Live data from Hacker News

Who owns your ATProto identity?

kevinak.se

61–70 of 159 posts

Re: Who owns your ATProto identity?

#61
post #22

Is author new at the whole web thing? Yes, people trust remote web servers. Yes, if you link multiple apps to an identity server (be it atproto, google, or self-hosted OpenID server), and your identity server is compromised, attacker will be able to impersonate you or lock you out. This is just how the web works, and there is no easy around it without losing features people care about. Sure, you can do client-side en…

> This is just how the web works, and there is no easy around it without losing features people care about [...] Well, apart from using a separate email address for every single "provider"? (Spoiler: there's no way I'm going to sign into your service with a shared email ... you get @ .com)

Some services only allow signups from the big free providers like gmail/outlook/etc. because those providers are doing more consistent KYC and anti-spam measures than anyone else by far, and unfortunately it does cut down on the amount of spam by a lot. For most people nowadays you cannot even create a new gmail account without directly linking it to a mobile phone.

Re: Who owns your ATProto identity?

#62
post #56

Earlier quoted context omitted.

Bluesky / AT is the most successful open social network in history and the only one to become culturally significant. It has been adopted by presidents, celebrities, journalists, and mainstream users. Bluesky has ~50M registered users and has sustained ~5M monthly active users for long while. There's no reason to believe it will fall substantially below this level. It is also in the process of adding (decentralized)…

"Registered users" is a meaningless statistic. Daily active users has consistently declined.

I'd be the last person to downplay the fact that the Bluesky app has a serious retention problem. But it has "broken through" in an incredible way and DAUs/MAUs are quite stable.

Registered users is not at all meaningless. Bluesky has those user's email addresses, the mobile app is still installed on many of their devices, they have accounts, and they can potentially be reactivated.

For example, if Bluesky announced a feature exciting enough, like subcommunities, it could email those 50M users and possibly bootstrap a serious open network competitor to Reddit.

Re: Who owns your ATProto identity?

#63

Earlier quoted context omitted.

"This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, like UFO sightings in the 1950s. If ever it is still possible to "tell" AI writing, it soon will not be. So best (IMO) just to respond to the substance of the writing and move on.

> "This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, Being able to tell who wrote something doesn't imply irrationality, panicking, or a reaction to new technology. > like UFO sightings in the 1950s. UFO sightings stayed confined to the 1950s and were a reaction to new technology? Or were the UFO sightings in the 1950s the only UFO sightings that were a reaction…

I think the main problem is you can't really ever tell with a high degree of certainty, people are just guessing based on what they see in an unscientific way. And the fact that AI is trained on human data, meaning what we see is in fact things humans have already done themselves, makes it even harder to "know" for certain IMO.

Re: Who owns your ATProto identity?

#64

Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your P…

This "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.

Personally I think it should be optional, but meaningfully optional in a way that's technically sound and easier than it is now. I kind of feel like long term I'd want "professional/public" code I'd put my name on, and separate code I'd work on under a pseudonym/handle.

Re: Who owns your ATProto identity?

#65

Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your P…

> Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account Even with GitHub we don’t hand over our private keys to the GitHub server, though. When I commit to my repos the commits are still signed by the private key that lives on my computer. Someone could take over my GitHub account and they wouldn’t be able to sign commits with the private key on my PC. They co…

right but that's possible with tangled too, that's a git specific thing

Re: Who owns your ATProto identity?

#66
post #4

This is where non-financial use of blockchain could really shine, IMO. Self-sovereign identity management with a smart contract-based process for recovering ids if keys get lost or hacked. Blockchains are pretty out of favor these days, but I really don't see a better solution for decentralized identity management.

What is the incentive for an individual to participate in a non-financial blockchain? Bitcoin-style blockchains “work” because everyone gets the possibility of a little reward for all the hassle and non-negligible CPU time of being a node.

For me the incentive is being able to own an identity that nobody can take away from me. And the assumption is that services will support this type of identity, so I don't have to make accounts on other systems that people can take away and now I've lost all access to any data I had.

Re: Who owns your ATProto identity?

#67

Earlier quoted context omitted.

"This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, like UFO sightings in the 1950s. If ever it is still possible to "tell" AI writing, it soon will not be. So best (IMO) just to respond to the substance of the writing and move on.

> "This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, Being able to tell who wrote something doesn't imply irrationality, panicking, or a reaction to new technology. > like UFO sightings in the 1950s. UFO sightings stayed confined to the 1950s and were a reaction to new technology? Or were the UFO sightings in the 1950s the only UFO sightings that were a reaction…

So I just read the article a bit more closely, and personally I see no reason to panic like you (and others here) are doing. The AI suspicion was presumably triggered by one of the subheadings, which follows the "It's not X, it's Y" schema. At this point it's almost a meme that this betrays AI.

But I say: who cares? The substance and the authenticity are what count. This article made some interesting points, and it was signed off on by a human author. Personally, I'm no more interested in whether the author used AI to produce the text than in whether they used a dictionary or thesaurus, as long as they stand by the words.

This whole "debate" has the feel of religion to it. I'm consistently surprised that there's so much woolly, unfalsifiable thinking on this subject. And here, of all places.

Re: Who owns your ATProto identity?

#68
post #56

Earlier quoted context omitted.

"Registered users" is a meaningless statistic. Daily active users has consistently declined.

I'd be the last person to downplay the fact that the Bluesky app has a serious retention problem. But it has "broken through" in an incredible way and DAUs/MAUs are quite stable. Registered users is not at all meaningless. Bluesky has those user's email addresses, the mobile app is still installed on many of their devices, they have accounts, and they can potentially be reactivated. For example, if Bluesky announced…

A chunk of these registered users are apparently "ghost accounts" hosted on a PDS on a trump.com subdomain.

https://bsky.app/profile/tyggero.cz/post/3moskpisnuc2t

Source: https://sifa.id/stats

Statement from Bluesky: https://bsky.app/profile/pfrazee.com/post/3mmp27wwnic2j

Re: Who owns your ATProto identity?

#69
post #10
post #8

Centralization is always a trap. No idea why people have such a hard time joining and supporting the Fediverse.

Because there is no single "default instance that is always a good choice and wouldn't go down randomly because of lack of funding". That's both a strong and a weak side of fedi

mastodon.social has been around for a decade now, seems stable enough.

Re: Who owns your ATProto identity?

#70

Earlier quoted context omitted.

> "This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, Being able to tell who wrote something doesn't imply irrationality, panicking, or a reaction to new technology. > like UFO sightings in the 1950s. UFO sightings stayed confined to the 1950s and were a reaction to new technology? Or were the UFO sightings in the 1950s the only UFO sightings that were a reaction…

I think the main problem is you can't really ever tell with a high degree of certainty, people are just guessing based on what they see in an unscientific way. And the fact that AI is trained on human data, meaning what we see is in fact things humans have already done themselves, makes it even harder to "know" for certain IMO.

> the main problem is you can't really ever tell with a high degree of certainty

This is false, it is trivial to find humans with 99%+ accuracy[1] and there is a well-known service with 99%+ accuracy when analyzed by 3rd parties with no affiliation.[2]

> people are just guessing based on what they see in an unscientific way

As we see above, this is just guessing in an unscientific way. :) It's important to be rational! We all agree on that. :)

FWIW it did used to be true that the 3rd party services were junk. And I don't support the idea of humans just winging it when there's consequences. The case we're in is about the most mundane and consequence-free, the vast majority of us use AI daily and we're commenting on an internet aggregator that is aggregating a blog article.

[1] People who frequently use ChatGPT for writing tasks are accurate and robust detectors of AI-generated text - https://aclanthology.org/2025.acl-long.267/

[2] Artificial Writing and Automated Detection” - https://bfi.uchicago.edu/insights/artificial-writing-and-aut...

Post reply on HN