It’s a lot harder problem then it might sound on the surface. And realize if you find bots 100%, they will change for round 2 and the game starts over.
It’s a lot harder problem then it might sound on the surface. And realize if you find bots 100%, they will change for round 2 and the game starts over.
(Assuming Twitter was actually incentivized to be anti-bot/bot-like behavior.)
And it wouldn't even stop the bots, because Twitter isn't limited to Americans, so bot makers could easily send fake official IDs from someplace Twitter can't check. Or send stolen offical IDs from other data breaches.
You can generate realistc photos of IDs from countries that Twitter cannot positively verify those bc in USA there are ways to check authentity of your document. But IDs from Russia or Ukraine - no way.
That would work only against casual bots. The big nation-sponsored botnets won't have issues with providing genuine government issued identities for bots. Which kind of defeats the whole purpose and wastes a lot of resources twitter would like to use elsewhere.
Just put in a super basic unlock process that is costly to game for "non-real" people
I think your "just" is hand-waving away a lot of complexity. A person deployed these bots, and if a bot account gets put into an arbitration process, that person can go through the process themselves to pass the arbitration, then set the bot running again.
That is not scalable, which is exactly the point.
Whenever I sign up at Twitter (entirely because some companies do support there) the account is flagged within a few minutes for "suspicious activity", such as making a coffee and coming back to the PC or searching for the company I want to contact.
They also have so many phone number and email they can use that to do additional checks.
They you can use the network effect: bots usually have something in commons: topics, likes, ip, followers...
If you have millions at your disposal, something can be done.
They are not, so I'm more encline to assume there is benefit for them to avoid doing so.
This information would not need to be stored, it would just be needed to verify an account as belonging to a real person.
Think about an account that is active 24/7 every day all year, or one that fires off multiple actions per second for long periods of time.
Beyond that, having a limited vocabulary, repetitive phrases, consistently accessing the same thing every few minutes, etc. are all low hanging fruit.
Arguably, those "legitimate" users don't bring anything of value to the platform or society as a whole and should rightfully be shunned.
Most online forums or chats have automated rules whereby posting too fast or too often will get you slowed down or banned. Sometimes legitimate users get caught by the filters, no big deal. Twitter could make their existing rules much more stringent.