







Note: this post has been revised to be split into two sections: a description of what happened, and my analysis. I hope to make it clear that, while I do not like ATProto in general, I am trying to make good-faith critcisms of specific design decisions and outcomes, and in fact, this post getting updoots on HackerNews appears to have gotten the attention of the team, so, mission accomplished. ref, ref My account has since been manually reinstated; this has not happened for any of the other users that have had this issue, as far as I know.
Who Actually Owns Your ATProto Identity? Hint: It's Probably Not You
ATProto gives your PDS operator full control of your signing and rotation keys, letting them impersonate you across every app in the ecosystem or kill

Taking control of your atproto account | jola.dev
Setting a rotation key on your atproto (Bluesky, Eurosky, etc) account means you can recover it even if the account provider shuts down.

atproto made simple: granular permissions - underreacted
atproto made simple: granular permissions - underreacted

There are no instances in ATProto | Hacker News
I feel like you've (perhaps purposefully?) misinterpreted "instances" just to plug ATProto specifically at the expense of ActivityPub (and RSS, a bit). I think you lower yourself by doing this:

Any other atproto app devs run into this UX snafu? User already has a bsky account; uses it to login to your app. User was only logged in to bsky.app, not bsky.social and doesn’t have a password saved there. User is very confused why their browser doesn’t remember their bsky password.
@iame.li what's your thoughts on this, re: choice of cryptographic keys in the standardized form of atproto
🚨 Docs News!! you all asked for it, so I did a medium-sized refactor of the Auth section of the atproto docs: atproto.com/guides/auth I appreciated all the little pushes here as well as contributions from @danabra.mov and @zzstoatzz.io — much happier with the flow here now and hope you will be too!
Auth - AT Protocol Docs - AT Protocol
atproto.com@masnick.com I’m listening to your interview with @reckless.bsky.social. This third party doctrine is interesting. Do you think that atproto data would be considered properly owned by the account individual? Would be interesting implications if that public data fall under search and seizure rights.
Too many of y’all get the shape of atproto fundamentally incorrect, thinking it’s about “data ownership,” but it’s literally never been about that, and if you keep banging that drum, you’ll miss the point, just like we have every other time.
Bryan (they/them) on pckt
pckt.blogsome thoughts on atproto as a post-app paradigm
Ecosystem Plugins
notes.wesleyfinck.org