Live data from Hacker News

Who owns your ATProto identity?

kevinak.se

151–159 of 159 posts

Re: Who owns your ATProto identity?

#151
post #72
post #22

Is author new at the whole web thing? Yes, people trust remote web servers. Yes, if you link multiple apps to an identity server (be it atproto, google, or self-hosted OpenID server), and your identity server is compromised, attacker will be able to impersonate you or lock you out. This is just how the web works, and there is no easy around it without losing features people care about. Sure, you can do client-side en…

Are you new to the whole p2p thing? This is a terrible standard to hold new technology to. The web is broken. https://secushare.org/broken-internet

Yes, I am familiar with multiple solution that want to replace the web. They can solve all sorts of interesting problems, except one: how to get adoption.

I have nothing against people exploring alternative networking systems, but let's be clear: the only reason to run GNUnet (or Nostr, or SSB) is if you are interested in GNUnet/Nostr/SSB itself, or if you want to add exclusivity and wall your garden away from random visitors.

But many people have the opposite goal - they want their content to be accessible, and they want everyone to be able to participate, even if they are a high school student with 10 year old iPhone. And this means web.

So let's talk about how we can actually reach people, and this means figuring out how to get this web thing to work.

Re: Who owns your ATProto identity?

#152
post #22

Is author new at the whole web thing? Yes, people trust remote web servers. Yes, if you link multiple apps to an identity server (be it atproto, google, or self-hosted OpenID server), and your identity server is compromised, attacker will be able to impersonate you or lock you out. This is just how the web works, and there is no easy around it without losing features people care about. Sure, you can do client-side en…

> Sure, you can do client-side encryption and pretend serve can't see the plaintext, but it's just a theatre, Keeping a private keep on the client to sign your activity is a fundamental cryptography practice. If you use a private key to sign your emails or git commits, it’s not security theater. If you were to have to upload your private key to GitHub or your email provider, that would be severity theater. > Is autho…

The key word is "web", and all associated ecosystem - the place where local devices are transient, and everything is in the cloud.

I personally have multiple regular PCs, sync the files around, do encrypted backups, and so on. I still have my files from 20 years ago, and I manage my personal keys.

But when I talk to other people, most people aren't like that! They don't do regular backups, they lose files all the time (phone broke -> files are gone), and when they transfer files, they do it via 3rd party, by emailing, dropboxing or uploading to Google Drive.

So how would they handle "private key"?

Most of then will never download the app, and will only use the website. I guess you can use browser web storage to store the key, but next time they run out of space and clear internet files, it would be gone. Or if their phone breaks. Or if the computer starts to behave strangely, so they wipe it all (not exaggerating, I've seen people do that). So keeping the key only in the browser is a terrible idea.

You can force them to download private key, but then what? Most people will simply forget it (after all, "I am just trying out this thing, no need to both with all the complex backups"), and the key will sit in Download folder until the PC/phone breaks. If you got lucky, they'll upload this to Google Drive/iCloud, so that megacrop will have a private key.

But the worst of all, even if you somehow magically get them to preserve the private key, it's useless. Remember, we are talking rogue operator here, and those are very likely the same people who are serving you the webpage and javascript blob that will obtain the key from local storage and decrypt. They will do the same thing hushmail did, which is to modify the webpage so it exfiltrates the private key.

(And yes, all of this can be worked around if you don't use web, and run the stuff locally. But this severely restricts users, and will kill the adoption)

Re: Who owns your ATProto identity?

#153
post #81

Earlier quoted context omitted.

> smart contract-based process for recovering ids if keys get lost or hacked How would that even work?

Perhaps some sort of namecoin or ENS-like petname system with multisig or some type of scripting that enables different recovery methods. For example, you could set your petname up so it can be controlled by a single keypair, which can be overridden after a certain time by a ring signature based on keypairs held by friends, family, peers, and trusted computing devices you leave in a safe deposit box. Or maybe you cou…

Do you need a blockchain for that though? There are cryptography schemes to share a secret (e.g. the recovery keys) between multiple parties, requiring at least N of them to get together to recover the original value of the secret.

Re: Who owns your ATProto identity?

#154

Earlier quoted context omitted.

You can host it for free on Cloudflare using my Cirrus PDS: https://cirrus.earth/

For anyone curious about the issues discussed in this topic, see: Identity and your signing key https://cirrus.earth/concepts/identity/ > Cloudflare secrets are write-only: once set, they cannot be retrieved through the dashboard or the API. This is good for security and bad for recovery. The wizard prints the key exactly once during pds init. Save it then. Also: Back up your signing key https://cirrus.earth/guides/b…

It's also worth noting that if you're using `did:plc` for your identity (the default for Bluesky and most places) then you can rotate your signing key if you lose it. It's only `did:web` that makes it impossible to recover or rotate a key.

Re: Who owns your ATProto identity?

#155

Sure, somebody else holds your identity, but it's pretty easy to control it yourself. By its nature if you're using somebody to host your stuff, you're trusting them with it. I made Cirrus so you can self-host your PDS for free, but you still need to trust Cloudflare to run it.

It’s great that tings like this exist but as long as this is how identities work on ATProto it’s unfortunately going to be a niche thing.

The easy way is to create an account on Bluesky. That's as simple as creating an account on any other social network. The important bit though is that you can then, if you want, migrate to a different host and take your identity with you, or if you're brave you can self-host. This is by its nature something for power users, but regular users can use Bluesky accounts without ever knowing or caring about PDSs, DIDs or signing keys etc.

Re: Who owns your ATProto identity?

#156

Earlier quoted context omitted.

The whole claimed point of ATProto is to avoid stuff like this. If centralization isn't a problem, just use GitHub, or X, because platforms that don't try to decentralize work better.

If you assume that Bluesky won't suddenly turn hostile (we'll get some warning) then being able to migrate your PDS is better than what X gives you and about the same as being able to move your git repo off of GitHub.

We have warning right now with it being a VC-funded company.

Re: Who owns your ATProto identity?

#157

Earlier quoted context omitted.

> "This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, Being able to tell who wrote something doesn't imply irrationality, panicking, or a reaction to new technology. > like UFO sightings in the 1950s. UFO sightings stayed confined to the 1950s and were a reaction to new technology? Or were the UFO sightings in the 1950s the only UFO sightings that were a reaction…

So I just read the article a bit more closely, and personally I see no reason to panic like you (and others here) are doing. The AI suspicion was presumably triggered by one of the subheadings, which follows the "It's not X, it's Y" schema. At this point it's almost a meme that this betrays AI. But I say: who cares? The substance and the authenticity are what count. This article made some interesting points, and it w…

> I see no reason to panic like you (and others here) are doing

You've already been told it's not a panic, and it's not cool you keep insisting it is. This is a sleezy tactic to make your opponent look less sane than yourself ("stop being so emotional", "calm down", "hey no need to be angry").

Re: Who owns your ATProto identity?

#158
post #81

Earlier quoted context omitted.

Perhaps some sort of namecoin or ENS-like petname system with multisig or some type of scripting that enables different recovery methods. For example, you could set your petname up so it can be controlled by a single keypair, which can be overridden after a certain time by a ring signature based on keypairs held by friends, family, peers, and trusted computing devices you leave in a safe deposit box. Or maybe you cou…

Do you need a blockchain for that though? There are cryptography schemes to share a secret (e.g. the recovery keys) between multiple parties, requiring at least N of them to get together to recover the original value of the secret.

No, but you need some sort of blockchain to enforce uniqueness in petname systems due to zooko's trilemma.

If you're okay with another side of the triangle, where all of the identities are keypairs, then you don't need a petname system or any name system. the name system is an optional convenience layer on top of the web of trust.

Post reply on HN