Has anybody thought about modelling #activitypub with a tool like https://alloytools.org/book.html
to find potential exploits? Thinking about the spec it’s missing any algorithms for authorization, but I already found a couple of edge-cases that make a server DoSssable or give an attacker the ability to spoof messages …
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Beady Belle Fanchannel (profpatsch@mastodon.xyz)'s status on Saturday, 28-Feb-2026 12:57:59 JST
Beady Belle Fanchannel