3 ms·
If anyone can hand out verifications to anyone they like then we’re back to square one. Why do we need these “Blue Checks”? It feels like BlueSky is trying to r
by FlyingSnake 1y ago
If anyone can hand out verifications to anyone they like then we’re back to square one. Why do we need these “Blue Checks”? It feels like BlueSky is trying to reclaim the lost clout for some of their influential users.
- steveklabnik 1y agoIt's in line with the protocol design. If only BlueSky themselves could verify, that'd be too centralized. Mind you, just because anyone can create a verification record doesn't mean that the default client shows them. > Why do we need these “Blue Checks”? Normie users care about this sort of feature.
- FlyingSnake 1y ago> Normie users care about this sort of feature. That’s a really weak argument because normie users want TikTokified social media with a clout based caste system. I thought BlueSky had a different goal in mind.
- steveklabnik 1y agoBluesky cares about both audiences.
- anon7000 1y agoBlueSky wants to make a social media platform that normies want to use. The whole idea is to design a protocol that can achieve huge scale and behave a lot like existing social media apps (which people "like") while still being open and flexible.
- erichocean 1y ago> BlueSky wants to make a social media platform that normies want to use. If true, they are failing—badly.
- krainboltgreene 1y agoEven if that were true, which it's very easily argued not, that would be even more of an impetus to implement things that "normies" want, not less.
- whywhywhywhy 1y ago>Normie users care about this sort of feature. They don't, but the original Twitter Bluecheck elites who ran to Bluesky really do
- steveklabnik 1y agoThat's not what I'm seeing, but you do you.
- azernik 1y agoWe need the blue checks to combat impersonation attacks. If a malicious actor pretends to represent a New York Times journalist, or your bank, or a government agency, you don't want users to be tricked into believing them.
- tasuki 1y agoVerification is a different thing than a "blue check". I might be against blue checks, but for sure I'm for anyone being able to hand out verifications. It creates a web of trust, and ideally one can choose who they trust and how many transitive levels.
- ivan_gammel 1y agoI'm not sure about the details of the protocol (maybe someone can check?), but the client software can probably distrust certain trusted verifiers or even use a public list of such revocations. If this opportunity is exploited by malicious actors, there must be a simple and fast escalation path to revoke verification (you complain to verifier, then to maintainers of revocation list).
- steveklabnik 1y ago> the client software can probably distrust certain trusted verifiers Any client can do whatever they want with the information, that's right. > or even use a public list of such revocations. Revocation is deletion, so it's hard to enumerate revocations.
- ivan_gammel 1y ago> Revocation is deletion, so it's hard to enumerate revocations. In decentralized design it is not. A server can continue to list verified accounts, a 3rd party revocation list may mention some of them, a client will show only accounts not in the list as verified.