Live data from Hacker News

Relaunching verification and what’s next

blog.twitter.com

51–58 of 58 posts

Re: Relaunching verification and what’s next

#51
post #44

I don't use twitter, but it always seemed to me that a blue check mark was an "upvote" from twitter, rather than authentication. Isn't this how it works? I don't think I'm able to get one if I asked for it.

Only because there are more notable, or influential people as some would put it. These are always going to be the priority and they happen to be individuals or organizations that tend towards the mainstream.

Giving General Motors a blue check mark is a no brainer because they are likely to be spending ad dollars. Giving celebrities of almost all levels, including short-lived ones, a blue check mark is also helpful because it has an impact on impersonation which is an attack vector on social networks.

The problem is that there are likely others in this celebrity bucket who are attack vectors, but bring reputational problems. Some pornstar might fall into this category. Twitter are much less likely to want to give them a blue check mark than a less well known comic. Someone can impersonate and attack a larger segment and Twitter's security team would probably advocate for reducing the risk, but the corporate arm of the organization won't go for this.

There isn't really anything nefarious here. It's just a case of the demand being so high and Twitter working out what they want to endorse. If they can get past some of the awkwardness of improving the posture around celebs like pornstars then I'd expect they'd extend the blue check mark to others who struggle. There are a lot of parties left out in the cold here. Things like this tend to be slow to evolve in corporate America.

Re: Relaunching verification and what’s next

#52

Earlier quoted context omitted.

PGP is possibly the only workflow worse than SMS based 2FA for humans.

How so?

I don't even know where to start: backwards compatibility to 90s era crypto, no forward secrecy, a web of trust model that encourages you to have a long-lived key – because with short-lived keys your trust has to be rebuilt after expiry, a cryptosystem that violently leaks metadata...

PGP should've died years ago; there are far better options today.

Re: Relaunching verification and what’s next

#53
post #25

Earlier quoted context omitted.

Pretty sure they were talking about verified profiles being hacked, changing their display name and avatar to Musk's, and then replying to Musk's tweet something along the lines of "I'm giving away free crypto, click here". In my view, 2FA should be a requirement for verification.

There is hacked verified accounts too, but also people setting up jokey accounts without the parody disclaimer pretending to be Musk or other influential people, then asking to 'double your Bitcoin by sending coins here'.

That blue checkmark is fairly unmissable. Handle is lower opacity when looking at a tweet. I have nothing to back it up, but having looked at a few cryotocurrency addresses that I've seen from breached accounts, I'm willing to claim it's far more effective to phish a blue checkmark and pretend to be Musk.

Re: Relaunching verification and what’s next

#54

Earlier quoted context omitted.

Pretty sure they were talking about verified profiles being hacked, changing their display name and avatar to Musk's, and then replying to Musk's tweet something along the lines of "I'm giving away free crypto, click here". In my view, 2FA should be a requirement for verification.

2FA has historicially been broken because it is usually attached to a phone number, and phone service providers are suseptable to social engineering. What twitter (and other websites) should be using is PGP, where the user holds the secret key, and there are separate forms on messages to view PGP signatures, and forms on accounts to view their public keys.

Convincing non-techies to use GPG just occasionally is going to backfire pretty quickly.

And I say this as someone who works at a journalist organization where if your editor catches you not using it, you're definitely gonna get scolded.

Software 2FA is much easier to enforce.

Re: Relaunching verification and what’s next

#55
post #43

I wrote on this awhile back, but Twitter should be verified-by-default. If you can verify your identity, you should be given the blue checkmark. That way you can restrict your feeds to those who are verified, or who can connect with you. I believe this would solve a lot of the vitriol and scam/spam issues rather quickly.

> 1 billion pending verifications > to be processed by 1000 customer support agents Good luck with that

You can automate a lot of that if you used government identification and removed the nascent requirements that are currently in place.

Quite a few places do this, it's not an intrinsically hard process.

Re: Relaunching verification and what’s next

#56

Earlier quoted context omitted.

Its just as often people that like to show their bodies as well as software developers, so bad take. Your observation happens, but you're reading way too far into it.

>people that like to show their bodies as well as software developers I really dont understand what you mean. >Your observation happens, but you're reading way too far into it. I also dont understand this lol. So you admit this happens but just don't think I should care that much? Well I do care about the rich parlaying their wealth into political power by buying up newspapers and social media companies ala Jeff Bezo…

After brands, verified accounts are mostly models, sex workers, followed by vain people that are closest to the verification database

Journals and newscasters would then be much smaller

I don’t have any other opinion on the matter (or quantitative sources)

Re: Relaunching verification and what’s next

#57
post #55

Earlier quoted context omitted.

> 1 billion pending verifications > to be processed by 1000 customer support agents Good luck with that

You can automate a lot of that if you used government identification and removed the nascent requirements that are currently in place. Quite a few places do this, it's not an intrinsically hard process.

You're kidding, right?

There are ~200 governments in the world, most of them don't even have digital infrastructure. Not even talking about resubmissions of blurred photos, fraud detection, human mistakes etc.

Re: Relaunching verification and what’s next

#58
post #49

This doesn't really change anything, as far as I can see. The entire premise is wrong. Being verified on Twitter SHOULD NOT BE AN OPTION AT ALL because of the perverse incentives it creates, and the way it warps and destroys the whole platform. The blue checkmark program started out as simply a way to prove you were the real you, if you were claiming to be someone important. But because of that element of "importance…

I'm not sure why this is downvotes. Many platform - dating apps, whatsapp, Facebook etc - use verification for verification. Only Instagram and Twitter use it for notability. Why not allow anyone to verify, and mark notability separately? Michael Jordan [blue check] [star] Michael Jordan [blue check]

What really is "verification" in that case? "The user is legally entitled to use this string of letters to designate themselves"?

The notability mark is useful: it means you're following basketball star Michael Jordan, which is probably what you meant. If you actually wanted to follow your brother-in-law Michael Jordan or a law professor Michael Jordan, there's really no simple binary mark that will help you separate them from each other. You'll have to do your research.

You can do also research on The Real Elon Musk Who Has Billions Of Dollars And Isn't Giving Any Of Them To You, and I honestly don't know if there's any way to help people who can't figure that out. But I could see Twitter at least wanting to try to help save people from themselves, because the bell curve has two tails.

Other than that... I'm not sure what any kind of verification really does. Maybe a dating app can help save you from wasting your time, because the whole point is that you're meeting strangers, some of whom will be bad people who get booted repeatedly. That's a completely different use case.

Post reply on HN