Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
  • Procurement Managers
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data / Password Recovery
        • File Integrity Management
        • Data Loss Prevention
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Developer Tools
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Blog, Emsisoft Blog

What is Mastodon and is it secure? | Emsisoft

What is Mastodon and is it secure?

This article was originally published by LOGON’s partner Emsisoft. Click here to view the original article.

As Twitter continues through its late 2022 transformation, a social media network called Mastodon is in the news as a potential alternative. Like Twitter, Mastodon is a micro-blogging website. However, Mastodon operates very differently from Twitter, bringing with it different security considerations.

Due to the shakeup at Twitter, Mastodon is experiencing a surge in interest and explosive growth. In just a few days, Mastodon saw its active user count at least triple, a move that seems to be led by information technology (IT) professionals, such as systems administrators, programmers, and information security practitioners.

Search interest in Mastodon – Google Trends

Journalists followed, and Mastodon’s growth may be now self-sustaining, meaning that in early 2023 it may well have a large enough user base to be as relevant to organizations of all sizes as more traditional social media networks, such as Facebook, Twitter, Instagram, or TikTok. So how does it work?

 

What Mastodon is

Unlike traditional, corporation-run social media networks, Mastodon is a decentralized network of servers – or “instances” – run mainly by volunteers. An administrator runs each instance, and that administrator may decide to federate – a fancy way of saying “connect” – the example with some other cases or not, as they choose.

A single, non-federated Mastodon instance functions like a centralized social media network. If you want to message someone specifically, they also need to have an account on that Mastodon instance, and you cannot send a Direct Message to someone’s Account on another model. Like Facebook or Twitter, such a Mastodon instance stands alone. Counter. Social is an example of a Mastodon instance that has chosen this path, ultimately growing into its social network with its culture.

Decentralized-but-federated social media networks like Mastodon, however, are more like email. Anyone can stand up an instance using any domain name they choose. If the instance administrator decides to federate with the “Fediverse” (the largest network of federated cases), then messages, statuses, likes, follows, and other social media interactions can be exchanged between points.

The Fediverse is full of similar decentralized platforms, with Mastodon being just one software option out of several. There are options for everything from image and file hosting to podcasting, and even a decentralized Pastebin alternative, with most Fediverse applications using the ActivityPub to share messages across the Fediverse.

The Fediverse – and Mastodon, along with it – is a very 1990s view of the internet and how it should work. Everything is about democratizing access to the services we use every day, preventing any single centralized source from owning our data, or deciding whether or not we can use a given type of service.

 

What Mastodon isn’t

Mastodon is not a Twitter replacement. Perhaps the most significant source of confusion amongst “bird app refugees” (yes, that is what former Twitter users are called on Mastodon) is that Mastodon clients look very similar to Twitter clients. However, many of the underlying mechanics work differently. These differences have implications not only in how the applications are used but also in different security considerations.

The most significant difference between Mastodon and Twitter is that “the algorithm” doesn’t exist on Mastodon. Traditional centralized social media networks are profit-driven: the more you interact with the application, the more money they make. As a result, there is an algorithm somewhere that surfaces the posts of others based on your interests. This might seem relatively small, but its impact cannot be overstated.

Decades of research have shown that feeding news, hashtags, and posts that make people angry get more views, clicks, and posts. And since “engagement” drives profit, the easiest way for a profit-driven social media network to make money is to keep them angry and thus engaged. Mastodon is deliberately designed not to behave like this.

Consider, for example, the primary social media interaction of “favoriting” or “liking” a post. This action would “elevate” a position in a traditional social media network. The more likes it got, the more likely that post would be presented to someone by The Algorithm.

On Mastodon, favoriting a post doesn’t elevate it; only the original post author sees that you favorited it, and in most instances, the number of favorites isn’t even counted. “Favoriting” lets the poster know you liked their post.

If you want to elevate someone’s post on Mastodon, you can “boost” it; however, that will only reblog the post to your followers, helping them discover great content, but not otherwise elevating the original post or the original poster.

Similar design decisions were made about the Mastodon search capabilities. The primary use for the search box is to find individuals so that you can follow them. You put in their mastodon handle and instance – for example, @[email protected] – and this allows you to find and follow accounts located on your model, as well as on any instance your instance is federated with.

The search box can also be used to search for hashtags, but it cannot be used to search for text inside an individual post. This limits the utility of Mastodon for data mining while also making it harder for journalists and trolls alike to find specific posts or posts that don’t use a hashtag.

 

Is Mastodon secure?

All of these differences have an impact on Mastodon’s security. In addition to the differences in the code bases of the applications, the design decisions underlying how these applications were designed in the first place to result in different attack surfaces and thus present a different risk profile to users.

So what does the security posture of Mastodon look like? The answer is “a lot like the decentralized social media platforms of the 80s and 90s”, with all the same attendant threats, advantages, and considerations. Whereas Facebook and Twitter have a risk profile that resembles a single gigantic online forum grown massively out of control, your mental threat model of Mastodon should be closer to email, Internet Relay Chat (IRC), or if you’re old enough to remember, interconnected Bulletin Board Systems (BBSes).

 

All social media has risks.

Regardless of which social media platform you use, the most significant risk you are likely to face is account takeover: someone might figure out how to log in to your Account, read all your Direct Messages (DMs), and maybe even impersonate you. As a result, security and privacy controls tend to be far more critical for mitigating your risk than worrying about any vulnerabilities in the underlying code of the platform.

Enabling two-factor authentication for all your social media accounts will elevate your security posture more than literally anything else you can do. Similarly, taking advantage of advanced posting restrictions (such as making sure posts are “friends only”) can make it harder for malicious individuals to seek you out as a potential target while still allowing you to interact with your friends on that platform.

Impersonation is probably the second biggest threat on social media. Grifters and con artists are constantly looking for any way to get victims to trust them. The ability to impersonate friends, co-workers and even celebrities has proven an effective means of attack.

Traditional social media platforms put effort into mitigating this with account verification, such as the old “Blue Tick” system that Twitter used to have, but no such system exists on Mastodon.

All social media platforms are also vulnerable to attacks from client software. Sometimes, the only clients you can use to interact with the forum are written and controlled by the company that runs the platform (TikTok is an example). In contrast, third-party clients exist for other platforms, which can give you a radically different user experience (Twitter and Mastodon are examples here). Software vulnerabilities may exist in social media client software that exposes your data, either to the client software developer or third parties.

The other primary security consideration that all social media platforms share is “who can read your supposedly private DMs.” Whoever runs the platform can do anything they want with your data on all platforms. Each forum has different controls and rules, but this is a universal vulnerability. Twitter, for example, is rumored to have had up to half the staff access to anyone’s DMs. Facebook also has a broad attack surface regarding who can read your DMs.

 

Mastodon security considerations

Decentralized social media platforms such as Mastodon have multiple instances, each with one or more administrators. The administrator of your model can read any DMs on their example. If you DM someone across instances, then the administrator of both cases can read those DMs. If this bothers you, you can stand up your own Mastodon instance, giving you complete control over DMs within that instance. This is the same threat model as email, IRC, BBSes, and other decentralized communications.

Additionally, “DMs” on Mastodon aren’t really “DMs” in the same way they are on other platforms and should be considered more vulnerable. DMs are just posts whose visibility is restricted to the people mentioned in the post, meaning that if you say somebody in a position, that particular post becomes visible to them.

Mastodon also tends to have many more clients to choose from than the centralized social media platforms. Each client will have a different set of bugs and a different set of vulnerabilities. While many social media platforms have third-party clients, the clients for Mastodon tend to be open source, with little or no commercial backing. This means you can generally alter them if you want, but there’s nobody to sue if the client compromises your data. 

As an emerging platform developed and administered by volunteers, several privacy risks have been identified with Mastodon and code bugs that contain serious vulnerabilities. Unlike vulnerabilities due to design choices, code bugs and most privacy issues will eventually be sorted as the Mastodon platform matures.

Another difference in the risk posture of Mastodon versus other platforms is stability. Individual Mastodon instances aren’t designed to handle millions of users, and the forum is intended to have thousands of models to distribute the load. Choosing to join more minor instances helps keep the network more stable. Still, it can mean that you aren’t as familiar with your instance administrator’s track record about privacy as you might be on the more populous instances.

Traditional, centralized social media platforms are designed for massive scale, making them stable even with millions (or billions!) of users. They often employ chaos engineers who attack the system from the inside to ensure it is resilient against multiple failures.

Centralized social media platforms, however, tend to be vulnerable to malicious attacks by the administrator (or CEO), something Mastodon is explicitly designed to be resilient against. If an administrator goes rogue, their instance can be “defeated” by the rest of the Mastodon network, constraining the damage they can cause to their model.

 

How to minimize your risk

Since the most significant concern you’ll face on any social media network is account takeover, the best thing you can do to protect your data is to enable 2-factor authentication (2FA) or multi-factor authentication (MFA). In Mastodon, this can be found under Account> Two-factor Auth.

You can also participate in Mastodon’s development by directly contributing code or simply participating in the conversation. For example, at the time of writing, there is a lively technical discussion on simplifying cross-instance following. The choices made here have the potential to have far-reaching security implications for all users of Fediverse Mastodon instances.

Unlike centralized social media, anyone and everyone can be part of developing – and securing – Mastodon.

Choosing your instance – and thus the individual(s) that act as administrator – is very important, though this is true of both centralized and decentralized social media platforms. Whether Mastodon or a more traditional social media platform, you need to care a great deal about who is in charge.

Lastly, you can help minimize your risk by following information security professionals on Mastodon to stay updated with information security news! A significant portion of the Information Security community from Twitter has joined Infosec. Exchange or Defcon.social Mastodon instances. Emsisoft can be found on the Fediverse at @[email protected], but we’re not very active yet.


Cybersecurity Engineered for Humans

Emsisoft brings the human experience back into the spotlight by providing smart virus and malware protection with personalized service and expert support.

Solution Highlight

Emsisoft Anti-Malware Free Trial

Get your free trial today with the Antivirus software from the world’s leading ransomware experts.

Start Your Free Trial
Contact Us Today

FOLLOW US ON

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter
  • YouTube
Read Next:
Application Security BlogArtificial IntelligenceBlogLOGON Blog
AI-Augmented Penetration Testing: Meeting the Scale Challenge
Application Security BlogArtificial IntelligenceBlogIT Management BlogLOGON Blog
The First Autonomous AI Cyber Attack is Here: Is Your Enterprise Ready?
Application Security BlogBlogLOGON Blog
Shift Left, Verify Right: The Blueprint for Modern Application Security Across Asia

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...

Fill in the form below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Watch On-demand Webinar

  • This field is for validation purposes and should be left unchanged.

Get Your Free UserLock Trial

  • This field is for validation purposes and should be left unchanged.

Download Your Free Trial 10-Day Trial Today

  • Downloading and evaluating Smart Package Studio is quick and easy
  • Includes a short introductory guide that suggests smart features to try
  • Access the full functionality of Smart Package Studio during the trial
  • This field is for validation purposes and should be left unchanged.

Request for Priority Support with our support team

  • This field is for validation purposes and should be left unchanged.
  • Drop files here or
    Max. file size: 30 MB.

    Get Free Assessment of your Web Asset

    Request a free non-intrusive security assessment of your website. Get a report with an overview of client-side security risks.

    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form

    Recommend a Topic

    • This field is for validation purposes and should be left unchanged.

    Partner with Us on the next episode

    • This field is for validation purposes and should be left unchanged.

    Watch On-demand Webinar

    • This field is for validation purposes and should be left unchanged.
    Start PreCrime Network for Free

    Oops! We could not locate your form.

    Book a Free Demo Today

    Get Your Free Trial

    Oops! We could not locate your form.

    Get Your Free Trial
    • This field is for validation purposes and should be left unchanged.
    • This field is hidden when viewing the form
    • This field is hidden when viewing the form
    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote

    Oops! We could not locate your form.

    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form
    Request for Training Quote
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • DD slash MM slash YYYY
    Request for Training Quote
    • This field is for validation purposes and should be left unchanged.
    • Please enter a number from 1 to 20.
    • This field is hidden when viewing the form