2016-06-29 UTC
# aaronpk yes, the security consideration starts out with "It is possible for an attacker to advertise a Webmention endpoint that points to an arbitrary URL." which is still true. but that case will only be hit if the attacker causes you to actually post a link to their site in your own post. so it's more like a targeted phishing attack in that sense.