you are viewing a single comment's thread
view the rest of the comments
[+] 1 point 1 year ago* (last edited 6 months ago) (1 child)
  • [–] 3 points 1 year ago (2 children)

    I do not, ActivityPub uses HTTP signatures to make sure messages and requests from other servers are legit,

    Essentially, it adds a "signature" header which contains a link to a users public key, a list of headers in the message and a signed hash of all the headers and the request.

    There's a better explaination here: https://docs.joinmastodon.org/spec/security/

    A delicated bot to scrape ActivityPub posts is possible, but generic bots shouldn't work. If a delicated bot is made, people can block its keys or server anyway.

  • source
  • parent
  • hideshow 4 child comments