Can anyone explain why the verified status isn't tied to key account information, such as the password and email address associated with it? Seems that hacking a twitter account for this sort of thing would become immensely less valuable if the account would effectively automatically lose the verified status upon being taken over.
Huh? So if I change my email and/or password I lose my identity? Flag it in the system to keep a closer eye on it sure, but you're thinking about an edge case that makes the experience exponentially worse for the normal person.
Maybe not tied to just one of those, but it seems that 'password changed + email changed + sudden increase in posting' is a pretty strong signal that the verified status should be questioned again.
It's because Twitter company has never cared about anything related to experience of using Twitter. It's just a dumb megaphone network with Engagement A/B tested hacks.
I’m surprised becoming verified doesn’t require something akin to Google’s enhanced protection program (e.g. requiring 2FA not including SMS, delaying password reset notifications, etc). I don’t think the average Twitter user needs to be subjected to that, but verified accounts being taken over have a bigger blast radius than just the individual losing their account; the scammers get notoriety and legitimacy with that blue check.
Detecting impersonation on Twitter is hard for users, but trivial for Twitter to do at Name/photo change time. They just don't care.
Name changes shouldn't even be atomic, at least for Blue Checks. Twitter UI should show "recently changed name" for a week. (And yes, I've thought about this is not unfair deadnaming. Celebrities shouldn't get to hide their name changes.)
Comments
Can anyone explain why the verified status isn't tied to key account information, such as the password and email address associated with it? Seems that hacking a twitter account for this sort of thing would become immensely less valuable if the account would effectively automatically lose the verified status upon being taken over.
Huh? So if I change my email and/or password I lose my identity? Flag it in the system to keep a closer eye on it sure, but you're thinking about an edge case that makes the experience exponentially worse for the normal person.
Maybe not tied to just one of those, but it seems that 'password changed + email changed + sudden increase in posting' is a pretty strong signal that the verified status should be questioned again.
Well at least tie it to the account name.
Some people change their account name on Twitter pretty often, since they use an alias, pun, etc. as their display name instead of a real name.
Yes but "Verified Account" means nothing if the name... isn't verified. Name verification is the the only purpose of Verification.
It's because Twitter company has never cared about anything related to experience of using Twitter. It's just a dumb megaphone network with Engagement A/B tested hacks.
I’m surprised becoming verified doesn’t require something akin to Google’s enhanced protection program (e.g. requiring 2FA not including SMS, delaying password reset notifications, etc). I don’t think the average Twitter user needs to be subjected to that, but verified accounts being taken over have a bigger blast radius than just the individual losing their account; the scammers get notoriety and legitimacy with that blue check.
Detecting impersonation on Twitter is hard for users, but trivial for Twitter to do at Name/photo change time. They just don't care.
Name changes shouldn't even be atomic, at least for Blue Checks. Twitter UI should show "recently changed name" for a week. (And yes, I've thought about this is not unfair deadnaming. Celebrities shouldn't get to hide their name changes.)
Account was hacked for yet another NFT scam.
There is no legitimate reason to allow this on an active account. This only happens on a hacked account or an ownership dispute. Freeze the account.
Especially a "verified" account.
Funny how i got NFT ads on this article.