• Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      6
      ·
      19 hours ago

      Domains only help you verify organizations and individuals you recognize directly.

      This verification system also allows 3rd parties (it’s NOT just bluesky themselves!) to issue attestations that s given account belongs to who they say they are, which would help people like independent journalists, etc.

      • Saleh@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 hours ago

        Idk. Celebrities and Politicians usually have other vetted channels such as their own website or a website of their ogranization representing them. It should be basic journalistic work to see if their social media links link to the account in question or not.

          • Saleh@feddit.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            46 minutes ago

            So it is not given to a centralized authority, that is guided by for profit motives and also does the moderation of its plattform.

            Where this can lead was shown with twiiter. The moment the central organization is captured, the central authority will abuse the authentification for its own goals. Then instead of just having to check for the authentification to be reliable you need to question everything that is on that plattform as a whole, which is infinetly more consuming, but also simply impossible.

    • BackwardsUntoDawn@lemm.ee
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 day ago

      I feel like domain usernames are still inherently susceptible to phishing, you can get a typo or similar character to try and trick someone that your username is an official one

    • Nick@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      ·
      1 day ago

      I saw some small talk about it, and it really just boiled down to domain verification is great for more tech savvy folks, but trying to get larger accounts (think politicians, celebrities, etc) is a lot harder. Having a visual check, using tools within the app or site, is a lot easier.

      And personally I like the idea of verification checks as long as it remains a simple means to do just that: verify the owner of the account. Morons like Musk and his ilk always thought it was a clout thing, and for a small minority that was probably the case, but by and large before he ruined it, it was great.

    • spongebue@lemmy.world
      link
      fedilink
      English
      arrow-up
      20
      arrow-down
      1
      ·
      edit-2
      1 day ago

      If they are, and there isn’t anything to display it, how are we to know what’s been vetted and what’s slipped through the cracks? Especially on a new account?

      • MangoPenguin@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        8
        ·
        edit-2
        1 day ago

        It’s the username so already quite visible.

        For example someone at say, NPR, could use a name like @bob.npr.org which is only possible by verifying ownership of the npr.org domain name, so there is no need to vet anything.

        • spongebue@lemmy.world
          link
          fedilink
          English
          arrow-up
          10
          ·
          1 day ago

          That’s great for an organization like NPR which may have the resources to tie its own domain name into Bluesky. For some freelance reporter or otherwise verifiable person, I’m not sure it’s quite so practical.