Mastodon 4.6 Introduces Profile Collections and Two-Factor Security Controls
Mastodon 4.6 introduces profile Collections and enhanced two-factor authentication options, focusing on user organization, security, and accessibility improvements.
Mastodon 4.6 Overview
Mastodon 4.6 introduces profile Collections and enhanced two-factor authentication options. The latest version focuses on a feature named Collections, which allows users to organize and share curated lists of profiles, alongside updates to server management tools, profile customization, and accessibility improvements.
Profile Collections
Server administrators now have the ability to enforce two-factor authentication for user accounts. This feature is being implemented across multiple domains managed by a server operator, including infosec.exchange, infosec.space, ioc.exchange, and convo.casa. The implementation follows a notification process informing users of the upcoming requirement.
How Collections Work
Collections enable users to create and distribute lists of profiles via shared links, integrating with Mastodon and external platforms. Each collection is limited to 25 profiles to prevent spam and ensure manageable content. Users must opt into discovery preferences to be included in collections, and they receive notifications when added. Removal from a collection is possible at any time.
Collection Updates
Updates to collection titles or descriptions trigger alerts to all listed profiles. While discovery of collections currently relies on manual methods, future updates aim to introduce browsing and recommendation systems.
Server Management and Security
Server operators can activate subscription-based newsletter features, enabling anonymous visitors to follow user posts. This functionality requires administrative permissions and is disabled by default due to potential server load impacts.
Profile Customization and Accessibility
Profile redesigns prioritize user preferences based on community feedback, allowing viewers to customize how content is displayed, such as viewing original posts exclusively or including boosts and replies. Featured hashtags are now more prominently displayed, and profile editing is integrated directly into the profile interface.
Accessibility Improvements
Accessibility improvements include support for alt text on profile media, benefiting visually impaired users. Additional controls let users manage tab visibility, such as hiding the Media tab or configuring its content to function as a portfolio.
Landing Page and Server Tools
A new landing page design targets institutional servers, emphasizing simplified navigation and localized content highlights. The release also includes updates to server administration tools and accessibility enhancements.
No Security Incident Details
No details about specific threat actors or security incidents are included in this update.
According to the release notes, the two-factor authentication enforcement follows a notification process to inform users of the upcoming requirement.
- infosec.exchange
- infosec.space
- ioc.exchange
- convo.casa
