/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Bluesky using domains to verify users has led to cybersquatting and impersonation, as domains don't offer enough social proof for the average person

Bluesky, until now, has had a reputation as being a more moderation-friendly alternative to X, Threads, Mastodon, and other social networks.

Tedium Ernie Smith

Context & Ripple Effects

Bluesky made custom domains its first paid service through a Namecheap partnership, and its later decentralization plans were also described as financially tied to domain sales. That makes the identity problem more than a moderation edge case: a product and revenue mechanism is being asked to carry trust signals it was not designed to communicate clearly to ordinary users.

The platform had already been developing trust-and-safety measures against abuse and spam in its earlier trust-and-safety work. The reported impersonation and cybersquatting show that account authenticity is a distinct usability problem, not merely a content-moderation one.

First-order effects

  • Users face a harder task of judging whether a domain-based handle actually belongs to the person or organization it appears to represent, while impersonators and squatters can exploit that ambiguity.
  • Bluesky must address the gap between technical control of a domain and the legible social proof users expect from identity verification.

Second-order effects

  • Public figures, brands, and institutions may face greater pressure to register and manage relevant domains defensively, raising the operational cost of maintaining an authentic presence on the network.
  • The weakness of domains as a standalone signal increases the value of complementary verification and trusted-account indicators—an issue reflected in Bluesky's later blue-check and Trusted Verifier program.

Third-order effects

  • If decentralized social networks rely on portable identifiers, they will still need platform-level trust layers that translate technical ownership into understandable identity signals.
  • The case underscores that moderation-friendly positioning depends partly on identity design: abuse controls cannot fully compensate when users cannot readily assess who is speaking.

The trend: Decentralized social platforms are learning that interoperable identity primitives need human-readable verification systems to function as trustworthy public networks.

Discussion

  • @metacurity.com Cynthia Brumfield on bluesky
    Crazy story in which extortionists engage in domain squatting of famous writers on Twitter not yet on BlueSky, set up BlueSky accounts and then skeet posing as the writers.  They then buy the namesake domain of another famous writer and then use the other fake accounts to pressur…
  • @karissabe Karissa Bell on bluesky
    Another great example if why verifying via domain isn't actually identity verification (and is far from the foolproof solution some people insist it is)
  • @hunterw Hunter Walker on bluesky
    Domain names as verification continues to be an excellent idea.  Whoever could have imagined domain squatting might be a wrinkle there.  No notes.  [embedded post]
  • @michaelmknight.com Michael Knight on bluesky
    I've complained about this form of verification and stated it can very easily be abused and verifies nothing.  Pinterest used to use the same method and was vastly abused.  It's quite concerning.
  • @bradhoward Brad Howard on bluesky
    This is a huge problem and the sooner they deal with it the better for the sites short and long term trajectory [embedded post]
  • @ernie.writing.exchange.ap.brid.gy Ernie Smith on bluesky
    Over on Bluesky, I caught a fairly up-close view of the system not working.  I didn't like what I saw.  —  https://tedium.co/2024/12/17/bluesky- impersonation-risks/  —  new @tedium
  • @ernie.tedium.co Ernie Smith on bluesky
    “I don't think they intended it that way, but Bluesky's use of the domain system for user verification passes the buck in a dangerous way.”  —  tedium.co/2024/12/17/b...
  • @awildsalem.com @awildsalem.com on bluesky
    people are buying up domain names for other bluesky users and abusing bluesky's “domain verification” in an attempt to extort money out of them?  and nobody at bluesky saw this coming?  —  wow.  shocking.  so glad this is the first time bluesky failed to anticipate ways their sys…
  • @conorsen Conor Sen on bluesky
    Now that he's finally been blocked, that Sam guy (not actually Sam) on here was the scammer.  He was seemingly trying to play “good cop” to get me to pay the ransom, and here are DM's with the actual Sam on X.  [images]
  • @hyperplanes @hyperplanes on bluesky
    Domain name verification is dumb and it pains me that some people continue to defend this obviously dumb idea.  It was a cute thought experiment in the mastodon days but it's actually bad for all the same reasons we abolished “extended validation” SSL certificates bsky.app/profil…
  • @emilyliu.me Emily on bluesky
    as of this week, when you verify your account by updating your username from a default like emily.bsky.social to your website @emilyliu.me, your former bsky.social username is reserved for you automatically (and prevents impersonators from claiming it).  you can revert back to it…
  • @conorsen Conor Sen on bluesky
    Looks like some guy is trying to do extortion on here: [image]
  • @robpegoraro.com Rob Pegoraro on bluesky
    I am not surprised to see some jerk try to weaponize the domain-name verification system here like this.  I am surprised to see that the moderators already appear to have nuked the would-be extortionist's account.  [embedded post]
  • @bobbylewis Bobby on bluesky
    flabbergasted by the mind that would impersonate a fast food brand on bluesky.  going the extra mile to buy an official-sounding URL for domain verification, then complete the deception by redirecting it to the actual corporate website. who is this for, and what happened
  • @stevetex@mastodon.social Steve Teixeira on mastodon
    This is a weakness of Mastodon verification as well... trustworthy verification is a huge need for social networks  —  https://techhub.social/...