@vyr they also have some icky growth/marketing based AI project https://equelsocial.com/story
so they might be ingesting federated content to feed their beast
@vyr agreed, but those don't protect against bad-actor servers at all.. we need better ways to limit federation for that
@f0x 100% we also need greylist federation
@f0x for those playing at home, this is the latest greylist bug tracker entry https://github.com/mastodon/mastodon/issues/21536 and i've added my own commentary speculating on what we'd need to actually implement this
@vyr nice, we're also compiling research on it for GoToSocial, and it's on our (funded) roadmap to work on.
As a stop-gap solution for the Mastodon 4.x public api shit I'm working on [FediFox Shield](https://git.pixie.town/f0x/fedifox-shield)
@f0x ah, one more reason why AUTHORIZED_FETCH and DISALLOW_UNAUTHENTICATED_API_ACCESS need to be on by default