Leaflet said I wrote this 3 months ago but I forgot to publish it. Sorry?
Hey everyone, Bit here. On social media such as Twitter (X), sometimes there will be impostors. I've had many accounts spamming me on X about a supposed "X Token" or "X Coin" cryptocurrency because of the (moderate) hype around X's upcoming financial platform, XMoney.
How do we fix that, making sure we can know who's the right person?
TwiXter's closed/flawed verification systems
We should probably mention the elephant in the room, X.
On X, there's the blue/gold checkmark. Sadly, those require subscription memberships (XPremium/Verified Orgs) and in some cases minimal actual verification. Basically the blue checkmark is just a sign you're an XPremium member.
Used to X (and Twitter before it) had blue checkmarks, and they were only given out to notable companies and individuals. For example, James Spann (notable weatherman) had a checkmark on Twitter before they changed the scheme to require Twitter Blue (now XPremium) membership.
Bluesky's Trusted Verifiers System
Now, Bluesky does have a centralized verification system in the form of their Trusted Verifiers system. Accounts like (Bluesky PBC themselves) and (New York Times) have a flowered checkmark, meaning they're one of the Trusted Verifiers and can give people a normal circle checkmark. Only Bluesky PBC themselves can give out Trusted Verifier status, and they can also give out a normal verification (in addition to the Trusted Verifiers they delegate). Also, clicking a circle checkmark on someone's profile will show who verified them.
However, the Trusted Verifiers program is closed and entirely controlled by Bluesky PBC. How does any run-of-the-mill company verify themselves?
ATProto Domain Verification
Because of Bluesky's architecture (the AT Protocol aka ATProto), every username has to be a domain. If you see someone with a *.bsky.social username, you can actually type that username as a web address in any browser and it will open that Bluesky profile.
But what if you didn't use the domain Bluesky gave you, and instead used your own? That's how any individual or company with a web presence can verify themselves on Bluesky.
If you have your own website and want to get verified, go to Settings -> Account -> Handle -> I have my own domain. You'll then be asked whether or not you have access to your domain's DNS panel, so you can either add a DNS TXT record or a .well-known/atproto-did file.
If you don't have a domain, they're not that expensive. Gravatar makes it easy to buy a domain that leads to a link-in-bio page, and game developers (and users alike) on itch.io can use their username from there to get an *.itch.io username on Bluesky (after spending at least $10 on the platform).
I think that any moderately-sized company joining Bluesky should do this verification; it makes your account appear more trustworthy (at least to me), and it makes your account more easily searchable (someone can just search your company website on Bluesky to find you).
Anyway, that's another short blog that I'm only publishing on Leaflet since it's very much tied to ATProto/the Bluesky platform. See you next time :>