Tedium - Stupidest Drama Ever 😖

Bad news, Bluesky fans: It has an extortion problem.

Hunting for the end of the long tail • December 17, 2024

Stupidest Drama Ever

An apparent extortion scheme involving famous writers and entrepreneurs lit up Bluesky the other night. It raises some important questions about whether Bluesky is up to the task of moderation.

Bluesky, until now, has had a reputation as being a more moderation-friendly alternative to X, Threads, Mastodon, and other social networks.

But what happens when the pedal is put to the metal, and shady figures attempt to test the network’s ground rules?

You may not find the results to your liking. That was a realization I made this week after getting an up-close view of an extortion attempt involving a prominent journalist and a well-known entrepreneur.

The initial message that Conor Sen received that kicked off this whole mess.

Here’s what happened: On Monday night, Bloomberg columnist Conor Sen announced on his account that he had been the targeted by an extortion attempt on Bluesky. Someone had purchased his namesake domain and was attempting to sell it back to him. I replied to the thread suggesting a couple of next steps for Sen, only to get an unusual reply: Sam Parr, the founder of The Hustle, suggested that he should give in to the extortion attempt, and that it was in fact not extortion. If Sen cared about his online identity, he should pay $10,000 to $25,000 to protect his identity.

This created a lot of back-and-forth between me and Parr, and led others to criticize the “braindead” take.

The real Sam Parr warning about the fake Sam Parr.

Turns out, it was all part of the scheme. The user had spent weeks building up accounts and buying up domains, then going after prominent blogging personalities. When the actual Parr showed up, the fake Parr started using the other sockpuppets to go after the real Parr, pushing him to buy the fake account.

The user took advantage of a disparity in the incomplete transition between X, formerly known as Twitter, and Bluesky, where a lot of real people are, but some prominent personalities have not yet shown up. And Bluesky, being put to the test, absolutely failed.

The fake Sam Parr attacking me for drawing attention to the impersonation.

It took hours for the network to do something about the obvious extortion attempt. When the real Parr showed up, the fake Parr tried to make it seem like he was the real one. And Bluesky’s moderators … blocked the actual Parr, not the fake one. At this point, I was fully engaged in the mess, and the attempted extorter was not happy about it.

At one point, he wrote to me: “You inserted yourself into something that didn’t concern you at all, drama queen.”

After he did that, I inserted myself again—on a post where a Bluesky employee was announcing a new moderation feature specifically related to verification, in which I screenshotted an interaction on X with Parr. That did the trick—the fake Parr was finally banned soon after.

It goes deeper than Conor Sen and Sam Parr, though.

This is not Matt Yglesias’ newsletter and that is not his domain.

A quick analysis of different websites and accounts shows that the user appeared to be impersonating and/or buying the domains of at least five other prominent creators:

  • Matt Yglesias, the well-known political blogger, who has experienced the issue with both his namesake domain and the Slow Boring Bluesky account (which is fake)

  • John LeFevre, an investment banker and prominent tweeter

  • Collin Rugg, an investor and owner of the conservative news site Trending Politics News

  • Alex Lieberman, the cofounder of Morning Brew

  • Sahil Bloom, a prominent author and investor

Outside of Yglesias, there’s a clear “type” at play, targeting people with backgrounds in business, investing, and entrepreneurship. (For disclosure, Tedium has been sponsored by Morning Brew in the past and just ran an affiliate ad for The Hustle last week.)

Some of these people own their domains; some of them don’t. The scheme is exploiting those that don’t.

Whoever is doing this is running a very aggressive scheme, one that Parr (in messages to Sen that the Bloomberg journalist publicly shared after the fake Parr was banned) compared to an infamous Twitter troll that was recently sued by a prominent real estate investor. I have no way of easily confirming it’s the same person—apparently, the person who sued spent a lot of money to uncover the troll—but it may be worth keeping in mind.

Usually we make our annual last-minute gift guide, a highlight of some of the year’s best issues, its own issue, but this year we thought we’d force you to visit the site to see it. Check it out here—and learn why you might be getting a forgotten cousin a vintage woodgrain cable box this year.

What all this means for Bluesky

Ultimately, I want to broaden the discussion here to highlight how this situation really undermines Bluesky’s reputation of being structured more effectively for moderation. For one thing, its success has led to the rise of questionable parties purchasing domains of known individuals. This is known as cybersquatting, and has been illegal in the U.S. for more than a quarter-century, thanks to The Anticybersquatting Consumer Protection Act of 1999. The problem is, the legal recourse around trying to mitigate these issues can be costly.

Cybersquatting is not a new issue, of course, but Bluesky’s decision to tie verification to domains as social proof shows the limitations of the strategy. After all, if Conor Sen doesn’t want to register his namesake domain, it just takes one questionable party to do it instead, put up a fake email signup form, and register an account. Domains simply don’t offer enough in the way of social proof for the average person. Bluesky needs to invest in ways to emphasize social proof more prominently, as well.

“The domain verification thing just isn’t going to work; they’re going to need something else,” Sen told me over DM.

The fake Conor Sen website, with a signup box that Sen does not own or control. Not linking for obvious reasons.

But even beyond that, the moderation response to this issue has been dreadful. Sen, who once worked on eBay’s trust and safety team, was dealing with the fake Parr harassing his account for nearly a day before Bluesky banned it. (The illegitimate ConorSen dot com website is still online, and promoting signups to a fake list.) And embarrassingly, when Bluesky took action, the network banned the actual Parr, not the fake one, which the fake account was then able to use to further harass Sen. The Bloomberg journalist ended up having to contact higher-ups at Bluesky publicly to help draw attention to the issue, but other fake accounts related to this incident remain online as of this writing.

“Unfortunately, I didn’t find Bluesky support very helpful, never got a response,” Sen added. “And the fact that I reported the fake Sam but it was the real Sam who got temporarily blocked wasn’t a good sign.”

Sen, Yglesias, and others shouldn’t have to be stuck with anonymous users trying to fake their identities on domains that aren’t theirs. And worse, the weight that Bluesky puts on domains is leading to impersonation fraud and cybersquatting involving domain registrars, which will be significantly harder to navigate and may require access to the legal system to resolve. I don’t think they intended it that way, but Bluesky’s use of the domain system for user verification passes the buck in a dangerous way.

It’s a goddamn mess, and it makes me appreciate why some people may want to skip Bluesky altogether. I’ve been a booster of the network so far—but they need to get this figured out, or all the prominent people who have put their stake over here may find themselves looking for the exits.

Non-Social Links

The ultimate cat-and-mouse game of the 1990s, the Kevin Mitnick FBI files, have been publicly released by the agency.

Credit where credit’s due: Saturday Night Live has had some excellent scripted sketches this season. I particularly liked this one about a magic car, inspired by The Love Bug, that turns out to be very much of its time.

I’m going to skip the AI-flavored Oreos.

Find this one an interesting read? Share it with a pal! And if you haven’t yet, our annual last-minute gift guide still makes for a fascinating read.

Share this post:

follow on Twitter | privacy policy | advertise with us

Copyright © 2015-2024 Tedium, all rights reserved.

Disclosure: From time to time, we may use affiliate links in our content—but only when it makes sense. Promise.

unsubscribe from this list | view email in browser | sent with Email Octopus

Older messages

Don’t Strip-Mine The Sky ☁️

Tuesday, December 10, 2024

Bluesky could be the Craigslist of social media—in a good way. Here's a version for your browser. Hunting for the end of the long tail • December 05, 2024 Don't Strip-Mine The Sky More thoughts

Do General Audiences Exist? 🎬

Tuesday, December 10, 2024

They're making way fewer G-rated films than they used to. Here's a version for your browser. Hunting for the end of the long tail • December 08, 2024 Today in Tedium: In the fall of 1968, the

How Giants Fall 📉

Tuesday, December 3, 2024

The CEO of Intel retired out of the blue. That doesn't sound good. Here's a version for your browser. Hunting for the end of the long tail • December 03, 2024 How Giants Fall The departure of

Belated Expansion 🕹️

Monday, December 2, 2024

Why a forgotten expansion port on a famous console is emerging now. Here's a version for your browser. Hunting for the end of the long tail • December 02, 2024 Hey all, Ernie here with a mea culpa.

Power User Vs. Strong POV 💻

Saturday, November 30, 2024

Elementary OS doesn't work like most Linux distros. Here's a version for your browser. Hunting for the end of the long tail • November 29, 2024 Power User Vs. Strong POV The just-released

You Might Also Like

Daily Coding Problem: Problem #1703 [Hard]

Thursday, February 27, 2025

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Goldman Sachs. Given a list of numbers L , implement a method sum(i, j) which returns

Charted | The $124 Trillion Global Stock Market, Sorted by Region 📊

Thursday, February 27, 2025

In this graphic, we show the world's 48000 publicly-traded companies, collectively valued at $124 trillion. View Online | Subscribe | Download Our App Enjoying Visual Capitalist? You'll love

AI CAPTCHA Fails Are the Internet’s New Comedy Show!

Thursday, February 27, 2025

Top Tech Content sent at Noon! Boost Your Article on HackerNoon for $159.99! Read this email in your browser How are you, @newsletterest1? 🪐 What's happening in tech today, February 27, 2025? The

Say Goodbye to Type Erasure

Thursday, February 27, 2025

View in browser 🔖 Articles Practical Kotlin: When and How to Use inline reified, noinline, and crossinline Master Kotlin's inline reified functions to tackle type erasure and boost performance!

SRE Weekly Issue #464

Thursday, February 27, 2025

View on sreweekly.com A message from our sponsor, incident.io: For years, on-call has felt more like a burden than a solution. But modern teams are making a change. On Feb 26 at 1 PM EST, hear why—and

Hands On: New VS Code Insiders Build Creates Web Page from Image in Seconds, More

Thursday, February 27, 2025

Home | News | How To | Webcasts | Whitepapers | Advertise .NET Insight February 27, 2025 THIS ISSUE SPONSORED BY: ■ Visual Studio Live! Las Vegas: .NET Developer Training Conference ■ VSLive! 4-Day

Re: Tomorrow's Password Class: How to sign up!

Thursday, February 27, 2025

Hi there, Do you reuse passwords? Do you struggle to remember unique passwords across accounts? Have you tried setting up a password manager but found it to be a hassle? You might not realize how

Documenting Event-Driven Architecture with EventCatalog and David Boyne

Thursday, February 27, 2025

If you're wondering on how to document Event-Driven Architecture, or you don't know that you should, I have something for you. We discussed with David Boyne, why data governance practices and

wpmail.me issue#708

Thursday, February 27, 2025

wpMail.me wpmail.me issue#708 - The weekly WordPress newsletter. No spam, no nonsense. - February 27, 2025 Is this email not displaying correctly? View it in your browser. News & Articles Shaping

Hackers stole 1Password logins - here's how

Thursday, February 27, 2025

Amazon AI races ahead; Research agents; Smartwatch trade-in -- ZDNET ZDNET Tech Today - US February 27, 2025 thief stealing passwords Hackers stole this engineer's 1Password database. Could it