Has anybody thought about modelling #activitypub with a tool like https://alloytools.org/book.html
to find potential exploits? Thinking about the spec it’s missing any algorithms for authorization, but I already found a couple of edge-cases that make a server DoSssable or give an attacker the ability to spoof messages …
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.xyz/users/Profpatsch/statuses/116143306459283485 on your instance and quote it. (Note that quoting is not supported in Mastodon.)