I really like the green checkmark system in Mastodon, but when relying on them for trust it's important to keep in mind *what* you are trusting:
* The security of the remote site (hacked site could vouch for an attacker)
* The security of the Mastodon instance (same)
* The integrity of the Mastodon instance (a modified version could let the owner disable the remote check)
This is one reason why I like self-owned instances on the account owner's domain.
#security #trust #GreenCheckmark
@tivasyk For any proprietary software or network: you must anchor your trust in that organization and its employees and you are dependent upon their ability to secure their property.