Friday, November 29, 2024

Bluesky Has A Big Verification Problem

Bluesky
After the U.S. Presidential election that saw former President Donald Trump made a triumphant and convincing comeback, liberals are calling for a boycott of "X", a social media platform owned by Trump's friend Elon Musk. Their suggested alternative is Bluesky.

However, as the upstart social media service tries to accomodate new members, the platform is facing some growing pains. Among them: scammers and impersonators hoping to capitalize on the attention — and Bluesky’s lack of a conventional verification system.

A recent analysis by Alexios Mantzarlis, director of the Security Trust and Safety Initiative at Cornell Tech found that 44 percent of the top 100 most-followed accounts on Bluesky had at least one "doppelganger," with most looking like "cheap knock-offs of the bigger account, down to the same bio and profile picture," Mantzarlis wrote in his newsletter Faked Up.

Unlike many of its counterparts, which offer checkmarks and official badges to government officials, celebrities and other high profile accounts, Bluesky has a more hands-off approach to verification. Instead of proactively verifying notable accounts itself, the company encourages users to use a custom domain name as their handle in order to "self-verify."

For example, an employer of Engadget currently has the Bluesky handle engadget.bsky.social. But if he wanted to "verify" his account, hee could opt to change it to Engadget.com. Some media organizations, like The New York Times, Bloomberg and The Onion have done this for their official accounts. Individuals are also able to verify by using a personal website.

But, the process is more complicated than simply changing the handle. It also requires entities to add a string of text to the DNS record associated with their domain. While in some ways it’s a clever solution to verification — only the actual owner of a website would be able to access the DNS record for a domain — it also has a number of drawbacks. It’s a manual process that’s not readily accessible to everyone who might wish to be verified. (Bluesky does sell custom domains for users who don’t already have one.)

Verification is even more complex for those wishing to verify multiple accounts associated with the same domain, which may explain why some outlets, like The New York Times and NPR have custom handles, but don’t extend that verification to their reporters on Bluesky. Even Bluesky’s own tutorial suggests organizations seek assistance from their IT departments.

No comments:

Post a Comment