







As atproto matures, adversarial actors will reveal all the places where trust is implicit rather than managed - maybe time to build reputation mechanisms for PDSs like we do for email servers? It'll likely need to be default-block/prove-healthy, or default throttle until proven typical?
Scoiattolo
They've got a huge network that I'm in the process of graphing. They're now setting up their own PDSes. It's sophisticated.
Mar 17, 2026 at 5:44 AM
Trust Infrastructure on ATproto
I agree with Nick that you have noted a big hard problem, with Zooko’s triangle type trade-offs. (For a semi-related example that is “easier” but still crazy difficult, see our “PeerFlow: Secure Load Balancing in Tor” https://doi.org/10.1515/popets-2017-0017 ) As noted or implied already in this thread: in the end, if someone can cheaply spin up indefinite unlinked identities and build good reputations for them, and if trust is based on such reputations, it is hard (impossible?) to avoid them s...

ATProto ideas
If AT Protocol becomes “a meaningful layer of the web” — even if it’s only tens of millions of users — then the winning ideas probably won’t only be futuristic...
A Model for addressing privacy on ATproto
When I first got involved with Northsky social, we knew we would have to eventually address the elephant in the room. How do we proactively protect a community from outside influences without relying purely on moderation? And more importantly, how do we keep bad actors from simply pulling their data straight from a relay?
Adversarial ATProto PDS Migration | Blog
An ATProto account lives on a Personal Data Server (PDS), and that service needs to be hosted somewhere by someone. There are a lot of options here, like a Raspberry Pi in your closet, a rented VPS in a datacentre, or a batteries-included service like bsky.social.
Adversarial PLC directory migration - microcosm
Contingency planning: what's our credible failover for the centralized underpinning of ATProto identities?
Adversarial PLC directory migration - microcosm
Contingency planning: what's our credible failover for the centralized underpinning of ATProto identities?
Meta CIB / ATP Dashboard
A comprehensive intelligence platform analysing 214 coordinated inauthentic behaviour and adversarial threat operations identified by Meta across 70 countries, spanning April 2018 to Q4 2025.
About Atproto w/ Dan Abramov | Wireframe Live
As atproto matures, adversarial actors will reveal all the places where trust is implicit rather than managed - maybe time to build reputation mechanisms for PDSs like we do for email servers? It'll likely need to be default-block/prove-healthy, or default throttle until proven typical?
Scoiattolo
They've got a huge network that I'm in the process of graphing. They're now setting up their own PDSes. It's sophisticated.
Some of us in the ActivityPub world feel jealous of AtProto’s success (like me). But more decentralization is a win for everyone. With Bridgy from @anew.social connecting protocols, this isn’t competition, it’s momentum. We’re stronger together, so let’s build the social web humanity deserves 🚀
If WSocial sold people on the idea that everyone they would interact with is ID-verified, then indeed, every single open ATProto community would act as a back door of sorts. The only way for them to deliver would be to de-federate entirely. And it's always a bad idea to bet against openness.
Wimster9030 🇪🇺 🇧🇪
I know, Daniel, but that's not the way WSocial "sold" it to us. We could only access trough ID-verification so we know for 100% they are EU and a "real person". That was the whole point. So we went trough that process, but now it seems that the backdoor are the other ATProt platforms to get in too.
#atproto does not need to win only by convincing people to post somewhere new. It can win by becoming the foundation for software people already need to use because of real-world relationship woodys-rows.pckt.blog/open-forks-of-boring-apps-wit…
Open Forks of Boring Apps With Authority
woodys-rows.pckt.blog