







@wsocial.eu - I was one of the first to subscribe after Davos, but now I wonder what's the use of WSocial. We had to show our ID to get access, but now it seems there are many backdoors without the need for verification. Maybe I just go back to Mastodon. Nice try, but I feel a little betrayed.
Jul 4, 2026 at 6:57 AM
Elena Rossini 🌈 (@_elena@mastodon.social)
Attached: 2 images I just refreshed the #WSocial website and it's showing a MAJOR redesign... with a label at the top stating "built on the open AT-protocol." This is the first time ever they acknowledge this – I know, as I've been visiting their website for MONTHS and also never heard about this in any interviews. So the claims in my exposé stand (the Internet Archive's Wayback Machine would confirm this). Of note: they changed their URL from wsocial.eu to wsocial.news BTW thanks for all your feedback ❤️
WSocial could change everything - matlfb.com
In early 2026, the European Union announced its own Twitter-like platform called WSocial. The most surprising part is that it is expected to be a fork of Blu...

Elena Rossini 🌈 (@_elena@mastodon.social)
Do you remember the surprise announcement of a new social network in Davos this past January? Something that promised to be the "first" European social network? Its name is #WSocial and it's a fork of #Bluesky. Its founders have ties with European politicians - but there is no official involvement by the EU. You wouldn't know any of this from media reports because they all rehashed their talking points. So I wrote a post about it, dispelling some myths: https://blog.elenarossini.com/w-social-uncovered-the-reality-behind-the-hype/ #OpenWashing
Elena Rossini 🌈 (@_elena@mastodon.social)
Scoop: #WSocial has been experiencing major technical problems for over a week: it is effectively a ghost town, filled with thousands of new accounts that cannot use the platform. Because my new article contains a possible solution to their problem, by the time you read this the issue may have been fixed. Or not. It has been going on for 7+ days, with complete radio silence by its developers and founders. My exclusive: 🔗 : https://blog.elenarossini.com/w-social-a-broken-ghost-town/ #SocialMedia #ATproto #RateLimiting
Aral Balkan (@aral@mastodon.ar.al)
Attached: 1 image Needless to say, do not sign up for W or give them your ID information no matter how simple they eventually manage to make it. You simply don’t need to. You’re already in a far superior – non-corporate, federated – space. Do not sign up for W. And warn your friends. The only time you have any power to stop this is now. If they succeed in gaining network effects, you will be as powerless to stop them as you are with X. And yes, they’re just another venture capital funded surveillance capitalist, people farmer, and burgeoning Nazi Bar. They just happen to be based in the EU. (As Nazi Bars traditionally have been.) #WSocial #NoWNoX #surveillance #capitalism #BigTech #VC @_elena@mastodon.social https://mastodon.social/@_elena/116770291207686239

Elena Rossini 🌈 (@_elena@mastodon.social)
SCOOP: #WSocial is doctoring metrics on its homepage, inflating the number of comments on posts by prominent people on its network. I suppose a more accurate tagline for them should be "Trust your feed?" My article about it: "W Social, Fictional Metrics and the Beauty of Open Data" 🔗 : https://blog.elenarossini.com/w-social-fictional-metrics-and-the-beauty-of-open-data/ #blog #BigTech #EUBigTech #TEP #TrustedEuropeanPlatforms #TrustYourFeed
⠠⠵ avuko (@avuko@infosec.exchange)
@elena@aseachange.com @aral@mastodon.ar.al I couldn't resist, so I've wasted my precious time looking at "W Identity" today. Things are not right. It is basically a repurposed https://github.com/PeterWaher/IoTGateway Just look here: https://root.widentity.eu/Settings/Master.md It has a socks4(?) open on port 1080, some xmpp stuff on 5222 and 5269, another (seemingly broken) version of the website on 8088. The following pages are accessible without auth: (found by a simple "`egrep -LR 'Privilege:|Login:' * |grep md | grep Root`" through the source) ``` /Settings/PersonalData/LocalDatabase.md /Settings/PersonalData/LocalSensorsAndDevices.md /Settings/PersonalData/EventLogs.md /Settings/PersonalData/NetworkIdentity.md /Settings/PersonalData/WebPages.md /Settings/PersonalData/Backups.md /Settings/Master.md /Copyright.md /Starting.md [http response 307] /Login.md /Entities.md /Templates/Repeat.md /AdminDropdownComponent.md /Script.md /AdminDropdown.md /AlertPopup.md /Master.md /PromptPopup.md /ConfirmPopup.md /Markdown.md /Emojis.md /Smileys.md /Index.md /MarkdownEditor.md /ScriptColors.md /Master.md ``` Others pages also exist (no 404), but are only available after login. Which brings me to the biggest problem of all. This is an **ADMIN** interface. Nobody should **ever** put an admin interface to an identity management platform on the internet. #WSocial #Widentity
Interesting point: "The only way to make sense of the European Commission's embrace of WSocial is that maybe it sees it as a trial run for MANDATORY age verification for social media across the European Union." @elenarossini.com
Elena Rossini on GoToSocial ⁂ (@elena@aseachange.com)
aseachange.comIf WSocial sold people on the idea that everyone they would interact with is ID-verified, then indeed, every single open ATProto community would act as a back door of sorts. The only way for them to deliver would be to de-federate entirely. And it's always a bad idea to bet against openness.
Wimster9030 🇪🇺 🇧🇪
I know, Daniel, but that's not the way WSocial "sold" it to us. We could only access trough ID-verification so we know for 100% they are EU and a "real person". That was the whole point. So we went trough that process, but now it seems that the backdoor are the other ATProt platforms to get in too.
It looks like W Identity, the part of @wsocial.eu that checks your papers before you go in, has a very basic XSS on its admin backend, found hours after launch. This seems almost too predictable... Cyberfriends, any thoughts on how bad? 23.social/@kantorkel/116767220594438841
kantorkel (@kantorkel@23.social)
23.socialHoly fucking shit guys im a W Social trusted verifier wsocial.eu/profile/scanash.com
Scan
W Social is the biggest lie on the AT Protocol
Holy fucking shit guys im a W Social trusted verifier wsocial.eu/profile/scanash.com
Scan
W Social is the biggest lie on the AT Protocol
This is a rough draft of a thought, but my sense of #WSocial is that it is an attempt to enclose the commons. By cultivating the idea that WSocial is only humans and bots are the primary drivers of mis/disinformation, they're establishing a framework which accomplishes two things:
Elena Rossini ⁂
Some thoughts on #WSocial, how they have been responding to criticism and why I believe they are showing the limits of free speech absolutism. I agree with @echna.bsky.social that "W Social seems to be on an X speedrun - without ever having been like Twitter." 🔗: aseachange.com/@elena/statuses/01M0SDV98GRDW…
This is a rough draft of a thought, but my sense of #WSocial is that it is an attempt to enclose the commons. By cultivating the idea that WSocial is only humans and bots are the primary drivers of mis/disinformation, they're establishing a framework which accomplishes two things:
Elena Rossini ⁂
Some thoughts on #WSocial, how they have been responding to criticism and why I believe they are showing the limits of free speech absolutism. I agree with @echna.bsky.social that "W Social seems to be on an X speedrun - without ever having been like Twitter." 🔗: aseachange.com/@elena/statuses/01M0SDV98GRDW…
@anna.wsocial.eu looks like bluesky is no different to X bot spamfest. Wsocial ABSOLUTELY needs to have a toggle in the settings to HIDE non-verified users. In other words there should be a way to interact ONLY with wsocial users without any other servers on AT.