Bluesky using domains to verify users has led to cybersquatting and impersonation, as domains don't offer enough social proof for the average person
Bluesky, until now, has had a reputation as being a more moderation-friendly alternative to X, Threads, Mastodon, and other social networks.
TediumErnie Smith
Context & Ripple Effects
Bluesky made custom domains its first paid service through a Namecheap partnership, and its later decentralization plans were also described as financially tied to domain sales. That makes the identity problem more than a moderation edge case: a product and revenue mechanism is being asked to carry trust signals it was not designed to communicate clearly to ordinary users.
The platform had already been developing trust-and-safety measures against abuse and spam in its earlier trust-and-safety work. The reported impersonation and cybersquatting show that account authenticity is a distinct usability problem, not merely a content-moderation one.
First-order effects
Users face a harder task of judging whether a domain-based handle actually belongs to the person or organization it appears to represent, while impersonators and squatters can exploit that ambiguity.
Bluesky must address the gap between technical control of a domain and the legible social proof users expect from identity verification.
Second-order effects
Public figures, brands, and institutions may face greater pressure to register and manage relevant domains defensively, raising the operational cost of maintaining an authentic presence on the network.
The weakness of domains as a standalone signal increases the value of complementary verification and trusted-account indicators—an issue reflected in Bluesky's later blue-check and Trusted Verifier program.
Third-order effects
If decentralized social networks rely on portable identifiers, they will still need platform-level trust layers that translate technical ownership into understandable identity signals.
The case underscores that moderation-friendly positioning depends partly on identity design: abuse controls cannot fully compensate when users cannot readily assess who is speaking.
The trend: Decentralized social platforms are learning that interoperable identity primitives need human-readable verification systems to function as trustworthy public networks.
Crazy story in which extortionists engage in domain squatting of famous writers on Twitter not yet on BlueSky, set up BlueSky accounts and then skeet posing as the writers. They then buy the namesake domain of another famous writer and then use the other fake accounts to pressur…
Another great example if why verifying via domain isn't actually identity verification (and is far from the foolproof solution some people insist it is)
Domain names as verification continues to be an excellent idea. Whoever could have imagined domain squatting might be a wrinkle there. No notes. [embedded post]
I've complained about this form of verification and stated it can very easily be abused and verifies nothing. Pinterest used to use the same method and was vastly abused. It's quite concerning.
Over on Bluesky, I caught a fairly up-close view of the system not working. I didn't like what I saw. — https://tedium.co/2024/12/17/bluesky- impersonation-risks/ — new @tedium
“I don't think they intended it that way, but Bluesky's use of the domain system for user verification passes the buck in a dangerous way.” — tedium.co/2024/12/17/b...
people are buying up domain names for other bluesky users and abusing bluesky's “domain verification” in an attempt to extort money out of them? and nobody at bluesky saw this coming? — wow. shocking. so glad this is the first time bluesky failed to anticipate ways their sys…
Now that he's finally been blocked, that Sam guy (not actually Sam) on here was the scammer. He was seemingly trying to play “good cop” to get me to pay the ransom, and here are DM's with the actual Sam on X. [images]
Domain name verification is dumb and it pains me that some people continue to defend this obviously dumb idea. It was a cute thought experiment in the mastodon days but it's actually bad for all the same reasons we abolished “extended validation” SSL certificates bsky.app/profil…
as of this week, when you verify your account by updating your username from a default like emily.bsky.social to your website @emilyliu.me, your former bsky.social username is reserved for you automatically (and prevents impersonators from claiming it). you can revert back to it…
I am not surprised to see some jerk try to weaponize the domain-name verification system here like this. I am surprised to see that the moderators already appear to have nuked the would-be extortionist's account. [embedded post]
flabbergasted by the mind that would impersonate a fast food brand on bluesky. going the extra mile to buy an official-sounding URL for domain verification, then complete the deception by redirecting it to the actual corporate website. who is this for, and what happened