Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • rglullisEnglish
    arrow-up
    6
    arrow-down
    0
    ·
    10 months ago
    link
    fedilink

    Right. Publicly available does not mean in public domain. But the issue here is not of copyright, but merely of gated access.

    • spadufEnglish
      arrow-up
      2
      arrow-down
      0
      ·
      10 months ago
      edit-2
      10 months ago
      link
      fedilink

      Totally. I’m just trying to bring it up whenever I see folks having this discussion because some people don’t seem to make the distinction. Worries me that some are so willing to cede that big social will illegally hoover up our data and there’s nothing we can do about it.