I mean, pretending to be someone in another instance, “stealing” the username, is trivial. I see the more likely targets being instance admins or high profile users. Should we worry somewhat about this?

  • PonyOfWar
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 year ago

    To an extent that’s true, but the standard web UI has this issue. It should not be like this in the standard configuration.

    • sim642@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      It’s open source so just open an issue about it if there already isn’t one.