13 ms·
Domain Names as Handles in Bluesky
- Lich 4y agoWhat’s the difference between blue sky’s at protocol and the SOLID POD project? They both seem to do the same thing, but AT protocol is narrower in that its more focused on storing social media related data.
- wmf 4y agoBesides what you said, Bluesky is happening (there is an iOS app that works that is in beta) and Solid is not happening (there are no interesting apps).
- doesnt_know 4y agoCurious how it would handle domain ownership changes. Obviously the account would still have standard credentials but once the new domain owner proves ownership does the old handle get reverted to something else so the handle can be used by the new owner or is that account name forever squatted?
- pfraze 4y agoEvery account gets identified by a DID which is long-lived but not human readable. Records use them instead of domains for links/follows/etc. That's how domain-name changes or debindings avoid causing issues.
- sbazerque 4y agoSo the domain is just a shortcut for the DID, in practice? That's interesting! And you're actually following the DID. I wonder how you present this to folks so it's understandable.
- pfraze 4y agoYep. The DID is kind of like an internal UUID, so we don't have to show it to them often. The three cases off the top of my head where you'll care 1. You're setting your own domain handle, in which case you're putting it in your dns record. In this case, it'll just be that string you're sticking in the TXT record. 2. You're migrating hosts. We haven't implemented this flow yet, and since the DID will be referenced in your data export you may not even be aware of it in this case. 3. You're a developer
- sbazerque 4y agoThe case I found more worrisome is you follow someone, they then start using a new domain, and now it seems you're following a different handle (IDK if handles are immutable in Twitter, maybe they are not?). Maybe BlueSky could offer a registrar that would do steps 1 & 2 for you transparently upon domain purchase.
- moron4hire 4y agoYou can change your handle on Twitter, but it's not recommended if you have any "follow me on Twitter @soAndSo" links out in the wild, because it opens people to handle squatters taking your old handle.
- pfraze 4y agoAh sure, that could be confusing -- though I believe Twitter allows you to change your handle as well. We could probably try to let people know when a handle changes, but we'll wait to see if it causes a problem before we get into it.
- ryan29 4y agoIdeally you could use the domain as a (vanity) pointer to an immutable handle and when someone follows the domain they'd actually be following an immutable identity that's a combination of the domain + immutable handle which reference each other. example.com <--> ryan29-abcdef I was trying to explain how I'd do it for a package repo a few months back. https://news.ycombinator.com/item?id=32755618 https://news.ycombinator.com/item?id=32755618
- teddyh 4y agoSo what, exactly, happens the moment a person’s domain is unavailable, or is transferred to a new owner? Does the account show up as the non-human-readable ID until the account owner can verify the ID with another domain? Or what?
- pfraze 4y agoServices will cache the mapping and probably give the old mapping until the cache gets updated. On a failed mapping, I suppose it'll fall back to the DID like you say unless we cook up a better answer.
- teddyh 4y agoNote: DNS already has a cache invalidation mechanism in the TTL of the DNS record. I think you’d be well advised to simply use that; i.e. just look up the domain every time, and let the DNS TTL be your caching mechanism for domain lookups. (You’d also probably better make sure your DNS resolver uses DNSSEC validation, and that your DNS resolving code path requests it by default.)
- doesnt_know 4y agoI was more curious about what happens to the previous owners handle when a domain switches hand. Is the old handle force reset to something else? What if they haven't logged in to change it but the new owner of the domain is setting up that handle?
- woodruffw 4y agoDomain names as handles are a cool idea, and you can already do a variant of them in the "fediverse" either by hosting your own instance of a service or by configuring a WebFinger alias (which is what I do). I'm less convinced by DIDs[1], which is what Bluesky seems to run on: I've yet to see an explanation for why the DID standard exists, given that it effectively punts all semantics (including basic things like cryptographic verification) onto unstandardized "methods" in an uncontrolled global namespace. [1]: https://www.w3.org/TR/did-core/ https://www.w3.org/TR/did-core/
- pfraze 4y agoWe use DIDs to avoid NIHing everything (we already NIHed enough) but weren't pleased with any of the DID methods available, and are currently using did:web for self-hosters and then a registry for non-self-hosters that we're running (did:plc) which we hope to spin out to a non-profit consortium. If something else with the right properties comes along then we'll adopt it, but you're right about how much variance can exist between the did methods due to the light spec and we don't expect to support a lot of them.
- woodruffw 4y agoThanks for the explanation!
- dane-pgp 4y ago> If something else with the right properties comes along then we'll adopt it Have you looked at DID-SIOP?[0] It's based on the "Self-Issued OpenID Provider" extension[1] to OpenID Connect, to make it easier for existing OIDC relying parties to support those identities. [0] https://www.didsiop.org/ https://www.didsiop.org/ [1] https://openid.net/specs/openid-connect-self-issued-v2-1_0.html https://openid.net/specs/openid-connect-self-issued-v2-1_0.h...
- pfraze 4y agoThat must be relatively new - I read every registered spec last summer. I’ll give it a look, thanks for the pointer
- Zetice 4y agoThis totally justifies my decision to purchase a domain that’s “myna.me” so I will be able to authoritatively claim “@myna.me” without worrying about jumping in and grabbing my “handle” early.
- deleted 4y ago[deleted]
- ryan29 4y agoI've wanted to have domains as identity for years, so I'm thrilled to see someone actually doing it. I want to use a domain validated identity for everything; social networks, package repositories, code signing, etc.. I hope this idea catches on. I think a more decentralized approach to identity combined with 3rd party attestations or filters could change the way the internet works. Imagine what could be built if everyone used domains as handles / identities. Social networks could go hands off for moderation and allow plugable moderation engines that rely on domains for identity, trust, reputation, etc.. I'm convinced that domain validated identities and attestation could usher in a revolution for reputation and trust. Are there any more projects doing similar things?
- 2h 4y ago> Social networks could go hands off for moderation and allow plugable moderation engines that rely on domains for identity, trust, reputation Every time this has been tried, it's failed miserably, as it should. People need to be able to post anonymously. Otherwise it's too easy to target the messenger, rather than the message. Think journalists, hackers, abuse victims, political dissidents, whistleblowers. Yes, this makes moderation harder. Sorry but that's life.
- ryan29 4y agoIf the social networks don't moderate, or let you opt out of their moderation, and you can opt in to whatever moderation system you want, how would that be any worse than trusting big tech to moderate fairly?
- 2h 4y agoI don't even understand what you're asking here, but it sounds like you're arguing against yourself, so please continue.
- nbrempel 4y agoDomain handles are a feature but not a requirement.
- 4y ago
- water-your-self 4y agoCan someone point me to good resources for blockchain DNS?
- olah_1 4y agoBy the time they release the app to the public, the hype will be dead. Same thing as Clubhouse. Invite-only just backfires ime
- technion 4y agoThanks for explaining the invite only situation. This sounds like the sort of thing I'd like to try out, so I hit "join" and got to the job application page. Spent some time looking for the sign up process.
- dvt 4y agoWakeup call: literally no one cares about the "protocol." Zoomers will still use TikTok & Instagram, millennials will still use Instagram & Twitter, boomers will still use Facebook. Bluesky is the classic solution looking for a problem.
- wmf 4y agoThat's why they built a fairly polished iOS app before "launching" the protocol.
- phailhaus 4y agoYep, none of these decentralized platforms will take off unless they offer something truly unique. They're way too focused on the implementation details right now. From the front page of Mastodon: > These posts from this and other servers in the decentralized network are gaining traction on this server right now. I mean, what the hell does that even mean to a layperson?
- rickrollin 4y ago> The web. Email. RSS feeds. XMPP chats. What all these technologies had in common is they allowed people to freely interact and create content, without a single intermediary. > Sign up for the Bluesky private beta. Welp this just seems counterintuitive.
- everfree 4y agoNothing seems counterintuitive to me about kicking off an open product by first doing a limited private beta.
- sneak 4y agoAll of those listed technologies got cancelled, shut down, or deprioritized due to rampant spam.
- altair222 4y agowhen? where? I still use xmpp and email, albeit less of RSS.
- ChrisArchitect 4y agoWhy are we watching bluesky build fediverse features slowly in public? Every time they post something it's like ok, another feature on some closed private "also ran" network no one will care about with any mass-adoption possibility for years.... It's just DOA. Mastodon was around for years with no attn and only got handed this miraculous situation and mass migration opportunity but it just got lucky basically. And it's not even it. This isn't happening again for Bluesky any time soon.
- wmf 4y agoI think the original plan was for Twitter to adopt AT Protocol so it would instantly have 100M+ users. That aside, with a better onboarding flow they might be able to lap Mastodon.
- LittleShaman 4y agoI'm curious why Twitter would adopt it. Breaking the walled garden would cost them. E.g wouldnt it mean allowing people to interact with twitter without using the official apps, meaning losing ad revenue? (Obviously why third-party apps were banned)
- NationOfJoe 4y agoI had not heard this before (not that i am super up on this kind of thing) is this a feature that was announced recently or before the change in ownership? I wouldn't think Twitter was ever likely to adopt something that will allow it's users to move away and easily keep their followers.
- barnabee 4y agoMastodon hosts an interesting set of communities in its own right, and its growth is good, but it really doesn’t seem to be in any serious way a replacement for what makes (made?) Twitter great and important.
- pmlnr 4y agohttps://indieweb.org/ https://indieweb.org/
- Nezteb 4y agoI’m a huge fan of #IndieWeb, the social web working group, and their various specifications: https://indieweb.org/Social_Web_Working_Group https://indieweb.org/Social_Web_Working_Group It’s not a new problem, but it definitely feels like an endless battle of specifications and implementations. Most recently I’ve settled on using https://micro.blog/ https://micro.blog/ but I wouldn’t be surprised if I change my mind again within the year as new competitors crop up.
- e-clinton 4y agoI own my first name .net… this could finally be a good use for it!
- KoftaBob 4y agoSimilar to how the nostr protocol does it: https://github.com/nostr-protocol/nips/blob/master/05.md https://github.com/nostr-protocol/nips/blob/master/05.md
- a3w 4y ago"@potus.whitehouse.gov” This assumes that - people know that domains are read from right to left, so that they know that president.whitehouse.gov.usofa.com is not a domain in the whitehouse.gov range (this example is bloated, but domain.com vs. $DOMAIN.com.$DOMAIN-social.net is a common pattern for fraud attempts I get) - people outside the US know it's .gov, not .com (rarely true?) But, better than nothing I guess.
- 8organicbits 4y agoCompared to a flat namespace, it's really helpful, even if some people don't know the rules. How many people have names like RealPerson or PersonOfficial on Twitter? Although I agree, it's not perfect. Is there a better approach they should do instead?
- a3w 4y agoThe lookup of whitehouse.gov (is that the same was house gov, where dotcom was a porn site?) should hopefully be a company name. So perhaps we could use organisations from the DNS system? Or flip the DNS name, write out which geographical or organizational topology applies to every aspect of it on mouseover/touch, to make it readable left-to-right in the case of english etc. And we could combine this, as proposed before, adding the information looked up from DNS for non-private accounts to every domain that is used in browsers or social media. The again, people bought a probably mafia owned companies stock because it looked like the software Zoom was the same as the name of that stock, which was an error. So there is no alternative except for trusting in the word of someone, that identity is what you think it is. But no, i do not think that GNUnet or how ever the HTTPS alternative for trust is called would be a better alternative to prevent fraudulent accounts. Another random idea: Social media could be kind of a reversed "obligatory imprint", i.e, having a natural person's or company's name as your acccount should mean that they should have a postbox for inquiries. Normally, pseudonymous content is required in germany to have an imprint refering to a legal entity. Reverse, because you claimed to be a legal entity, so be liable for that here. Enforcement could be done via ".well-known" addresses on hosts that serve the actual imprint sites? Or with more effort, by sending codes to physical postboxes, that need to be matched for every company or organisation. Tl;DR: Further research into UX and thread models is in order, IMHO.
- comprev 4y agoSounds similar to Keybase. A central platform which allowed the user to "verify" a few different platforms - Reddit, HackerNews, Twitter, etc. It got acquired and promptly nosedived.... with users leaving faster than rats from a sinking ship.
- altair222 4y agoAre people here forgetting that the fediverse exists? Im confused
- nathias 4y agowe don't like fediverse because its a bad soultion, federation combines the negatives of centralization (censorship) and decentralization (disparat userbases with few users ).
- altair222 4y agowho is "we"?
- nathias 4y agowe, the 'people here forgetting that the fediverse exists'
- altair222 4y agoalso disparat-ness is literally the essence of the whole internet, what are you even talking about?
- alxmng 4y agoThe censorship model is mostly the same, right? If you don't self-host, your host can censor your communication and refuse to relay or peer certain messages.
- 8organicbits 4y agoCensorship seems like a non-problem on mastodon. If you are using someone else's server, and you break their rules, you'll lose your account. Just try another server. If you run your own server you make the rules. Other servers and users may block/mute your server but some may not. If everyone blocks your server and no one else joins your server, then maybe no one wants to hear you. You are not entitled to force people to listen to you.
- _8j50 4y agoRegistrars and PKI CAs should be the same orgs (can't do only one) and each domain registration should come with a certificate. How is this not a thing? Only a valid CA for a valid TLD registrar should issue certs for a domain name, not arbitrary CAs. So much could have been avoided with this. If you're gonna tie your identity to it. PKI is very important. EV pki cert gives me more confidence in the authenticity of your account. How many people do you think I can fool with trump-white-house.trust (or many other cheaper/easier TLDs)?
- DeathArrow 4y agoWhy not permit more than one user for a domain? Like user@domain.extension?
- dspillett 4y agoSo, an email address? Unless that is the point you are making of course (as I type this I realise how slow I might be being!). Alternately if they want to stick to the domain structure: user.domain.tld (I've not checked to see if that is already supported). The problem with both of those though is that you are then less in control of your identity – the domain owner has the power to stuff you over if you are just a user of it. Because of this issue for you as the user, it means that the identity is not as trustworthy to the service because the domain owner can take control of it themselves or reassign it.
- stanleydrew 4y ago> The problem with both of those though is that you are then less in control of your identity – the domain owner has the power to stuff you over if you are just a user of it. I don't think this is true. When you control the domain then you control email and subdomain address spaces. In the context of the given example, there's no difference in control between dholms.xyz and dan@dholms.xyz or dan.dholms.xyz when the same person registered or created all of them.
- dspillett 4y ago> when the same person registered or created all of them Exactly. How does the service trusting that the address or subdomain as identity know that they refer to the person that created them? I have surname.tld, I create dave@surname.tld for me and wayne@surname.tld for my brother. If Wayne annoyed me and I was a dick about it I could revoke the name or reconfigure it in order to act in his name maliciously. The same for sub-domains. How does a service wanting to trust the address as ID know which of us has that control? My identity is more strongly linked to my token (address/sub-domain) than Wayne's but there is no way to infer this from the identifying tokens themselves. Of course a hack at domain registrar level could stiff it all over, so even only using top-level domains isn't perfect, but there is definitely a difference in the level of identity stability guarantee between domain and sub-domain or email address. (So the is a difference between dholms.xyz, and dan@dholms.xyz or dan.dholms.xyz)
- netfortius 4y agoIsn't this what Z-lib has just recently implemented, for its users?
- RobotToaster 4y agoSo, is this still completely closed source?
- sainez 4y agoThis looks very interesting. I just had an idea for something along similar lines today when thinking about how we can be resilient against the coming wave of AI-generated spam. But I definitely think that the protocol itself must be open for it to be viable.
- jeroenhd 4y agoUsing domain names as handles seems like a great idea... for those whose names are easily represented by Latin-1. Does this mean that either homograph attacks or punycode are going to make it into Bluesky? Or is this another protocol that's built around English and nothing else?
- i5heu 4y agoIs this a copy cat of Mastodon as a commercial service? Did i get this right?
- djschnei 4y agoSeems like a direct implementation of how Nostr handles verification. Nip-05 describes how it's done and is successfully implemented in most Nostr clients: https://github.com/nostr-protocol/nips/blob/master/05.md https://github.com/nostr-protocol/nips/blob/master/05.md
- m3kw9 4y agoSo is this a cool feature or just gonna prevent your everyday person from signing up, “what? I have to do what to sign up?!”
- mminer237 4y agoIt sounds like it defaults to "@yourname.bsky.social" and setting it to a domain is something optional you would do afterwards if you want.
- MagicMoonlight 4y agoThat's a really good idea. You can't cheat it in the same way as you can cheat twitter (get the tick as Mark Cornly and then rename yourself to Elon Musk)