Live data from Hacker News

Who owns your ATProto identity?

kevinak.se

131–140 of 159 posts

Re: Who owns your ATProto identity?

#131

Earlier quoted context omitted.

> the main problem is you can't really ever tell with a high degree of certainty This is false, it is trivial to find humans with 99%+ accuracy[1] and there is a well-known service with 99%+ accuracy when analyzed by 3rd parties with no affiliation.[2] > people are just guessing based on what they see in an unscientific way As we see above, this is just guessing in an unscientific way. :) It's important to be rationa…

> This is false, it is trivial to find humans with 99%+ accuracy Sorry but no, this is also false. AI is largely trained on human data. What it outputs is also largely what a human would output. We could both easily make up the exact same sentences (especially smaller ones) and there is NO way to tell what the real source of a sentence is, especially considering the source can be multiple things (AI and human) at the…

You rather undermine your point (with which I agree) in that last sentence!

Re: Who owns your ATProto identity?

#132

Most people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your P…

This "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.

Social coding feels like the tiktokification of coding. It's already a thing on GitHub. In the old RMS days of free software, people wrote software and they released it. GitHub tries to make the process more about the issue tracking and stars than about the actual software.

Re: Who owns your ATProto identity?

#133
post #17

Who owns your domain name? Hint: it’s probably not you. Your hosting provider could take down your domain, or even steal traffic and direct it to their own IPs

More importantly, ICANN can seize your domain if you don't comply with US law (e.g. if you call for a boycott of Israel) unless it's under another country's ccTLD.

Re: Who owns your ATProto identity?

#134

Earlier quoted context omitted.

You can register a recovery key which allows overriding the signing key. This allows users to move from an adversarial PDS. I do think Bluesky should push for more users to add a recovery key, but I also understand why they haven't. Moderation tools arent limited to specific PDS's, labels are public. If an account has received many reports it will have been labelled by Bluesky's moderation account and other independe…

How to adversarial migrate: https://www.da.vidbuchanan.co.uk/blog/adversarial-pds-migrat... *requires your own PLC key, which the vast majority of users do not have, protonmail has good prior art here (imo)

Yeah, I think Bluesky should put more effort in getting users to create their own PLC key. It's trivial for someone who knows about it to do it, but of course the average user has no idea what atproto is. They need to explain it in a user-friendly way and have a simple tool to do it.

I'm not aware of what Proton does here, I'll look into that.

Re: Who owns your ATProto identity?

#135

Sure, somebody else holds your identity, but it's pretty easy to control it yourself. By its nature if you're using somebody to host your stuff, you're trusting them with it. I made Cirrus so you can self-host your PDS for free, but you still need to trust Cloudflare to run it.

It’s great that tings like this exist but as long as this is how identities work on ATProto it’s unfortunately going to be a niche thing.

Re: Who owns your ATProto identity?

#136

Earlier quoted context omitted.

How to adversarial migrate: https://www.da.vidbuchanan.co.uk/blog/adversarial-pds-migrat... *requires your own PLC key, which the vast majority of users do not have, protonmail has good prior art here (imo)

Yeah, I think Bluesky should put more effort in getting users to create their own PLC key. It's trivial for someone who knows about it to do it, but of course the average user has no idea what atproto is. They need to explain it in a user-friendly way and have a simple tool to do it. I'm not aware of what Proton does here, I'll look into that.

When you create a proton account, they create a recovery file for you and have copy about the importance and relevance at that point in onboarding. In other words, users shouldn't have to create their own PLC key, it should be created and downloaded on device automatically. I immediately thought "this is what bluesky should have done" when that happened (proton is recent for me), because this PLC key thing always comes up.

Re: Who owns your ATProto identity?

#137

It seems most ppl who dislike X has already settled, a small amount moved to DeSo like atp or ap, most just stayed or went offline. Unless China GFW magically collapsed, there seems no reason ATProto user base will continue to grow. So, when will the monetization/enshitification phase begin? I'm asking this not bc I like enshitification, but the app view design seems such a perfect fit for user data mining/targeting,…

Atproto is not decentralised, it’s faux decentralised. You can technically be sovereign, but incentives and the way things have been done results in massive centralisation - 99.9% of users are on a Bluesky PDS and have not registered a higher priority rotation key. And they won’t, ever, because that’s how humans work.

The day Bluesky decides to enshittify there’s a very real possibility that they might also just stop allowing people to extract their keys and splinter off the network. The enshitification begins when VCs turn upp the heat it they start getting low on cash.

Re: Who owns your ATProto identity?

#138
post #8

Centralization is always a trap. No idea why people have such a hard time joining and supporting the Fediverse.

Higher friction and fragmentation are Fediverse features (not bugs) that give it a different grain. ATProto has different tradeoffs that lead to a different form of social media. I'm glad both exist, and bridging efforts are worth paying attention to for anyone frustrated with the distinctions.

Yes - the trade off is centralisation.

Re: Who owns your ATProto identity?

#139

Earlier quoted context omitted.

Sure, it may overestimate the exact count, but that doesn't change the fact that tens of millions of real people have downloaded Bluesky and signed up. Right now, Bluesky has one large community, which is already great for some people but not most people. Once Bluesky adds Communities, new communities can form, making it interesting to the other 90% of people who were excited initially and then turned off by it being…

I think your association with Blueksy is painting a rosier picture for yourself than reality portends. Do you know how many of those accounts never added a profile picture or even liked a single post? Do you think people are likely to reactivate to something they checked out once and has only shrunk since? Can ActivityPub/Mastodon add some new feature that will reactivate all the people who tried that out and moved o…

I'm not claiming to know what reality portends, but I do think my guess is about as good as anyone's.

Bluesky did something ActivityPub/Mastodon never did, which is reach a mainstream audience of non-technical people. But its growth has been severely limited for one reason: the network is niche and uninteresting to most people.

Communities are a potential solution to this problem. If they work, it is plausible that tens of millions of users reactivate and, eventually, hundreds of millions of people join the network.

Re: Who owns your ATProto identity?

#140
post #57
post #17

Who owns your domain name? Hint: it’s probably not you. Your hosting provider could take down your domain, or even steal traffic and direct it to their own IPs

If its an Onion (Tor) hostname, you absolutely do own it. Sure, its not memorable being a 128 bit hash. And nobody else can impersonate nor take. And for lower bandwidth tasks, Tor Onions can't be beat. Just make sure to use 2fa on services you offer to keep the trash out. Things like fail2ban don't work the way you intend.

Let me just require a phone number for my totally anonymous drug-market service
Post reply on HN