W Social and why I hate it


So. That's a definite statement in the post title and I'm going to stand by it. I hate W Social, for various reasons. Doesn't mean you have to agree with any of it, but hopefully it'll give you some food for thought.

The premise of W Social

By-EU for-EU verified account social media, more or less. The idea is that you can only use W Social if you verify your identity; also known as showing your passport to an identity verifier and they'll go "yep, you're you!".

Why this is such a bad idea

Identity verification, in my opinion, is an awful idea that doesn't serve the purpose that many proponents claim it has. It does not "protect the children". It does not "create a safer internet". All it does is hand over your PII to an organization that will now decide if you are you. And you have to hope that this organization knows what they're doing when it comes to IT security, because well, there's enough precedent to show that most companies utterly suck at it.

And while it's one thing to get your e-mail address leaked, it'd be something different if images of your passport or ID card suddenly happen to exist ("oopsie") and get leaked ("double oopsie").

W Identity

W Identity is the honestly totally and entirely separate company registered in the same country and with the same offices and the same officers that handles identity verification. This is something to keep in mind. You'll see why later.

One of the first things that you'll see when you go to their website (widentity.eu) is that... it has this really nice aesthetically pleasing black background. And no content. Nothing. Zip. Zero. Zilch. No links to privacy policy, no links to terms of use, no links to anything that would potentially identify what the hell this company even is or does.

The only way to get to W Identity's privacy policy? A google search. It'll take you to https://widentity.eu/privacy-notice (not auto-linked on purpose). Which means that probably, something from W Social links there. Or not. But it has been referred to in the past - except, you know, it's kind of hidden.

The security issue right out of the gate

So back a while ago when W Identity was apparently test-driving a few things, they managed to catch an XSS vulnerability in their login form. Slightly simplified this means that by crafting a link to that login form that you click, I can inject content into that page that isn't supposed to be there. Things like javascript. Which means that if I send you this crafted link, it'll more than happily send you whatever data you enter into the login form - while it also still does what it originally was supposed to do. And you wouldn't know it's happening.

And all it requires? That link. I can email it to you. I could put it in a post. I could find a way to get people to click on it. XSS vulnerabilities in general aren't hard to exploit, the hardest part is convincing someone to click that specially crafted link. But now consider your parents for a minute and how often you've told them, whilst facepalming, to not click every random bullshit link they see.

Let that sink in for a minute.

I'm not entirely up on the legal aspects of this in Europe, but I'm thinking this was a reportable offense that W Identity should've reported to the appropriate data protection agencies. I don't think they have, at the very least I haven't heard or seen anything that even indicates it was given any thought or consideration.

W Social, or how I "borrowed" some code and called it good

So. The actual social site itself? That's just Bluesky's social app. W Social forked it, added some things, and then mysteriously close-sourced it. There's a blurb I found about it (that I can't seem to find again, natch!) that said the reason they closed it was to audit the code.

Now there's nothing that says you can't close source something; there's a lot of projects that are built on open source with additions that are proprietary. But for most licenses you're still obligated to publish the non-proprietary bits. In my own opinion at the very least you should make it clear what the ancestry of your own app is.

The idiocy, it hurts...

An advantage of open source is that it tends to get looked at by many eyes. Many eyes catch many things. If you want to spend money on a proper professional source code audit, then why not audit your upstream? Call it a donation to the open source ecosystem, and "be the good guy(tm)".

No. No. Close sourcing something and then auditing it is a much better idea. (I hope you can smell the sarcasm here).

Oddly enough, from experience, a comprehensive audit of Bluesky's social app? That'd be a month or two of work for a small and competent team. And yet, it's been a while longer than that since W Social did it's "for the greater good, close source all the things" bit.

So what are they doing?

Openwashing - to an extent. They're also being incredibly cagey about, well, everything. In a way that doesn't really encourage a feeling of confidence.

So what is W Social really then?

A forked copy of Bluesky's social site. And a PDS. They run their own PDS. With what I would guess is either some changes to the PDS code itself, or a proxy in front of that enforces the "you can only log in with a verified W Social account" bit. Which coincidentally also means you can't migrate an existing AT Protocol account to it.

Everything else, though, things like relays, appviews, and moderation is still handled by Bluesky's infrastructure. But W Social glosses over that in a very slimy manner.

What exactly then is your problem?!

I know this is a slightly ranty post so let me get the salient points together, and put some bullets in front, and like... organize it a little perhaps.

  • W Identity looks, smells, and feels like a scam site. There is nothing about it that makes anyone feel confident that these people know what they're doing.
  • Tied with the above, W Social put out a job posting that can be best summarized as "you need to be a vibe coder and know AI because fuck having actual experience amirite?!"; this combined with W Identity's already shoddy reputation and shoddier security handling should send anyone in their right mind running for the hills. I'll explain that after... for those of you who are still here.
  • W Social seems to be perfectly content fracturing AT Protocol. The whole idea of AT Protocol is that your identity is portable. W Social has pretty much said "nope, fuck you" to that by forcing people to create an entirely new account on W Social. No migrating to it. Which doesn't make me feel confident you can migrate away from it either. I haven't tried because I'm so incredibly not giving W Identity my passport. (Joke's on them, the embassy has it because renewal. Kek.)
  • W Social does not actually respond to any of these allegations, does not mention Bluesky, does not mention what exactly it is they're doing. Instead they (and I guess I should say Anna Zeiter, the apparenty CEO of the whole thing) only really speaks up when new EU organizations have joined W Social.
  • W Social was announced in Davos. Before really anything properly existed. This makes me feel a certain way because that's what techbro's do. Announce at some conference where your target audience is pretty much captive, make it sound good, show them the polished turd, and sit back and wait.
  • W Social is for-profit. There's investors. There's no way, on this planet, an investor will invest unless they get a return on said investment. Otherwise it'd be called a donation.

Randomish foot-notish bits

Vibe coding and security - it don't blend Doc!

If we use the most generous definition for vibe coding, the chances of there being security implications is pretty high. Why, well, because an agent is nothing more than an always-on intern. They know something. But they don't know it all. They also don't know what they don't know. So if I tell it "make me a site that verifies passports" for instance, I'm pretty sure something will come out the other end. Chances are it's full of security holes, even if they aren't obvious.

Because what happens to uploaded images? Are they temporarily stored? Are we sure that's even temporary and not forever? Does it use an S3 bucket? Did whoever do the vibing know how to securely use one? The questions go on, and on, and on.

And that's assuming...

Your PII isn't sent to another 3rd party service that does the actual verification. Because it might just be someone else. Can't find any mention of it anywhere, but... you know. It could be the case. The fact it's not actually explained anywhere makes me go hmm and should make you go hmm as well.

So why the vitriol?

Because it fucks me off that W Social is doing what it's doing when something like Eurosky exists. An open and transparent effort, headed by an actual non-profit foundation that is in the process of setting up an entire AT Protocol stack (PDS, relay, appview, social site, moderation). Did I mention open and transparent yet?

And I'm just a grumpy old fart who's seen the attitude that W Social and it's leadership seem to have play out badly a few too many times.

There's also the ever increasing amount of W Social users that are now posting about how - shudder - there's Bluesky people in their feed. And how W Social should be it's entirely own thing. And why does AT Protocol allow this?! And W Social should close AT Protocol from everyone else (okay that's a paraphrase off something I read that may not have literally said that but it kind of was implied)

The dilution of the meaning of AT Protocol and what it stands for and aims to achieve, now that's something that definitely gets on my mantitties.

And last but not least; the idea that someone has to create a new account on W Social, has to verify their passport, to be allowed through the gate into AT Protocol park, while every other app and social site just tells people "yeah no there's the grass, get on it, try not to stick your dick in it" - that is just wrong on a lot of levels. And it seems that most W Social users I've seen posts from are absolutely outraged at the fact they had to show ID to play, and none of "us" did.

TL;DR:

W Social is a for-profit, closed, non-transparent, ID verification required, rather dodgy looking alternative to uh, just about everything else. And that's bad.

<endrant>





Log in to leave a note.