nearly 2 years ago, my chrome got hacked. (I don't use chrome any more don't worry)
All my accounts were compromised.
my mastodon account got used by someone in dallas, texas, usa; obviously not me since i'm in da nang, viet nam
anyway, my account was protected totp 2fa yet they still got in
after trying and failing to get back in, and filing at least 2 appeals, the mastodon team have "reviewed" my appeal and rejected it. based on what, i wonder? despite the amount of time it took to respond to me, this reeks of ai-management and is very clear that a human wasn't involved in this decision.
anyway, tl;dr:
mastodon accounts can apparently be accessed using session tokens even when you have 2fa/totp set up AND the staff/system will ban your account even after you regain control 🤷

