Bluesky's AT Protocol - Federation Architecture Overview
blueskyweb.xyz
blueskyweb.xyz
The only market it seems to be gaining traction in from my perspective is millennials who have nostalgia for old Twitter -- and as someone who grew up with old Twitter, I can say I don't really miss it.
As someone who doesn't seem to be a deep into the specifications (ActivityPub nor AT Protocol) as you are, how does ActivityPub handle people moving across servers without loosing old content and interactions? Like if I use server A but want to move to server B, how does that work in practice? How does server C who used to communicate with server A get notified that they now have to communicate with server B instead?
> The service feels too much like "Elon bought Twitter, now we need to make Twitter again"
Strange feeling considering bluesky was first announced in 2019 as a Twitter project, eventually spun out as a separate entity in 2021, and Elon didn't start the acquisition of Twitter until 2022 sometime.
This implies that:
- If the old server is offline or unwilling, you cannot move - Your old toots and interactions will still be tied to the old address, so you leave those behind.
There is some talk going on to find ways to mitigate this and it might be possible to fix the second issue.
The first issue is a bit trickier though. If you were to remove trust from the server, it becomes way harder to fight spam.
> Our solution for portability requires both signed data repositories and DIDs, neither of which are easy to retrofit into ActivityPub. The migration tools for ActivityPub are comparatively limited; they require the original server to provide a redirect and cannot migrate the user's previous data.
So it seems that AT Protocol has a solution to that specific problem, while ActivityPub does not. So there is some differences between the protocols after all, and it might seem like they have at least one reason for creating a new protocol rather than trying to adjust ActivityPub to fit as a solution?
This is just like any other system that combine content delivery and identity on the same channel (e.g. web sites). Even if those 2 were separate, if your centralized identity provider is down, there is no way to update clients that depend on it, or to safely attest a new identity.
Allowing unverified servers to claim an identity or kick off a migration is a recipe for widespread hacking.
But, there's nothing fundamental about ActivityPub that prevents this: https://shadowfacts.net/2023/activitypub-portable-identity/. You can absolutely have posts identified by your identity (read: domain) rather than where they're hosted. Complete and seamless moves are possible, Mastodon just doesn't implement them.
Thanks for sharing your article, lots of good points in there.
Have you seen the ecosystem study BlueSky published in 2020? https://gitlab.com/bluesky-community1/decentralized-ecosyste...
Bit more of a summary https://twitter.com/bluesky/status/1511811083954102273
BlueSky/AT Protocol seems to have pretty distinct design goals that are not possible with ActivityPub.
ActivityPub of course uses the same cryptographic certification virtually all the web does, just TLS/HTTPS and relies on the host cert to be valid. But if you wanted to add further levels of verification like pubkeys and sigs, there's absolutely nothing stopping you.
I guess the race is on, then. Surely ActivityPub, with its much larger user and developer base, will grab the best ideas from AT Protocol and squash this redundant newcomer.
Seems based on that variable, ActivityPub has the benefit of being more widespread, but that tends to also make changes go through slower. ActivityPub being a specification maintained by W3C also make changes extra slow, but stable at least, while AT Protocol probably won't have any stability guarantees for a long time.
Sure you could implement BlueSky-over-activitypub, but would it be usefully compatibile with mastodon-over-activitypub? If not, why add the complexity.
Felt very much like in practice it just gives you tools to make mostly-insular federated apps, rather than letting different apps interact.
Because that would just restart at square one? It's like we've learned nothing about centralization since the web1 era.
I think we should abandon whole idea of feed. Instead give me people/account/tag specific feed like Instagram or WhatsApp stories. With this I choose what I want to see. It would drastically reduce noise and my time on platform. The platform should be delight to use not something that is constantly trying to suck me into drama.
This would also eliminate need of Big Graph Services.
It's still unclear to me how the federated economics will work out
I believe that a platform which doesn't have such financial incentives could produce a different spin on an algorithmic feed which isn't as unhealthy.
I also believe it should always be optional, and transparent. I probably wouldn't want to use it - I'm only interested in what the people i explicitly follow have to say.
- Decentralized email (with a gateway to legacy email via the @freenet.org domain)
- Decentralized microblogging (think Twitter or Facebook)
- Instant Messaging (Whatsapp, Signal)
- Online Store (Amazon)
- Discussion (Reddit, HN)
- Video discovery (Youtube, TikTok)
- Search (Google, Bing)
Bluesky is just a decentralised social media.
The alternative would be storing the user data on a distributed data structure(like a pki network or distributed hash table) so that it's not tied to a single provider.
If you gave your email address to someone, you cannot change it on their devices. Your domain registrar with DNS for the domain case, or your ISP for the IP case, can stop email deliveries to you or redirect them somewhere else.
With a decentralized email, people email "you". Not "your username" on Google's service, or your username on a domain you rent from others, and not your username on an IP you rent from a centralized authority.
Not much to it really.
And yeah, for sure the only reason people outside of bluesky cannot see the content is because they're still figuring out how to actually serve image bytes over HTTP, which turned out to be a technically difficult problem that there is no prior research about.
Isn't the the saying: "if it's free, you're the product"?
the ethical model is obviously ActivityPub tho
adding more than snark to my reply: I want to know if the PBLLC intends to submit this protocol to the IETF or W3C. We do the RFC thing for a reason folks.
when “how do we monetize this?” becomes the driving force of a social thing, the experience changes in very real ways.
Im more interested in the Mastodon/Bluesky approach to re-decentralizing (we had thriving forums long ago). But eventually cost does add up and monetization (or a benevolent benefactor) has to be considered.
> Soon, we’re launching a sandbox environment to begin the testing phase of federation for the AT Protocol with allow-listed servers.
It's a work-in-progress. As I'm sure you know, you can't build and launch everything at once, so the rather small dev team has a roadmap, and is building and testing features in sequence.
When they get close to launching a new major feature, like federation they make announcements and posts about it, to encourage discussion and debate about it, and look for early adopters who are willing to test it out.
So... You're saying you like AT Protocol/Bluesky then? Because if that's what you're trying to say, your post kind of reads like you don't like it, but then what you want is exactly what they are trying to provide...
There's an earlier blog post that talks about the "algorithm marketplace" that is worth looking up.
I don't think this team "sees" any use cases for sorting feeds right now. In the current beta there are two feeds, your followers which is chronological (and the default) and "What's Hot" which is a haphazard very much placeholder timeline of the "most interacted with" posts, and I think that just means "13 likes or more, then chronological" at the moment.
It's super basic and not at all the priority for them. From all I've seen in my time in the beta, the most important use case they are working towards is "let everyone pick their own way of sorting/filtering/moderating their timeline".
Unpopular opinion for HN: I like recommend content. Especially with TikTok where the vast majority of content I consume (and I think most others) is generated by non-friends. Crafting the perfect list of who to follow is tough work so when the algorithms can do it I'm happy. Of course, the recommend content needs to be good and interesting to me. I suspect most people's frustration with it is the result of getting bad recommend content. Though for some people recommend content might be particular bad for you if your interests are more niche.
But I also agree that I wish you could turn recommend content off. If it's recommendations are bad, I agree it shouldn't be shoved down your throat, but also please don't force a recommend content free world on the rest of us.
The wild success of TikTok suggests you’re wrong. HN can be an echo chamber at times.