1,298 karma · joined February 3, 2020
What about using Nostr relays to also back up your data passwords? I built a library called Tablinum around this idea. Local first but backed up to Nostr relays using NIP-59 gift wrapped events.
> So let's talk in practice: when you sign up for Bluesky, they store the private key for you. This way, for users that don't care about any of these details, they do not have to think about it at all. It's saved with the rest of your account data, you don't have to worry about backups or anything.
> However, at any time, any user can register a rotation key with the PLC directory. To do this, you generate a new public and private key, and then store that private key wherever you'd like. All the usual caveats here apply. You can then use your existing private key to add this new public key to your account. Once you do that, it shows up in your DID document as a rotation key. You can use that rotation key to add more keys, remove the Bluesky owned keypair, whatever you want. Now it's not stored by Bluesky.
> The majority of users have not done this, it's true. But they can. Whenever they'd like.
The Bluesky PDS stores (and has access to!) your private keys. They are in full control of your identity. It just so happens that 99.99% of users are on the Bluesky PDSs AND 99.99% of users will choose the path of least resistance and in practice NEVER register an external rotation key. This is exactly the problem. It is massively centralized and a rug pull from Bluesky would effectively just kill off the network.
It's insane that this is just hand-waved away because "you can just self-host" or "you can just register an external rotation key". If you think users will actually do this I have a bridge to sell you.
The fact that the PDS in practice owns your identity in the vast vast majority of cases is such a dumb trade off that it’s honestly laughable. Should Bluesky decide to splinter off of the network there would be like 50000 people left.
Stop telling people that it’s decentralised in any meaningful way and be honest about it instead. That’s the issue. The dishonesty and tricking users.
The day Bluesky decides to enshittify there’s a very real possibility that they might also just stop allowing people to extract their keys and splinter off the network. The enshitification begins when VCs turn upp the heat it they start getting low on cash.
“The signing key is entrusted to the PDS so that it can manage the user's data, but rotation keys can be controlled by the user, e.g. as a paper key. This makes it possible for the user to update their account to a new PDS without the original host's help.”
No one (not literally of course) self hosts their PDS. Like 99.9%, if not more, are using the Bluesky PDSes.
https://kevinak.se/blog/who-actually-owns-your-atproto-ident...
People in the Bitcoin space have been screaming at the top of their lungs about this for decades at this point, but it's hard to work against the marketing machine that comes from these ICOs.
I think it would be better if you actually engaged with the article and articulated any criticism you have with it instead of just writing things off because I like other solutions to decentralized social media more.
1. I absolutely feel very strongly about decentralization. If there is a part of the stack that isn't it opens up the whole project to the kind of issues I'm talking about in the blog post.
2. Then it is not made to be resistant to the above problems
3. Actually, this is where you are wrong! If atproto implemented a more robust, decentralized default identity system I would be a very happy camper.
I make comments because I care about the subject, obviously. I use Bluesky a lot and I don't want it to end up like Twitter.