I just went around and did some basic nmap-ing on the most popular Mastodon instances, and there's some seriously sketchy stuff in there. Publicly reachable Postgres servers, tons of open internal HTTP ports, SSH with password login, multiple Mastodon instances that seem to be running on mail server VMs, …
I guess if you're just running a single-user instance for yourself, sure, but those are all 2000+ user instances.
So has anyone here tried the various Android clients and can recommend? #LazyToot
Fixing science with the Web — Former @w3c — Web, Science, Politics, Philosophy, roguish good looks. (he/him)
Server run by the main developers of the project It is not focused on any particular niche interest - everyone is welcome as long as you follow our code of conduct!