglish
    arrow-up
    6
    arrow-down
    50
    ·
    10 months ago
    edit-2
    10 months ago
    link
    fedilink

    anything I write on the internet should be treated as my private information. If I want to keep any conversation private, I will still post it in a public website.

    EDIT: I’m so sorry that my stupid comment offended some people. Always forget how special some people can be on this website. Once again I’m sorry for my lack of better judgement.

    • PeriodicallyPedanticEnglish
      arrow-up
      18
      arrow-down
      0
      ·
      10 months ago
      link
      fedilink

      Wow, why are you so triggered just because some people didn’t think you were funny?

      • froggersEnglish
        arrow-up
        1
        arrow-down
        9
        ·
        10 months ago
        link
        fedilink

        About as triggered as those who downvoted me.

        • PeriodicallyPedanticEnglish
          arrow-up
          8
          arrow-down
          0
          ·
          10 months ago
          link
          fedilink

          No, you’re right. Everyone who downvoted probably also went on an angry tirade first, but they just didn’t type it out. Totally the same. 👍

      • stoy
        cake
        English
        arrow-up
        12
        arrow-down
        1
        ·
        10 months ago
        link
        fedilink

        He thought he was funny, he repeated what the above poster said to repeat.

    • solrizeEnglish
      arrow-up
      4
      arrow-down
      0
      ·
      10 months ago
      link
      fedilink

      I don’t think your comment was offensive per se. It was just ridiculously naive. If we are trying to build practical tools, they have to fit how things work in the real world, not how they work in anybody’s dreams. If you want to have private conversations on a public website, use encryption.