Pixelfed leaks private posts from other Fediverse instances

23 points by strugee


freddyb

Also, if someone on a server follows you, that other server’s admin can also read everything because they are the admin.

landon

This seems systemic? What’s to stop me from reading “private” posts by deliberately writing a badly behaved server that does this? Moreover what’s the point of “provate” posts if I have to trust an unknown third party to behave nicely in order to keep them that way? It feels a little odd to call them that if my server is expected by protocol to send them to anyone who asks.

It feels less like a leak and more like a garden hose spigot on the side of the house that we only realized existed when a neighbor left it on, and we’ve reprimanded the neighbor and they said “sorry, I’ll be sure to turn it off when I’m done next time”