Rendered at 15:53:26 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ACCount39 19 hours ago [-]
This might be one of the closest things I've seen to actually being able to own your account - instead of having it not just owned by a second party in every way that matters, but also beholden to a third party via an e-mail or a phone number you can't possibly own in any meaningful way.
That's pretty important in a world where the likes of Google can and will just reject your attempt to log in with a valid password on the grounds of "we don't like you", and force you to "confirm" yourself using a phone number that's defunct since 2009.
The issue is, as often is the case, adoption.
rkagerer 12 hours ago [-]
You can still own an email. Some people out there have their own domain and successfully self-host, despite the challenges.
If you're interested in this but uncomfortable exposing your mailserver to the world, there are proxies that can help (eg. SpamHero) and which could theoretically be swapped out to a competing service if needed while still retaining ownership and control of your domain / address / message history.
verdverm 19 hours ago [-]
did:web is closer to owning your own identity, this is a central database controlled by an organization
The PLC makes it easy for Bluesky to be a custodian and onboard new users
FiloSottile 19 hours ago [-]
Sort of.
I like to insist that the PLC Directory collects and distributes updates to highlight how it's different from a database. The latest state of the account is signed by the key that created it, or by a key that succeeded it. The directory can't inject any values, it's just a low-complexity solution for data availability: the "how do I learn about updates" part.
It could decide to hide/reject updates, but then it could just as well be forked and replaced if it did that. If downstream applications decide to get their account updates somewhere else, that's the directory now, without any loss of continuity for the accounts.
You don't get that from a simple database.
One could argue domain registrations, and so did:web, are more of a database controlled by a (large, international) organization than PLC. Plenty of tradeoffs of course.
someonebaggy 18 hours ago [-]
Data flow: all the internet's creators ----> Jack Dorsey ----> all the internet's consumers
We're all watching the first step of enshittification and thinking "this is fine"
verdverm 19 hours ago [-]
one of the other feature of PLC compared to did:web is that it presents the identity history, but this is also problematic for some people (dead naming and right to be forgotten)
I believe there is work around did web for an extension that would enable verifiable history
xyzzy_plugh 18 hours ago [-]
IMO perfect is the enemy of good here. If your personal email account you use for literally everything is firstname.lastname@mailprovider then you're already in the same situation. This isn't any worse, but it is strictly better.
You can always create a new identity, I don't think anything has changed there. If you don't want your new identity connected to your old identity, then don't.
The right to be forgotten is whole separate problem. The only hope here, really, is that entropy takes care of it for you. I don't see how a chain of trust system can fundamentally be compatible with the right to be forgotten unless you relax the rules a bit.
cmjs 18 hours ago [-]
Nobody owns a domain name. You rent it, subject to the whims of the registry. Miss a single payment and you loose it forever.
Even if you always pay up on time, despite price rises etc, they can still decide to take it away: https://neil.fraser.name/news/2026/09/03/
PLC is imperfect, like every solution to identity so far, but it's a lot better (in terms of ownership / control of your own ID) than DNS.
idiotsecant 12 hours ago [-]
I think ENS basically solved this already. Turns out nobody really cares about the problem much.
tancop 6 hours ago [-]
The problem with ENS is only Brave and Opera support it. That's less that 5% of users. If Chrome had a way to add custom domain resolvers in extensions it would be a lot more useful because you wouldn't need to tell people they have to install a whole new browser.
idiotsecant 4 hours ago [-]
I guess that is technically correct, but I'm not sure that's a weakness of the underlying protocol
someonebaggy 4 hours ago [-]
Permanent human-readable names are subject to squatting. Who owns microsoft.eth? I bet it's not Microsoft.
ACCount39 19 hours ago [-]
Doesn't did:web suffer from the same flaw as e-mail on your own domain - not being able to actually own a domain?
verdverm 18 hours ago [-]
it's a shame the way handshake and crypto went, that was an actually great use for blockchain
Just curious, how is this different from something like a PGP key server?
cmjs 18 hours ago [-]
A PGP key server hosts PGP keys; the PLC directory hosts DID documents.
copperx 19 hours ago [-]
The same difference between Dropbox vs an FTP account.
ForHackernews 20 hours ago [-]
Better than the eyeball-scanning ghouls.
tehnoslow 19 hours ago [-]
I have to agree
verdverm 20 hours ago [-]
atproto is currently permissionless world readable, that seems worse to most people (I asked low 100s) than being in a siloed platform with some amount of control over who can see their content
oh, maybe you mean Sam Altman's World with their eye scanning for identity, that is quite dystopian
tancop 6 hours ago [-]
Spaces are in alpha and implemented in at least 4 PDS codebases. Until then there's a lot of use cases where world readable is not a problem, like personal blogs or instagram/twitter style social media.
I think a model where public really means public and private means private is more clear to users than a closed platform where neither is true. Facebook is actively using your private posts for ad targeting and they can remove your public content at any time for no reason. With atproto that can only happen if you pick a bad hosted PDS out of many.
ForHackernews 19 hours ago [-]
Yes I was referring to Altman's "WorldCoin" eyeball-scanning scheme.
jdw64 17 hours ago [-]
I came in thinking it was P(rogrammable) L(ogic) C(ontroller), but this is something I've never seen before. Is there anyone who could explain this PLC to me?
epistasis 16 hours ago [-]
It's core to the AT Protocol method of opening up social feeds. Some introductory blog posts that helped me:
That's pretty important in a world where the likes of Google can and will just reject your attempt to log in with a valid password on the grounds of "we don't like you", and force you to "confirm" yourself using a phone number that's defunct since 2009.
The issue is, as often is the case, adoption.
If you're interested in this but uncomfortable exposing your mailserver to the world, there are proxies that can help (eg. SpamHero) and which could theoretically be swapped out to a competing service if needed while still retaining ownership and control of your domain / address / message history.
The PLC makes it easy for Bluesky to be a custodian and onboard new users
I like to insist that the PLC Directory collects and distributes updates to highlight how it's different from a database. The latest state of the account is signed by the key that created it, or by a key that succeeded it. The directory can't inject any values, it's just a low-complexity solution for data availability: the "how do I learn about updates" part.
It could decide to hide/reject updates, but then it could just as well be forked and replaced if it did that. If downstream applications decide to get their account updates somewhere else, that's the directory now, without any loss of continuity for the accounts.
You don't get that from a simple database.
One could argue domain registrations, and so did:web, are more of a database controlled by a (large, international) organization than PLC. Plenty of tradeoffs of course.
We're all watching the first step of enshittification and thinking "this is fine"
I believe there is work around did web for an extension that would enable verifiable history
You can always create a new identity, I don't think anything has changed there. If you don't want your new identity connected to your old identity, then don't.
The right to be forgotten is whole separate problem. The only hope here, really, is that entropy takes care of it for you. I don't see how a chain of trust system can fundamentally be compatible with the right to be forgotten unless you relax the rules a bit.
PLC is imperfect, like every solution to identity so far, but it's a lot better (in terms of ownership / control of your own ID) than DNS.
oh, maybe you mean Sam Altman's World with their eye scanning for identity, that is quite dystopian
I think a model where public really means public and private means private is more clear to users than a closed platform where neither is true. Facebook is actively using your private posts for ad targeting and they can remove your public content at any time for no reason. With atproto that can only happen if you pick a bad hosted PDS out of many.
https://overreacted.io/open-social/
https://overreacted.io/where-its-at/
https://overreacted.io/a-social-filesystem/