Live data from Hacker News

Bluesky adds direct messages

bsky.social

191–200 of 208 posts

Re: Bluesky adds direct messages

#191

Jack Dorsey out, plaintext DMs in. Slow clap for Bluesky.

My offer still stands to help the Bluesky folks implement these types of things if they can't figure it out. Call me!

From discussions with security professional friends and folks on E2E encryption of protocols: I don't think it's that they can't figure it out, it's that they know it's hard to get right and harder to fix later, so they're taking their time to do it right in the first place. They don't want to end up like Telegram or Matrix with furries doing unflattering writeups on their security.

Re: Bluesky adds direct messages

#192

Use social media direct messages to establish a connection on a secure messenger designed for direct messaging, and for nothing else. When people try to initiate conversations with you in DMs, have a ready answer to pivot the conversation elsewhere. Social platforms like BlueSky have radically different design constraints than direct messaging applications. The implications range from security to social dynamics to l…

E2E Encryption is on the road map for Bluesky as it requires some protocol changes. The devs are encouraging people to use the DMs to exchange Signal info, and reminding people to not use DMs for sensitive info. https://bsky.app/profile/pfrazee.com/post/3kt457v6aq72n

It wouldn't matter if they implemented "E2E" encryption. "E2E" is necessary but insufficient for messaging security. It would still be a terrible idea to rely on Bluesky DM's, even if they met some floor of cryptographic quality, for the same reason that it's a bad idea to use Facebook DMs, despite their cryptography being close to the gold standard for large scale social apps.

Re: Bluesky adds direct messages

#193
post #191

Earlier quoted context omitted.

My offer still stands to help the Bluesky folks implement these types of things if they can't figure it out. Call me!

From discussions with security professional friends and folks on E2E encryption of protocols: I don't think it's that they can't figure it out, it's that they know it's hard to get right and harder to fix later, so they're taking their time to do it right in the first place. They don't want to end up like Telegram or Matrix with furries doing unflattering writeups on their security.

I agree that the furry interpretation of privacy is intimidating, but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to. The PDS could store these messages encrypted, so the PDS owner cannot read the messages.

I don't think https://tweetnacl.cr.yp.to/ is hard to mess up. Similar to the interior of a furry suit, you won't know what is going on in there.

Re: Bluesky adds direct messages

#194

Earlier quoted context omitted.

The 3 main communities seem to be English speaking, Japanese, and Portuguese. The community is way smaller than Xitter for sure but are the percentages that off?

I've never been exposed to non-US content on Bluesky unlike Mastodon where it's a melting pot from every possible niche and location. To me it seems like Mastodon's focus on hashtags as discovery mechanism won hard in this space thus allowing such diverse communities to thrive on the platform.

There are hashtags on Bluesky as well.

There's an implicit language filter around your default language. It was implemented because the Japanese is comparatively as large as the English audience and a lot of English language users were complaining about searches and feeds being filled by Japanese posts. I chat a lot with Japanese Bluesky because I'm fluent in Japanese; probably 50% of my Bluesky activity is with Japanese Bluesky. I've made friends with a Japanese tech reporter and they share their articles with me occasionally, so it's fun to see a non-English speaking perspective.

Unfortunately I think a lot of the people who use Mastodon and are trying to dunk on Bluesky are doing so in bad faith or not quite bad faith but a non-willingness to explore Bluesky with the same openness and curiosity as Mastodon (this may purely be from a time perspective, I mean we're all human and only have so much time to devote to internet shitposting.) I used and stopped using Mastodon before the whole Xitter thing, because I had 2 instances shutdown on me for various reasons and didn't want to bother trying again. I'm mostly on Bluesky and it seems to have the same features as Mastodon sans the easy to build instances because ATProto is a more complicated protocol. I find the network of Bluesky (or at least my feed) to be a lot less tech focused and for me this is a win. I already engage with tech people on HN, parts of Reddit, and Discord. I don't need yet another tech site full of the common tech tropes like ranting emotionally into the void or getting hung up on niche things that only tech people care about. Just my $0.02.

The feedback about not cross-pollinating non-English-speakers is good though and I've been working on a feed that uses some ML to generate cross-cultural feeds around certain topics. It's been slow going because work has been tough and I'm locked in wedding "hell" in my personal life.

Re: Bluesky adds direct messages

#195
post #163

Earlier quoted context omitted.

Having tried both BlueSky and Mastadon I found Bluesky pretty easy to use and Mastadon bewildering. There were so many Mastadon servers I didn't know where to start. I guess maybe it doesn't matter what server something is on because the app can connect to all of them, but then discussion topics would be repeated in multiple places and it all seemed so disjoint. Like the chaos of old IRC networks but amplified. All i…

> One thing I like about Bluesky is when a thread starter mutes one of the posters, it mutes them for everybody in the thread, not just the original poster. Oh interesting. This is a really cool feature. It kinda nudges it in the direction of being a private, self-run micro-blogging platform, where replies are essentially comments that you can moderate.

There's actually a few projects, mostly in Japanese, that use ATProto as a blogging platform. Kinda like how there's other applications using AP.

Re: Bluesky adds direct messages

#196
post #111

Earlier quoted context omitted.

>Mastodon is only marginally more useful than IRC at this point, and is completely useless to the average person. I as a developer have yet to even figure out how it's supposed to work. I don't know how you define "average person" but plenty of people who aren't developers are on Mastodon. This argument that Mastodon is "too complicated" is perennial, despite the obvious evidence to the contrary in the growth of its…

> plenty of people who aren't developers are on Mastodon How many of them are gonna stick around once their instance goes offline, or the admin does something crazy (which isn't impossible considering how many of these are ran as personal/fun projects by geeks rather than actual businesses), or their instance gets into a feud with the others and results in defederation? All of this is overhead. It's overhead that can…

My person in deity the standard you're defending is the lunatic dumpster fire that is Twitter, where Elon just decides shit at random like "likes are private now" and "you can just pay for a checkmark" or "I'm unbanning all the nazis lol."

I personally haven't experienced any of the "overhead" of Mastodon that you're mentioning, and making seem far more common than it is, but Mastodon seems far more stable than Twitter as a platform and a community at the moment.

And sure, some people might not like it, and that's fine. There are and will always be alternatives. But anything is better than Twitter.

Re: Bluesky adds direct messages

#197
post #144
post #111

Earlier quoted context omitted.

>Mastodon is only marginally more useful than IRC at this point, and is completely useless to the average person. I as a developer have yet to even figure out how it's supposed to work. I don't know how you define "average person" but plenty of people who aren't developers are on Mastodon. This argument that Mastodon is "too complicated" is perennial, despite the obvious evidence to the contrary in the growth of its…

It's been on a steady downward slide for the last year, from almost 2m during The Exodus to about 900k active users now. People sign up, but most don't stick around. I also can't help but notice my own timeline has slowed to a crawl, and it's mostly the same few people. It's not vibrant and busy like it used to be.

Aggressive growth and addictive velocity are cancerous, let it reach a healthy equilibrium. Slow can be good, too.

I'm following ~500 people at the moment, and getting relays from a few instances. I see a constant flow of new stuff but I can also easily leave and do other things, because Mastodon isn't designed to maximize engagement and addiction. I don't feel a constant need to post or comment or chase endorphins. The scale is just fine for me.

Re: Bluesky adds direct messages

#198

Um... So all the money, all the development, to create Twitter² and they just added DMs? That seems an underwhelming achievement.

The headline is that it's not a shithole ridden with ads, spam, influencers, scams, etc. That's the important part of replacing Twitter.

What are the criteria for deciding how to either stop influencers from signing up, or how to permaban them as soon as they start?

It would be something no other platform has managed. Including this site.

Re: Bluesky adds direct messages

#199
post #191

Earlier quoted context omitted.

From discussions with security professional friends and folks on E2E encryption of protocols: I don't think it's that they can't figure it out, it's that they know it's hard to get right and harder to fix later, so they're taking their time to do it right in the first place. They don't want to end up like Telegram or Matrix with furries doing unflattering writeups on their security.

I agree that the furry interpretation of privacy is intimidating, but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to. The PDS could store these messages encrypted, so the PDS owner cannot read the messages. I don't think https://tweetnacl.cr.yp.to/ is hard to mess up. Sim…

> but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to.

Furry cryptography nerd here.

No. This is inadequate.

> I don't think https://tweetnacl.cr.yp.to/ is hard to mess up.

Yes it is! If you're doing to encrypt some things in a constrained use-case, sure, NaCl is better than hand-rolling it yourself. But it's not sufficient for end-to-end encryption. Here's a few things that TweetNaCl (and other NaCl variants) is, without further protocol design, inadequate to protect against:

1. Invisible Salamanders. NaCl uses xsalsa20poly1305, which is not key-committing.

2. Forward Secrecy. NaCl's crypto_box doesn't give you this at all.

3. Key Compromise Impersonation. See also, Toxcore, which built atop NaCl: https://github.com/TokTok/c-toxcore/issues/426

4. How do you do group messaging? If you do it as just pairwise, do you use the same public key as your p2p messaging? There's a lot of ways that can subtly go wrong.

There is a damn reason end-to-end encryption involves authenticated key exchanges and forward-secure double ratchets.

Re: Bluesky adds direct messages

#200

Earlier quoted context omitted.

I agree that the furry interpretation of privacy is intimidating, but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to. The PDS could store these messages encrypted, so the PDS owner cannot read the messages. I don't think https://tweetnacl.cr.yp.to/ is hard to mess up. Sim…

> but at the very least I think Bluesky could start with generating a private key on each client device, and then using a simple box algorithm to encrypt messages towards the user they want to talk to. Furry cryptography nerd here. No. This is inadequate. > I don't think https://tweetnacl.cr.yp.to/ is hard to mess up. Yes it is! If you're doing to encrypt some things in a constrained use-case, sure, NaCl is better th…

Well, exactly. My point is that in a constrained use-case NaCl would be sufficient.

If you want to rotate keys, then simply delete your private key and since we trust Bluesky so much we can use the PDS to share new pubkeys once we rotate. In fact, this would work for signing keys too! Then the PDS wouldn't be able to write messages for you if it wanted to.

For group messaging you simply encrypt the message to each recipient.

If they want to upgrade to a Axolotl from this, great! But starting with plain text is not private messaging, it is group messaging with your PDS admins and whoever they want to share that data with.

Post reply on HN