Additional attack on accounts via functionality of QR scan to login: Upon joining a guild/community, phony "CAPTCHA bot" prompts to confirm you as human by providing a QR box to scan with app, which allows taking your account.

Only scan QR box for login from login prompt at, not on a diff. location or from a bot or unofficial account.

Mastodon is a "FOSS" social sharing hub. A multi-host substitution for capitalistic platforms, it avoids risking a particular company monopolizing your communication. Pick a host that you trust — you can still talk with all hosts running Mastadon. Any individual can run a Mastodon instantiation and join in this social hub in a jiffy.