@Bradley_JF @willoremus this makes the bot problem worse in every way
Go to Twitter now, and it’s basically impossible to find quality replies to tweets. Twitter surfaces blue check accounts and all the top blue checks are 0 follower accounts spewing rightwing content
In the very unlikely event that I remember I'll bookmark this post so I can update with what actually happens.
The change to polls is more likely to be of a concern to people I think.
@willoremus
Mastodon doesn't need any more toxic twitter blowins, moaning about how not twitter it is and then revelling in dragging their reinforced 144 character biases and pettiness to the table.
Let them roll around in their pig shit with Napoleon and the dogs, this is Snowball town.
@willoremus So the only way to have something I never wanted in the first place is to become "verified". Which means forking over money.
Thanks but no thanks. Is there anything else I never wanted that you wish to withhold from me, Muskrat?
@moontzu @willoremus Only paid users will be allowed to have SMS-based 2FA. TOTP is still (currently) free.
Which is a weird "plus" of paying: you can use a 2FA method that's generally recommended against.
I dunno: I got my (now 75yo) mom using TOTP-based authentication a couple years ago, now. It wasn't *too* painful.
Yeah, it's not actually difficult to use an authenticator app instead of SMS. But for some users, any amount of friction will keep them from implementing new security measures.
It took me a while to transition from SMS 2fa on most things simply because SMS requires the absolute LEAST setup, even though the difference in effort is miniscule and honestly the authenticator is faster in use because I'm never waiting for something to come through.
I switched to TOTP, early, because I generally can't bring my phone into my customers' facilities. Most are subject to one form or another of data-privacy compliance-requirements – either due to industry-prescribed requirements or legal ones. With TOTP, I can use a tool like Authy (on a web-reachable virtual desktop) to provide the requisite portability (and then protect the desktop's login with a USB key).
I've also had a couple different problems with SMS:
1. Codes can take a few seconds or they can take SEVERAL minutes (sometimes longer than the sent code's TTL)
2. Many site's SMS destination-validator's don't like my phone-number because I use VOIP-apps instead of my phone's native dialer. Even if I were to use my SIM's number, because I use a reseller of T-Mobile, the numbers aren't actually treated like T-Mobile numbers (and get treated as not valid by some validators).
Yeah. I use `Fi` for my SIM, and, even though it's T-Mobile, not every site (particularly banks', for some reason) seem to accept that it's a valid, SMSable number.
But I further complicate that by using a VOIP app to handle both my calling and SMS (because the option to use ZRTP is nice to have).