99% of people who could benefit from owning a domain should never have to know what a DNS record or TLS cert is. This should all be managed by apps through a simple delegation system built on OAuth2.
You log on to bsky.app, they say, "want to connect a domain?". You say yes and get redirected to your domain registrar, where you grant access to for bsky.app to have control over bsky.example.com until you revoke access.
DomainConnect[0] should solve this but in practice it's turned out to be very gatekeepy in my opinion.
I have not ready anything about the protocol yet, is there something in it that keeps all your data accessible to you after a ban?
Is list of contacts, other people's posts and such part of that move or what exactly is left to someone after they are banned?
There's a thing called DID that identifies you. There's a few options, but one is called "DID PLC" with a sample implementation here:
https://github.com/did-method-plc/did-method-plc
With the disclaimer that I haven't dug into it seriously enough, I understand it's a public key (that I can also rotate) that I can use to prove that an account somewhere else is really mine. Note that I have no idea what the private key is, or how to dig it out - I'm sure that's documented somewhere, but I wasn't interested enough for now.
TL;DR: there definitely is a theoretical mechanism for users to "take their toys with them." How it works out in practice is a different matter. I suspect most users wouldn't know they're supposed to keep a bundle of data stored somewhere for a dark hour. I also wonder how the protocol protects itself from people accidentally putting that data in public.
The whole "we can just use DNS names as ID and it'll be unbannable" idea is just relying on the fact that domain names aren't normally used as social media IDs and that more neutrality is expected from registrars, and neither of these presumptions are guaranteed.
Once enough users start using domain names and gets >100k daily likes with anime illustrations, same people as who were problems ARE going to get mad and set up their systems to just hammer Namecheap, GoDaddy, Gandi, Porkbun, until their support gives in just like it always happened. If they didn't, they inject faults in credit card payments, make their authoritative servers unresolvable in UK, Apple devices, on 1.1.1.1 and 8.8.8.8, so on and forth, until they do.
Using a decentralized protocol and providing custom domains is sufficient for me.
If you're optimizing for censorship resistance and your threat model is that registrars want to take you down because there are enough people mad about what you're posting, you're going to have to make UX tradeoffs that most people don't and shouldn't need to.
> If they ban you then you take everything, including your profile domain, ...
This reads like censorship resistance against moderation/management going insane on its own, to me. And in reality, that rarely happens. It's ongoing on Twitter, kind of, but that's less than once in a decade occurrence, and the crazy element wasn't internal.
What happens more often is some fundamentalist group or something starts harassing companies, often leveraging advertisers, credit card companies, perhaps some backend APIs too, sometimes even foreign laws way outside jurisdictions, to get them swallow their agendas. That leads to bans and insane policies getting introduced.
And, if you look at what happened to Twitter in last few years, I think you can see the latter of above two descriptions is closer to what happened to it; whether it was foreign conspiracy, or purely to that guy's insanity, or politics, it was external force that lead to the situation that necessitated escape. It was sane-ish up to the acquisition.
Once the community degrades to having no social standards there is no point in moderation.
This is not really true. DNS allows you to set your name to a domain, but ultimately all of your posts are tied to your DID. If you wanted to move from steveklabnik.bsky.app to steveklabnik.whatever.app, you could do that still, no DNS required. You won't lose anything. The DNS stuff is effectively vanity.
The other direction we've got is did:web, which is already used in some cases, and has some tradeoffs but is a strong option.
In general, I guess I'm just pessimistic of the ability for any DID system to exist that isn't either centralized or majorly user-unfriendly. I think that reasoning on a "local scope" like ActivityPub does and worrying less about global identity is just a better long-term solution for users and works better with how people are practically using social media today (think about the proliferation of a million discord servers each with effectively their own user identity....)
> In general, I guess I'm just pessimistic of the ability for any DID system to exist that isn't either centralized or majorly user-unfriendly.
That's fair. Time will tell :)
I think the questions about indexers and firehose servers are more relevant to the question of centralizations. Identity is much easier to solve.
In the DNS, that’s called a subdomain. I.e. a group of users can come together and buy a domain name and all use different subdomains, completely without any additional cost per user.
I don't think so. Anyone can set up a server with a DNS entry and then hand out subdomains to users. It's only sekf-hosted folk who need to pay for a domain name
(we run the largest instance of atproto outside of bluesky)