if you see "me" messaging about joining a Telegram or buying crypto, please double check the Mastodon server they're on!

I'm only on hachyderm.io, and there's now someone trying to impersonate me on a different instance, asking people to join their telegram.

remember! you can double-check that my profile belongs to me by looking at the verified links in the bio section.

if you're not familiar with how those work, any time you see a green check on a link in someone's bio you can trust that they have control over that website or page.

and you should do this for your own account!

@molly0xfff
This worked for my first account, I moved to my current server (ohai.social), and it has not worked since, despite (duh) updating the link. I checked the html on the referenced page, the verification text appears verbatim. And it worked once, before.

I know this never happens in software, but I cannot help suspecting there is a bug.

@molly0xfff Sorry to bug you but is there some massive delay in this being detected? I’ve been waiting 24 hours and it doesn’t seem to pick it up…
@molly0xfff Great tip, thanks! For some reason, I needed to delete my profile link and then re-add it to get this to work.
@molly0xfff just in case someone is reading this and wants to know how to add verified links, here are the docs https://docs.joinmastodon.org/user/profile/#verification
Setting up your profile - Mastodon documentation

Get started with your new account.

@molly0xfff but having "something" show up green there is pretty easy to replicate. And if people do not know your home server they might also not know what other URLs are "you".

This is one of the hard problems to solve, I think.

@molly0xfff there are SO MANY big accounts that don’t take this seriously.

@molly0xfff I feel like it might be too easy to impersonate people since it's a bit of a hassle to click on the bio, then go back to the post again after checking. Not only a hassle, but also you need to know about this feature.

My first thought is that maybe accounts with a verified link should get that link, with the green checkmark, added right below their name/username, in a smaller type, on each post?

@forteller it would have to somehow display which link was verified, though. i could change my username/display name to "elon musk" and keep my currently verified sites to get a tickmark, so people would need to have enough info to be able to check that the link makes sense.

truly motivated scammers could also register some other domain like mollywhite.lol and verify that, so there are always vectors to get around it, but at least they have to work for it.

@molly0xfff Yes, I meant to display the actual link, not just the checkmark. That other part, about registering a similar URL, was something I started thinking about while writing that previous post too, but as you say, at least it's a bigger barrier. And not possible to guard against, I think.
@molly0xfff now let's say I register hachydern.io, run an instance and show fake green links with your fake profile?
@molly0xfff not that I would of course but this verified link stuff seems very fragile

@TTimo if you're just running the out-of-the-box software, you wouldn't be able to verify the links without having control over my domain.

i suppose someone could tweak the mastodon software to show falsified green links, though.

@molly0xfff yes that is exactly what I'm saying. Fishing with similar looking domains and modified server.
@TTimo yeah, certainly possible

@molly0xfff At least the birdsite finally suspended mollyOxfff... Hopefully it stays that way?

It's going to take some time for people to realize usernames in a federated system aren't fully qualified and always need to be seen in a namespaced context. Local instance accounts not showing a full username adds extra confusion/risk. I wonder if there are things that can help with usability, such as allowing tagging of "I've verified this user by looking at their profile" to display specially?

@molly0xfff Yeah I'm still out on this as well - you can verify the author has control over the page, but how can you verify "the page" is the real page? Federated still has some identity problems that were somewhat resolved with a team of paid people verifying identities.
@readonly that is the trouble with decentralized identity 😁 perhaps we should bring PGP keysigning parties back into vogue
@molly0xfff Oh boy! Can't wait to explain PGP to gran!

@molly0xfff what if, now hear me out, we paid $8 a month to be verified?

/illshowmyselfout

@molly0xfff Provided your instance can actually parse the offending page!
@molly0xfff I should figure out how that works at some point.
@molly0xfff that's pretty interesting. Doesn't seem like all clients support this functionality (pinafore doesn't seem to) 🤔
@molly0xfff Awesome, didn't know about this, thanks!