Live data from Hacker News

Relaunching verification and what’s next

blog.twitter.com

41–50 of 58 posts

Re: Relaunching verification and what’s next

#41
post #40

Earlier quoted context omitted.

> won't let you download the tweets you've liked/saved, or your follower/following Take a look at data/{like,follower,following}.js in the data export .zip.

Yes, they just contain numeric userids and tweet ids; not usernames or tweet data. The information is opaque and useless, you can't even construct URLs from them.

like.js contains full tweet text and working URLs. It's true that usernames aren't given. It's not true that Twitter "won't let you" download these lists at all.

Re: Relaunching verification and what’s next

#42

Earlier quoted context omitted.

2FA has historicially been broken because it is usually attached to a phone number, and phone service providers are suseptable to social engineering. What twitter (and other websites) should be using is PGP, where the user holds the secret key, and there are separate forms on messages to view PGP signatures, and forms on accounts to view their public keys.

PGP is possibly the only workflow worse than SMS based 2FA for humans.

Depends on how you mean "worse"; PGP is very secure with poor UX, SMS is less secure but honestly decent UX.

Re: Relaunching verification and what’s next

#43
I wrote on this awhile back, but Twitter should be verified-by-default. If you can verify your identity, you should be given the blue checkmark. That way you can restrict your feeds to those who are verified, or who can connect with you. I believe this would solve a lot of the vitriol and scam/spam issues rather quickly.

Re: Relaunching verification and what’s next

#45

Earlier quoted context omitted.

You're leaving out the most important part, being verified but having no organic support means powerful interests are backing you against the population. Often this is journalists that push unpopular war propaganda and strategically ignore corruption and war crimes committed by the US and Israel.

Its just as often people that like to show their bodies as well as software developers, so bad take. Your observation happens, but you're reading way too far into it.

>people that like to show their bodies as well as software developers

I really dont understand what you mean.

>Your observation happens, but you're reading way too far into it.

I also dont understand this lol. So you admit this happens but just don't think I should care that much? Well I do care about the rich parlaying their wealth into political power by buying up newspapers and social media companies ala Jeff Bezos and Jared Kushner and the Qutaris and I would hope you do too.

Re: Relaunching verification and what’s next

#46
post #43

I wrote on this awhile back, but Twitter should be verified-by-default. If you can verify your identity, you should be given the blue checkmark. That way you can restrict your feeds to those who are verified, or who can connect with you. I believe this would solve a lot of the vitriol and scam/spam issues rather quickly.

> 1 billion pending verifications

> to be processed by 1000 customer support agents

Good luck with that

Re: Relaunching verification and what’s next

#47

The magic URL seems to be: https://twitter.com/settings/account/request_verification

Worked for me and there was one requirement that was a bit strange that I didn't see documented anywhere; you have to add a 'Hashtag URL', which is "The URL of a Twitter search for a specific and notable hashtag that you created or is about you." See: https://twitter.com/geerlingguy/status/1395463184681771016

Re: Relaunching verification and what’s next

#48

Earlier quoted context omitted.

PGP is possibly the only workflow worse than SMS based 2FA for humans.

Depends on how you mean "worse"; PGP is very secure with poor UX, SMS is less secure but honestly decent UX.

Separating UX and "security" from a cryptosystem is impossible. Poor UX leads directly to security vulnerabilities.

Heck, we've seen that in library code: your AES implementation may be sound, but if the library interfaces make it easy to reuse an IV, or use a null IV[1], you have a broken cryptosystem.

[1]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5408

Re: Relaunching verification and what’s next

#49

This doesn't really change anything, as far as I can see. The entire premise is wrong. Being verified on Twitter SHOULD NOT BE AN OPTION AT ALL because of the perverse incentives it creates, and the way it warps and destroys the whole platform. The blue checkmark program started out as simply a way to prove you were the real you, if you were claiming to be someone important. But because of that element of "importance…

I'm not sure why this is downvotes. Many platform - dating apps, whatsapp, Facebook etc - use verification for verification.

Only Instagram and Twitter use it for notability.

Why not allow anyone to verify, and mark notability separately?

  Michael Jordan [blue check] [star]

  Michael Jordan [blue check]

Re: Relaunching verification and what’s next

#50

I always find it kind of odd when someone is verified on twitter but only has a few thousand followers. The impression it leaves is almost worse than not being verified at all.

This parody is so accurate it hurts: https://www.youtube.com/watch?v=ni8CpIJpmqw ('how twitter verification works' by Gus Johnson)
Post reply on HN