Live data from Hacker News

Who owns your ATProto identity?

kevinak.se

141–150 of 159 posts

Re: Who owns your ATProto identity?

#141

It seems most ppl who dislike X has already settled, a small amount moved to DeSo like atp or ap, most just stayed or went offline. Unless China GFW magically collapsed, there seems no reason ATProto user base will continue to grow. So, when will the monetization/enshitification phase begin? I'm asking this not bc I like enshitification, but the app view design seems such a perfect fit for user data mining/targeting,…

Atproto is not decentralised, it’s faux decentralised. You can technically be sovereign, but incentives and the way things have been done results in massive centralisation - 99.9% of users are on a Bluesky PDS and have not registered a higher priority rotation key. And they won’t, ever, because that’s how humans work. The day Bluesky decides to enshittify there’s a very real possibility that they might also just stop…

ATP is more decentralized than X at least. Decentralized as a term is almost as loaded as Democratic. :)

Anyway I think we can agree on enshitification is coming soon. I'm just looking for signs of that's actually happening (or a counter theory that it would not happen)

Re: Who owns your ATProto identity?

#142

Wait what?! For a protocol that incorporates the DID spec this is disappointing to discover. Unless I'm mistaken the DID spec allows provable hierarchical relationships between DID identities – why can't a child DID be created from our master signing identity that has the authority to CRUD on our behalf but still be provably distinct from our root identity? Not even sure why the PDS would require our signing key that…

Oops upon closer reading of the article and the comments here i see that the atproto standard does apparently allow for the above, at least to some degree. If there is indeed hierarchical support for the DIDs then you should be able to disavow any child identity from a master identity and leave no public uncertainty (ie the true owner of the key hereby disavows the following sub keys) So if the worst case scenario pr…

The point of the article is that 99.9% of users will not take custodial control of their identity - not that they can’t.

Re: Who owns your ATProto identity?

#143

Earlier quoted context omitted.

But without private keys they can't pretend to be the same you. There is a very big difference here.

Right, if Bluesky ever does do something hinky with your PDS, the operation will be signed with their key and persisted in the operation log which they're unable to touch. You can outright remove Bluesky's key if you want, though I think that only works within some number of days of creating it.

It's probably one of few places where blockchain would be actually useful; just use it as a history of users keys to validate against, so any domain takeover or similar event would at least not allow stealing user's handle

Re: Who owns your ATProto identity?

#144

Earlier quoted context omitted.

Oops upon closer reading of the article and the comments here i see that the atproto standard does apparently allow for the above, at least to some degree. If there is indeed hierarchical support for the DIDs then you should be able to disavow any child identity from a master identity and leave no public uncertainty (ie the true owner of the key hereby disavows the following sub keys) So if the worst case scenario pr…

The point of the article is that 99.9% of users will not take custodial control of their identity - not that they can’t.

Well it's a very well understood concept in cryptocurrency – you just keep your seed phrase somewhere like on a paper wallet. And if you're less paranoid then millions of people use some thing like MetaMask which there could be an equivalent of for identity management relevant to atProto– or maybe there is?

Re: Who owns your ATProto identity?

#145

One of the core features of AT is the ability to move your repo hosting provider (PDS) at any time. This is the "data portability" problem that ActivityPub never solved. Bluesky Social, PBC runs a PDS service (bsky.social) for free, there are a number of free public alternatives, and thousands of users self-host. Self-hosting your own PDS can be done with Raspberry Pi or $5/mo VM and requires very little work. It run…

You can host it for free on Cloudflare using my Cirrus PDS: https://cirrus.earth/

For anyone curious about the issues discussed in this topic, see:

Identity and your signing key https://cirrus.earth/concepts/identity/

> Cloudflare secrets are write-only: once set, they cannot be retrieved through the dashboard or the API. This is good for security and bad for recovery. The wizard prints the key exactly once during pds init. Save it then.

Also:

Back up your signing key https://cirrus.earth/guides/back-up-signing-key/

Re: Who owns your ATProto identity?

#146

Earlier quoted context omitted.

The whole claimed point of ATProto is to avoid stuff like this. If centralization isn't a problem, just use GitHub, or X, because platforms that don't try to decentralize work better.

Atproto gives users choice for where their data is hosted as well as the ability to migrate their data to a new host. Users who dont want to put trust in a provider can host it themselves. How is that not an improvement over being locked in to a single centralized provider?

The end of the article explains why this isn’t necessarily better than a centralised service. Yes - you can self host but no one (yes, there a few exceptions) does in practice. Your PDS host can pretend to be you on any atproto application.

Re: Who owns your ATProto identity?

#147

Earlier quoted context omitted.

This "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.

Social coding feels like the tiktokification of coding. It's already a thing on GitHub. In the old RMS days of free software, people wrote software and they released it. GitHub tries to make the process more about the issue tracking and stars than about the actual software.

I definitely use Github stars as a bookmarking mechanism

Re: Who owns your ATProto identity?

#148

Earlier quoted context omitted.

This "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.

Check out https://radicle.dev then.

Radicle is too confusing to me. I want to like it though, it looks cool. I appreciate it doesn't look like a Temu Github like almost every alternative.

Re: Who owns your ATProto identity?

#149

Earlier quoted context omitted.

Atproto gives users choice for where their data is hosted as well as the ability to migrate their data to a new host. Users who dont want to put trust in a provider can host it themselves. How is that not an improvement over being locked in to a single centralized provider?

The end of the article explains why this isn’t necessarily better than a centralised service. Yes - you can self host but no one (yes, there a few exceptions) does in practice. Your PDS host can pretend to be you on any atproto application.

How the addition of user choice doesn't make it better. I agree it's suboptimal, but I feel its still a clear improvement over centralized services. Getting to choose who, if anyone, I trust as my provider is better than having no choice.

Re: Who owns your ATProto identity?

#150
post #93

Earlier quoted context omitted.

If that's the case, then I stand corrected, but a source for that claim would be helpful.

I was rounding up, the actual number is ~45 million: https://bsky.jazco.dev/stats (these stats are based on real activity, not PLC identities) At current rate it will 50M in 6 months.

Why do you project 10% growth over the next 6 months? Looking at the other metrics on that page which have history (total unique likers, posters, followers), the numbers are flat or declining.

That shape doesn’t seem great for a social media company.

Post reply on HN