> It won't take much effort for someone to write a payload running on random compromised webservers
@monsieuricon that's not true because generally servers don't accept incoming payloads if they don't have a valid HTTP Signature.
So a random compromised machine also needs access to a random compromised fediverse actor (in order to have access to its private key) so it can generate a valid signature/digest.
It's not much harder, but still.