some quick thoughts/notes (I am on the bluesky team, but this isn't an official policy statement): - content on bluesky is public, but we have not set expectations/comms around that well yet, and this dump may be a surprise to some existing accounts. where exactly bluesky falls on the spectrum from "congressional register (immutable)" to "public web" to "public IRC or discord room" to "private signal group" is still…
Thanks for weighing in It's disappointing to hear that follower-only/circles (whitelisted viewers) posts are basically incompatible with the current protocol. I'd hoped something could be done where the post content was encrypted in such a way that only specific authenticated users could decrypt it, or something along those lines
I downloaded all 1.6M posts on Bluesky
281–290 of 294 posts
Re: I downloaded all 1.6M posts on Bluesky
#282Earlier quoted context omitted.
Who signs new nodes in the tree? The server or the content creator? What prevents a server from creating content for anyone? So you can confirm it was not changed, but cannot confirm that the original addition came from the real person? I don't see anything in the docs that talk about cryptographic signatures or key management.
From what I can tell after digging into the code, the server is responsible for signing everything. I was really hoping that users would have more control in regards to this. I have a similar concern, what prevents the server from publishing without the users consent? Also, I keep seeing discussion about being able to move identities to a new server, but to do that, you need to update your corresponding DID Document…
I suspect that the solution would be to run on a trusted server, maybe your own.
Re: I downloaded all 1.6M posts on Bluesky
#283Earlier quoted context omitted.
[flagged]
Would you please stop posting ideological flamewar comments? It's not what this site is for, and destroys what it is for. https://news.ycombinator.com/newsguidelines.html
… but I’m open to the possibility that I’m viewing my own comments in an overly favorable light, and appreciate your feedback.
Re: I downloaded all 1.6M posts on Bluesky
#284Earlier quoted context omitted.
Right I’m saying I don’t particularly care about the governance structure of the protocol underlying my social media network. A centralized network run by a nonprofit or a b-corp and a relatively open API sounds great to me. User safety is a dealbreaker though. Pretty sure I’m not alone.
What nonprofit do you trust to run such a thing? When their employees receive targeted harassment from political vigilantes, what do you think is going to happen? When the nonprofit board is stacked with Musk or Trump acolytes, what do you think is going to happen? Media organizations are hugely vulnerable targets and they — nonprofit or commercial — are not proving resilient to outside pressure and influence. Decent…
Decentralization cannot possibly increase diversity if it doesn't provide strong user safety measures. And decentralization makes that infamously hard problem much harder. I think you would end up compromising on one or the other.
Re: I downloaded all 1.6M posts on Bluesky
#285Earlier quoted context omitted.
Strong user safety features are at odds with a federated protocol. IMHO federation is a mistake.
>Strong user safety features are at odds with a federated protocol. The whole philosophy behind Mastodon is the idea that literally the opposite is true. Servers that are aligned in their safety feature preferences are able to federate with each other and de-federate with servers that don't share those safety features. For all of the dissing of Mastodon, one thing even its critics begrudgingly admit is that it has be…
As a user I don't want to deal with too much abuse but I also don't want to have to worry about my server not being able to connect to my friend's server. These goals seem like they're at odds. I could see it working if most users coalesce around a single server or a small network of servers with similar rules.
Re: I downloaded all 1.6M posts on Bluesky
#286Earlier quoted context omitted.
Who signs new nodes in the tree? The server or the content creator? What prevents a server from creating content for anyone? So you can confirm it was not changed, but cannot confirm that the original addition came from the real person? I don't see anything in the docs that talk about cryptographic signatures or key management.
From what I can tell after digging into the code, the server is responsible for signing everything. I was really hoping that users would have more control in regards to this. I have a similar concern, what prevents the server from publishing without the users consent? Also, I keep seeing discussion about being able to move identities to a new server, but to do that, you need to update your corresponding DID Document…
If the server just maliciously messed with your data repository, you just use the recovery key. If the malicious content server did not try to rotate the recovery key, you can just use it to reset the signing key, regardless of if the content server rotated it. If it did malicious try to rotate the recovery key, as long as you notice within 72 hours, you can fork a new DID history from some state that was current within the last 72 hours that has your old recovery key.
Either way, you use the recovery key to rotate the signing key, to something you control. Now, you can repoint your DID to a new content server, upload your unadulterated post history to it.
Also, the core of the protocol does not strictly require that the content server have your publishing keys. In theory a client can create new posts, sign them and upload them. This will mean that certain API methods that exist that do things like add a new post won't work, which is theoretically fine if you only ever want to post from fully trusted clients that could be given access to your signing key, create a new commit, and upload it.
Also it is not yet clear if all servers will allow such usage. In theory a content server could refuse to host the data repositories for users if it lacks the signing key for the user.
Footnote: These content servers are formally called Personal Data Servers. I used content servers throughout this post to be clear that I am not talking about plc.directory or other such ancillary servers.
Re: I downloaded all 1.6M posts on Bluesky
#287Earlier quoted context omitted.
From what I can tell after digging into the code, the server is responsible for signing everything. I was really hoping that users would have more control in regards to this. I have a similar concern, what prevents the server from publishing without the users consent? Also, I keep seeing discussion about being able to move identities to a new server, but to do that, you need to update your corresponding DID Document…
> I have a similar concern, what prevents the server from publishing without the users consent? I suspect that the solution would be to run on a trusted server, maybe your own.
Re: I downloaded all 1.6M posts on Bluesky
#288Earlier quoted context omitted.
Would you please stop posting ideological flamewar comments? It's not what this site is for, and destroys what it is for. https://news.ycombinator.com/newsguidelines.html
I don’t perceive “be open to vibrant discourse and charitable to your outgroup” to be either an overtly ideological position or flamewar fodder … … but I’m open to the possibility that I’m viewing my own comments in an overly favorable light, and appreciate your feedback.
No one on the receiving end of that will feel like they are being met with open, vibrant, charitable discourse! You have to show those qualities, not tell them.
I'm sure your intentions were good—it's just that the mechanics of "vibrant discourse and charitability to outgroups" are trickier than they seem. Nothing is easier than to unintentionally break them without realizing it. Therefore we all need to work hard at it consciously and listen to feedback when we get it wrong. Me most of all.
(btw the second half of your comment was just fine)
Re: I downloaded all 1.6M posts on Bluesky
#289Earlier quoted context omitted.
> I have a similar concern, what prevents the server from publishing without the users consent? I suspect that the solution would be to run on a trusted server, maybe your own.
most people won't want to manage their keys, the UX around that sucks, so federation only in name?
"Everybody is their own server" is decentralization
Re: I downloaded all 1.6M posts on Bluesky
#290Earlier quoted context omitted.
> It works pretty well on email. As someone who has been running mail servers for 20 years, no, it does not. I'm sure other mail admins will agree.
> I'm sure other mail admins will agree. Don't be.