

:this:
not 100% sure that’s true about sending DMs to users on other instances (activitypub uses public key signing to ensure data integrity so I’m assuming they couldn’t do so without those keys from our DB), but certainly they could put up a honeypot and try to ID users.
yep, it’s still a big fucking problem.