4 ms·
Twitter doesn't take impersonation[0] too lightly. They review accounts that have been flagged as an impersonation account, but still you can create jokey accou
by ______- 5y ago
Twitter doesn't take impersonation[0] too lightly. They review accounts that have been flagged as an impersonation account, but still you can create jokey accounts, as per their clause:
> Twitter users are allowed to create parody, newsfeed, commentary, or fan accounts.
You have to have a disclaimer saying the account is a parody to avoid people thinking the account is the real person[1]
[0] https://help.twitter.com/en/rules-and-policies/twitter-impersonation-policy https://help.twitter.com/en/rules-and-policies/twitter-imper...
[1] https://help.twitter.com/en/rules-and-policies/parody-account-policy https://help.twitter.com/en/rules-and-policies/parody-accoun...
- lozenge 5y agoAre they going to do anything about verified accounts changing their names? https://www.theguardian.com/politics/2019/nov/20/twitter-accuses-tories-of-misleading-public-in-factcheck-row https://www.theguardian.com/politics/2019/nov/20/twitter-acc...
- zwily 5y agoThis seems like the biggest no-brainer to me. You should have to reverify after changing your account name.
- ______- 5y agoIt is common to see verified accounts using the name section as a tweet-compose function, often adding jokey phrases in there to confuse people. But yeah, this practice should not be allowed and should be a red flag behavior.
- jeffbee 5y agoI thought the GP meant scams perpetrated by the actual Elon Musk.
- input_sh 5y agoPretty sure they were talking about verified profiles being hacked, changing their display name and avatar to Musk's, and then replying to Musk's tweet something along the lines of "I'm giving away free crypto, click here". In my view, 2FA should be a requirement for verification.
- ______- 5y agoThere is hacked verified accounts too, but also people setting up jokey accounts without the parody disclaimer pretending to be Musk or other influential people, then asking to 'double your Bitcoin by sending coins here'.
- input_sh 5y agoThat blue checkmark is fairly unmissable. Handle is lower opacity when looking at a tweet. I have nothing to back it up, but having looked at a few cryotocurrency addresses that I've seen from breached accounts, I'm willing to claim it's far more effective to phish a blue checkmark and pretend to be Musk.
- testific8 5y ago2FA has historicially been broken because it is usually attached to a phone number, and phone service providers are suseptable to social engineering. What twitter (and other websites) should be using is PGP, where the user holds the secret key, and there are separate forms on messages to view PGP signatures, and forms on accounts to view their public keys.
- 35fbe7d3d5b9 5y agoPGP is possibly the only workflow worse than SMS based 2FA for humans.
- testific8 5y agoHow so?
- 35fbe7d3d5b9 5y agoI don't even know where to start: backwards compatibility to 90s era crypto, no forward secrecy, a web of trust model that encourages you to have a long-lived key – because with short-lived keys your trust has to be rebuilt after expiry, a cryptosystem that violently leaks metadata... PGP should've died years ago; there are far better options today.