15 ms·
A new form of verification on Bluesky
- deleted 1y ago[deleted]
- greyface- 1y ago> Bluesky’s moderation team reviews each verification to ensure authenticity. How is this compatible with Bluesky's internal cultural vision of "The company is a future adversary"[1][2][3]? With Twitter, we've seen what happens with the bluecheck feature when there's a corporate power struggle. [1]: https://news.ycombinator.com/item?id=35012757 https://news.ycombinator.com/item?id=35012757 [2]: https://bsky.app/profile/pfrazee.com/post/3jypidwokmu2m https://bsky.app/profile/pfrazee.com/post/3jypidwokmu2m [3]: https://www.newyorker.com/magazine/2025/04/14/blueskys-quest-to-build-nontoxic-social-media https://www.newyorker.com/magazine/2025/04/14/blueskys-quest...
- hombre_fatal 1y agoI don't see how it's incompatible. The problem with Twitter (before the whole blue check system was gutted into meaninglessness) was that not enough verification badges were handed out. It's not exactly a dangerous situation. Bluesky's idea of verified orgs granting verification badges to its own org members would be an example of a much more robust and hands off system than what Twitter had. The dangerous scenario is what happened to Twitter after the Elon takeover: verification becomes meaningless overnight while users still give the same gravity to verification badges which causes a huge impersonation problem. But that possibility is not a reason to have zero verification.
- righthand 1y agoWhat’s stopping me from making an org that hands out verifications to anyone?
- d4mi3n 1y agoPresumably a contractual agreement with BlueSky. Trust needs to stem from somewhere, so you’re either looking at a web-of-trust model where somebody (BlueSky or BlueSky clients) makes decisions on what sign-offs to trust, or you trust BlueSky to perform due diligence on partner orgs that provide this service and to hold them accountable when that trust is breached. The WoT model works but as GPG has shown it requires your end users (people? BlueSky client developers?) to manage who they trust as an authority on anything.
- godelski 1y agoYour profile says you're a security engineer, so I'm hoping you can help me understand. What was the problem with the current DNS system? I definitely think there could be improvements like displaying domain instead of TLD but still. And why not move into a system like multiparty keys? Keys assigned by domain holder, need to be signed, and verified accounts must login with a private key that validates. That way you don't just get that the account is validated but the post is too. Yeah, this would require more technical expertise to do but the organizations we're usually most concerned about would have no problem with that. Besides, tooling gets easier when there's meaningful pushes to make it available to general audiences
- verdverm 1y agoThere was once Handshake, but they failed mainly because they didn't want to work along side the current system, they wanted to replace it completely with a blockchain. It's actually one of the good use case IMHO, but their leadership didn't want to play nice with what we already have so transition could happen smoothly
- d4mi3n 1y agoWhat is appropriate here really depends on what properties BlueSky wants to assert about it's ecosystem. > What was the problem with the current DNS system? I definitely think there could be improvements like displaying domain instead of TLD but still. As commenters earlier in this thread have noted, one property BlueSky claims it wants to develop/maintain is resistance against BlueSky itself becoming an adversarial party--say in the event it is bought out by an eccentric multi-billionaire who may take steps to discredit certain parties or reduce their reach or reputation. I don't think the current DNS verification methodology helps or hurts in a BlueSky is hostile scenario. I think the only issues with the current DNS username verification system as I understand it are the same issues with any DNS based verification system in that vanilla DNS was not a protocol designed to be resistant to adversarial use and as a result there are many ways for people to tamper with DNS records, DNS queries, and confuse systems that incorrectly trust DNS records to be trustworthy or well-formed. DNS cache poisoning is a thing. Domain takeovers have and will continue to happen. Now, if we're talking about what technologies are suitable for username verification in a word where BlueSky is adversarial, we have a very different conversation. I think the scope of such a scenario extends a lot further than usernames. If your primary interface into the AT Protocol feed is the BlueSky website or the official BlueSky application, you are trusting BlueSky to validate usernames. An adversarial BlueSky could easily decide if your interface marks someone as trusted or untrusted without your knowledge. The only way I could think to avoid this would be to use a different interface to the global feed, but then you run into new problems that are more difficult to avoid: the fact that most BlueSky users don't host their own data (though this is doable with https://atproto.com/guides/self-hosting https://atproto.com/guides/self-hosting). BlueSky also manages the global feed, so barring a competitive global index, you'll still be consuming a feed curated by BlueSky's AT Protocol services and implementation. I'd close this by saying I am _not_ an expert in the AT Protocol, BlueSky's systems, or this space in general. This is a very fast and loose risk assessment I made after reviewing the AT Protocol and a bit of research on how BlueSky says it provides it's services. My current assessment is that if the community wants to be robust against BlueSky becoming adversarial, there needs to be a lot more support for self-hosting of PSPs and similar data stores, alternative global indexes, and likely also independent governance of the AT Protocol itself.
- TiredOfLife 1y agoThe problem with Twitter (before the whole blue check system was gutted into meaninglessness) was that verification badges were merit and nepotism and not identity based
- mattl 1y agoThat’s not true though. They were for journalists and public figures.
- comeonbro 1y agoHere is probably the most well-known instance of Pre-Musk Twitter removing blue checks from the accounts of public figures for reasons other than the account not being who it claims to be: https://techcrunch.com/2017/11/15/twitter-removes-verified-checkmarks-from-several-white-supremacists-profiles/ https://techcrunch.com/2017/11/15/twitter-removes-verified-c... Not pictured: innumerable other accounts which were never granted a blue check in the first place, despite being the easily verifiable real accounts of journalists and public figures. It was de facto a caste system of political favor and connections.
- deleted 1y ago[deleted]
- dijit 1y agoNearly everyone I interacted with on Twitter (pre-Musk) got their verification badge by essentially being in the San Francisco tech community. No matter how prominent someone might be on this side of the Atlantic, it never mattered, meanwhile mid-managers and coders at no-name startups had blue checks because, I mean, they knew someone at Twitter- and who else is verifying people? I don’t really fault them for verifying people they personally knew. But it meant that you had a situation where (and no offence meant to them) “nobodies” (as in, non-promenant figures) were “in the club” with heads of state, companies and heads of industry. So there was a definite whiff of nepotism, because it was a de-facto status symbol.
- fortran77 1y agoThe problem I had with twitter was the check was supposed to mean one thing and one thing only: that the person was who he or she claimed to be. What twitter starting doing was removing blue checks from people who were causing problems for the platform (but not behaving bad enough to kick off). This made no sense because people still needed to know if a person was who he claimed to be (e.g., Milo Yiannopoulos) even if the person was controversial or problematic or just plain nasty. Blue Checks weren't "gutted". Now they just mean something else -- you're a premium subscriber.
- wyclif 1y agoThis is absolutely correct—I remember quite clearly how it all went down. When Twitter first rolled out verification, it was supposed to ensure that the person you were following or interacting with was the person they claimed to be.
- burningChrome 1y agoThis was also because there were so many people setting up fake accounts using real celebs. The most famous of which was probably the Dave Chapelle, Kat Williams story that Chapelle tells where a fake Chapelle account was feuding with a fake Kat Williams account. https://www.youtube.com/watch?v=7_Egh9mW5y4 https://www.youtube.com/watch?v=7_Egh9mW5y4
- NelsonMinar 1y agoThe problem is that X (formerly Twitter) is still calling blue checks "verified". Even though nothing about the account is verified. It's deliberately misleading.
- hombre_fatal 1y agoI use the word "gutted" to refer to the level of trust in the old system that was abandoned in the identical-looking new system. The correct way to have rolled that out would have been a brand new icon, but they wanted to cash in on the reputation of the old system. "Now you can pay for this once-coveted badge!"
- ein0p 1y agoWhy is it "meaningless overnight" on Twitter? Twitter knows who you are if you're paying them montly. Ergo, you are "verified".
- lexandstuff 1y agoBecause the original point of it was to distinguish journalists and public figures, so you could tell imposters apart from real people. Now its purpose is to show who has a premium subscription. Totally different feature using the same name.
- ein0p 1y agoBut not all "journalists and public figures" received the checkmark. It was entirely up to the ultra-woke Twitter management who gets a checkmark and who doesn't. I frankly don't see why the current, deterministic setup is better than the former non-deterministic one.
- darthrupert 1y agoUltra-woke Twitter? What the hell are you blathering about?
- ein0p 1y agoThis, specifically: https://www.esquire.com/style/news/a45458/jack-dorsey-stay-woke-shirt/ https://www.esquire.com/style/news/a45458/jack-dorsey-stay-w...
- DonHopkins 1y agoNow it's ultra-racist ultra-fascist Twitter management. Do you actually think that's better? Why are you whining about "woke" people who have long since been fired, but embracing the racists and fascists who are now running and being platformed and amplified on Twitter? Yes, "Twitter". If Elon Musk can publicly abuse, humiliate, lie about, deadname, and misgender his own daughter to his millions of followers, than I can deadname Twitter.
- tedunangst 1y agoWhat happens when the government of Turkey objects to your verification?
- wmf 1y agoComing soon from Bluesky: per-country verification.
- yellowapple 1y agoThat'd certainly be a neat feature: national/regional/local governments running their own verifier accounts and providing Bluesky/ATproto verification to their residents.
- snotrockets 1y agoSame as the current labeling/moderation service: any participant can verify any other participant. Which verifiers gets a check to appear is a property of the AppView. If Bluesky becomes evil, you just configure your AppView not to trust their verifications. Of course, that's the problem: right now we mostly have one AppView (bsky.app), which is the current SPOF in the mitigation plan against the "Bsky becomes the baddies" scenario.
- shrink 1y agoI built handles.net[1] to make it easy for organisations to manage their member's handles, I think that using domain names for identity is neat and valuable, I have a vested interest in its success as a paradigm but... domain name "verification" is not the right solution today for non-technical people. I shared this sentiment a few months ago[2] and I have only become more confident in that assessment since. The approach they've taken ("trusted verifiers") is an approach aligned with their values, as it is an extension of the labelling concept that is already well established in the ecosystem. As an idealist, it is a shame that they gave up, I think they could have had an impact on shifting how non-technical people view domain names and understand digital identity... but as a pragmatist, this is the right choice. Bluesky has to pick their battles, and this isn't a hill to die on. [1] https://handles.net https://handles.net [2] https://news.ycombinator.com/item?id=42749786 https://news.ycombinator.com/item?id=42749786
- adityavinodh 1y agoYeah my initial reaction was not too positive. There's something weird to me about simply delegating verification to a third party organization. I'd prefer a more pure solution. Maybe we don't have a solution yet that is simple enough for widespread adoption. The domain based identity does seem a bit too complicated for the average user.
- yellowapple 1y ago> The approach they've taken ("trusted verifiers") is an approach aligned with their values, as it is an extension of the labelling concept that is already well established in the ecosystem. That just leaves me wondering why they bothered with a new separate system instead of just using the existing label system. A "verified by bsky.social" or "verified by nyt.com" or whatever label would do the job perfectly well, no?
- steveklabnik 1y agoI would have liked to have seen a justification for this as well. One thing about labels is that they can apply on a per-post granularity as well as a per-account granularity, but verification is purely account-level. Another is that they have slightly different semantics, you can lose your blue check if you change your handle or display name, but labels stay the same no matter what. That's probably the real justification for making it its own feature.
- mpalmer 1y agoBluesky remains the single best example of how decentralization works best as components of the architecture, not its raison d'etre.
- pessimizer 1y agoNo, it's the best example of how after you take a bunch of VC money you won't ever give up an iota of control or ability to rugpull, no matter what the original purpose of your organization was.
- mpalmer 1y agoTrue to your name if nothing else. Bewildering to me that seemingly any move in the right direction for social media is criticized with even more venom. How exhausting it must be to be stuck in such a frame of mind. Showing users that these ideas work is a win, it doesn't matter what Bluesky does in the future.
- 9283409232 1y agoI'm glad BlueSky is trying to innovate in this space but there is reason to be pessimistic. Eventually VCs want a return on investment and Bluesky doesn't actually make money as far as I know.
- ChrisArchitect 1y ago<checks Twitter development timeline> Yep, right on schedule. Fine with this albeit very 'manual'...but not clear if any other choice. I do really like the domain username scheme and if anything this news just draws more attention to that because there's sooo many organizations/news outlets etc not taking advantage.
- yellowapple 1y agoThe lack of domain-based verification among organizations is indeed bewildering. Surely these orgs have IT departments, right? Even the most junior of help desk techs should be able to figure out how to create a TXT record and paste in the gobbledegook that Bluesky provides to link that to an account. If these orgs don't have IT departments, then, well, pay me $20 and I'll do it for you.
- preciousoo 1y agoWhy not let users pick their own Trusted Verifiers?
- benwilber0 1y agoI'm guessing because users will just "verify" themselves, and then the whole thing is meaningless.
- steveklabnik 1y agoIn the current system, anyone can verify anyone else.
- preciousoo 1y agoUsers can then choose to subscribe or unsubscribe from a Trusted Verifier, if one starts to act in an unsavory manner. That a Verifier exists doesn’t mean people have to use it
- deleted 1y ago[deleted]
- steveklabnik 1y agoThat's absolutely possible for them to pivot to in the future. We'll see.
- deleted 1y ago[deleted]
- paxys 1y agoI like the idea of a trust hierarchy. Bluesky verifies NYT, then NYT verifies all their journalists. Makes the entire process a lot more scalable.
- Robotbeat 1y agoNYT journalists as a privileged class… With actions like this, Bluesky is not exactly beating the allegations.
- 9283409232 1y agoI actually don't know what you are talking about.
- JustSkyfall 1y agoI presume he’s saying that Bluesky’s a very left wing social media platform.
- mrguyorama 1y agoCalling NYT left wing is patently absurd. They've spent the past 4-8 years platforming writers to say absolute horseshit about trans people and equivocate between Biden having like 6 leftover classified documents in his house vs Trumps bathroom of for sale state secrets.
- 9283409232 1y agoEverything that doesn't worship the Emperor is left wing these days.
- Robotbeat 1y agoBelieve it or not, plenty of left wingers have a bone to pick with the East Coast traditional media establishment as well, NY Times in particular. And the traditional media also seems to have a symbiotic relationship with Trump, whose chaos drives news ratings.
- pityJuke 1y agoGood! I’ve been using a third-party labeller (which is a great hack), but making it more user friendly and official is a great thing. I’m a proponent of verification only for “important people”. Yes, the definition of important is funny, and people may feel slighted by it: but I’ve yet to find a system that helps me identify high quality sources so immediately on a social media platform.
- jchw 1y agoI think the best way to look at things is to look at platforms that don't and have really never had issues with verification to begin with. An oddly good example is YouTube, which has a verification feature that's so uneventful and drama-free I reckon a lot of people hardly even notice it. Even fairly small scale musicians and creators, at least relatively speaking, can have verification symbols. (Of course, there can be issues with e.g. account takeovers and people changing their name/icon to try to fool you, but that's not really a problem with the verification process itself.) The trouble with what platforms like Twitter did was by trying to stick to some definition of important, they took what should be a mundane "yep, this is the person it looks like" icon and made it into a status symbol that everyone wanted. Twitter had a hard time defining the boundaries: Shouldn't they verify their most influential users even if they're not real world celebrities or public figures? What happens if someone who is verified says something that they don't like? How do you prevent corruption when you give other organizations special privileges for verification? For Twitter and Instagram verification, people were bribing employees and getting verification just because they joined an organization (like an eSports team or a news organization.) This was not a good status quo. Bluesky is probably headed towards the same problem if they try to be the bearer of who's important. Obviously, you can't verify any Joe Schmoe, but honestly you can just set a reasonable threshold based on their status in the platform for as to whether or not they should be eligible to get verification. When you do stuff like say "You should be able to be verified because you work for NYT", that's just weird. Being a journalist doesn't magically make you important, or mean that your posts will be worthy of greater consideration, yet that's what you're setting people up for when you make verification into a big ordeal like this, and it's the reason why Twitter would unverify people for e.g. having an opinion too far outside the Overton window. And using in-platform metrics to determine eligibility seems reasonable anyways... If you have like 10 followers, your verification status is utterly meaningless anyways. I think if they want to solve the problem for journalists they should've verified the organizations and then made this separate from verifying individuals. Then accounts under that domain could just have some sort of special badge. This especially makes sense because otherwise you could literally just have your personal account become verified by having a couple month stint at the NYT or something, which is non-sensical.
- throwawa14223 1y agoThis seems like an anti-feature. The appeal of Bluesky is exactly the lack of a Twitter like central authority.
- arghandugh 1y agoThe opposite. It’s Twitter before Twitter was turned into a campaign of degenerate malignancy, with several escape hatches built-in.
- throwawa14223 1y agoTwitter was awful before Musk and is awful in a different way now. Emulating old awful is not good just because new awful is different.
- pessimizer 1y agoIf you were one of the people making twitter awful before Musk, you'd prefer a service that was old awful, rather than new awful. They just want the Shah back.
- NoTeslaThrow 1y agoI suppose if what you don't like about twitter is the people there (or the moderation), bluesky would make a lot of sense. I can't help but feel like the combination of catering towards businesses (verification) and people who don't like conflict (moderation) is recreating the same problem with a different demographic. Am I anti moderation? No, not really. But the attitude blue sky users have towards it feels very much like wanting to be validated for not liking twitter('s users) rather than a forum for adults who enjoy seeing content from people wildly unlike themselves, which is what drew me to twitter 15 years ago.
- ajb 1y agoNot convinced by this. We need a way to reflect that human "social trust" is born distributed, and centralising trust subverts it. But here, while they introduce third party verifiers, rather than individuals deciding which verifiers to trust, bsky is going to bless some. So this is just centralised trust with delegation.
- TheJoeMan 1y agoAre there any good examples of a working "vouch" system? I vouch for a few friends, they vouch others, etc. But if my credibility is revoked, everyone downstream of me is either yanked or needs a new voucher.
- jsheard 1y agoI think the more exclusive private torrent trackers usually work on that basis.
- godelski 1y agoArXiV. Though they don't revoke papers that way
- fp64 1y agoA long time ago there was this “web of trust”, I don’t think it exists anymore. Was one of the big CA and you could get different certificates through some form of vouching, I think it even went as far as meeting people to show your ID and then they sign you or something. As it was run by a big CA, not really distributed but IIRC they kept their involvement minimal. It’s been a long time but if you’re curious maybe look into that
- stego-tech 1y agoThey can justify it however they want to all day long, but we've got enough real-world examples of verification to show that its core use isn't about protecting users, but about authorizing acceptable speech on a platform and protecting advertisers. Domain verification was genuinely all the verification needed. This checkmark system is just a copy-paste troublemaker from Twitter, and we all saw how well that turned out whenever a celebrity or billionaire's account got hacked to shill grifto schemes. Training users to only look for a symbol just desensitizes them to the complexities of identity and sanctioned speech.
- pessimizer 1y ago> Training users to only look for a symbol just desensitizes them to the complexities of identity and sanctioned speech. This is what their users are looking for. They don't want complexity, they want to know who they're supposed to listen to.
- stego-tech 1y agoI don't know why HN is down voting you; you're right. That said, your gray-status is exactly why I long since stopped pointing out that's what people want, and instead shifted my argument towards educating readers why that's bad. The dearth of informed electorates is a crisis plaguing humanity as a whole, and we sorely need to start shining a light on the practices that create this harm ("answer engines") rather than shaming users that engage with those traps alone.
- derefr 1y agoGiven usernames-as-domains, is there a reason to not just piggyback this on the X.509 web of trust? After all, we already have an established and highly-monitored set of sibling "trust roots" — we call them Certificate Authorities. And we already have an identity-validation system coupled onto X.509 FQDN-as-CN (i.e. TLS) certificates — certificate validation levels. BlueSky could just: 1. require a domain username for verification; 2. require that the domain presents an Organization Validated (OV) cert for verification as a "public individual" (i.e. the kind with a "personal brand" — which usually implies "worth registering as an LLC"); 3. require that the domain presents an Extended Validation (EV) cert for verification as a corporation. ...and the whole problem of identity validation becomes outsourced, and federated, and decentralized. (Federated because multiple sibling CAs; decentralized because every computer administrator gets to decide for themselves which CAs their machine should trust.) --- A rebuttal might be that "EV certs can't be used for this, because EV certs are too expensive, take too long to get, and don't integrate well with automatic per-subdomain DV cert issuance via ACME." But (IMHO) that's not a problem to be worked around; that's a problem to be fixed. Why leave a broken generalized web-of-trust infrastructure sitting there unused? If an online casino can KYC/AML you in two minutes with a passport scan and a 3D camera photo, it shouldn't be impossible to do for OV+EV validation what we did for DV validation with ACME. (Ideally in such a way that you can do the interactive process once, receiving not a cert, but some kind of collateral; and then, later on, any ACME server should accept that collateral during an interactive domain ownership probe, to upgrade the DV cert it's issuing you into an OV/EV cert.) --- The other neat thing about this approach is that, in a "fat" native BlueSky app (i.e. not just an Electron wrapper), the app wouldn't have to trust the BlueSky service to say who's verified. The app could TLS-validate each domain username itself, to compute the appropriate badge for that user — just as a web browser does when you visit a website. And it would presumably use your machine's OS TLS CA store for that validation, just as (some) browsers do.
- giaour 1y agoBlueSky users are already kind of doing this. Members of the US House and Senate tend to use their .house.gov/.senate.gov domains as usernames, which is a very trustworthy signal that the account is legitimate.
- 1y ago
- Tireings 1y agoIt could be perfect to have a basic network of trust as feature. Can't be that hard to have this
- deleted 1y ago[deleted]
- doodlebugging 1y agoI'm not a bluesky user yet but in reading through the post I discovered a problem with their implementation of the ID verification. They describe it as a "blue check" when in fact it is a white check on a blue circular background. Just nit-picking I guess but sometimes I read a passage that describes something and I conjure an image in my mind of what I would see should I open my eyes with it all laid out in front of me. This does not fit the image that is described in the post and makes we want to question the author's observational skills.
- mattl 1y agoIt’s what the verification mark is typically called
- doodlebugging 1y agoWhy isn't it a blue check on a white circular background? That would make it a blue check. It doesn't matter to me since to date I am not a user, I just thought it was interesting that people would accept a non-truth as an ID verification.
- somat 1y agoThis is better than twitters nonsensical verification but still does not close the loop all the way. I think what is needed are a set of equivalency verification's. Sort of like the domain verification used in getting a TLS certificate. Something like bluesky user X is equivalent(has control) to domain A(domain verification) to youtube account B (youtube verification) to mastodon account C (mastodon verification) to D@nytimes.com (email verification) So logically I would expect a protocol that allows cross domain verification. Best I can come up with is something that works sort of like domain verification extended to user@domain verification. that is, a better engineered version of "make a youtube video with the string 'unique uuid code' in the comment" so that we can verify you own that youtube account" The problem is that some domains would have no problem standing up this sort of verification. The Times only benefits from verifying it's employees. However I can see fellow social media sites balking as this equivalency weakens their walls that keep people in.
- ammar2 1y agoWhat you're proposing is reminiscent of Keybase's account verification system. You make a post or equivalent on each platform with cryptographic proof that it's you. (e.g here's mine for GitHub https://gist.github.com/ammaraskar/0f2714c46f796734efff7b2ddbf8622c https://gist.github.com/ammaraskar/0f2714c46f796734efff7b2dd...).
- toss2025away 1y agokeybase.io
- thunkingdeep 1y agoBluesky is riddled with pornography, even with the strictest settings enabled. I genuinely don’t feel comfortable scrolling any of the curated feeds in a public place except for my direct “Following” only feed. Not sure how big of a priority this is for the team that runs it, but I would probably use it 20x more if it was ran competently.
- Zak 1y agoThat hasn't been my experience with it, and I'm curious as to what usage pattern gets that result other than intentionally following accounts that post pornography. My account that follows and posts tech and general interest stuff gets tech stuff and politics in its discover feed. My account that posts bird photography and follows photographers gets photographs of animals and landscapes, and politics in its discover feed. It's politics I can't avoid there, not pornography.
- thunkingdeep 1y agoI mostly discuss politics. I’ve talked about some technology stuff on there too, but it’s easily 95% politics.
- Zak 1y agoI should also note I have adult content set to allowed and all moderation categories set to warn or show, nothing set to hide. I can't recall seeing any porn at all outside of a couple searches meant to test the moderation settings.
- yellowapple 1y agoYeah, I can confirm that I have to go out of my way to find anything NSFW on any of my feeds (even while following multiple artists who occasionally post some risqué drawings), whereas politics are unavoidable. Granted, I'm probably part of the problem, since I do post (and repost) some political stuff every once in awhile, but still.
- Edmond 1y agoFor folks interested in a PKI certificate based approach to solving verification problems: https://news.ycombinator.com/item?id=40298552#40298804 https://news.ycombinator.com/item?id=40298552#40298804 Delegation similar to bluesky's "NYT org issues certs to journalist" is also possible and done in a far more versatile manner. If you have a domain and want the ability to issue certs to others, email me...this will just be for experimenting of course :)
- mhh__ 1y agoThe old blue checks were very useful as a way of knowing who was approved by the regime. So I sort of look forward to this, even if I still really struggle to even casually use bluesky.
- SV_BubbleTime 1y ago>even if I still really struggle to even casually use bluesky Trend. I mean, what even are network effects!?
- mhh__ 1y agoMore that I actively despise most of what I see on the front page
- kristianc 1y agoI think I've seen this movie before and it doesn’t end with meaningful community trust. It ends with people paying for status, accounts impersonating others with a wink and a checkmark, and eventually, trust being eroded by the very signal designed to uphold it.
- sillysaurusx 1y agoIt’s ironic that many comments are skeptical of strong centralized moderation, but they’re posting these comments on a forum with perhaps the strongest and most centralized moderation team of the entire internet. All I’m saying is that if weak moderation has had a positive effect somewhere, it’s worth showcasing that. Otherwise the evidence is decisively in favor of strong moderation. In terms of how to keep the moderation team from deteriorating, other platforms could learn a thing or two from HN: put someone competent in charge of the team, and give them lots of incentives to do well.
- wmf 1y agoHN moderation is easy mode because it's a small site and politics is "banned". Trying to do HN-quality moderation of political discourse among millions of users seems impossible.
- SV_BubbleTime 1y ago>it's a small site and politics is "banned". Well, the “wrong” politics are.
- JohnKemeny 1y agoYes, HN is turning into Reddit, am I right? Don’t mistake banned for politics with getting downvoted because your arguments don’t hold up.
- SV_BubbleTime 1y agoBubble people telling themselves bubbles things
- DevOps72 1y agoThere are a lot of users that have complained about the s-banning on this site. While the moderation team of this site seems to be well-intentioned, it does inevitably lead to a very strong slant. S-banning users doesn't make them or their viewpoints go away. They just end up happening elsewhere. Because those conversations do end up happening elsewhere, this site is famous for leaving readers with a strongly false impression of what viewpoints are actually popular among whatever you would want to call this Silicon Valley hacker / VC scene space. The highly insidious thing about censorship is not only you don't know what you're not seeing but you don't know you're not seeing it -- you don't know what's missing.
- blotfaba 1y agoIt's giving Twitter "official teller of truth" vibes
- steveklabnik 1y agoI got verified in the initial round of verification. On a technical level, this sort of works like a Root CA: anyone can verify anyone by publishing a `app.bsky.graph.verification` record to their PDS. Bluesky then chooses to turn those from trusted accounts into the blue check, similar to browsers bundling root CAs into the browser. * https://pdsls.dev/at://did:plc:z72i7hdynmk6r22z27h6tvur/app.bsky.graph.verification/3lndpy3ngb62l https://pdsls.dev/at://did:plc:z72i7hdynmk6r22z27h6tvur/app.... <- bluesky verifying me. it's coming from at://bsky.app, and therefore, blue check * https://pdsls.dev/at://did:plc:3danwc67lo7obz2fmdg6jxcr/app.bsky.graph.verification https://pdsls.dev/at://did:plc:3danwc67lo7obz2fmdg6jxcr/app.... <- me verifiying people I know. it's coming from at://steveklabnik.com, and therefore, no blue check. I am not 100% sure how I feel about this feature overall, but it is something that a lot of users are clamoring for, and I'm glad it's at least "on-protcol" instead of tacked on the side somehow. We'll see how it goes.
- yellowapple 1y agoI wish it'd work like labelers and other moderation features: with users able to choose which verifiers to use. I trust the NYT as far as I can throw them when it comes to verification, for example, whereas I'd be interested in something flagging Bluesky employees or contributors to a given GitHub repository or whatever other bizarre things people would use this for like they already use labels.
- steveklabnik 1y agoWhat's good is that the technical design here allows them to pivot into that if they choose, and alternative clients can already do that if they wish.
- pinoy420 1y ago[dead]
- mmooss 1y ago> I trust the NYT as far as I can throw them when it comes to verification You don't trust the NYT to verify its own reporters? Also, why do you say that in any circumstance? Who do you trust?
- A4ET8a8uTh0_v2 1y agoIf I was in a less charitable mood, I would categorize it as a misguided attempt at re-implementing previously failed ecosystem. But I am in charitable mood so allow me to say instead 'bold move. lets see if it pays off'.
- jarjoura 1y agoIf you contextualize this as a form of limiting the power and reach of bots, and you avoid going down the rabbit hole of speech and censorship, then this move is actually a very clever way of scaling that out. Trust is always going to be a game of cat and mouse, and this seems like just another move.
- FlyingSnake 1y agoHamartia: The tragic flaw that takes the hero to the top will lead its downfall. It seems to me that BlueSky is trying to rewind the clock and be the pre-Elon Twitter. They had a decent chance to become what Signal is to messaging, but looks like they are trying to be just another Social Media company. We’re truly in the post-social media age.
- ChrisArchitect 1y ago"yessss FINALLY we have a caste system for professionals who were too stupid to figure out how to use a domain!" haha
- rambambram 1y agoHey, I have this personal homepage. Available under a domain name. I trust myself, so I put a PNG of a blue check on it. If you don't trust me, I also have a blue check on my website that is put there by my best friend. Now you have to trust me. I guess I'm verified now, authenticated even. The web really was better with more pseudonyms. I don't care if you are you, I can read your text, judge it on it's merits (according to my yardstick) and I basically don't care if you or other people consume information that is true or false. Am I missing something?
- kmoser 1y ago> Am I missing something? The ability to put fake blue checks on your website isn't the point. Bluesky (and the web at large) is slowly becoming filled with spam and AI-generated content. Even if you're OK with more spam (not sure why you would be but you do you), why would you be OK with more content generated by non-humans (the vast majority of which attempts to pass as human)? This just makes it harder to find needles of authentic human content in a haystack of slop. Various levels of verification make it easier to distinguish what's real from not real, for whatever definition of "real" you prefer. Without any such verification, the web just becomes a bigger wasteland.
- StressedDev 1y agoReal life people use AI. A good example of this is the lawyers who submit court filings with AI generated legal citations. The get caught because the citations are fake (the case cited does not exist).
- rambambram 1y ago> The ability to put fake blue checks on your website isn't the point. That's my point. ;)
- jjulius 1y ago>Various levels of verification make it easier to distinguish what's real from not real, for whatever definition of "real" you prefer. Exactly! ;) Bullshit is still bullshit, whether it's under a real name or a pseudonym. Additionally, blue checks don't stop "real/verified" people from copy/pasting AI-generated content.
- gus_massa 1y agoCan a country verify it's president? Can a country I don't like verify it's president that I don't like neither? Prime minister? Members of the Senate? All citizens? Their own bot farm?
- aboardRat4 1y agoI've always found those blue checks to be a ridiculous idea. Internet was intended to be anonymous.
- galaxyLogic 1y agoShouldn't there be some kind of points-system to the verification? If I am verified by 2 parties each of whom is verified by 10 parties each of whom is verified by 1 party then my verification score would be 20 (= 2 x 10 x 1). Then people could trust me beinhg me 20 x more than somebody who is only verified by one party who is only verified by one party who is not verified by anybody?
- wilg 1y agoIt seems like the main problem with verification is that everyone is conflating what verification is or is supposed to be. It doesn't mean "this person is trustworthy" it means "this person is who they claim to be". But people desperately want it to be the former, or some sort of club. But these are completely orthogonal concepts that demand different solutions. Bluesky should do better here though, their definition of "verified" is buried in the blog post as "authentic and notable". This is okay I guess, sort of matches old Twitter. But a bit wishy-washy. One idea could be to link verification badges to Wikipedia (or Wikidata) entities so you understand who is confirming what about the account. "This Mark Cuban Bluesky account is the same as the Mark Cuban in this Wikipedia article" and let the Wikipedia editors fight over noteworthiness etc.
- JSteph22 1y agoIt sounds like you just disagree with Bluesky's definition. If it's only for notable people, then it is a sort of club.
- wilg 1y agoNo, I'm saying they should be much clearer about what their definition is. I also suggested a way to use implement their same "authentic and notable" definition via a trusted and democratic third-party like Wikipedia.
- uriegas 1y ago[dead]
- thuanao 1y agoWhat’s the value in verification, exactly? Seems like a solution to a problem that doesn’t exist. Do non-idiots really get confused into thinking Jack Dorsey’s account is someone pretending to be Jack Dorsey? Before Twitter did any sort of verification it was not difficult to determine whether an account claiming to be someone was actually that person for anyone who was actually interested. I suspect a lot of people have this delusional fantasy where “verification” is going to shape political discourse in their favor.
- SV_BubbleTime 1y agoI’ll bet you $100 that you have argued with bots before.
- robertlagrant 1y ago> Before Twitter did any sort of verification it was not difficult to determine whether an account claiming to be someone was actually that person for anyone who was actually interested. It was if you were a regular, non-technical user or not terminally on Twitter.
- NoTeslaThrow 1y agoI'm trying to remember a single moment in the last twenty years of desiring identity verification and I just can't think of anything. Maybe people trying to protect their "brand"? Is there really that much demand for branded content?
- btbuildem 1y agoPardon the naive question, but could verification not be accomplished by requiring to tie a form of payment to an account? Eg, a CC or equivalent? Outsource the identity validation to other institutions (eg banks), and benefit from their deep investment into identity verification. Would that not work?
- uwemaurer 1y agoWe had this idea to use a page rank based algorithm to compute a influence score based on the score of the people who follow you. A high score usually indicates a trusted account. Check it out here: https://bluefacts.app/top https://bluefacts.app/top
- jeswin 1y ago> Additionally, through our Trusted Verifiers feature, select independent organizations can verify accounts directly. As someone who believes in equal access and privilege, this is just horrible. "Trusted Verifiers" - how does the bsky team decide which orgs can be trusted? One could argue that this is worse than Twitter. And of course, the echo chamber is going to get worse.
- ndjeosibfb 1y agobluesky is the twitter alternative for people who want more censorship and echo chambers there’s nothing surprising about this
- hashstring 1y agoBeing on both until recently, BlueSky feels less like an echo chamber than X to me. Censorship is a negative frame when it also provides healthy platform moderation and safety.
- concordDance 1y agoMaybe BlueSky has changed since last I looked, but it used to very progressive activist politically. On Twitter I can see right wing, centrist and left wing commentary.
- raincole 1y agoBlueSky is never a counterpart of Twitter. It's closer to that of SocialTruth. I think even the default subs on Reddit are far less progressive than BlueSky.
- hashstring 1y agoAre you talking Twitter or X? X is in many ways much closer to TruthSocial than any other platform currently is [1] [2]. The only thing that grounds X a bit is the (old) Twitter user base that’s still on there, which is and has been declining. It’s also interesting that your view of progressive might be different than mine. In this current age, I guess even advocates for DEI are considered too “progressive”. Which (in my opinion) relates more to a shift of right to far right, which shifts the balance, and people mistake it for what are really just centric viewpoints being “leftist”. To me, BlueSky is the best current alternative to what Twitter originally was. [1] https://www.npr.org/2024/10/22/nx-s1-5156184/elon-musk-trump-election-x-twitter https://www.npr.org/2024/10/22/nx-s1-5156184/elon-musk-trump... [2] https://www.nbcnews.com/tech/social-media/elon-musk-turned-x-trump-echo-chamber-rcna174321 https://www.nbcnews.com/tech/social-media/elon-musk-turned-x...
- nout 1y agoI prefer the Nostr approach that also has domain based verification, but it opens up the door for anyone with domain to do it. https://github.com/nostr-protocol/nips/blob/master/05.md https://github.com/nostr-protocol/nips/blob/master/05.md
- NullPointerWin 1y agoCan anyone just make their own blue check now?
- zero0529 1y agoI see a lot of resistance against the trusted verifier system and I am curious on why it is any different from CAs
- baxuz 1y agoI'm not sure what is being verified here. Except that the someone has access to a bluesky handle and a DNS record. And even that is not a guarantee as it needs to be validated by the bluesky team, for which it helps, in their own words – to have connections with them. Otherwise I could buy dozens of domains and spin up bots to churn out AI slop as "validated" accounts. I could buy linustorvalds.com for 25k and impersonate him. It's still a two-tier system for clout-chasers. If you're cool enough, you get a "Officially Cool™" badge from the bsky team. If you're not, hope that a 3rd party provider decides to give you one. Or you're a second-grade netizen.
- egberts1 1y agoKinda like Lobster.rs Not a good look.
- jamesfisher 1y ago> Trust doesn’t come only from the top down [...] So, we’re also enabling trusted verifiers: organizations that can directly issue blue checks. Is this not still a top-down system, just with one level of indirection? Something not-top-down might look more like the web-of-trust model.