hachyderm.io is one of the many independent Mastodon servers you can use to participate in the fediverse.
Hachyderm is a safe space, LGBTQIA+ and BLM, primarily comprised of tech industry professionals world wide. Note that many non-user account types have restrictions - please see our About page.

Administered by:

Server stats:

8.9K
active users

Adrianna Pińska

I periodically revisit alternative web clients for Mastodon, to see if anyone is doing anything more interesting than just squirting your timeline at you as-is.

I just found Phanpy (phanpy.social), which I really like. It visually distinguishes boosts and threads, and expands posts without leaving the timeline (such a low bar!). It also has a really nice modern stylesheet. I'm going to try using it exclusively for a while. :blobfoxhyper2:

phanpy.socialPhanpyMinimalistic opinionated Mastodon web client

@confluency Trying it out after your reco and looks really nice!

@confluency
POTENTIAL #SECURITY THREAT: The above website, #phanpyDotSocial is #CloudGlare and may be a #socialEngineering attack on #fediverse users to open them up to #accountTakeover.

If the above website asks one to login to ones #mastodon instance with their password then its a CloudGlare #phishing website/#honeypot.

We will not access on ethical grounds.

Tagging some boosters to warn them @njoseph @kkremitzki @michelin

@dsfgs @njoseph @kkremitzki @michelin Can you elaborate on what you think the threat model is? What is "CloudGlare"? Is this a typo, or a specific security criticism of CloudFlare?

The site does *not* prompt for a password; it uses the same app authorization mechanism as other client apps.

It's listed as an alternative client on the official Mastodon website: joinmastodon.org/apps If you believe that it's insecure, you should report an issue in the website repository: github.com/mastodon/joinmastod

joinmastodon.orgGet an app for MastodonBrowse official and third-party apps for the decentralized social network Mastodon

Thanks @confluency for info that it uses tokens. Has issues, though fewer. One still must trust the third-party won't engage in account takeover actions or network level #tracking/telemetry.

According to a popular #adblocker it does fatech bad cloud(G)lare #telemetry js.

Horrified M'don would endorse untrustable third-parties, but unsurprised.

(our instance deletes external toots after a while, for reference is response to hachyderm.io/@confluency/11097) @njoseph @kkremitzki @michelin