> apparently my server's administrator would be able to silently prevent me from seeing other "enemy" servers' messages, and they could even read my DMs.
There's an interesting problem here - how do you know that your server's software and configuration hasn't been modified in a way that subtly lets these things happen?
I've always wanted a PaaS, operated by a too-big-to-make-exceptions security-hardened company (here's looking at you, Google!), that lets you deploy any image or set of images, but has a centrally managed ingress that ensures that the only access is over HTTPS (so no direct access to any requisitioned databases) and furthermore reports a hash of the image(s) as an HTTP response header with every single response, with no way to change or suppress this
You could then have, say, a Mastodon implementation that also reports all appropriate central configuration (say, blocklists, or disabling the ability of users to port out) at a public endpoint, and, importantly, is trusted to report that accurately, because you could validate what code it's running via the HTTP response. You could audit that security updates are being applied, that nobody is running a fork that gives them access to your DMs, and, if Mastodon gave visibility into this, you could also validate whether administrators all have 2FA enabled and how many of them there are (and hold your server admins to account socially).
Of course, you do have to trust the PaaS provider not to make exceptions to the rules, but no more so than we currently trust any certificate authority.
Does anyone know if anything like this exists right now?