4 ms·
This is a fine example of technical exposition. Very easy to read and understand! Like many others, before this post I hadn't the vaguest idea what atproto was;
by SilverSlash 1y ago
This is a fine example of technical exposition. Very easy to read and understand! Like many others, before this post I hadn't the vaguest idea what atproto was; I always assumed it was some decentralized thing a la crypto. But this actually makes a lot of sense to me and it feels like an objectively good thing.
Except for one thing which has been pointed out by others. Anyone can access *all* of my data over this protocol. I like the idea that a lot of my data is directly accessible similar to the early web. But it would be nice if some of that data was only accessible if the accessor was permitted.
I don't really know much about auth tokens but I'm guessing they shouldn't be that hard to incorporate into this thing? When BlueSky or whatever app queries "@username.com/private/documents" the server expects an auth token, whereas it does not when the app tries accessing "@username.com/bluesky/posts".
- hirenj 1y agoI was ruminating about how Atproto would be great for re-thinking the peer review system for scientific journals. Imagine a world where a preprint is “published” onto the social web, from which you could aggregate reviews/comments. I eventually ended up thinking about exactly what you raise - it would be great to have some degree of access control on this so both comments and published things can be selectively shared (with an option to make everything public later on, maintaining all the links).
- danabramov 1y agoYes, something like this is planned in longer term. The team decided to tackle public data first because scaling aggregation while preserving meaningful ownership is hard. So far I think they’ve succeeded at that. Private or semi-private comes with a set of different challenges. Indeed scoped tokens are coming (via OAuth scopes) but that’s used for writes. The same mechanism could be extended for private reads in the future, like you describe. There’s questions about what shape private data would have though. See https://pfrazee.leaflet.pub/3lzhmtognls2q https://pfrazee.leaflet.pub/3lzhmtognls2q and https://pfrazee.leaflet.pub/3lzhui2zbxk2b https://pfrazee.leaflet.pub/3lzhui2zbxk2b for recent thoughts on this topic from Paul who works on atproto.