Live data from Hacker News

Who owns your ATProto identity?

kevinak.se

71–80 of 159 posts

Re: Who owns your ATProto identity?

#71

Earlier quoted context omitted.

> "This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, Being able to tell who wrote something doesn't imply irrationality, panicking, or a reaction to new technology. > like UFO sightings in the 1950s. UFO sightings stayed confined to the 1950s and were a reaction to new technology? Or were the UFO sightings in the 1950s the only UFO sightings that were a reaction…

So I just read the article a bit more closely, and personally I see no reason to panic like you (and others here) are doing. The AI suspicion was presumably triggered by one of the subheadings, which follows the "It's not X, it's Y" schema. At this point it's almost a meme that this betrays AI. But I say: who cares? The substance and the authenticity are what count. This article made some interesting points, and it w…

[dead]

Re: Who owns your ATProto identity?

#72
post #22

Is author new at the whole web thing? Yes, people trust remote web servers. Yes, if you link multiple apps to an identity server (be it atproto, google, or self-hosted OpenID server), and your identity server is compromised, attacker will be able to impersonate you or lock you out. This is just how the web works, and there is no easy around it without losing features people care about. Sure, you can do client-side en…

Are you new to the whole p2p thing? This is a terrible standard to hold new technology to. The web is broken.

https://secushare.org/broken-internet

Re: Who owns your ATProto identity?

#73
post #56

Earlier quoted context omitted.

"Registered users" is a meaningless statistic. Daily active users has consistently declined.

I'd be the last person to downplay the fact that the Bluesky app has a serious retention problem. But it has "broken through" in an incredible way and DAUs/MAUs are quite stable. Registered users is not at all meaningless. Bluesky has those user's email addresses, the mobile app is still installed on many of their devices, they have accounts, and they can potentially be reactivated. For example, if Bluesky announced…

I don't believe the firm behind Bluesky can go to an investor and say "look at all these email addresses we have" and raise on that.

Re: Who owns your ATProto identity?

#74
post #60
post #42

Earlier quoted context omitted.

Yes you do own your domain, as much as you can own your house. Your hosting provider can only take down your hosting, not your domain. Seizing domain names isn't very common. And by the way, with Web3 domains, you have full ownership via your own private key, with no need to pay rent. Is it possible to lose your house that you own? Yes. It's far more rare to lose a domain you own, by it being seized. DNSSec is used t…

> Yes you do own your domain, as much as you can own your house Uh, no. I can legally shoot and kill intruders due to castle doctrine and stand your ground laws in my physical home. And legal invasions require being in front of a judge and a search warrant. A domain can be seized for 'terms of service' (aka kangaroo court) reasons. Stand your ground nor castle doctrine doesn't apply to your digital house.

Domains typically can’t be seized for arbitrary ToS violations, as registrars who do this can lose their accreditation with ICANN (and thus their ability to host domains at all). If the registrar could “frame” you for something like DNS abuse then maybe they could justify a suspension, and if they don’t unsuspend it after you correct the issue, you’d have to file a complaint with ICANN to (hopefully) get it back. If something like this happened and became public, though, the registrar would lose tons of business, as people would develop doubts about the registrar’s reputation.

Re: Who owns your ATProto identity?

#75

Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your P…

This "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.

Check out https://radicle.dev then.

Re: Who owns your ATProto identity?

#76

Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your P…

This "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.

> I don't want the same account I use for social for my code

Then create separate accounts?

Re: Who owns your ATProto identity?

#77
post #68

Earlier quoted context omitted.

I'd be the last person to downplay the fact that the Bluesky app has a serious retention problem. But it has "broken through" in an incredible way and DAUs/MAUs are quite stable. Registered users is not at all meaningless. Bluesky has those user's email addresses, the mobile app is still installed on many of their devices, they have accounts, and they can potentially be reactivated. For example, if Bluesky announced…

A chunk of these registered users are apparently "ghost accounts" hosted on a PDS on a trump.com subdomain. https://bsky.app/profile/tyggero.cz/post/3moskpisnuc2t Source: https://sifa.id/stats Statement from Bluesky: https://bsky.app/profile/pfrazee.com/post/3mmp27wwnic2j

Based on your comments, it seems like you're trying to spread FUD?

The stats page you linked to explains exactly what's going on. These spam PLC identities have nothing to do with with the tens of millions of real Bluesky registered users.

Either you misunderstood or you're being intentionally dishonest.

Re: Who owns your ATProto identity?

#78

Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your P…

The whole claimed point of ATProto is to avoid stuff like this. If centralization isn't a problem, just use GitHub, or X, because platforms that don't try to decentralize work better.

Re: Who owns your ATProto identity?

#79
post #60
post #42

Earlier quoted context omitted.

Yes you do own your domain, as much as you can own your house. Your hosting provider can only take down your hosting, not your domain. Seizing domain names isn't very common. And by the way, with Web3 domains, you have full ownership via your own private key, with no need to pay rent. Is it possible to lose your house that you own? Yes. It's far more rare to lose a domain you own, by it being seized. DNSSec is used t…

> Yes you do own your domain, as much as you can own your house Uh, no. I can legally shoot and kill intruders due to castle doctrine and stand your ground laws in my physical home. And legal invasions require being in front of a judge and a search warrant. A domain can be seized for 'terms of service' (aka kangaroo court) reasons. Stand your ground nor castle doctrine doesn't apply to your digital house.

Let's compare apples to apples, shall we.

How many houses were actually seized, repossessed, commandeered with "eminent domain", slowly taken over via "adverse possession", encroached on with easements and air rights, and whatever else? Versus how many domains?

There is no violence on the internet. You can't shoot intruders. And that's a great thing.

Put in legal terms, you do NOT have this level of ownership to your house... and you certainly do not have sovereign immunity on your land: https://en.wikipedia.org/wiki/Allodial_title

Usually the best you can get is this: https://en.wikipedia.org/wiki/Fee_simple

You probably have something more like this: https://en.wikipedia.org/wiki/Freehold_(law)

What you are describing is more like the king of England being able to shoot people on his own property, and have full sovereign immunity (in theory, I mean recently a British prince was arrested on allegations of far less).

Re: Who owns your ATProto identity?

#80
post #73

Earlier quoted context omitted.

I'd be the last person to downplay the fact that the Bluesky app has a serious retention problem. But it has "broken through" in an incredible way and DAUs/MAUs are quite stable. Registered users is not at all meaningless. Bluesky has those user's email addresses, the mobile app is still installed on many of their devices, they have accounts, and they can potentially be reactivated. For example, if Bluesky announced…

I don't believe the firm behind Bluesky can go to an investor and say "look at all these email addresses we have" and raise on that.

Of course investors care about registered users, for the same reason I explained. But yeah, they do care a lot more about retention and growth rate for good reason. Bluesky Social, PBC has raised $120M+ dollars from investors.
Post reply on HN