Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent users from impersonating old account when moving to custom domain #1704

Open
DeckardHoliday opened this issue Oct 3, 2023 · 2 comments

Comments

@DeckardHoliday
Copy link

Is your feature request related to a problem? Please describe.
One of the biggest concerns I've seen people have about attaching their account to their own domain is people using their same account name on bsky.social to impersonate them. Many have created a dummy bsky.social account to prevent this. 

Describe the solution you'd like

  • If you sign up with Bsky.Social and add a domain later: Auto forward the previous Bsky.social account to the new one

  • If you sign up with a domain at the start: Add a field for a bsky.social username that will be forwarded? (Not sure about this one, but something along those lines)

Describe alternatives you've considered

As I said before, most people just make a dummy account and have a single post to notify users where their main account actually is. I've done this as well so no one can use my business name account to impersonate me.

Additional context

I imagine the intent is that by attaching your domain that would be considered the 'verified' account, and any other account would be assumed to be an impersonation or not the real account, and then the impersonation warning would pop up if that was detected/reported. The problem is that the fear of impersonation is what is preventing the people I know from ever using their domains for their BSky accounts.

I'm not sure the best way to go about this, but I think the account forwarding would help people feel that they are safe to bring in or create their own domain? But I'm also seeing this as a potential avenue for exploit/abuse of this kind of system so I'm not entirely sure the direction.

@pfrazee pfrazee transferred this issue from bluesky-social/social-app Oct 3, 2023
@pfrazee
Copy link
Collaborator

pfrazee commented Oct 3, 2023

I'd personally be in favor of this, I think it's low cost and decent benefit

@mschwendener
Copy link

mschwendener commented Oct 3, 2023

For me, it's the main reason that I haven't tried changing my handle to my existing custom domain.

If it can't be done automatically, let me decide if the old handle can be reused or should be blocked from being reused.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants