Live data from Hacker News

I was right about ATProto key management

notes.nora.codes

131–140 of 198 posts

Re: I was right about ATProto key management

#131
post #29

Earlier quoted context omitted.

So I agree with you that they should work like email -- but I've always said that Mastodon is better because it is like email; aka the power is in the nodes. What do you think is wrong about Mastodon? Genuinely curious because I also am super skeptical that ATProto brings anything that we really need.

ActivityPub supports a less compelling user experience for many people: you only have a partial view of the network (you won’t see all the replies to the posts of people you follow on other servers), no global search, etc

This is how offline social networks work, and it might be fundamentally the only way social networks end up working. If each instance can't filter what it receives, then spam is too easy. If every message is globally flooded, the system scales as O(N^2) and is easily vulnerable to DoS.

Re: I was right about ATProto key management

#132

Earlier quoted context omitted.

Email is the prime example of federated communication. From protocol inception to painful expansion and aging protocol all until corporate apropriaton. But I still think federation is the way forward, absolute centralisation is bad I'll let you figure why, but absolute decentralization is also bad, limitations due to its nature, unusual working for most users... Meanwhile federation is right in the middle, and users…

Email is by far the least secure form of communication in common use right now. It's trivial to impersonate others over email, and every MTA that processes your email has access to the full contents, because they are never encrypted except in flight (and except by a few tiny disparate groups using PGP, and even these groups can't authenticate one another). And not for lack of trying, I should add.

None of this is fundamental to the federated model. It's only because email is older than modern security practices.

Re: I was right about ATProto key management

#133

Earlier quoted context omitted.

There are different types of attacks possible though, most broadly you can divide them into "design holes" and "implementation holes". This seems to be about preventing a design hole, and those you need to prevent with architecture/design, you can't just fix those once the implementation and documentation is done.

But the design hole is treating (IMO unfortunately) transient identities (the web's domain name system) as something that should persistently identify something. Adding hacks like this doesn't fix the underlying mismatch but creates new issues as seen in the article. Or to put it another way: Domain names changing hands is how the web works. If you design your system to support web identities in a way that domains ca…

I totally agree. This is the fundamental reason I've stayed off there until now. I'm not about to tie my permanent identity to a domain which I might not own tomorrow. And did:plc is not an option for obvious reasons.

Re: I was right about ATProto key management

#134
post #22

Earlier quoted context omitted.

Peer to peer, not federation, is the way forward. We should only build peer to peer social protocols. Websites and communities should simply sample from the swarm and make it easy for non-technical users to post and consume. They should be optional and not central points of failure (or control). {Twitter, YouTube, Reddit, Instagram, TikTok, WhatsApp, Discord} should work like {Email, BitTorrent, PGP}. Bluesky and Mas…

Unfortunately, the swarm is 99.99999% advertisements for penis enlargement pills. How can a P2P system filter them out? A federated system relies on each admin to filter them out. A centralised system does even better, relying on a single dictator to filter them out. A P2P system requires every user to filter every spam message, together consuming far more effort than the spammer needed to send it.

You can centralize spam lists while still having the base communication protocol decentralized - that way people have the option on making their own decisions on whether "advertisements for penis enlargement pills" are really a problem - and let's be honest that's far from the only thing that gets moderated.

Re: I was right about ATProto key management

#135
post #75

Earlier quoted context omitted.

We don't need large scale social networks in the first place. The Discord model of small communities is the way forward. Keep groups small enough for natural human social rules to apply. Slows down global dissemination of information for sure, but that's what the news is for, and anything important will eventually travel between communities anyway.

I don't understand how you can seriously pose Discord as an alternative in this conversation as it's entirely centralized and full of all sorts of toxic behavior and failure modes. Like at least suggest old school forums, IRC, or usenet.

The GP didn't say Discord itself, but the Discord-like model of small communities. Ironically it's also the old web forum model.

Re: I was right about ATProto key management

#136

Earlier quoted context omitted.

> No, they asserted their opinion as a fact. Interesting idea, let's see if they confirm they were talking facts . I'll be very surprised. I'm the worst person to take issue with this. This has been my biggest pet peeve for the longest time as well. Right until my frame of mind flipped randomly, and I recognized that by getting upset over blatantly subjective matters being discussed with zero cushioning like this, I'…

There is no ambiguity that needs further clarification, I am talking about the words as written. Their entire message clearly conveys they believe there is an objective design standard that everyone should strive to adhere to, and they are criticising a website for daring to deviate from their ideal standard as though it were an objective flaw and not a matter of personal preference. > getting upset over blatantly su…

You are asserting your opinion as fact

Re: I was right about ATProto key management

#137

Earlier quoted context omitted.

According to them. They shared their opinion.

No, they asserted their opinion as a fact. There is a world of difference between "I prefer x" and criticising something while asserting "everyone should do x (because I prefer x)".

You're allowed to criticize something without engaging in social legalese.

Re: I was right about ATProto key management

#138
post #42
post #15

"View -> Page Style -> Basic Page Style" is required to read any of the text.

Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. https://news.ycombinator.com/newsguidelines.html

Backseat moderating is also against the guidelines. If you believe the comment needs moderator attention, flag it. It's pretty ironic you can't say this rule without breaking it

Re: I was right about ATProto key management

#139
post #72

fair enough, the did:web flows are not documented even for technical atproto developers, and there needs to be a self-serve way to heal identity/account problems elsewhere in the network (the "burn" problem). I do think that did:plc provides more pragmatic freedom and control than did:web for most folks, though the calculus might be different for institutions or individuals with a long-term commitment to running thei…

I'm not too familiar, but isn't there a way to host your own did:plc auth server?

No, did:plc is centralised, not federated or anything. The whole ecosystem relies on a server at Blue Sky PBC

Re: I was right about ATProto key management

#140
post #42
post #15

"View -> Page Style -> Basic Page Style" is required to read any of the text.

Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. https://news.ycombinator.com/newsguidelines.html

I wish there was a rule against rule lawyering. Those comments are way more annoying than gp. (queue recursive replies)
Post reply on HN