@kirby @dushman You'd think they'd have some way of verifying that the signature actually comes from the authorised party.
Like, say, having them post it from their fedi account. Set up a very simple AP server that just listens to /inbox or whatever it is, does a quick check about the sender's IP to verify cert or whatever, then just appends it to the list.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
zergling_man@pawoo.net's status on Wednesday, 27-Dec-2023 18:14:35 JSTZergling_man