![](https://lemmy.dbzer0.com/pictrs/image/1375069b-4764-4d51-9d2b-3686adeae6cf.png)
![](https://lemmy.ml/pictrs/image/st9xYggWap.png)
13·
2 months agoFrom the PR:
Note that this behaviour is configurable. It’s default is a 500 char limit because that is the Mastodon default.
That’s a shit default, and a shitty way to treat a standard that is meant for all sorts of communication. ActivityPub is not Twitter, and it is not just for short-form communication. In fact, a majority of the web is longer-form communication that isn’t a mere 500 characters long.
Retorting with “this behaviour is configurable” is dancing around the issue. Good, sane defaults mean everything in programming.
Right. This is just trading one set of security pitfalls with a second, much worse set of security pitfalls.