20 ms·
Open Social
- jrm4 1y agoThis is such an important idea -- and yet I feel like the hyper-individualized "bluesky" implementation pictured is a less good practical idea than Mastodons more "server/host" way of doing things. I get that theoretically the two should be similar or even identical in practice, but I feel like the way Bluesky goes so hard at "literally individuals maintain control over their own stuff" is kinda too hard for most, and that Mastodon's "just trust the server" way, which ABSOLUTELY has it's own problems, of course -- is still better, mostly because we have better practice in this style, in the form of good ol email.
- micromacrofoot 1y agoThey should be interoperable... I should be able to take my account from bluesky and host it on any other pub server The server shouldn't need to be specific to mastodon/bluesky networks either Ghost (the blogging platform) is kind of a peek into this — you can host your microblogging account there and interact with other activity pub networks like mastodon this is the promise of the activitypub standard, anyone that uses the standard can interact with anyone else using the standard...
- danabramov 1y agoI've tried to lightly allude to Mastodon here: >Social aggregation features like notifications, feeds, and search are non-negotiable in modern social products. Conceptually, Mastodon is a bunch of copies of the same webapp emailing each other. There is no realtime global aggregation across the network so it can only offer a fragmented user experience. While some people might like it, it can't directly compete with closed social products because it doesn't have a full view of the network like they do. The goal of atproto is enable real competition with closed social products for a broader set of products (e.g. Tangled is like GitHub on atproto, Leaflet is like Medium on atproto, and so on). Because it enables global aggregation, every atproto app has a consistent state of the world. There's no notion of "being on a different instance" and only seeing half the replies, or half the like counts, or other fragmentation artifacts as you have in Mastodon. I don't think they're really comparable in scope, ambition, or performance characteristics.
- jrm4 1y agoYeah, the goals of atproto are REALLY GOOD ones. The only thing I'm skeptical of is the extent to which "centralized state of the world" really needs to be a core of the protocol -- and does that sort of thing introduce the same kind of centralization that makes it vulnerable to enshittification? My gut is that IT DOES. Put differently, there's presently nothing about TECH of the Mastodon model that prevents building tools that achieve similar "centralized everything" goals on top of Mastodon; only, you know, people and trust, the easiest part </sarcasm>. Mastodon's probably the best long-term model and it's email that makes me think that.
- jpereira 1y agoIn my view the atproto approach asks the users to make fewer required complex decisions, but gives them the freedom to make many voluntary ones. If someone wants to use a particular application, they basically just need to sign in. If they don't have an existing ATProto account, they can just make one, in the flow of the application they're signing into. Later they can chose different clients, or different infrastructure, or move their account, to their own hosting even if they want. Mastodon requires a complex decision upfront, which server do I trust, which is analogous to where you create your account on ATProto, but unlike ATProto, doesn't give the tools to seamlessly transition later. The trust lens I think is a good one. You want to let different users make different tradeoffs in effort without having that leading to a worse experience..
- jrm4 1y agoI mean, this might depend on who your intended audience is? As perhaps pie-in-the-sky my desire is, I'd like to see one of these things replace twitter (as opposed to smaller communities.) And it seems to me that the more frictionless model is the one that looks like something people are used to; just "sign up with a thing." That does leave the interconnection to the servers and others, but that may be how it has to be?
- iameli 1y agoBluesky is incredibly just "sign up with a thing." Except even easier, because you don't have to pick an instance first.
- jrm4 1y ago"Sign up with a thing" -- but then what about after that? You've made a bunch of stuff, what happens to it? Offloading THAT mentally to a different "service" or "account" I think is easier than this all-in-one thing. Again, I like the IDEA a lot; if you'd presented it to me like in 2000 before a lot of this stuff took off I would have been all about it. Today? No, I think it's reasonable to offload that to so-and-so-dot-com, each as a separate account. Like the phrase "I have a facebook" always sounds weird to ME, but I think that's "the way."
- mcny 1y agoNow here is a controversial question... Can we have a free of cost top level domain? What are the actual costs associated with registering a domain? If let's encrypt can provide secure certificates free of cost, why can't a different no profit provide domains free of cost as well? It doesn't have to be pretty. It could be a UUID v7 stacked on top of another UUID v7 for all I care but it would be globally unique and available free of cost. And once you go to the site, your browser will remember it anyway so you don't need to type the monstrosity. Or is it a really bad idea™?
- ramon156 1y agoI might not be fully understanding the idea, but the difference here is that a let's encrypt certificate can be generated on the fly. domains are considered branding, and getting a 5 letter domain nowadays is impossible. The cost here is that you're renting a domain that others might want aswell, people don't really want your LE cert
- charcircuit 1y agoX lets people own a 5 letter username for free. Renting names is not even industry standard for platforms. It seems like it's only DNS that charges for names.
- notatoad 1y agorunning a domain costs money. there's no way around that - it requires server resources to respond to dns queries, and that requires servers and electricity. so to offer it for free means somebody has to subsidize it. letsencrypt can operate because big companies with lots of money want their ads to be delivered without being intercepted by an ISP. what's the motivation for anybody to subsidize free domains?
- deadbabe 1y agoHow about DNS on a blockchain?
- tantalor 1y agoWe already had that in 2007: https://en.wikipedia.org/wiki/OpenSocial https://en.wikipedia.org/wiki/OpenSocial It was a complete disaster
- rickette 1y agoShindig https://shindig.apache.org/ https://shindig.apache.org/ was the reference implementation of this spec. Was pretty novel at the time.
- danabramov 1y agoThis doesn’t similar to atproto, which is what I discuss in the article. “Open social” isn’t an official term btw, I just like it enough to refer to this movement. I think recycling names from dead projects to refer to new concepts is fine. You’re welcome to ignore the article’s title.
- simonw 1y agoYeah, the linked article did make me smile because the previous iteration of OpenSocial - which had a LOT of buzz around it back in 2007-2010 - was such an ambitious swing that completely missed. Apparently I wrote about it a fair bit back then, mostly noting how confusing it all was: https://simonwillison.net/tags/opensocial/ https://simonwillison.net/tags/opensocial/
- niutech 1y agoWhy disaster? Google used it successfully in their products like Orkut. It was a novel federation protocol at that time.
- LightChaser 1y agoSadly, it's hard to imagine a world where something like this will ever catch on. The target audience for "traditional" social media is very different from the niche of people who want decentralized social media. Most people just use social media as a means to an end and don't really care about the systems behind it. If the answer is that most people should just make a bluesky account, that defeats the whole purpose because then everyone will still be on one or two large providers.
- A4ET8a8uTh0_v2 1y agoUnfortunately, yes. The problem is, basically, people.
- deleted 1y ago[deleted]
- mozzius 1y agoEven if everyone is on bsky.social, that's still a huge improvement on the status quo. It's not like the web isn't decentralised just because lots of people are on AWS - you can move away at any moment, adversarially if necessary.
- Kye 1y agoLooking forward to the future where an app just sort of silently backs up your PDS/keys on your device until the day you need it and everyone finds out they can log into whatever platform replaces the one that blew up like nothing happened.
- dingnuts 1y ago[flagged]
- fruitworks 1y agou mad?
- 1y ago
- SoftTalker 1y ago99% of social media users don't care about any of this. If it's one extra step or configuration they need to learn, or includes a word like "protocol" that they need to understand, they won't use it.
- steveklabnik 1y agoThat's one reason why Bluesky has gained a lot of traction. All of this is under the surface, not something you need to care about unless you want to.
- verdverm 1y agoI would contend not all of it is under the surface The Bsky team regularly highlights other apps, custom feeds, and moderation choice
- steveklabnik 1y agoThe important part is that you don't need to know about any of this to use the service. Of course, the protocol enables user-level features.
- extraduder_ire 1y agoYou don't need to know how any of those features or websites work to use them. I'd also argue that most users have no idea who the people working on the site are. (even if reading the replies under their personal posts gives a different impression) The end user just sees they can subscribe to a moderation list that hides any post labelled as "Beans", or that they can have a feed next to their Discover feed that's an endless stream of people getting ligma'd. Or that they can use their account to log into a seemingly unrelated site.
- danabramov 1y agoRight, which is why the article makes the point that it’s invisible to the end user several times. That’s also why it frames the benefits in the concrete way that shows up in the products — like products being able to riff on each other’s data. My audience for this article is slightly technical so I put some focus on the technical parts. I don’t try to avoid mentioning the “protocol” for the same reason why teaching to make websites involves mentioning HTTP. I 100% agree with you though and that’s important for broader communication. What people care about are good products.
- b_e_n_t_o_n 1y agoI'm a simple man, I see a Dan post and I click. I'm a bit concerned that the open web only won because of first mover advantage. What gives me hope is OSS winning. I'd love to see something like atproto win though. It's clear that a major issue with social media is network effects preventing better apps from becoming popular.
- verdverm 1y ago> a major issue with social media is network effects preventing better apps from becoming popular. One thing ATProto does is enable real competition in social apps, assuming they all run on the atproto fabric. One of the core hopes is that we can get everyone over to something like atproto once, to get them out of the silos, such that this is there last time they have to "move" their social network
- b_e_n_t_o_n 1y agoThe challenge will be that first move, yeah. Current social media companies have every incentive not to let users do that.
- tynanpurdy 1y agowith every additional user, every additional post, the value of the open network only grows, and eventually becomes too big to ignore.
- extraduder_ire 1y agoAIUI, HTML won because it was free. There were competing paid for online hypermedia standards at the time, but many cost money. Anyone could make a web browser or server quite easily.
- deleted 1y ago[deleted]
- BrenBarn 1y ago
- tshaddox 1y agoThe bit about aggregation is interesting, but it's not clear to me what the performance characteristics will be for very popular accounts. Presumably Justin Beiber's repo cannot be expected to handle 100 million WebSocket connections, all of which push out a message the instant he posts something. Is it vital to have more centralized hosts which can implement the sort of hybrid push vs. pull models that Twitter famously needed to implement?
- steveklabnik 1y agoIn atproto, those websocket connections aren't between users's repos, they're between an application and user's repos. Bieber has one connection per application doing aggregation, not per follower.
- verdverm 1y agoRelays also provide an important scaling building block, such that every app can listen to the relay, which listens to all the repos, instead of many app<->pds.
- psnehanshu 1y agoAnd if Justin's pds goes down, then his followers won't be able to consume his content.
- psionides 1y agoThey read the content cached from the AppView, not directly from the PDS
- evbogue 1y agoDoes this article mention anywhere that Dan is a former employee of Bluesky and I just missed that disclosure?
- danabramov 1y agoThanks for the nudge, should deploy soon. https://github.com/gaearon/overreacted.io/commit/26d40321dc706378944cc2c7f6f1f5da4d47bd76 https://github.com/gaearon/overreacted.io/commit/26d40321dc7...
- swyx 1y agowait what? where does he work now?
- danabramov 1y agohttps://overreacted.io/im-doing-a-little-consulting/ https://overreacted.io/im-doing-a-little-consulting/
- tetrisgm 1y agoI feel very conflicted about this work. On one side I find these ideas extremely compelling. This is aligned with the Indie web body of work, that pictures anyone having a personal website of their own content and ownership over that. And this page an article are beautifully put together. On the other hand, we haven’t really seen a lot of developers adopting these standards for their own projects (like using this for their personal website or open source project). Nor from casual users (including people who make their own blogs and websites). I am deeply concerned about the apathy people have towards the idea of ownership, openness and interoperability. It gives the idea that people just want to be fed TikTok and Instagram reels. I respect the vision and the work. Will personally see if we can use this for our work. But I wonder how we make this into something that’s not just a micro niche hobby.
- nunobrito 1y agoYou are correct, and yet depends on ourselves to popularize and make this tech happen. Maybe, just maybe a newer startup out there will have a CEO/CTO that is deeply influenced by open social and delivers a success app that reaches the masses. One never knows, but for sure it won't happen when we do nothing.
- tetrisgm 1y agoHas the experience of spinning up an instance been simplified?
- verdverm 1y agoWhat do you mean by "instance"? There are several protocol components you can run independently, each filling a different role and having different complexity levels If you mean the PDS, not sure if it is simpler than the unknown point you are looking to compare against. Bsky did just announce that you can migrate back to their PDS hosting to make trying out alternatives a one-way trip
- tetrisgm 1y ago
- nunobrito 1y agoGood article, very clear. Can you also do one for NOSTR? The functioning is similar, albeit there is no need for hosting user data since it can be sent to multiple relays and live reachable to others from there. Thanks in advance.
- danabramov 1y agoI probably won’t do it myself but this one should be helpful: https://shreyanjain.net/2024/07/05/nostr-and-atproto.html https://shreyanjain.net/2024/07/05/nostr-and-atproto.html
- nunobrito 1y agoThanks for sharing. By coincidence (or not so much) I had lunch this week with a founder of bluesky along with a others and many names were mentioned that I'd never heard about. They were mentioned on that article and now understand better. Quite a lot of food for thought today. Thank you for that.
- est 1y agonostr started as simple but now there's like a million NIPs.
- deleted 1y ago[deleted]
- api 1y ago> Open source has clearly won. Yes, there are plenty of closed source products and businesses. But the shared infrastructure—the commons—runs on open source. Lost me right there. Open source is the infrastructure that powers closed cloud. None of the openness makes it to the end user. It only benefits highly technical users and businesses. Open source was made irrelevant (to non-technical users) by the shift to services and cloud.
- animanoir 1y ago[dead]
- bumseltagbaerbi 1y ago[flagged]
- ceayo 1y agoWow, I always imagined Activitypub to be the better protocol and AT a cheap knock-off, but reading this article made me realize at is, actually, way better - primarily because multiple programs can access the same identity. This is really a great feature to have! This article was a real mind-opener for me.
- verdverm 1y agoYou'd probably like this article too, same ideas from the distributed engineer perspective https://atproto.com/articles/atproto-for-distsys-engineers https://atproto.com/articles/atproto-for-distsys-engineers
- danabramov 1y agoThanks! I’m glad it’s clicking. The comparisons with AP are always frustrating for this reason as it doesn’t try to do anything similar in scope.
- psnehanshu 1y agoimo ActivityPub sounds better than ATProto, hence people assume the former is superior. This is a branding issue.
- danabramov 1y agoYea maybe! I think at:// is an even stronger brand in a sense though. Actually makes sense as something browsers may support one day, “at://alice.com” makes sense at “stuff at alice dot com”, “authenticated transfer” is a decent acronym, “atmosphere” for the ecosystem is just great (and wasn’t even coined by the team).
- paulryanrogers 1y agoDoes that mean there is a centralized identity service?
- steveklabnik 1y ago
- jrowen 1y agoOpen source has clearly won. This is clearly a wild claim that almost undermines the rest of the argument, but to the extent that we can accept that there are open source software packages that decision-makers deep in that industry will reliably choose for their business...it's not clear how this revolution will extend to "regular people." They just want easy. Make something as easy and fun as Instagram. They don't give a crap about all this, they don't want to think about it.
- pfraze 1y agoThat first point is so true, as a programmer I never use open source
- airspresso 1y agoIn the tech industry, open source has clearly won. You're right that most end users don't particularly care. The engineers building solutions definitely care, and prefer to build on top of open source dependencies.
- jrowen 1y agoI just don’t understand that assertion when there is very clearly still a massive proprietary closed-source software industry. How are you measuring? A lot of people use open source packages, because they’re free and easy, to build closed source products. Does that count as a win for open source? In my experience most engineers aren’t that fervent about it. Either way, with social, and the network effects required, you’re targeting end users. The widest net with the lowest common denominator. Whatever success open source has had among people that live and breathe these issues every day is not replicable there. I’m probably coming off as just a hater or anti-open source or something but I’m really not, I just feel like there’s a certain perspective that is a lot more niche and esoteric than its proponents realize.
- Kye 1y agoA complementary article I wrote: "Nobody cares about decentralization until they do" https://kyefox.com/nobody-cares-about-decentralization-until-they-do/ https://kyefox.com/nobody-cares-about-decentralization-until...
- brap 1y agoI think we tend to do a lot of idealization. The vast majority of non-techies don’t care whatsoever about decentralization.
- verdverm 1y agoOne can explain features that are possible on ATProto but not Big Social without talking about "decentralization". My pitch to the non-technical typically follows or covers these points - Social today is not healthy - Single account instead of N - All apps keep your data in your database - User level choice over apps, algos, moderation. Esp algos, my social media usage patterns have changed for the better since I started using custom feeds - Real competition in social media - Take back our shared digital experience from a handful of billionaires deciding everything and keeping us locked into their attention economy
- danabramov 1y agoYes, which is a point the article repeatedly makes. I totally agree with you. See also https://knotbin.leaflet.pub/3lx3uqveyj22f/ https://knotbin.leaflet.pub/3lx3uqveyj22f/ which I linked to close to the end of the article.
- drnick1 1y agoThis "Open Social" stuff is too complicated I think. I don't see what's wrong with having your own website. It takes a couple of minutes with the help of GPT to write an HTML 1.1 basic page and host it from home on your own hardware. Or better yet, don't have an online presence at all.
- pfraze 1y agoBit apples to oranges, isn't it? You're not exactly able to do tiktok with personal websites
- igor47 1y agoI have my own site. But the people love engagement - it motivates a lot of content creation. Back in the day we had web log rings and WordPress comments, but that stuff is dead on the modern web, it's too adversarial an environment. My blog has no meaningful engagement, I don't even know if anyone ever reads it. It works for me since I write primarily for myself, but this is just not the case for most people
- knowtheory 1y agoI'd argue that ATProto is the next iteration of open internet. It's what an internet where accounts/identity and verifiable content attribution are built in, and nobody using the technology needs to think about any of that. There's a space here where we can move from nobody having smart phones or hosting digital presences -> everyone having digital presence provided by Facebook/Instagram, and icloud/google accounts -> Accounts w/ something like ATProto where its your stuff, you get to decide where you keep it, and you get to decide who gets access to it.
- danabramov 1y agoPersonal websites are great. They don’t do large-scale aggregation which a lot of people enjoy and look for. The article is about an approach to large-scale aggregation with important properties of personal sites. For what it’s worth, you can host atproto repositories from your home too — some people run them on Raspberry Pi.
- numpad0 1y agoI'm starting to feel many of "next big Twitter to fill its power vacuum" projects are tackling the problem slightly wrong - they all perfect the Twitter feature set, then hit the wall with user growth and content deprivation chicken and egg problem. People gather where there are others and that's still around the rotting whale. That OpenAI timeline thing that just launched is more better approach, it solves content problem by just gathering data in background and feeding it to the user anyway. That particular implementation might not work but it sounds correct. IMO, not much of value of Twitter for most users is in ability to post tweets, it's in data bandwidth. 99.9% of users don't post anything interesting, those might as well be local text file or oit of band shared filler content. The value is in content sourcing, so something like multi-social RSS reader with optional P2P should be the way to go. Just IMdimO, though...
- danabramov 1y agoWhile I use microblogging to frame the initial narrative, as explained in the article, this isn’t limited to Twitter-like products. Tangled is “GitHub on atproto”, Leaflet is “Medium on atproto”, and so on. The problem with client-side P2P is you can’t do large-scale aggregation with consistency. Large-scale aggregation with consistency is what normal people expect from social apps. Re: the OpenAI thing you mentioned, that's actually a perfect example of something atproto excels at. Since the data already exists in the network, you can crawl/index it and run your own tooling that does something proactive on cron jobs etc. See https://github.com/graze-social/iftta https://github.com/graze-social/iftta for some initial work in that area.
- Kye 1y agoI like that labeler that shows which lexicons a user has in their repo. https://bsky.app/profile/recordcollector.edavis.dev https://bsky.app/profile/recordcollector.edavis.dev
- emseetech 1y agoSocial networks rarely come up by being "the same but..." They come up by doing something unique that can't be done on older platforms.
- dgaffney 1y agoThank you Dan for the post! I think two other things to point out: 1. Because open social has to actually compete for a user's business, any sufficiently mature platform build in the ecosystem will necessarily trend towards being more responsive to those users needs, which will trend towards a better product than the legacy crop, 2. Precisely at a moment where governments lean on large, visible corporate entities to enact desired policies, splintering that ownership helps ensure a resilient communications network
- xnx 1y agoI'm glad to see someone recognize the critical importance of authors owning their domain. Without that, you will alway be at the mercy of someone else. The rest is just technical detail.
- Spivak 1y agoTechnically on Bluesky even if you don't own your own domain you can still move all your stuff to a competitor and everything will still work. The only thing you can't do is keep your original handle but no "links" to your account (posts, followers, comments) will be broken because there's a stable identifier for your account that's independent of your handle. You will still be verifiably the same person on the other server.
- swyx 1y agoi'm interested in making a new social network on atproto. does anyone have resources to recommend where to start?
- verdverm 1y agohttps://discord.atprotocol.dev https://discord.atprotocol.dev Lots of people there to direct you to specific resources
- Timwi 1y agoIf you think that there are specific resources, you can just post them here. The fact that you didn't, and instead linked to a corporate walled garden, is very suspicious.
- danabramov 1y agoSuspicious of what? What do you expect to find in the corporate walled garden of Discord?
- verdverm 1y agoI posted links in another comment once I was back at a computer
- Kye 1y agohttps://atproto.com/guides/applications https://atproto.com/guides/applications
- ireadmevs 1y agoAll of this is meant for 100% public data, right? Or is there a concept of visibility control? Can I create private communities, with data flowing just inside?
- danabramov 1y agoFor now, yes, only 100% public data lives on the protocol (you can still, of course, augment protocol data with the stuff you hold in the DB). In the future, the plan is to also enable some types of private data on the protocol. See these recent notes from Paul on the state of things: - https://pfrazee.leaflet.pub/3lzhmtognls2q https://pfrazee.leaflet.pub/3lzhmtognls2q - https://pfrazee.leaflet.pub/3lzhui2zbxk2b https://pfrazee.leaflet.pub/3lzhui2zbxk2b
- verdverm 1y agoThere is also a Working Group that just formed to push the envelope on private data / permissioned spaces Links to my own efforts on this - https://github.com/blebbit/atproto https://github.com/blebbit/atproto (fork) - https://youtu.be/oYKA85oZc8U?si=DIf09hu8-REw-yHj&t=3758 https://youtu.be/oYKA85oZc8U?si=DIf09hu8-REw-yHj&t=3758 (presentation I gave last week)
- advisedwang 1y agoI'm a little saddened to see that each app has it's own collection type, even if they are able to use each others collections. That means that apps will only interoperate to the extent that they are explicitly designed to. One of the beautiful (but perhaps not that practically relevant) things about ActivityPub is that a Mastodon user can subscribe to a Pixelfed user without anything special being done. It's like if Twitter, Instagram, Reddit, YouTube, and Substack all automatically interoperated.
- verdverm 1y agoSee https://github.com/lexicon-community https://github.com/lexicon-community for the effort towards common lexicon
- danabramov 1y agoYeah, atproto pushes this down to be a community/governance issue. Nobody is preventing apps from working out a common standard and supporting it. However, nobody is forcing them to do that either. So it will play out with natural dynamics. What atproto ensures is that there's a convention for strongly-typed foward-evolving schemas and how they get validated (and reverse domains specify the authority). But ultimately cooperation is up to the community.
- verdverm 1y agoFor anyone who wants to read up more on this, another of Paul's (non-math) Notes (also, not the same Paul :) https://www.pfrazee.com/blog/lexicon-guidance https://www.pfrazee.com/blog/lexicon-guidance
- ltjbukem 1y agoAP intercompatibility is fun, but it starts to fall apart once you leave the safety of the "Note" (statuses) and "Question" (polls) types (which is what Mastodon, Pixelfed, Misskey, Pleroma, etc. all use as their primary elements). Everything outside of it becomes either loosely converted to a note (Mastodon does this for a lot of things, see https://docs.joinmastodon.org/spec/activitypub/#payloads https://docs.joinmastodon.org/spec/activitypub/#payloads) or is discarded by the instance. The only types that I know of which have been able to have native support from multiple AP implementations are micro-blogging and Lemmy's community system, with everything else essentially being a monoculture (or just extremely one-sided towards a specific implementation) due to a lack of interest from other implementations in providing full, standardized support. This isn't an inherent protocol limitation, but I do think that the community could do better in organizing standards outside of the core documents. ATproto's system is a bit more well defined (you HAVE to abide by the lexicon/schema of the data collection to be accepted by implementations, reference implementation and some third-party ones have schema validators to do so) and allows for easier intercompatibility, but I do think that it could be a bit looser than it is right now (selective support for additional fields) to provide proper "sidecar" values in a record (they'll be in the user's PDS but it won't validate and could be rejected by indexers). Bridgy Fed does this to include the originating URL from APub and the original text, which third-party clients could certainly take advantage of if they detect that the post comes from a Bridgy account. (https://fed.brid.gy/docs#bluesky-fields https://fed.brid.gy/docs#bluesky-fields)
- isodev 1y agoYes, it’s interesting but there is no way the instantiation of the protocol (Bluesky) remains free of investor influences. It would require a great deal of capital for anyone to recreate the “network” in such an eventuality. So yes, it’s cool but not really Open.
- pessimizer 1y agoThey took VC a long time ago.
- verdverm 1y agofor clarity, Bluesky is an app and ATProtocol is an Open Social fabric they built along with it and what Bluesky is built on top of In the long-term, ATProtocol will be separated from Bluesky the company and end up as a standards and in some shared governance structure
- BigTuna 1y agoThere are already working alternate implementations of every protocol component.
- isodev 1y agoSo what, the governance is not open and what good is a perfectly written engineering spec without the actual place where people hang out? It’s just a lot of tech jargon masking yet-another “let’s make someone very rich” scheme.
- danabramov 1y agoThey’re actually making first steps to bring it to IETF: https://docs.bsky.app/blog/taking-at-to-ietf https://docs.bsky.app/blog/taking-at-to-ietf You can be as cynical as you like but I actually tried hard to avoid tech jargon in the article. I’d appreciate you giving it a read — happy to answer questions or discuss specific concerns.
- parasitid 1y agohttps://solidproject.org/ https://solidproject.org/
- backproblems204 1y agoGreat read, love these ideas
- arjie 1y agoThat was very well written. I have to admit that because AT Protocol was Bluesky's I thought it was some corpo version of ActivityPub, but based on this post it makes a lot of sense. The data is in a 'repository' of my choice. I think I like that very much and it aligns with the kind of general principle I have where it's better to apply filtering etc. on the read side rather than on the write side so that I can publish all sorts of things that I want into my repo and others can then read etc. that stuff. The arrows do seem to imply that commenting on my posts goes into my repo, but I'm sure that's just an imprecision trying to express an idea. The whole thing seems very cool and decentralized. When I went to see what it takes to run a separate PDS on AT, though, I see that it's all nice and packaged up and has certain assumptions: 1. It takes care of SSL etc. 2. It will stand up HTTPS/WSS servers to handle a bunch of RPC So in practice, you don't get https://roshangeorge.dev https://roshangeorge.dev and at://roshangeorge.dev because for the latter you kind of need https://roshangeorge.dev/xrpc https://roshangeorge.dev/xrpc and wss://roshangeorge.dev Therefore, you probably end up with https://roshangeorge.dev https://roshangeorge.dev and at://at.roshangeorge.dev and then you can run https://at.roshangeorge.dev https://at.roshangeorge.dev and wss://at.roshangeorge.dev All minor stuff and doesn't take away from the main point, but it was a thing.
- whyrusleeping 1y agoThe default pds packaging takes care of SSL, but thats not a requirement, just something we try to make easy for users. Also at:// URIs are of the form at://DID/..., and your human readable handle is bound to your DID through DNS TXT records _atproto.roshangeorge.dev, but applications all know to render that as just roshangeorge.dev. That DID points to a document that specifies where your server lives, so the HTTPS/WSS routes can live wherever you want them to. Also likes/replies/etc on your posts go in their authors repos not yours, your intuition is correct there.
- extraduder_ire 1y agoYou can authenticate a handle via a file in ./well-known/ at the domain too, which is how bluesky does it for their default handles.
- deleted 1y ago
- bArray 1y agoI really dislike that BlueSky named their protocol the "AT protocol" [1], when we already have the AT command set which remains important [2]. [1] https://atproto.com/ https://atproto.com/ [2] https://en.wikipedia.org/wiki/Hayes_AT_command_set https://en.wikipedia.org/wiki/Hayes_AT_command_set
- simonw 1y agoI can forgive them that. There are only 26*26 = 676 two-letter acronyms to go around, and they had the decency to call it "AT protocol" which makes it clearly different from "AT command set".
- est 1y agowell if you think the name is bad, there's also Go, which is conveniently typed as Golang.
- eigencoder 1y agoLoved the breakdown of a topic I wasn't familiar with. I just can't help but think that the whole ethos of Open Social Media is misguided. I think that social media isn't good for us -- not just because of the big companies making it worse, but because the technology itself doesn't promote health. It feels like trying to make cigarettes open-source. Sure you can stick it to big tobacco but at the end of the day you're still making cigarettes.
- gdulli 1y agoAs long as the Eternal September remains on Twitter, there's nothing unhealthy about being on Bluesky. The format isn't the problem, it's the people who use it as a stupid culture war battlefield. Those people seem content to remain on Twitter.
- xigoi 1y agoThere is a lot of “culture war battlefield” stuff on Bluesky too.
- oaxacaoaxaca 1y agoHuge missed opportunity not using Alice and Tom for the relevant initials lol
- popcar2 1y agoI don't have a horse in which decentralized protocol wins, but while ATProtocol sounds great on paper I'm still inching closer to liking ActivityPub more. I'm pretty active on Lemmy[1] which is quite active and fun to browse 1. 99.99% (literally) of AT users are on Bluesky, which is helmed by a for-profit corporation. The argument is that they don't control the protocol but considering it is THE dominating instance of that protocol, what's stopping them from strong-arming the protocol and changing how it works to benefit them? Better yet, what's stopping them from doing a rugpull and closing off their open service? What if bluesky decides 5 years from now that you aren't allowed to move your account? This isn't some hypothetical scenario, this already happened before. A lot of social medias started off with fairly open features and APIs and slowly choked them out for profit. 2. Users don't really care about protocol, they care about momentum and userbase. Piefed/Lemmy/Mbin are all popular-ish Reddit alternatives using AP. It was already a struggle to reach a point where posts could get over a hundred comments a day, how are you going to convince people to move to another platform again? I'm worried this will just end in splintering an already niche community and cause people to just give up and go back to using popular platforms. Being able to move accounts is a very neat feature but it's not a reason enough to move. You can already export your settings and make an account on another instance in 20 seconds then import your settings again, which would bring back your subscriptions and blocks and all you set up from account 1. To me it's not a huge deal. See also: https://arewedecentralizedyet.online/ https://arewedecentralizedyet.online/ [1]: A fediverse Reddit alternative, e.g https://lemmy.world/ https://lemmy.world/ and https://programming.dev/ https://programming.dev/ . See also Piefed which I think is better nowadays https://piefed.social/ https://piefed.social/
- self_awareness 1y agoI know that Mastodon is not the same as ActivityPub, but I don't know how can it be treated seriously if it allows disappearing replies. Whatever we write will disappear after some time. Sometimes. Because sometimes not. Maybe it's an implementation problem, I don't know, but it was one of my two reasons for my exit from Mastodon.
- F3nd0 1y ago
- BinaryIgor 1y agoSometimes I wonder - maybe websites were enough? Most people on most platforms are readers/consumers, not producers anyways. Maybe having a personal website was a good filter for publishing after all? Maybe personal websites + sites like hackernews that allows us to discuss our and other people's work is the best the Internet could be.
- woah 1y agoMaybe pianos were enough. Radio has made it so families no longer gather round and sing in the evenings and TikTok is even worse than radio
- BinaryIgor 1y agoIt depends; not everything that's newer is automatically better. Web and websites did the heavy lifting of instant and world-wide information sharing. With social media, open or closed, there are many non-obvious tradeoffs; I am not sure whether on the whole, we are better off with or without them - time will tell
- Eisenstein 1y agoEven if the information consumers are 99% of the users, making the features available for the content creators leads to much better content. Plus people want the ability to be able to post content if they need to. I shall point to the /r/ask* subreddits as an example.
- amadeuspagel 1y agoHacker News doesn't allow you to build an audience, so every post has to appeal to the average HN reader to get attention.
- INTPenis 1y agoThis has already been covered many times but the design of the AT protocol requires a lot more resources than AP. Meaning it will be reserved for large organizations, while AP has a lower entry of threshold. I want both to thrive, but I prefer AP for small communities.
- steveklabnik 1y agoDepending on what exactly you mean, this isn't the case. For example, running your own PDS is very cheap. If you want to fully run a full copy of everything yourself, it's going to be more expensive, sure, but those costs have gone down dramatically over time. The most expensive bit is running $34/month: https://whtwnd.com/bnewbold.net/3lo7a2a4qxg2l https://whtwnd.com/bnewbold.net/3lo7a2a4qxg2l
- nulfrost 1y agoHm? Which part of the stack requires a lot of resources? Each part (PDS, Relay, AppServer (AppView)) can be run on a PI. Blacksky (not a large organization by any means and completely community funded) is almost running the entire bluesky stack themselves. IMO there's not much of a reason to run every part of the stack yourself unless you want to be completely independent from bluesky. At the very least if you want to host your own data then that just means running a PDS, which means finding the cheapest VPS you can that fulfills the min spec. Mine costs about 7 bucks per month and I never have to think about it. I'm also running a relay for no reason other than for learning purposes for about 30 bucks a month. The AppServer, if you want index the full bluesky network (39M users) will run you about 200-300 dollars a month. Again, not really needed but you can if you want. There's also experiments people are trying out to only index smaller parts of the network, e.g. only users you follow which would mean hosting an AppServer would be even cheaper. FWIW, I like both protocols and want them to succeed, anything that gets people off of closed social media.
- INTPenis 1y agoIt sounds like the AT protocol is improving in the right direction, but the numbers still say it's highly centralized and therefore closed social media owned by one monolithic entity. AP has its issues, namely not being at all consistent, but that trade-off allows anyone to run all the components of the network without breaking their bank.
- bonoboTP 1y agoHow does blacklisting / moderation etc. work here. How does blocking work? How do people make sure to distance themselves from political enemies? Do the aggregator cache servers block certain user domains? How do you ensure that the aggregator returns valid and non-forged comments and likes?
- steveklabnik 1y ago> How does blacklisting / moderation etc. work here. Anyone can run a moderation service. Users subscribe to the services they want. When you flag a post or account for moderation, you choose which service you send the report to. > How does blocking work? Blocking works by publishing a "hey I've blocked this person" record in your database. Applications then can use this to enforce that. > How do people make sure to distance themselves from political enemies? I'm not sure what this means. > Do the aggregator cache servers block certain user domains? They could, and this is also a property that's not really about blocking, that is, you could choose to cache only part of the network if you choose, which could be useful for various reasons. > How do you ensure that the aggregator returns valid and non-forged comments and likes? Cryptography, basically.
- bonoboTP 1y ago> I'm not sure what this means. I'm trying to imagine how a situation analogous to Gab vs Mastodon may arise and play out here, or if the setup is different. Like would they just live side by side, with various frontend aggregators that present one or the other world to you? > Cryptography, basically. How do I, the user with a browser verify that? Do I need to use a different client program, or a browser extension? The aggregator site can show me a green checkmark or whatever, but that's just a claim by the aggregator. Am I expected to fire up a terminal window to compute signature validations to check if Alice really put a like on that comment?
- steveklabnik 1y agoAh, I see. Yeah, you could build alternative clients that only show you part of the network if you want. Or run your own separate copy of the entire network. Because the two models work differently, there’s not an exact analogy. You could also use one of the various PDS browser websites to go check their PDS, or a terminal tool, sure. I will be honest and the details of exactly how the cryptography stuff works is not my strongest point when understanding the protocol, maybe someone else can chime in and give you a more detailed description here.
- poolnoodle 1y agoEvery day I am more convinced that we don't need these global conversation platforms at all.
- Eisenstein 1y agoI know this sounds pithy, but why are you here then? Or do you think that only other people shouldn't have them?
- poolnoodle 1y agoI should have been more precise. We don't need microblogging.
- tolerance 1y agoThis looks to be turning into a curious case study on how network states develop.
- motoxpro 1y agoI really hope this doesn't catch on. Having ever random site on the internet being able to see every bit of my data sounds like a nightmare. Unless I am misunderstanding something.
- xigoi 1y agoThey will only see the data you post publicly. You know, like with a personal website or with any other social media platform.
- danabramov 1y agoThis is for public data. Think Twitter posts, StackOverflow answers, Reddit comments, etc. The stuff you don’t want companies to gradually start locking up for their own gains (as they tend to). The protocol will likely be extended for private and semi-private data in the future, which would work by granting explicit permissions to apps. For now, app developers would keep private data in databases, same as usual.
- not--felix 1y agoAfter developing my own rss reader[1] i think atproto could be the successor of rss. It is the same principal. The only difference is it is more complex and there are more components like the firehose, which is optional, the reader could just scrape their following themself. I think the resource usage is also only a problem if you want a view of the entire network, if we treat it more like rss it would be totally fine to just keep the portion of the network we are interested in. Its not as straight forward as rss, because of types like comments and likes. To notice them you need to listen to the entire network stream, but you do not need to save everything. I am really excited where this will go. [1] https://ivyreader.com https://ivyreader.com
- danabramov 1y agoYeah. I was thinking of emphasising RSS as a comparison more but didn’t end up using it much. But I do like to explain atproto as basically typed and signed JSON RSS over HTTP and WebSockets.
- deleted 1y ago[deleted]
- rakoo 1y agoThis is a beautifully written introduction to the architecture of AT, but after much consideration I will still remain on ActivityPub for the time being. I love the idea to define data formats first, and then build on top of that. It's the only way we should do everything, because if you have the data, everything can be re-built on top. Unfortunately the way AT works is all contained in here: > Social aggregation features like notifications, feeds, and search are non-negotiable in modern social products. [...] Coincidentally, that’s the exact mechanism you would use for aggregation. You listen to events from all of your app users’ repositories, write them to a local database, and query that database as much as you like with zero extra latency. [...] This might remind you of how Google Reader crawls RSS (rip). In order for the social aspect to work, all data must at some point or another be aggregated in a single place. Said single place must then be huge, as it scales linearly with the activity of the network; in a still-capitalist world this means that this single place will always be run and led by money, unless some extraordinary volunteers-based project like Wikipedia springs up. The example of Google Reader is to the point: it was the biggest tech company at the time, provided a service for free, and decided to stop because it didn't care anymore. In fact Google Reader is a very good comparison. AT works exactly as if you had websites, each with their own RSS feed, and then a big relay called Google, providing search, feeds, notifications, ... but as we all know by being the middleman between producers and readers Google gained an astonishingly high power. That is the business model described by Cory Doctorow when he talks about enshittification. Put yourself in the middle, and everyone will depend on you. The only way an AT based product works at scale, ie with everyone easily talking to everyone, is with one or a few mega intermediaries between everyone of us. I fear this is not going to solve any of the issues we have. What is different in ActivityPub ? Intermediaries are definitely useful for some services, but once your network is built you don't need them anymore: content flows directly between the repository, no middlemen needed. In short: if we want a single network at large scale, AT requires large scale centralization points, while AP certainly needs them but could survive without them. Either we face that, or we start exploring and living within small-scale networks
- Timwi 1y agoWhat I found most exciting while reading this article was the promise that you can “up and leave” and take your data with you without breaking links, because the links are based on a domain name you control. This is not so in ActivityPub. The data you post is owned by/controlled by the instance you're on. In the language of the article, you're still a row in somebody else's database. I was on Mastodon for a while until the instance I was on shut down. I naively assumed that I could export and re-import my posts but that was not so. Everything is deleted. I technically have an archive of it in the form of some JSON files, but as illustrated by the article, this is now dead data. The same will happen again if/when my current instance shuts down. The only way around it is to run my own instance, which for the vast majority of people is a ludicrous proposition.
- zhoukekestar 1y agoThis is all based on the premise that you maintain ownership of the DNS. Once you lose control of your domain due to legal issues in the relevant country, those references/citations become invalid. However, this is still a great improvement over the current situation.
- Kye 1y agoThere's still a way: https://whtwnd.com/bnewbold.net/3lj7jmt2ct72r https://whtwnd.com/bnewbold.net/3lj7jmt2ct72r It's one of those in-progress things that will get better and easier to use.
- steveklabnik 1y agoMy sibling links a great post on this, but to say it in a slightly shorter way, the core of identity is a DID, not a domain. You can update the domain associated with your DID if you lose control of the DNS and it will all transparently update.
- danabramov 1y agoI’ve skirted around this in the post to keep conceptual clarity but you can always move away from the domain (as a handle) without breaking links. This is because there’s a more persistent identifier that represents your identity (or at least there’s an option of having one, and that’s the default mechanism). Links between records actually use that identifier instead of the domain handle. For a more technical overview, see “identity” here: https://mackuba.eu/2025/08/20/introduction-to-atproto/ https://mackuba.eu/2025/08/20/introduction-to-atproto/
- robertdaniels 1y agoThe AT Protocol's approach to decentralized data repositories is excellent for empowering users with greater control, but it also creates vulnerabilities to automated abuse, such as bots disrupting event streams or fabricating repositories to distribute spam. I've integrated Sceptive bl0ck API to access IP and behavioral intelligence, which has reduced false positives from aggressive crawlers by at least 70% on my setup.
- Lich 1y agoWhat happened to Solid Pod? Tim Berners Lee’s project? I feel like it’s another project of this type, and even predates AT, but ever since its announcement hasn’t made much waves.
- est 1y agoI really hope ATProto considered static-hosting by design. Like RSS, people can host it on github pages, a service would poll it periodically to aggregate. This would lower the barrier of entry by a large margin. Maybe not all of bsky functions are viable, but I hope certain core part of "open social" can happen in this way. But ATProto chose wss:// isntead.
- deleted 1y ago[deleted]
- kyledrake 1y agoThere was this amazing demo I was given at the at proto dev con of a working web site using the protocol https://danielmangum.com/posts/this-website-is-hosted-on-bluesky/ https://danielmangum.com/posts/this-website-is-hosted-on-blu... It could definitely work as an alternative for the HTTP based web.
- bachback 1y agoDNS is much more foundational and overlooked here. how does the world agree that "x.com" resolves the way it does?
- danabramov 1y agoHow is it overlooked? It’s mentioned several times, including the mention that atproto builds on top of DNS among other things.
- geokon 1y agothe view of social media as just data that can be rehosted i think misses a large part of its success Twitter and Instagram are fundamentally different scenes bc of their restricted formats. Twitter has/had character limits. Instagram was primary for photo sharing. if you try to cram a long political rant in an instagram photo or description.. it is fighting against the app format and limitations. This sculpts the apps "culture" im sure it can work, creating a hodge podge of random unstructured content.. like the blogosphere or Facebook. But it wont displace the walled gardens. You can make a Kiki app that only shows images, but youre following someone who is using Booba app which allows him to post pictures with descriptions. And suddenly nobody really knows what to expect
- xigoi 1y ago> Twitter has/had character limits. Instagram was primary for photo sharing. if you try to cram a long political rant in an instagram photo or description.. it is fighting against the app format and limitations. This sculpts the apps "culture" A big part of Twitter’s “culture” is creating “threads” to work around the character limit, which kind of defeats the point.
- danabramov 1y agoDesigners of atproto actually agree with you so the data is not unstructured! It’s structured by schemas (called “lexicons”) controlled by app developers. Data in user repositories is treated as untrusted input by apps, and rejected if it doesn’t pass the corresponding schema. Schemas are evolved in a backwards-compatible way with a nudge towards future extension (eg open unions are default). That’s exactly why you can’t make a 500 character post on Bluesky. The Bluesky server will ignore your record as being invalid.
- geokon 1y agoah okay, i hadnt come across this. seems like a potentially viable strategy > Schemas are evolved in a backwards-compatible way with a nudge towards future extension (eg open unions are default). unions of schemas? Doesnt that lead to a facebook-ized kitchen sink app that does everything? you can effectivelt filter to .. say .. only photos with a photo-only app. But that doesnt form a app/schema culture
- darkamaul 1y agoI’m really impressed by the quality of this post, as others have mentioned. It’s very well written, and the clarity of the drawings adds a lot to the overall explanation. It perfectly illustrates the old saying: a picture is worth a thousand words. I had never heard of this protocol before (even though I’ve been using Bluesky since the Twitter/X takeover), but after reading this, I feel even more confident that the migration was the right call.
- suyash 1y agoI'm curious how did he create those illustrations - by hand or AI generated?
- deleted 1y ago[deleted]
- danabramov 1y agoI’ve used https://excalidraw.com https://excalidraw.com and exported to SVG. It’s very nice for quick technical illustrations.
- SilverSlash 1y agoThis is a fine example of technical exposition. Very easy to read and understand! Like many others, before this post I hadn't the vaguest idea what atproto was; I always assumed it was some decentralized thing a la crypto. But this actually makes a lot of sense to me and it feels like an objectively good thing. Except for one thing which has been pointed out by others. Anyone can access *all* of my data over this protocol. I like the idea that a lot of my data is directly accessible similar to the early web. But it would be nice if some of that data was only accessible if the accessor was permitted. I don't really know much about auth tokens but I'm guessing they shouldn't be that hard to incorporate into this thing? When BlueSky or whatever app queries "@username.com/private/documents" the server expects an auth token, whereas it does not when the app tries accessing "@username.com/bluesky/posts".
- hirenj 1y agoI was ruminating about how Atproto would be great for re-thinking the peer review system for scientific journals. Imagine a world where a preprint is “published” onto the social web, from which you could aggregate reviews/comments. I eventually ended up thinking about exactly what you raise - it would be great to have some degree of access control on this so both comments and published things can be selectively shared (with an option to make everything public later on, maintaining all the links).
- danabramov 1y agoYes, something like this is planned in longer term. The team decided to tackle public data first because scaling aggregation while preserving meaningful ownership is hard. So far I think they’ve succeeded at that. Private or semi-private comes with a set of different challenges. Indeed scoped tokens are coming (via OAuth scopes) but that’s used for writes. The same mechanism could be extended for private reads in the future, like you describe. There’s questions about what shape private data would have though. See https://pfrazee.leaflet.pub/3lzhmtognls2q https://pfrazee.leaflet.pub/3lzhmtognls2q and https://pfrazee.leaflet.pub/3lzhui2zbxk2b https://pfrazee.leaflet.pub/3lzhui2zbxk2b for recent thoughts on this topic from Paul who works on atproto.
- 0xbadcafebee 1y agoIt doesn't matter who controls social media; federated or not, social media is inherently harmful to humans. In a few years we will find out it's like cigarettes. Addictive and harmful, and needs regulation, if not outright bans. But going back to this obsession about data. It's really an obsession with control. But none of you really have control. You hope that you can "engineer" your way into control of your own lives, of your data, even of the way the world works. But engineers do not have power. Businessmen do. Until you realize that, you will continue writing technical specifications like this, making micro-communities, and missing the big picture. Control requires power. Power requires money. If you can't monetize it, you have no control. Whatever federated thing you think is going to win, isn't going to win, if there isn't enough money to back it. Because someone with money will just make the biggest "federated thing" (or not; it could be completely proprietary and billions of people will still use it), and eventually close it off once they have enough users. You cannot engineer your way out of money, politics, or human nature.
- danabramov 1y agoI tried to make the case that the design of web itself creates different dynamics than the design of today’s social networks in a demonstrable way (walking away from hosting is still easy so it became commodified). I get your pessimism but I wonder how you’d engage with that argument. I think it shows the shape of the thing actually matters.
- Kye 1y agoAnisota is one of the more interesting attempts at a new presentation: https://anisota.net/profile/dame.is https://anisota.net/profile/dame.is
- hollowonepl 1y agoI think it would be better articulated if comparisons to ActivityPub were made. Those are I believe two competing visions of Open Social defined as communication protocol, not a platform. Otherwise it just sounds like evangelizing employer and that compromises the whole “open” concept of the article, fairly.
- lowkeyokay 1y agoThe author surely knows about competing protocols but prefers at. It would be just as easy to argue the author is biased if a comparison was made. Maybe more informative though.
- danabramov 1y agoI thought about covering others at first but it ended up distracting from the point I wanted to make. I tried to make a strong case for this particular vision in this article. I could write something separate as a comparison, or maybe let other voices speak for their thing. In short, I don’t think ActivityPub solves any of the stated problems (ability to walk away without cooperation; forking products; giving new life to old data). In that sense it doesn’t mirror “open source but for data” and doesn’t match the premise of my post.
- hollowonepl 1y agoI don't believe anybody else can do it with good start you've made. I think above is nice headline for some more complete assessment as a follow-up article. indeed!
- wsve 1y agoThe author is talking about owning a domain and how having that domain gives you ownership over your data... But I can't but think that, at least in the US, domain names are rented from private Internet service providers. There is no ownership involved. One way or another, we are still paying a company. The assumption of the article is that ISPs are stable and net neutral enough that one would not worry about the ISP going under or seeking some personal vendetta against you and booting your domain. A separate entity may no longer be hosting our data, but a private entity is the gatekeeper of whether anyone is able to see your data. All that to say, if we want true ownership of domains, ISPs need to be a nationalized, democratized service.
- infinitifall 1y agoThere are clearnet websites for flat earthers, anti-vaxxers, cults, hacker groups, classified document leakers, nazi groups and terrorist organisations. Finding a registrar that lets you say what you want is a solved problem.
- a2128 1y agoCurrently most people publish stuff on big platforms so governments, activists and billionaires will go after these platforms to influence or control what's being talked about. I worry that if we never had big platforms, or we moved past them, all of the focus would be on going after registrars and hosts instead. It's not a bulletproof system unfortunately
- gr__or 1y agoWhile I agree with the sentiment, I think it confuses ISPs with registrars. There are still many ISPs that do that service as well, it's less common than it used to be. It is quite common for national TLDs (like .de, .jp or .cn) to be managed by not-for-profit entities, under contract with their respective governments... which might also not be great wrt censorship. There is also the general issue of equal access, where shorter, more memorable domains get more expensive and hodling domain names is only disincentivized for people without enough funds. I would very much like to see an alternative system to domain names, probably something more in the web of trust space.
- wilt6269 1y agoI can’t help but cringe whenever I see a Bluesky fan stubbornly clinging to the past by calling X ‘Twitter.’ This one went even further - using the old logo and even the outdated URL.
- dave1010uk 1y agoThat was an example of a social media company changing, with users not being able to migrate their data. Scroll a bit further and you'll see X.
- danabramov 1y agoMy post retraces a historical progression of social media, and it was indeed called "Twitter" at the time. You can scroll a bit down and you'll see "X" a bit below. In general, actually reading the articles you comment on won't hurt you.
- wilt6269 1y agoI did read the thread — and I’m specifically referring to the third (and final) diagram where it still literally labels X as “Twitter.” No amount of timeline layout gymnastics explains that. It feels less like faithful documentation and more like a pretext to take a swipe at the acquisition by “some guy,” which then segues into the whole “getting cooked by the algorithm” bit.
- airspresso 1y agoThat's clinging to straws. Many of us still prefer to call it Twitter since the new name makes no sense, especially when placed in a sentence.
- utopiah 1y agoAny implementation if I don't care? Like if I want my Web application to support either ATProto, AP, and eventually whatever else is around the corner even if it means only have the lowest common denominator?
- danabramov 1y agoIf you just care about the identity part, atproto uses a flavor of oauth.
- utopiah 1y agoThanks. Well that's a good question, namely what do I actually expect out of federation. In my case it's to remix pedagogical exercises. So I need : - actual content (e.g. exercise and assets) to remix (imagine changing the language) but also optionally - author ID for attribution - a stable URL for provenance, again from attribution but possibly metadata (e.g. how many times played on origin server, language, etc)
- cy6erlion 1y agoGreat post. Why use Social Media when you can use your own blog with RSS. I think it's because of Network effects, Social Media gives you an identity/address within a social network that has demand for your posts and a supply of posts that interests you. The Social Network itself should be vybrant for strong Network Effects to take place, this is inherently centralizing sorta like super markets. Thus the idea of Decentralization and Social Media don't go well together. Decentralization is also more complex for the developers and particularly for the users, this creates a market for people offering services to operate decentralized systems, which ends up centralizing the network. This is how the WWW, Email, Git, BTC all got more and more centralized.
- bumseltagbaerbi 1y ago[flagged]
- vollbrecht 1y agoWhat would in practice happen in a two user scenario where user A replied to user B, and later user B's repository gets completely deleted. We have this cache thing via wss connections. Do they invalidate this messages from user B? Is user's A worldview now completely dead? Owning a thing in the internet is a complicated topic i guess. Preserving past information via copying what a user said so that it does not get lost maybe also in the interest of some users (equivalent to the webarchive). I understand that this contradict the whole "owning your data" premise, but fundamentally since it was open in the first place the thing always can be copied right? Whatever content is produced in this "open social" network, some of it may have long lasting "value" to an individual. Is there anything to make sure that what they interacted with can not completely broken by the other site of the party?
- danabramov 1y agoIf the user chooses to delete their account, it is a separate event on the network, which well-behaved apps should respect (and update their caches accordingly). So an app like Bluesky would display this as a reply to a deleted post. If the user's repo just goes down (e.g. the host is down), then indeed it won't be available upstream and only cached versions will remain. It might be that the user is having problems, and the repository will be up on a different host later. It's up to each application how to handle this, but it seems reasonable to keep serving cached content since there was no explicit deletion instruction. E.g. I presume Bluesky would keep showing both replies in the conversation. >I understand that this contradict the whole "owning your data" premise, but fundamentally since it was open in the first place the thing always can be copied right? Yeah this is a tricky thing. The general guideline is that the user expresses intent (e.g. can delete post or entire repo) and well-behaved apps respect that intent. But of course there can be non-well-behaved apps that don't, or that permanently archive everything ever emitted.
- NaomiLehman 1y ago"Open source has clearly won." is this a joke?
- danabramov 1y agoDominant programming languages, servers, package managers, UI libraries and components, and much development tooling (IDEs, language servers) is largely open source. This wasn't the case when I started programming.
- js8 1y agoThe thing I miss the most in social networks is the ability to verify the provenance of information through social graph (chain of trust). Ideally, if I see a post or comment, a process that I control should be able to establish whether the user is trustworthy, by asking the intermediate nodes whether the next hop is trustworthy. Essentially, I should be able to walk that chain of trust to see whether the information comes from a trustworthy source (and possibly input user's own evaluation of the chain links and nodes). Unfortunately, social media companies do not let users access the social graph, because not being able to ascertain provenance of information is what makes paid advertising possible. It would also greatly help to combat bots.
- Kye 1y agoThe social graph, at least in Bluesky's own collection[0], is made up of the sum of follow records in individual repositories on PDSes. Anyone can enumerate them. [0] A collection is basically an app's particular set of records stored in a user's PDS repository. Here's an example using the Bluesky CTO's follow records: https://pdsls.dev/at://did:plc:ragtjsm2j2vknwkz3zp4oxrd/app.bsky.graph.follow https://pdsls.dev/at://did:plc:ragtjsm2j2vknwkz3zp4oxrd/app.... These are summed up by Bluesky's app server (app view) and then used to fill out following lists in apps that connect to that server through its API. A fact checking or web of trust tool could pull these records down and use it for exactly this purpose. It could even weight by who they repost, for example.
- KolibriFly 1y agoIt captures something that I think a lot of us in tech have been feeling but haven't quite articulated: that the social web feels increasingly rented, and the rent keeps going up
- ronbenton 1y agoWe’d be lucky if the rent was paid in dollars but, instead, it’s paid in psychological manipulation
- ethbr1 1y agoPsychological manipulation is only being performed because it generates dollars.
- ronbenton 1y agoCorrect
- strgcmc 1y agoTrue of course that dollars is the end goal, but frankly it'd be better if they just took the dollars out of my pocket directly, instead of poisoning my brain first so that they can trick me into giving some dollars... Obviously I'm being hyperbolic, but I think eventually if society survives past this phase, our descendants will look back and judge us for letting psychological manipulation be a valid economic process as a way to generate dollars, in much the same way we might judge our ancestors for ever building up a whole industry to hunt whales for oil for fuel (meaning, they might acknowledge that fuel is important and necessary to power an industrializing society, but they would mock us for not understanding how to refine petroleum sooner, and how silly going through the tech tree of fucking whale hunting is, just to get some fuel). It is fucking silly/absurd/dangerous, that we go through the tech tree branch of psychological manipulation, just to be able to sell some ads or whatever.
- vvpan 1y agoCheck out Technofeudalism by Yanis Varoufakis, he really expands on the idea of web being mostly rent-seeking and not productive.
- mountainriver 1y agoThe protocol is cool, but Bluesky continues to trend downward. My experience on it wasn’t positive. It could be interesting to see what other apps may be born out of the protocol though!
- pessimizer 1y agohttps://bsky.jazco.dev/stats https://bsky.jazco.dev/stats Yes, down in every measure over the last 6 months. I think it's primarily used by a lot of people to organize sockpuppet-aided raids on twitter towards people who are instantly banned by mass-reporting the second they create an account on bluesky. It's basically old 4chan for unfunny people who think they're better than everybody else. I'd be positive about any distributed social protocol, though, no matter who delivered it. The problem is that this was a Dorsey project that he already abandoned and denounced because it took a bunch of VC and is just waiting for the rugpull. Now you're supposed to trust a bunch of people you never heard of and a few famous paid evangelists.
- CommenterPerson 1y agoVery well done. I hope this happens soon. I'm an engineer but not the software kind and I will look into this area more closely and try to support it. Thank you.
- dark_mode 1y agoAwesome read! Question: > What’s more interesting is that Tangled prefilled my avatar based on my Bluesky profile. It didn’t need to hit the Bluesky API to do that; it just read the Bluesky profile record in my repository. I'm a bit confused by this. If a bluesky avatar contains an image, isn't that stored (at least by default) within bluesky? Meaning that Tangled will have to hit the Bluesky API? Or maybe Dan is saying that his own repository is not hosted with Bluesky in which it would make sense, if wherever his repo is stored is getting hit to retrieve the image.
- steveklabnik 1y agoThe “Bluesky API” is the appview, but the avatar is stored in your PDS. Even if you’re using a PDS hosted by Bluesky, it’s a different component that’s being asked to serve the avatar.
- dark_mode 1y agoInteresting. Ok just saw this https://github.com/bluesky-social/pds https://github.com/bluesky-social/pds > Self-hosting a Bluesky PDS means running your own Personal Data Server that is capable of federating with the wider ATProto network. So pds (personal data server) is like the container where you chose to store the data and it follows a certain standard. If the container is hosted is bluesky, i still consider it a "bluesky api" but I understand the nuance better now.
- fnwbr 1y agoI think I understand the theory. But in fact it looks like tangled.sh is indeed using a "proprietary" Bluesky API rather than... e.g. calling `danabra.mov` right away to fetch his avatar: https://tangled.org/@tangled.org/core/blob/master/avatar/src/index.js#L72 https://tangled.org/@tangled.org/core/blob/master/avatar/src... ... or am I misunderstanding?
- dark_mode 1y agoThat does look weird to me. I would expect it to more generic because this would be miss data stored in PDS outside bluesky. At least according to my layman understanding.
- paool 1y agoWhat is the incentive of someone to create an app and just pay for all the hosting involved? Also, does everyone need to have their own domain name in order to have an identity cuz that seems like a non-starter.
- dark_mode 1y ago> What is the incentive of someone to create an app and just pay for all the hosting involved? If you're creating a social app, website, or whatever, you still have to host all your users' data regardless. This is just about the protocol you use which enables universal compatibility, meaning users have the choice to store elsewhere. > Also, does everyone need to have their own domain name in order to have an identity cuz that seems like a non-starter. Not really. Bluesky is a good example; when you first sign up it does it for you under their own top domain by default iirc, but the great thing is you can actually use your own domain.
- dark_mode 1y agoI wonder if there's a at protocol usecase for replacing something like Disqus in blogs, personal websites etc.
- tomgag 1y agoPersonal opinion: Bluesky is "fedi-washing". Better Mastodon or Nostr. https://gagliardoni.net/#20250818_battle_of_socials https://gagliardoni.net/#20250818_battle_of_socials
- deleted 1y ago[deleted]
- dark_mode 1y agoI like the skepticism against Bluesky, and I agree that where VC money is involved things are mostly sketchy. However, this post was about the at protocol, which seems like you just hand-waved in one sentence: > The AT Protocol used by Bluesky has some interesting features, although to be honest I don't know how many of these are just impossible to achieve on ActivityPub or are just WIP lagging behind due to funding constraints. I don't think the debate between them is super useful because their architectures are very different. You also mentioned an issue with the bluesky relay, but others already exist so it's not techincally tied to Bluesky. Heck, I think the fact multiple can exist at the same, while degrades the social aspect, still makes it decentralized. As for the identity management issue, they announced just last week that it's getting branched to an independent entity: https://docs.bsky.app/blog/plc-directory-org https://docs.bsky.app/blog/plc-directory-org
- tomgag 1y ago> I don't think the debate between them is super useful because their architectures are very different. Sure, that's true, but I, personally, care mostly about one question: Who holds the keys to the kingdom? In this respect, I think the AT Protocol fails spectacularly, mainly due to the lack of a credible strategy to implement really self-custodian identities. > You also mentioned an issue with the bluesky relay, but others already exist so it's not techincally tied to Bluesky. Heck, I think the fact multiple can exist at the same, while degrades the social aspect, still makes it decentralized. Yes, but this is also true for Nostr, Diaspora, Mastodon, etc. The difference being, last time I checked (and of course things might have changed in the meantime) with AT Protocol it was only possible to self-host part of the infrastructure (and hosting the relay is insanely demanding). > As for the identity management issue, they announced just last week that it's getting branched to an independent entity: https://docs.bsky.app/blog/plc-directory-org https://docs.bsky.app/blog/plc-directory-org This is another example of gaslighting from Bluesky that just makes me angry. How in the holiest of Hells does an "Identity directory controlled by a Swiss Association" make the whole thing better? Sorry, not buying it. I don't have a horse in the race, but won't fall for the marketing.
- tneely 1y agoI've always thought it would be interesting to apply this sort of approach to health data. I own my data and control where it's stored and how it's accessed. And hospitals anywhere can interact with my data as needed while labs, doctors notes, etc. all live with the hospitals.
- zumu 1y agoI've been on and off thinking about this problem for years. Very excited to see an ecosystem popping up. But I wonder, why JSON if the web is already built on HTML documents? Is it possible to just store our data in a web of authenticated html documents and have the protocol be built on that? Are there other open standards we can leverage to reduce the amount of new infra / protocols? I wonder if there's a less complex "good enough" mvp version.
- fogzen 1y agoAT seems cool — but it’s not built on the web. That’s a dealbreaker for me. I can’t link to a Bluesky post. I can’t use Bluesky from the browser. It’s a silo’d network. The indie web has the right idea: Use the web, build ontop of blogs, degrade gracefully. We could have central aggregators just like Bluesky crawling the web with microformats. The polished experience with Bluesky has little to do with the tech and everything to do with financing and talent. Give me millions of dollars in grants and I’m sure I can build a polished UX too.
- steveklabnik 1y ago> I can’t link to a Bluesky post. I can’t use Bluesky from the browser. What do you mean? Both of these things are trivial. Here is a link to my most recent post on Bluesky: https://bsky.app/profile/steveklabnik.com/post/3lztkahefs225 https://bsky.app/profile/steveklabnik.com/post/3lztkahefs225 You can sign into bsky.app (or deer.social, or anisota.net, or...) in your browser and post just fine.
- fogzen 1y agoThose are proxies specific to that service, no? AT posts aren’t webpages, there is no canonical HTTP URL for an AT post, nor is the post an HTML document. Bluesky happens to provide an HTTP browser-based front-end, which is not part of the AT protocol. It may seem inconsequential to some, but AT is fundamentally hostile to the web. The goal of AT is to move syndication and content off the web to another network. No. I’m done with that.
- mawise 1y agoAlso worth reading, the IndieWeb's "Social Reader"[1] concept. Built more on websites/blogs as the foundational units. [1]: https://indieweb.org/social_reader https://indieweb.org/social_reader
- rpwverheij 1y agoIt seems a bit like this is reinventing what Linked Data (RDF) and Solid PODs already do. Solid: Personal storage repositories and granting access to different apps to read/write to it. Linked Data: you can link to other people's data with IRI's (URLS) and a common format is JSON-LD. What's different here and why is it better? Do we really need another standard / protocol?