Em :official_verified:<p>Tiny Mastodon AND Privacy Tips :mastodon: 🔒:</p><p>Depending on your situation, <br>you might want to increase your privacy and security levels on Mastodon. </p><p>Here are a few easy things <br>you can do for this. Pick and choose what works best for you (instructions are from a browser's web interface):</p><p>Enable 2FA ✌️</p><p>Why? Reduces account takeover </p><p>How? Go to Preferences > Account > Two-factor Auth. Pick a method here and make sure to carefully note and safely store your "Backup recovery codes."</p><p>Activate Auto-Delete :nes_fire: </p><p>Why? Reduces unwanted parties collecting your data overtime</p><p>How? Go to Preferences > Automated post deletion. Select "Age threshold" and "Exceptions" based on your preferences.</p><p>Default to Private 🚪 </p><p>Why? If you post on more sensitive/personal topics, you might want to limit visibility to your followers only. Know that your posts will not be "boostable," however. You can change this per post as well.</p><p>How? Go to Preferences > Preferences > Other. In "Posting Defaults" you can adjust the "Posting privacy" to "Followers-only".</p><p>Approve Followers ✅ </p><p>Why? If you want to limit who can see your Followers-only posts, you might want to restrict who can follow you.</p><p>How? Go to Preferences > Public profile > Privacy and reach. In "Reach", uncheck "Automatically accept new followers". You will have to approve each new follower manually.</p><p>Block Corporate Media ⛔ </p><p>Why? If you post about sensitive topics, you might want to reduce visibility from larger corporate media such as Meta's Threads, who might use your information in different ways.</p><p>How? Follow these instructions: <a href="https://mastodon.moule.world/@MOULE/110586343942660169" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mastodon.moule.world/@MOULE/11</span><span class="invisible">0586343942660169</span></a></p><p>Cautiously Use Direct Messages 🤐 </p><p>Why? Direct Messages (Specific People messages), are not end-to-end encrypted on Mastodon. This means your instance's administrator(s) could technically read your messages, now or later on. </p><p>How? For any sensitive discussion, you should transfer to a trustworthy end-to-end encrypted (E2EE) application. For example, share your Signal's username, Matrix's handle, or throwaway E2EE email address in DM to continue the conversation there.</p><p>Verify External Accesses 👀</p><p>Why? Verify the apps that have access to your Mastodon account are the ones that you want. In case of doubt, ask your instance's administrator.</p><p>How? Go to Preferences > Account > Authorized apps. Make sure every app there is something that you use or that your Mastodon instance's administrator uses.</p><p>Stay safe my friends! 🔒💚</p><p><a href="https://infosec.exchange/tags/TinyMastodonTip" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TinyMastodonTip</span></a> <a href="https://infosec.exchange/tags/TinyPrivacyTip" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TinyPrivacyTip</span></a> <a href="https://infosec.exchange/tags/Mastodon" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Mastodon</span></a> <a href="https://infosec.exchange/tags/Fediverse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fediverse</span></a> <a href="https://infosec.exchange/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a></p>