9 ms·
Introduction to AT Protocol
- don_searchcraft 1y agoWould love for more platforms to embrace the AT protocol.
- verdverm 1y agoI'm working with some people on permissioned spaces for atproto (spec and pds changes). This will unlock a ton of use-cases not possible today Working Group is forming this fall, we'll be at IETF, Montreal in Nov Also building one such platform that needs permissioned spaces, if you want to follow along https://github.com/blebbit/atproto https://github.com/blebbit/atproto https://bsky.app/profile/blebbit.app https://bsky.app/profile/blebbit.app Off the top of my head, there are also WGs for E2EE messaging, web monetization, and geo. Lot's of infra getting built this year
- koolala 1y agoWould be great to have a new modern alternative to the E-mail standard that is usable for both public and private messaging.
- jazzyjackson 1y agoemail has come a long way with SPF, DKIM, and DMARC, and its cool that anyone can purchase a slice of the global namespace that is transferable between providers, but AFAIK the biggest road block to using email in a distributed self sovereign way is reputation and getting your messages delivered to google and outlook users partially because of the nonstop spam. Do we have any new tools to prevent spam in a post-email world? Or can we just use the current email structure with some better GUI around PGP and Hashcash and force anyone who wants to send a message to burn 10 cents worth of electricity ? I'm curious what you're looking for in an email standard ?
- fluoridation 1y agoA quick back-of-the-envelope calculation says that USD 0.1 would be about 700 Wh, so, give or take, a high-performance desktop processor running full tilt for over four hours. Personally, I'd prefer something like an expansion of how XMPP works. By default you only see what people in your contact list have sent you, and anything else is marked "dubious", and it's up to you to read it or not. I think it's a mistake that email servers have been given the responsibility to filter unwanted traffic. Email servers should have only ever simply passed along whatever they received (excluding excessively large messages, of course).
- oever 1y ago> By default you only see what people in your contact list have sent you, and anything else is marked "dubious", and it's up to you to read it or not. Any email client could implement this policy. You could even prioritize mail over who sent it or whether it's a reply to a mail you sent or have already read.
- fluoridation 1y agoYes, but if the third server down the line didn't propagate the email, there's not much the client can do. That's what sucks about email as a protocol; it's been taken over by a handful of providers who will refuse to play ball with anyone outside their club, or who doesn't have the time to monitor the continuously-updated black lists.
- JimDabell 1y agoThere’s a fairly direct route to solving this with email. The problem that needs to be solved is that knowledge of an email address is the only thing needed to send to it. Introducing recipient consent as an additional requirement solves spam and phishing. The first email a sender sends to a recipient has an attachment that serves as a request to email them for a specific purpose (e.g. human:human, mailing list, transactional). This email is not delivered to their inbox immediately, but to a separate “friend request” style queue. When the recipient approves, the sender receives a Biscuit token [0] and the email is delivered to the inbox. Subsequent emails are sent by attenuating a one-time-use token from the master token, which is included in a header. Because they have verifiable authorisation, this can skip all existing spam heuristics because the receiving mail system knows for certain the recipient authorised this sender. Biscuits can also be attenuated to reduce scope. Want the hotel you are staying at to only be able to send you email for the next 30 days? No problem. Mailing list providers can reject tokens that are scoped to transactional email. A sender can reduce blast radius of compromises by attenuating new tokens to give to third-party providers. Authorised senders who spam can have all their historical emails quarantined at once and their ability to send in the future removed. Recipients can see who gave spammers their email address. People who send mail are incentivised to implement this because it improves delivery rates by bypassing all existing spam filters, including IP reputation. “Ask for a token and you’ll never hit a spam filter again” is something a lot of people would jump at the chance for. No need for providers like Mailchimp, you could go back to sending mail directly from your own servers. Recipients are incentivised to implement this because it will cut down on spam and phishing significantly. This can be implemented independently of the other side because the fallback situation is the status quo – the initial email just has an attachment that goes ignored, and subsequent emails are sent without tokens and are subject to existing spam filters. It’s possible for spammers to send lots of unsolicited contact requests, however separating things out into a spam-free inbox and a “this new person wants permission to email you” queue makes it far more manageable than the current ocean of potential spam in an overflowing inbox. Determining “is this new contact legitimate?” a handful of times is much easier than determining “is this email legitimate?” thousands of times more often. What you’re essentially doing with this is bootstrapping a social graph on top of email. You can then add a bunch of other nice things on top of that, like public key cryptography, but the actual diff between current email and this system is surprisingly thin. [0] https://www.biscuitsec.org https://www.biscuitsec.org
- verdverm 1y agoWe might be able to do this with permissioned spaces. There are instances or use-cases where you want an outside entity to make changes to a user's repo - email / inbox [or @mail since it is @atproto :] - unsubscribe from email - notifications / rsvp The cool thing is that we could use the stackable moderation infra for dealing with bad actors https://bsky.social/about/blog/03-12-2024-stackable-moderation https://bsky.social/about/blog/03-12-2024-stackable-moderati...
- jazzyjackson 1y agostackable moderation for ignoring senders is a cool idea. I'll keep an eye out for permissioned spaces, is there encryption and signatures involved at all? (everything on bluesky is signed with PKI, iirc?) And just unsolicited feedback but "Blebbit" is a deeply terrible name. It turns my stomach for some reason. I don't even know what a bleb could be or what it could represent besides, like, an ulcer.
- verdverm 1y agoYour content is signed with a key, but there isn't PKI in the same sense as certificates There are two efforts around "permissioned" and "encrypted" spaces/content, where encrypted is the E2EE / signal like stuff and permissioned is more like Google Docs or the Discord like permissioning systems. There are use-cases for both re: name, the second person to dislike, outnumbered by those who do like, will add you to the tally the name is a play on plebeians / plebs / blebs, not to belittle, but to emphasize this is for the people, not the oligarchs. Credible Exit Philosophy is important to me and the ATProtocol ecosystem. It means that users can leave an app without losing their data, that they can move their database without losing access, that the majority of Bluesky users could switch to an alternative if they become adversarial. What it means is that ATProtocol bakes competition into our shared social fabric that all apps build on
- gargron 1y agoActivityPub can be used for both public and private messaging, though I don't think the e-mail standard needs to be retired anytime soon.
- JdeBP 1y agoThere was once an idea named IM2000. Then the world invented pull-style electronic communications systems via another route. You're looking at one. * https://news.ycombinator.com/item?id=10410164 https://news.ycombinator.com/item?id=10410164 * https://jdebp.uk/Proposals/IM2000/ https://jdebp.uk/Proposals/IM2000/
- riffic 1y agothere shouldn't be a rush to replace the things that have stood the test of time. Lindy's law would suggest a protocol that's been around 40+ years is fundamental and won't be going anywhere anytime soon.
- snvzz 1y agoWhen it comes to SMTP for email, time has only served to highlight its inadequacy. DMAC, DKIM, SPF, S/MIME, PGP are all ugly workarounds. The issues are fundamental.
- riffic 1y agothose ugly workarounds are actually brilliant signs of adaptability (not signs of failure). SMTP isn't inadequate, it's resilient. There's a good chance we'll still have SMTP around another 50-500 years.
- snvzz 1y agoNo, we won't w/o breaking changes. There's no way. Even ignoring pressing issues like lack of mandatory E2EE, SMTP requires encoding binary data into text. This includes the main body for most emails these days. Awfully wasteful. So it will go the way of FTP.
- snvzz 1y agoThere's DIME[0]. I wish I heard about the effort more often, as it's sorely needed. 0. https://en.wikipedia.org/wiki/Dark_Mail_Alliance https://en.wikipedia.org/wiki/Dark_Mail_Alliance
- tetrisgm 1y agoBeen pondering for my team to use it for our product’s timeline. I don’t particularly want our user base to be Bluesky, but it’d be good to have support for the protocol, and control over the system. Have there been any products go embraced this? Or is it like ActivityPub where basically the whole thing is Mastodon.
- psionides 1y agoFor now mostly just small things that the Bluesky dev/user community is playing with, but check out e.g. Tangled which is meant to be a GitHub alternative on ATProto: https://tangled.sh https://tangled.sh
- verdverm 1y agoTikTok: https://bsky.app/profile/skylight.social https://bsky.app/profile/skylight.social Insta: https://bsky.app/profile/pinksky.app https://bsky.app/profile/pinksky.app Twitch: https://bsky.app/profile/stream.place https://bsky.app/profile/stream.place Events: https://bsky.app/profile/smokesignal.events https://bsky.app/profile/smokesignal.events
- dom96 1y agoPinterest: https://bsky.app/profile/scrapboard.org https://bsky.app/profile/scrapboard.org
- ihndan 1y agoAnd here is an app to generate unified feed for such apps: https://bsky.app/profile/atpage.one https://bsky.app/profile/atpage.one
- verdverm 1y agoBuild your own feeds / algorithms in the browser: https://graze.social https://graze.social
- gargron 1y agoActivityPub is embraced by: - Threads - Flipboard - WordPress - micro.blog - NodeBB - PeerTube - Pixelfed - GoToSocial - Akkoma - ...and countless smaller projects It is by no means just Mastodon.
- wyldfire 1y agoI'll save you a click: it's unrelated to the Hayes AT commands [1]. [1] https://en.wikipedia.org/wiki/Hayes_AT_command_set https://en.wikipedia.org/wiki/Hayes_AT_command_set
- nate_nowack 1y agowould love fb marketplace disruptor on atproto
- mdaniel 1y agoIsn't the problem the network effect, and not the protocol whatsoever?
- nate_nowack 1y agoyea i dont think there's any blocker from a protocol perspective, im just saying i'd love to see it happen. adoption for sure among the largest hurdles id guess
- Cyberdog 1y agoRetvrn to Craigslist.
- omni_rizzler 1y agothere is a marketplace in nostr if u interested
- dom96 1y agoATProto is a lot of fun to work with, but of course by no means perfect. The biggest challenge right now is dealing with private data, I hope they can figure out a way to support it soon.
- verdverm 1y agosee my comment in another thread, things are happening!
- verdverm 1y agoIf you are interested in building on ATProtocol, one of the best places to start is the Discord (until we have an atproto native alt @blebbit.app) https://discord.atprotocol.dev/ https://discord.atprotocol.dev/ Of course the spec is good too, very easy read https://atproto.com https://atproto.com https://docs.bsky.app https://docs.bsky.app
- tomrod 1y agoWhat sorts of things can be built on the protocol?
- psionides 1y agoAnything "social" basically - the first ideas that come to people's minds are of course things like: GitHub but on ATProto, Instagram on ATProto, Tiktok on ATProto, Reddit on ATProto…
- jazzyjackson 1y agoWhy isn't there a Discord built on ATProto ? [Serious Question, wondering if there are trade-offs that make this especially annoying]
- psionides 1y agoSo, one big problem is that there's basically no way to have shared-private data in the protocol - it's either private to you, or fully public. Hence no "locked accounts", "followers-only posts" and so on on Bluesky, and this also prevents more sensitive ideas like e.g. "Strava on ATProto" (where you probably don't want to share your run map with the whole world!). They are working on this, but it's still gonna take a while as I understand.
- jazzyjackson 1y agoAh thanks for the answer. What's the PKI story on bluesky, doesn't every identity have a corresponding public key? So if I had a list of people I wanted to a post to be visible to, couldn't I "just" encrypt it with a key that is decryptable by each of those individuals via their pubkey?
- acheron 1y agoIn this house, we believe “AT protocol” refers to Hayes modem commands. ATDT2024561414
- Angostura 1y ago+++ ATH0
- imoverclocked 1y agoThis brings back memories of hanging my 56k modem up with a specially crafted ping command :)
- imoverclocked 1y agoA slightly more modern usage for cell modems that still implement AT commands in 2025: AT+QSINR? AT+QRSRQ AT+QRSRP AT+QNWINFO -- getting current status/band of a link
- JdeBP 1y agoI see the error of forgetting the long distance prefix and dialling some poor innocent to squeal tones in xyr ear during Zone Mail Hour is alive and well. (-:
- blainsmith 1y agoIf you want to find other apps that are using Bluesky and ATProto we run https://blueskydirectory.com https://blueskydirectory.com for that. Feel free to add any apps you find to it!
- omni_rizzler 1y agothis directory does not load
- verdverm 1y agoHere's another great resource about the ATProto distributed design https://atproto.com/articles/atproto-for-distsys-engineers https://atproto.com/articles/atproto-for-distsys-engineers
- chombier 1y agoThat was a nice read, thanks.
- trollied 1y ago+++ATH0 Those old enough will know :)
- voxadam 1y agoNO CARRIER
- esseph 1y agoThinking about changing my ring tone now... ;)
- jeffreygoesto 1y agoAT&N34 ha!
- dd_xplore 1y agoI bought a 5G modem made by waveshare, I had lot of fun tinkering that device with AT commands.
- donpdonp 1y agoATDT1170,
- sedatk 1y agoHere is an excerpt from the offical docs for the curious: "Why not use ActivityPub? ActivityPub is a federated social networking technology popularized by Mastodon. Account portability is a major reason why we chose to build a separate protocol. We consider portability to be crucial because it protects users from sudden bans, server shutdowns, and policy disagreements. Our solution for portability requires both signed data repositories and DIDs, neither of which are easy to retrofit into ActivityPub. The migration tools for ActivityPub are comparatively limited; they require the original server to provide a redirect and cannot migrate the user's previous data. Another major reason is scalability. ActivityPub depends heavily on delivering messages between a wide network of small-to-medium sized nodes, which can cause individual nodes to be flooded with traffic and generally struggles to provide global views of activity. The AT Protocol uses aggregating applications to merge activity from the users' hosts, reducing the overall traffic and dramatically reducing the load on individual hosts. Other smaller differences include: a different viewpoint about how schemas should be handled, a preference for domain usernames over AP's double-@ email usernames, and the goal of having large scale search and algorithmic feeds."
- hiena03 1y agoRelevant post by Christine Lemmer-Webber (Co-creator of ActivityPub) https://dustycloud.org/blog/how-decentralized-is-bluesky/ https://dustycloud.org/blog/how-decentralized-is-bluesky/
- verdverm 1y agoa very opinionated piece that leads by conclusion rather than building up to it. The main part of ATProto that is centralized is the PLC and that will eventually be made (most likely) into a consortium. PDS hosting is debatable That being said, it should be possible to run completely independent atproto networks today. We have several dev infra setups for doing it in the ecosystem
- dokyun 1y ago> it should be possible to run completely independent atproto networks today But does anyone do it? It doesn't really matter if it's /theoretically possible/ if no one actually does it. Running an ActivityPub server is piss easy, anyone can do it on a $5 VPS or in their basement, and that's one of its big strengths.
- xphos 1y agoHere I was thinking I'd see old AT commands for controlling radios. Learned something new
- sitzkrieg 1y agotheyre not old and still used in many many cell modems :-)
- xbar 1y agoYup. Bluesky's name collision was pretty avoidable here but I guess they thought the obvious name was BS.
- slyrus 1y agoSame. ATS11=43 was magic back in the day.
- deleted 1y ago[deleted]
- dunham 1y agoI believe that's still used in phones for communication between the computer and the cell phone hardware.
- thesuperbigfrog 1y agoATDT <My Favorite BBS> . . . ATH
- deleted 1y ago[deleted]
- BobbyTables2 1y agoWas fully expecting to see descriptions of “ATD” and “ATH”…
- bobmcnamara 1y agoRING, RING, RING, ATA, CONNECT!
- snvzz 1y ago+++ATH0
- donatj 1y agoYes, exactly! I was expecting https://en.wikipedia.org/wiki/Hayes_AT_command_set https://en.wikipedia.org/wiki/Hayes_AT_command_set
- mrheosuper 1y agoI was expecting the old AT protocol i use to communicate with Radio module
- chrismorgan 1y ago> unicode scalars, which most languages index strings in Very few do. Of moderately popular languages, Python is the only one I can think of. Well, Python strings are actually sequences of code points rather than scalars, which is a huge mistake, but provided your strings came from valid Unicode that doesn’t matter. Languages like Rust and Swift make it fairly easy to access your string by UTF-8 or by scalar. Languages like Java and JavaScript index by UTF-16 code unit and make anything else at least moderately painful. > This is somewhat of an unfortunate tech debt thing as I understand, and it was made this way mostly because of JavaScript, which doesn’t work with UTF-8 natively. But this means you need to be extra careful with the indexes in most languages. I’m confused here. You established indexing is by UTF-8 code unit, then said it’s because of JavaScript which… doesn’t do UTF-8 so well? If it were indexed by UTF-16 code unit, I’d agree, that’s bad tech debt; but that’s not the case here. Bluesky made the decision to go all in on UTF-8 here <https://docs.bsky.app/docs/advanced-guides/post-richtext#text-encoding-and-indexing https://docs.bsky.app/docs/advanced-guides/post-richtext#tex...>—after all, the strings are being stored and transferred in UTF-8, and UTF-8 is increasingly the tool of choice, and UTF-16 is increasingly reviled, almost nothing new has chosen it for twenty years, and nothing major has chosen it for ten years, it’s all strictly legacy. Hugely popular legacy, sure, but legacy.
- psionides 1y agoHmm… Yeah, I guess each language does it kinda differently. At least Ruby also does it similarly like Python. > I’m confused here. You established indexing is by UTF-8 code unit, then said it’s because of JavaScript which… doesn’t do UTF-8 so well? It's not that UTF-8 is because of JavaScript, it's that indexing by bytes instead of UTF-8 code units is because of JavaScript. To use UTF-8 in JavaScript, you can use TextEncoder/TextDecoder, which return the string as a Uint8Array, which is indexed by bytes. So if you have a string "Cześć, #Bluesky!" and you want to mark the "#Bluesky" part with a hashtag link facet, the index range is 9...17 (bytes), and not 7...15 (scalars).
- chrismorgan 1y ago> indexing by bytes instead of UTF-8 code units When the encoding is UTF-8 (which it is here), the code unit is the byte. They called the fields byteStart and byteEnd, but a more technically precise (no more or less accurate, but more precise) labels would be utf8CodeUnitStart and utf8CodeUnitEnd.
- tomgag 1y agoI didn't write this for the HN crowd, but here we go anyway: https://gagliardoni.net/#20250818_battle_of_socials https://gagliardoni.net/#20250818_battle_of_socials Happy to correct any factual inaccuracies.
- ltjbukem 1y agoI think that your description of ATproto relays is a conflation of the role of an AppView (or backend) in ATproto and a Nostr relay. Relays (by default) are not designed to be a permanent archive of content, and are really meant as content streams for backends to ingest and index appropriately. The storage cost is also overestimated, as people have begun to host third-party variants of the Bluesky AppView (which is partially open-source due to its dependence on internal code for some non-essential to microblogging functionality): https://whtwnd.com/futur.blue/3ls7sbvpsqc2w https://whtwnd.com/futur.blue/3ls7sbvpsqc2w The note at the end about Bluesky being able to censor, verify and ban users from the protocol is also largely incorrect, with some asterisks as is for a complex system. The Turkish accounts that were censored were hidden from the platform in Turkey via the app's labeler system, which allows for "composable moderation". You can use this system to implement geoblocking in Bluesky clients based on your IP address when you open the app, which is what they did to ban those accounts from being seen in Turkey. The application of labelers (outside of Bluesky's main moderation service which the Bluesky-hosted AppView follows) is client-side, and any client that doesn't want to respect the default geoblocking behaviour (or implement mod labels at all) can just ignore it. The Politico columnist that was banned from Bluesky has their account taken down from the whole network because their account was hosted on a Bluesky PDS, which could be (somewhat because, again, the default AppView follows a default labeler for displaying content through the AppView's API) bypassed by moving their account to another PDS that isn't operated by Bluesky. If your account was banned from Bluesky while also being on a non-Bluesky PDS, you would still have access to the ecosystem (and a half-working version of Bluesky that is basically a shadowban due to the default client and AppView conflicting with the labeler's takedown action). Speaking of PDSes, they also do quite a bit more than just store user data. As an user's identity is dependent on a PDS to exist as a proper account, most user actions have to be routed through it to allow applications to store their data on-protocol and to authenticate the user. The verification system is implemented through a record type (or "Lexicon") that is stored on an account that basically confirms that the record owner has verified the target. The system is also odd in that there are two types of verified accounts, "trusted verifiers" (think Twitter's business verification system) and regular verified accounts. Trusted verifiers are chosen by the client and can verify their own set of accounts, giving them the regular checkmark. Clients that haven't implemented support for the checkmarks or allow users to choose their own trusted verifiers can basically see whatever checkmarks they want, or just disable the system altogether (which is possible in the default client). How Bluesky uses DIDs are... complicated. ATproto supports two DID methods for accounts, did:web and did:plc. Web DIDs are used mainly for services on the network, but can also be used for regular accounts. PLC is a more complicated system, which becomes quite obvious when you find out the original acronym meaning was "placeholder". PLC is (in regards to the general protocol) not a decentralized system, as its current iteration is a DID document pastebin with authentication and version history. I do think that the method's current centralized status can be mitigated somewhat (synchronization between various directories, then having a consensus system for establishing the validity of the documents' current states), but the system could always be replaced at any point to either incorporate new features or to choose a new model for how documents are publicized. Sorry for the long read but as you see I've wasted way too much time into reading through developer posts and documentation, had to unload it somehow.
- avidphantasm 1y agoWas hoping that BlueSky somehow used the AT command set.
- grishka 1y agoOne nitpick about ActivityPub actor identity — the username doesn't have to be part of your ID (the URL that points to the JSON object representing your actor). It is in Mastodon, but some other software (Smithereen that I work on, and also Misskey) uses opaque identifiers derived from database row IDs. This allows for cleanly changeable usernames since you can just update your `preferredUsername` and `url` fields.
- fsmv 1y agoIt still doesn't solve the account migration issue though right? If you move to a different instance your old instance still has to redirect. How do people find you on mastodon if your instance isn't in your username anyway?
- grishka 1y agoYour instance is in your username. The full username is "@grishka@mastodon.social". You use WebFinger (https://mastodon.social/.well-known/webfinger?resource=acct:grishka@mastodon.social https://mastodon.social/.well-known/webfinger?resource=acct:...) to convert that to the ActivityPub actor ID, which in my case would be "https://mastodon.social/users/grishka https://mastodon.social/users/grishka". And yes, that's one weakness of this system — there is no "real" account migration. Most you can do is set up two-way references between your old and new accounts and ask your followers to unfollow the old one and follow the new one. But your past content doesn't carry over. But then idk, Bluesky's identity service is completely centralized, so the fediverse is better with regard to independence?