8 ms·
> Most people don't have domains, and so their identity will be owned by a third party. Indeed, and as a result, such users will always be vulnerable to specif
by solatic 1y ago
> Most people don't have domains, and so their identity will be owned by a third party.
Indeed, and as a result, such users will always be vulnerable to specific risks like sudden bans, i.e. when the hosting service becomes adversarial. The only full protection is to own your own domain off a neutral TLD, with protocols that use DNS to describe how traffic should be routed.
But, because most users don't have domains (as you pointed out), the state-of-the-art can still be improved upon with partial flexibility and protections, when the hosting service is cooperative. This project allows people to keep their Bluesky handle (because they don't own a domain) while (hypothetically) moving their data hosting to a different provider, unlike current Big Social where your data is stuck on Facebook/X/Instagram/TikTok/YouTube forever. Bluesky has an interest in this because it also allows people to set up their own handle and move their hosting to Bluesky.
Sometimes we improve upon the existing state of the art not by delivering perfect solutions, but by delivering improvements upon limitations that we accept as a given (like the fact that most users will not set up their own domains).
- braebo 1y agoNobody owns their domain — it still bugs me that we just lease them on yearly renewals by the good grace of the anointed registrars who may, at the will of governments or through sheer negligence, relieve us of such “ownership”.
- danabramov 1y agoI responded to this here (https://news.ycombinator.com/item?id=45471337 https://news.ycombinator.com/item?id=45471337) but I want to emphasize this: your domain is "just" a handle. If something happens to it, you still control your identity, so you can point it at a different domain. Apps just display "invalid handle" instead of your handle but your posts/follows/data stay intact. You can go through a "change handle" flow then and fix it. Unlike with web redirects, you don't need cooperation from whoever owns the old domain because it's the DID Document that controls which handle you use, and you still control the DID Document even if you lose your handle. (That's part of what my article tried to explain by showing the flow: domain is resolved to DID, DID is resolved to hosting, links are stored with the DID.) When you change your handle, all your followers/posts/etc stay with you, it just seamlessly updates in the apps you use.
- vollbrecht 1y agoThanks for trying to explain this to us. You are insisting here on talking about the "handle" part, though isn't the crucial part of the complete chain weather we use either did:web or did:plc? So as you outlined yourself in the article. If you a) use did:web b) ever loose access to that domain you are cooked. No amount of handle changes can help here. If one looses a handle domain one can loose a did:web domain also, so that just moved the problem to a more opaque place. So your identity is always either a) attached to a domain you might loose b) to some plc provider that might stop work for you. Please correct me if i get anything wrong here, as that is just how i understand it.
- danabramov 1y agoThe PLC is being spun out into a separate entity independent of Bluesky. The intention is for it to become something analogous to ICANN. So hopefully, with time, even Bluesky shutting down wouldn’t affect it. It’s also very simple software and is not difficult to run. People are already running PLC mirrors (e.g. https://plc.wtf/ https://plc.wtf/). So if push comes to shove it should be possible to figure out the next step. Although this does require trust and coordination across the ecosystem which is tricky. See https://updates.microcosm.blue/3lz7nwvh4zc2u https://updates.microcosm.blue/3lz7nwvh4zc2u for some thoughts on that.
- Kye 1y agoWhat happens if whoever has the old domain now connects a DID with it? Is this where the rotational key + the fact that everything is signed with it comes in? My concern here is with embeds and links on the wider web that have no notion of ATProto DIDs and only know example.com/@example.com
- danabramov 1y agoYes, that's why did-based links are better for web permalinks. But that's not different from usernames being recycled on other social sites.
- solatic 1y ago
- kevinak 1y agoIsn't the solution to the identity problem of domains just to use public/private key pairs like Nostr does?
- aidenn0 1y agoWho knows what will happen with at, but with e-mail owning your own domain is no longer sufficient to participate in e-mail federation. I have a domain, which I use for e-mail and multiple times per year I need to use gmail to get reliable delivery of e-mail. My mom is even caught in a Kafkaesque bind with one company where they told her that to access her account, she needs to change her e-mail, as they refuse to deliver to domains registered with GoDaddy (yes, registered, regardless of e-mail host), but she can't log in without getting a security code to her e-mail.