4 ms·
Yes, and what if they had a tab in the Bluesky app where you generated a keypair, registered the pubkey at your PDS and then began signing messages in the app?
by evbogue 2y ago
Yes, and what if they had a tab in the Bluesky app where you generated a keypair, registered the pubkey at your PDS and then began signing messages in the app? You could rotate keys on demand and update the PDS every time you make a new one.
- lukev 2y agoYeah but if you lost your phone you'd be screwed. There's ways around it... the identity mechanism supports multiple keys so you could have a backup in escrow. But most people don't want to worry about key management at that level. Hell, I know exactly how everything works, and key management still scares me. The consequences of a mistake are huge.
- evbogue 2y agoYes, that key is screwed because it's lost, stolen, at the bottom of the river, etc. But this is when you generate a new key and store that pubkey at your PDS so the Appview can find and index your new posts from your new phone. It's the same thing that happens when I reinstall Debian on my Thinkpad and upload a new ed25519 pubkey to Github so I can push again. Edit: or we could backup the key.
- pfraze 2y agoOriginally that was the design. We just felt it wasn’t feasible as the primary operation. The PLC registry supports an override key for adversarial migrations, which was our chosen alternative
- evbogue 2y agoI don't think it should be the primary operation, not with the scale that Bluesky has achieved. We need this in the Bluesky App so a handful of p2p weirdos can feel they are authentically using a distributed social platform without caesars and all of that. I'll look into the registry override too, maybe I can hack something together around that.