Blog, Emsisoft Blog
What is Mastodon and is it secure? | Emsisoft
As Twitter continues through its late 2022 transformation, a social media network called Mastodon is in the news as a potential alternative. Like Twitter, Mastodon is a micro-blogging website. However, Mastodon operates very differently from Twitter, bringing with it different security considerations.
Due to the shakeup at Twitter, Mastodon is experiencing a surge in interest and explosive growth. In just a few days, Mastodon saw its active user count at least triple, a move that seems to be led by information technology (IT) professionals, such as systems administrators, programmers, and information security practitioners.

Search interest in Mastodon – Google Trends
Journalists followed, and Mastodon’s growth may be now self-sustaining, meaning that in early 2023 it may well have a large enough user base to be as relevant to organizations of all sizes as more traditional social media networks, such as Facebook, Twitter, Instagram, or TikTok. So how does it work?
What Mastodon is
Unlike traditional, corporation-run social media networks, Mastodon is a decentralized network of servers – or “instances” – run mainly by volunteers. An administrator runs each instance, and that administrator may decide to federate – a fancy way of saying “connect” – the example with some other cases or not, as they choose.
A single, non-federated Mastodon instance functions like a centralized social media network. If you want to message someone specifically, they also need to have an account on that Mastodon instance, and you cannot send a Direct Message to someone’s Account on another model. Like Facebook or Twitter, such a Mastodon instance stands alone. Counter. Social is an example of a Mastodon instance that has chosen this path, ultimately growing into its social network with its culture.
Decentralized-but-federated social media networks like Mastodon, however, are more like email. Anyone can stand up an instance using any domain name they choose. If the instance administrator decides to federate with the “Fediverse” (the largest network of federated cases), then messages, statuses, likes, follows, and other social media interactions can be exchanged between points.
The Fediverse is full of similar decentralized platforms, with Mastodon being just one software option out of several. There are options for everything from image and file hosting to podcasting, and even a decentralized Pastebin alternative, with most Fediverse applications using the ActivityPub to share messages across the Fediverse.
The Fediverse – and Mastodon, along with it – is a very 1990s view of the internet and how it should work. Everything is about democratizing access to the services we use every day, preventing any single centralized source from owning our data, or deciding whether or not we can use a given type of service.
What Mastodon isn’t
Mastodon is not a Twitter replacement. Perhaps the most significant source of confusion amongst “bird app refugees” (yes, that is what former Twitter users are called on Mastodon) is that Mastodon clients look very similar to Twitter clients. However, many of the underlying mechanics work differently. These differences have implications not only in how the applications are used but also in different security considerations.
The most significant difference between Mastodon and Twitter is that “the algorithm” doesn’t exist on Mastodon. Traditional centralized social media networks are profit-driven: the more you interact with the application, the more money they make. As a result, there is an algorithm somewhere that surfaces the posts of others based on your interests. This might seem relatively small, but its impact cannot be overstated.
Decades of research have shown that feeding news, hashtags, and posts that make people angry get more views, clicks, and posts. And since “engagement” drives profit, the easiest way for a profit-driven social media network to make money is to keep them angry and thus engaged. Mastodon is deliberately designed not to behave like this.
Consider, for example, the primary social media interaction of “favoriting” or “liking” a post. This action would “elevate” a position in a traditional social media network. The more likes it got, the more likely that post would be presented to someone by The Algorithm.
On Mastodon, favoriting a post doesn’t elevate it; only the original post author sees that you favorited it, and in most instances, the number of favorites isn’t even counted. “Favoriting” lets the poster know you liked their post.
If you want to elevate someone’s post on Mastodon, you can “boost” it; however, that will only reblog the post to your followers, helping them discover great content, but not otherwise elevating the original post or the original poster.
Similar design decisions were made about the Mastodon search capabilities. The primary use for the search box is to find individuals so that you can follow them. You put in their mastodon handle and instance – for example, @[email protected] – and this allows you to find and follow accounts located on your model, as well as on any instance your instance is federated with.
The search box can also be used to search for hashtags, but it cannot be used to search for text inside an individual post. This limits the utility of Mastodon for data mining while also making it harder for journalists and trolls alike to find specific posts or posts that don’t use a hashtag.
Is Mastodon secure?
All of these differences have an impact on Mastodon’s security. In addition to the differences in the code bases of the applications, the design decisions underlying how these applications were designed in the first place to result in different attack surfaces and thus present a different risk profile to users.
So what does the security posture of Mastodon look like? The answer is “a lot like the decentralized social media platforms of the 80s and 90s”, with all the same attendant threats, advantages, and considerations. Whereas Facebook and Twitter have a risk profile that resembles a single gigantic online forum grown massively out of control, your mental threat model of Mastodon should be closer to email, Internet Relay Chat (IRC), or if you’re old enough to remember, interconnected Bulletin Board Systems (BBSes).
All social media has risks.
Regardless of which social media platform you use, the most significant risk you are likely to face is account takeover: someone might figure out how to log in to your Account, read all your Direct Messages (DMs), and maybe even impersonate you. As a result, security and privacy controls tend to be far more critical for mitigating your risk than worrying about any vulnerabilities in the underlying code of the platform.
Enabling two-factor authentication for all your social media accounts will elevate your security posture more than literally anything else you can do. Similarly, taking advantage of advanced posting restrictions (such as making sure posts are “friends only”) can make it harder for malicious individuals to seek you out as a potential target while still allowing you to interact with your friends on that platform.
Impersonation is probably the second biggest threat on social media. Grifters and con artists are constantly looking for any way to get victims to trust them. The ability to impersonate friends, co-workers and even celebrities has proven an effective means of attack.
Traditional social media platforms put effort into mitigating this with account verification, such as the old “Blue Tick” system that Twitter used to have, but no such system exists on Mastodon.
All social media platforms are also vulnerable to attacks from client software. Sometimes, the only clients you can use to interact with the forum are written and controlled by the company that runs the platform (TikTok is an example). In contrast, third-party clients exist for other platforms, which can give you a radically different user experience (Twitter and Mastodon are examples here). Software vulnerabilities may exist in social media client software that exposes your data, either to the client software developer or third parties.
The other primary security consideration that all social media platforms share is “who can read your supposedly private DMs.” Whoever runs the platform can do anything they want with your data on all platforms. Each forum has different controls and rules, but this is a universal vulnerability. Twitter, for example, is rumored to have had up to half the staff access to anyone’s DMs. Facebook also has a broad attack surface regarding who can read your DMs.
Mastodon security considerations
Decentralized social media platforms such as Mastodon have multiple instances, each with one or more administrators. The administrator of your model can read any DMs on their example. If you DM someone across instances, then the administrator of both cases can read those DMs. If this bothers you, you can stand up your own Mastodon instance, giving you complete control over DMs within that instance. This is the same threat model as email, IRC, BBSes, and other decentralized communications.
Additionally, “DMs” on Mastodon aren’t really “DMs” in the same way they are on other platforms and should be considered more vulnerable. DMs are just posts whose visibility is restricted to the people mentioned in the post, meaning that if you say somebody in a position, that particular post becomes visible to them.
Mastodon also tends to have many more clients to choose from than the centralized social media platforms. Each client will have a different set of bugs and a different set of vulnerabilities. While many social media platforms have third-party clients, the clients for Mastodon tend to be open source, with little or no commercial backing. This means you can generally alter them if you want, but there’s nobody to sue if the client compromises your data.
As an emerging platform developed and administered by volunteers, several privacy risks have been identified with Mastodon and code bugs that contain serious vulnerabilities. Unlike vulnerabilities due to design choices, code bugs and most privacy issues will eventually be sorted as the Mastodon platform matures.
Another difference in the risk posture of Mastodon versus other platforms is stability. Individual Mastodon instances aren’t designed to handle millions of users, and the forum is intended to have thousands of models to distribute the load. Choosing to join more minor instances helps keep the network more stable. Still, it can mean that you aren’t as familiar with your instance administrator’s track record about privacy as you might be on the more populous instances.
Traditional, centralized social media platforms are designed for massive scale, making them stable even with millions (or billions!) of users. They often employ chaos engineers who attack the system from the inside to ensure it is resilient against multiple failures.
Centralized social media platforms, however, tend to be vulnerable to malicious attacks by the administrator (or CEO), something Mastodon is explicitly designed to be resilient against. If an administrator goes rogue, their instance can be “defeated” by the rest of the Mastodon network, constraining the damage they can cause to their model.
How to minimize your risk
Since the most significant concern you’ll face on any social media network is account takeover, the best thing you can do to protect your data is to enable 2-factor authentication (2FA) or multi-factor authentication (MFA). In Mastodon, this can be found under Account> Two-factor Auth.
You can also participate in Mastodon’s development by directly contributing code or simply participating in the conversation. For example, at the time of writing, there is a lively technical discussion on simplifying cross-instance following. The choices made here have the potential to have far-reaching security implications for all users of Fediverse Mastodon instances.
Unlike centralized social media, anyone and everyone can be part of developing – and securing – Mastodon.
Choosing your instance – and thus the individual(s) that act as administrator – is very important, though this is true of both centralized and decentralized social media platforms. Whether Mastodon or a more traditional social media platform, you need to care a great deal about who is in charge.
Lastly, you can help minimize your risk by following information security professionals on Mastodon to stay updated with information security news! A significant portion of the Information Security community from Twitter has joined Infosec. Exchange or Defcon.social Mastodon instances. Emsisoft can be found on the Fediverse at @[email protected], but we’re not very active yet.


Cybersecurity Engineered for Humans
Emsisoft brings the human experience back into the spotlight by providing smart virus and malware protection with personalized service and expert support.
Emsisoft Anti-Malware Free Trial
Get your free trial today with the Antivirus software from the world’s leading ransomware experts.



