Another dust-up with Dansup lol…
cross-posted from: https://lemmy.crimedad.work/post/903768
The author of the article characterizes their findings as a vulnerability in Pixelfed, that it was treating all follow requests as approved. An update has already been released to make Pixelfed honor that setting, but the vulnerability still exists with ActivityPub in the feature itself. It gives users a false expectation of privacy, which is not safe.
I didn’t even consider that, but yes if votes can’t be private then it’s bad to pretend that they are. It looks like there’s been some debate on the topic, but the decision was apparently to keep pretending.