10 ms·
Who owns your ATProto identity?
- noname120 3mo agoAI fluff
- opem 3mo agoand what makes you say that?
- Zopieux 3mo agoIt has all the tells. There are websites which list them, please search "LLM tropes".
- bluebarbet 3mo ago"This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, like UFO sightings in the 1950s. If ever it is still possible to "tell" AI writing, it soon will not be. So best (IMO) just to respond to the substance of the writing and move on.
- refulgentis 3mo ago> "This was AI" itself has all the tells of an irrational panic which typically accompanies new technology, Being able to tell who wrote something doesn't imply irrationality, panicking, or a reaction to new technology. > like UFO sightings in the 1950s. UFO sightings stayed confined to the 1950s and were a reaction to new technology? Or were the UFO sightings in the 1950s the only UFO sightings that were a reaction to new technology? I'm not sure how this being clarified will be able to explain how identifying the writer of text is the same as a UFO sighting in 1950, but I'm open to it, I try to stay rigorously rational (c.f. X does not imply Y in first pull quote) > If ever it is still possible to "tell" AI writing, it soon will not be. Why not? n.b. I quit my job at Google to build an AI client and have been working on it full time for 3 years. I love AI. I don't think there's a rational argument that justifies the idea it's better to never opine the author of some writing was AI, and the arguments offered here are particularly weak, at their face. As an opinion, solely? Fair enough.
- ranger_danger 3mo agoI think the main problem is you can't really ever tell with a high degree of certainty, people are just guessing based on what they see in an unscientific way. And the fact that AI is trained on human data, meaning what we see is in fact things humans have already done themselves, makes it even harder to "know" for certain IMO.
- refulgentis 3mo ago> the main problem is you can't really ever tell with a high degree of certainty This is false, it is trivial to find humans with 99%+ accuracy[1] and there is a well-known service with 99%+ accuracy when analyzed by 3rd parties with no affiliation.[2] > people are just guessing based on what they see in an unscientific way As we see above, this is just guessing in an unscientific way. :) It's important to be rational! We all agree on that. :) FWIW it did used to be true that the 3rd party services were junk. And I don't support the idea of humans just winging it when there's consequences. The case we're in is about the most mundane and consequence-free, the vast majority of us use AI daily and we're commenting on an internet aggregator that is aggregating a blog article. [1] People who frequently use ChatGPT for writing tasks are accurate and robust detectors of AI-generated text - https://aclanthology.org/2025.acl-long.267/ https://aclanthology.org/2025.acl-long.267/ [2] Artificial Writing and Automated Detection” - https://bfi.uchicago.edu/insights/artificial-writing-and-automated-detection/ https://bfi.uchicago.edu/insights/artificial-writing-and-aut...
- ranger_danger 3mo ago> This is false, it is trivial to find humans with 99%+ accuracy Sorry but no, this is also false. AI is largely trained on human data. What it outputs is also largely what a human would output. We could both easily make up the exact same sentences (especially smaller ones) and there is NO way to tell what the real source of a sentence is, especially considering the source can be multiple things (AI and human) at the same time! There is no amount of literature you could provide or anything you can do or say that would change my mind on this.
- drdexebtjl 3mo ago> It's not the data, it's the keys is a heading edit: >On ATProto, your PDS doesn't just store your Bluesky posts. It stores everything. >Not just your Bluesky account. Your ability to post, commit, publish, or interact across every ATProto app. >The repo data itself isn't the issue. It's all public anyway, >An attacker, a state actor with a warrant, or a rogue employee doesn't just get read access. They get the signing keys
- Zopieux 3mo agoSo annoying to read. Meanwhile, the key information ("backup key with higher priority") is mentioned in a sentence without any kind of elaboration or link to some follow-up/how-to.
- Stmz_Kinetics 3mo agoI have also the online services and i don't know where to put the people feedback, the reddit banned my account, and also here , it says , wait until we allow you to post
- verdverm 3mo agoProbably doesn't matter for the "40M+ users", most of them have churned at this point and growth is negative. This is good critique for the next iteration of open social protocols, but fundamentally atproto did not fail because of technical reasons. The next iteration should make privacy the default and core to protocol, and be very mindful of how the leadership / social dynamics played out.
- singpolyma3 3mo agoBased on all the traffic and development activity I'm not sure on what basis one would say "failed"
- pessimizer 3mo agohttps://bsky.jazco.dev/stats https://bsky.jazco.dev/stats
- ftfish 3mo agoSource? What I see here doesn't look good. https://bluefacts.app/bluesky-user-growth https://bluefacts.app/bluesky-user-growth Never mind the pivot to reddit. https://www.cnbc.com/2026/06/04/bluesky-twitter-rival-reddit-social-media.html https://www.cnbc.com/2026/06/04/bluesky-twitter-rival-reddit...
- adithyassekhar 3mo agoWhat’s the definition of success here? Instagram like user counts?
- bikelang 3mo agoArguing that success is purely about the ultra high numbers seems to miss the forest for the trees. Is HN a failure because it did not reach the level of DAU as Reddit? The quality of discussion and community here is certainly substantially higher. I feel the same about Mastodon and Bsky vs Twitter. I’ll take community I actually want to engage with over sheer numbers any day.
- scyclow 3mo agoThis is where non-financial use of blockchain could really shine, IMO. Self-sovereign identity management with a smart contract-based process for recovering ids if keys get lost or hacked. Blockchains are pretty out of favor these days, but I really don't see a better solution for decentralized identity management.
- AndrewStephens 3mo agoWhat is the incentive for an individual to participate in a non-financial blockchain? Bitcoin-style blockchains “work” because everyone gets the possibility of a little reward for all the hassle and non-negligible CPU time of being a node.
- vid 3mo agoWhat's the incentive for people to participate in file sharing networks? To some degree it's access to a world of free media (same as access to a world of decentralized identities), but to a large degree it's an interesting hobby/excuse to be interested in tech. Some people have racks of hard drives dedicated to hobbies like this, just because it's interesting and is worthy.
- majorchord 3mo agoFor me the incentive is being able to own an identity that nobody can take away from me. And the assumption is that services will support this type of identity, so I don't have to make accounts on other systems that people can take away and now I've lost all access to any data I had.
- AndrewStephens 3mo agoI think what you are looking for is something like Mastodon or related activity-pub service. You can run your own instance and nobody can take that away from you. No need to drag a blockchain into it - just host whatever services you need.
- 3mo ago
- triyambakam 3mo agoWhat's the evidence for this? I'd be very keen to understand. This looks Claude written which is fine but adds an extra layer of skepticism for me.
- kevinak 3mo agoYou can just read the documentation: https://atproto.com/guides/overview#account-portability https://atproto.com/guides/overview#account-portability “The signing key is entrusted to the PDS so that it can manage the user's data, but rotation keys can be controlled by the user, e.g. as a paper key. This makes it possible for the user to update their account to a new PDS without the original host's help.”
- Noaidi 3mo agoCentralization is always a trap. No idea why people have such a hard time joining and supporting the Fediverse.
- sheo 3mo agoBecause there is no single "default instance that is always a good choice and wouldn't go down randomly because of lack of funding". That's both a strong and a weak side of fedi
- ftfish 3mo agomastodon.social has been around for a decade now, seems stable enough.
- webdevladder 3mo agoHigher friction and fragmentation are Fediverse features (not bugs) that give it a different grain. ATProto has different tradeoffs that lead to a different form of social media. I'm glad both exist, and bridging efforts are worth paying attention to for anyone frustrated with the distinctions.
- kevinak 3mo agoYes - the trade off is centralisation.
- iand 3mo agoHow is the fediverse different. Can't the owner of an instance post as you? Can they read all your data stored on their instance and pass it to anyone they want to?
- deleted 3mo ago[deleted]
- skybrian 3mo agoMost people don’t worry about it for the same reason they don’t worry about GitHub abusing their GitHub account and are even willing to use “login with GitHub” to access their other accounts. Account takeover by a third party is a bigger risk. If you’re concerned about supply chain risks, there are more important concerns than “what if GitHub itself is a bad actor.” It’s solvable if you’re willing to self-host your PDS. But I’m skeptical of the attempts to make a PDS an “everything account.” Why should you use the same PDS for your social media posts and your git repos and your blog posts? Seems like we need to get better at locking things down in practice before that kind of centralization?
- NetOpWibby 3mo agoThis "social coding" thing Tangled has going on is cool but I don't want it. I hear they're figuring out private repos but for me, I don't want the same account I use for social for my code. I'm probably in the minority though.
- rafterydj 3mo agoPersonally I think it should be optional, but meaningfully optional in a way that's technically sound and easier than it is now. I kind of feel like long term I'd want "professional/public" code I'd put my name on, and separate code I'd work on under a pseudonym/handle.
- satvikpendem 3mo agoCheck out https://radicle.dev https://radicle.dev then.
- NetOpWibby 3mo agoRadicle is too confusing to me. I want to like it though, it looks cool. I appreciate it doesn't look like a Temu Github like almost every alternative.
- packetlost 3mo ago> I don't want the same account I use for social for my code Then create separate accounts?
- jacobgold 3mo agoOne of the core features of AT is the ability to move your repo hosting provider (PDS) at any time. This is the "data portability" problem that ActivityPub never solved. Bluesky Social, PBC runs a PDS service (bsky.social) for free, there are a number of free public alternatives, and thousands of users self-host. Self-hosting your own PDS can be done with Raspberry Pi or $5/mo VM and requires very little work. It runs in a Docker container with SQLite. https://github.com/bluesky-social/pds https://github.com/bluesky-social/pds
- opem 3mo agoExcept it isn't as straightforward as most people would think. The last time I checked this, I think there were some issues with Bluesky app view and it didn't show accounts from a self hosted PDS
- quasigod 3mo agoWhen was the last time you checked that? That is definitely not currently true and hasnt been for as long as I've used Bluesky.
- jacobgold 3mo agoYou may have seen a temporary bug. It's completely straightforward and it works. Tens of thousands of users are doing it successfully. https://blue.mackuba.eu/stats/ https://blue.mackuba.eu/stats/
- mdasen 3mo agoYou have the ability to move, as long as Bluesky Social PBC allows it. They hold the keys for your DID. If they don't allow you to move to another PDS, you can't move. The original theory was that you'd hold the private keys, but that's something that would hugely limit adoption so they decided to hold the keys themselves. In terms of moving your backlog of posts to a new server, part of the issue is liability (not merely legal liability, but reputational as well). When you have a user on your platform and they're posting stuff, you're moderating them in real time. If they turn out to be a horrible troll, you've get the reports. Let's say a horrible troll has been on EvilServer and EvilServer has been ignoring the reports against them. They now want to move to your GoodServer and bring all their post history with them. As an admin of GoodServer, you can't see that everyone has been reporting this troll for years. They're now moving over lots of horrible, inflammatory, potentially illegal posts to your server.
- rbren 3mo agoWho owns your domain name? Hint: it’s probably not you. Your hosting provider could take down your domain, or even steal traffic and direct it to their own IPs
- PunchyHamster 3mo agoBut without private keys they can't pretend to be the same you. There is a very big difference here.
- chuckadams 3mo agoRight, if Bluesky ever does do something hinky with your PDS, the operation will be signed with their key and persisted in the operation log which they're unable to touch. You can outright remove Bluesky's key if you want, though I think that only works within some number of days of creating it.
- PunchyHamster 3mo agoIt's probably one of few places where blockchain would be actually useful; just use it as a history of users keys to validate against, so any domain takeover or similar event would at least not allow stealing user's handle
- opem 3mo agothat is why you have did:plc in ATProto but that doesn't resolve the concerns raised in this article.
- handoflixue 3mo agoCan you move a DNS record AND make it look like I signed off on it? The author's concern seems to be more focused on impersonation
- Zambyte 3mo agoDo you use your own CA? Would you expect users to even notice if the certs were suddenly issued by LetsEncrypt? Or are you signing traffic using something other than TLS, where the domain name doesn't really matter anyway?
- jimmydoe 3mo agoIt seems most ppl who dislike X has already settled, a small amount moved to DeSo like atp or ap, most just stayed or went offline. Unless China GFW magically collapsed, there seems no reason ATProto user base will continue to grow. So, when will the monetization/enshitification phase begin? I'm asking this not bc I like enshitification, but the app view design seems such a perfect fit for user data mining/targeting, that it's hard to believe it was not part of design consideration in day one.
- kevinak 3mo agoAtproto is not decentralised, it’s faux decentralised. You can technically be sovereign, but incentives and the way things have been done results in massive centralisation - 99.9% of users are on a Bluesky PDS and have not registered a higher priority rotation key. And they won’t, ever, because that’s how humans work. The day Bluesky decides to enshittify there’s a very real possibility that they might also just stop allowing people to extract their keys and splinter off the network. The enshitification begins when VCs turn upp the heat it they start getting low on cash.
- jimmydoe 3mo agoATP is more decentralized than X at least. Decentralized as a term is almost as loaded as Democratic. :) Anyway I think we can agree on enshitification is coming soon. I'm just looking for signs of that's actually happening (or a counter theory that it would not happen)
- theamk 3mo agoIs author new at the whole web thing? Yes, people trust remote web servers. Yes, if you link multiple apps to an identity server (be it atproto, google, or self-hosted OpenID server), and your identity server is compromised, attacker will be able to impersonate you or lock you out. This is just how the web works, and there is no easy around it without losing features people care about. Sure, you can do client-side encryption and pretend serve can't see the plaintext, but it's just a theatre, see Hushmail incident for example. And having people export uber-key by default is pretty terrible idea. Sure, allow advanced users (like post author) to do it. But for the common person, the exported key is just another way to get account compromised, via malware or backup provider hacking. Or if they are not backing up stuff, then the key will get lost next time they upgrade.
- logifail 3mo ago> This is just how the web works, and there is no easy around it without losing features people care about [...] Well, apart from using a separate email address for every single "provider"? (Spoiler: there's no way I'm going to sign into your service with a shared email ... you get <youservice>@<me>.com)
- ranger_danger 3mo agoSome services only allow signups from the big free providers like gmail/outlook/etc. because those providers are doing more consistent KYC and anti-spam measures than anyone else by far, and unfortunately it does cut down on the amount of spam by a lot. For most people nowadays you cannot even create a new gmail account without directly linking it to a mobile phone.
- Aurornis 3mo ago> Sure, you can do client-side encryption and pretend serve can't see the plaintext, but it's just a theatre, Keeping a private keep on the client to sign your activity is a fundamental cryptography practice. If you use a private key to sign your emails or git commits, it’s not security theater. If you were to have to upload your private key to GitHub or your email provider, that would be severity theater. > Is author new at the whole web thing? Unnecessarily mean comment.
- opem 3mo agoBoth nostr and atp sucks at key management imo. The Farcaster network does a good job here with their chain of trust model and a smart contract on etherium blockchain to recover identities in case of losing access to a private key. Ironically its also the blockchain aspect of Farcaster for which I never tried it.
- Muromec 3mo agoSo does a CA issuing my certificate, but there is some oversight in what they do.
- jeroenhd 3mo agoThat's different. While your CA can hand out new certificates, it doesn't know your keys (unless you messed up when uploading your CSRs). CAs have to prove they're not faking certs through the certificate transparency logs, there's no such limitation on Bluesky. A more apt comparison is a shared host that does certificate management for you. Those are also often considered less secure, of course.
- skywalqer 3mo agoWhy aren't the keys stored encrypted?
- varun_ch 3mo agoI think most people don’t need to worry about their host abusing its power to impersonate them, but the cool thing is, the people who do need to/want to worry (journalists, politicians, celebrities, activists, open source maintainers, etc etc etc) can self host a PDS and be a lot safer, and still interact with everyone else.
- tengada1 3mo agoWait what?! For a protocol that incorporates the DID spec this is disappointing to discover. Unless I'm mistaken the DID spec allows provable hierarchical relationships between DID identities – why can't a child DID be created from our master signing identity that has the authority to CRUD on our behalf but still be provably distinct from our root identity? Not even sure why the PDS would require our signing key that just seems very sloppy to me. As you can tell I know very little about atProto, and I did participate in the development of the DID standard and I am dismayed to see such an inelegant solution in such a promising protocol.
- tengada1 3mo agoOops upon closer reading of the article and the comments here i see that the atproto standard does apparently allow for the above, at least to some degree. If there is indeed hierarchical support for the DIDs then you should be able to disavow any child identity from a master identity and leave no public uncertainty (ie the true owner of the key hereby disavows the following sub keys) So if the worst case scenario presented in this article took place where a PDS was falsifying information and pretending to be you, you could presumably somehow revoke the child key that you provided to the PDS. I'll have to look more closely at this You could even publish a signed selective retraction (delete the fake posts or mark them as fake) with proof that you control the key 1 level above the key that posted them
- kevinak 3mo agoThe point of the article is that 99.9% of users will not take custodial control of their identity - not that they can’t.
- tengada1 3mo agoWell it's a very well understood concept in cryptocurrency – you just keep your seed phrase somewhere like on a paper wallet. And if you're less paranoid then millions of people use some thing like MetaMask which there could be an equivalent of for identity management relevant to atProto– or maybe there is?
- ascorbic 3mo agoSure, somebody else holds your identity, but it's pretty easy to control it yourself. By its nature if you're using somebody to host your stuff, you're trusting them with it. I made Cirrus so you can self-host your PDS for free, but you still need to trust Cloudflare to run it.
- kevinak 3mo agoIt’s great that tings like this exist but as long as this is how identities work on ATProto it’s unfortunately going to be a niche thing.
- ascorbic 3mo agoThe easy way is to create an account on Bluesky. That's as simple as creating an account on any other social network. The important bit though is that you can then, if you want, migrate to a different host and take your identity with you, or if you're brave you can self-host. This is by its nature something for power users, but regular users can use Bluesky accounts without ever knowing or caring about PDSs, DIDs or signing keys etc.