Cloudguy says we should log out of Amazon
sackheads.social
sackheads.social
If so, founder of smoothwall, history in the UK security scene. Not to say that means that what's happening here is as serious as what's being alluded to, but has some background in the area.
I guess this would filter non-technical people, but Let's Encrypt existence has made any argument against web certificates moot. There's no sensible reason not to.
* https://www.thesslstore.com/blog/third-party-content-injecti...
These risks however aren't a major concern for me, and people who choose to send me mail don't assume security or deliverability.
Ex RedHat, co-founder SmoothWall, Ex director Cloud Security Alliance, Ex CTO Gartner Group
They should probably use a CDN, and I imagine putting a blog behind a CDN is easier than putting your Mastodon instance behind one.
Configuring a CDN correctly of course will work, but I've done some basic analysis of the network and that is not happening, looks like a lot of first-time sysadmins running Mastodon without knowing about these sorts of things.
That doesn't work when people post links like this though. Maybe we need something like activitypub://@username/postid that can be opened in the user's default client if they have one, or could be resolved to the original instance if not via webfinger. Unfortunately never going to happen, but it would be in the spirit of the systems.
Can you sus-out for fellow MAANGers if this is righteous anger, prudent caution, or John McAfee-level flat-earther paranoia?
It depends on how worried you are about stalkers. If your address leaking is a big deal to you (which, it validly is for some), then yeah, do the thing. Everyone else need not panic though.
For Google users, there is the APP that works with smartphone embedded keys and FIDO2 keys like Yubikeys and Titankeys.