really... surprised it got submitted here
incidentally i'm running pleroma, not mastodon. minor detail but you know
it's right at the end of the article - the attacker was abusing the "create a preview card of any posted URL" feature - he'd post a link, wait for pleroma to go and grab the url to preview it, then narrow down which one was mine based on user agent
i added an upstream proxy and anonymised the user agent, so even if he were to do that, the most he'd find was my proxy box
I also pull-requested a user agent anonymisation setting (pleroma.http.user_agent) to make this better