Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- ATProto and its advocates increasingly sound like all the crypto-based decentralized platforms that failed. The difference is that crypto people actually had reasons to run nodes, they got paid to, while ATProto expects enthusiasts to do so for the love of the game or act like bluesky and have 99% of the "decentralized" platform on a centralized node.
It never catches on with application developers because it requires you to already worship the protocol and build around it.
by Striving7340 - We don't even get paid to be in this cult, that's how organic it isby pfraze
- I don't think anyone ever got paid to "run nodes".by andunie
- I came out to have a good time and I’m honestly feeling so attacked right nowby FatFingers23
- What's even the point of publishing anything online any more if you don't hope to become an influencer? The nature of the game has changed, and now does everything possible to discourage it.by inigyou
- This is the least human take I've seen on this site so far, and I don't even think you're a bot.by polymer8563
- You could say the same about publishing offline. We can always do it simply because we enjoy it and one or two others might find some enjoyment or utility in it as well. It doesn't have to matter, it doesn't have to influence anyone. It's fine as a relatively solitary practice like any other.
- The intention is good. I like the reviews idea. Since the author has hit the limitations of ATProto, could ActivityPub be an answer?by vzaliva
- I really think ATProto is decentralized "the right way" for the general public. So I would very much like it to support this kind of thing.by LelouBil
- I doubt it, since you'd own your data even less as a user than with ATProto. (stuck to a server without the ability to fully move backlinks, data, and identity to another. at least all those things stay the same when you move between PDSes!)
- I created a web-of-trust forum built on ATProto. https://caterpilla.rs
Probably one of the most fun projects I’ve ever worked on, and I largely attribute that to the protocol.
I’m particularly interested in the permissioned data spec, but don’t want it to hold me back, so some functionality is on ice, and I went live without it.
by vinnymac - > A restaurant review is a restaurant review whether I am the only one who ever sees it or it gets shouted to the rooftops. A book review I share with my book club is identical to a book review I share with my wife or publish on my web site.
That is only true if you completely ignore social context and relationships between the subject (reviewer), the object (the reviewed) and the audience. The author does mention being autistic, so perhaps he doesn't see it this way, but to me it would be very important to have a system where anything I record for a narrow audience doesn't become available to the public.
The thing though is that I've been so conditioned to not trust digital platforms that I never publish anything online unless I am 100% comfortable with having that information available to the public. So, in effect, I'd never put anything on my PDS unless it was meant for public consumption, rendering all this "permissioned data" effectively pointless.
by rglullis - > it would be very important to have a system where anything I record for a narrow audience doesn't become available to the public
That's precisely what the author is arguing.
- I switched from codeberg to tangled, and the transition couldn't have been smoother. Being on the ATmosphere really helps with peace of mind.by arikrahman
- Speaking about Tangled, is there an article somewhere about how they use ATProto ? Like what are in the records and allby LelouBil
- I love tangled, but there are certain repos I don't want public. So with all ATProto data being public you can never have a private repo which is disappointing.by jjuel
- Disclaimer: I have not looked carefully at the permissioned data proposal, but I know atproto reasonably well.
Stepping back for a momement, it's clear that permissioned data is driven by real world use-cases (Bluesky needs DMs, Tangled needs private repos, etc). However, I think the synergies with the existing atproto needs to be pretty significant to warrant developing yet another encrypted space spec. We already have various double ratchet protocols, Matrix is having a huge boom. From the point of view of an app developer, does everything need to be handled by atproto, or could we accept that atproto is just for the public stuff?
by sbt - I would prefer this to be more geared towards things like Private social profiles or shared with specific circles than DMs, which are already served by E2EE.
There's no issue in using ATProto to "link" an external service, like Tangled does with it's "knots" which host the git data.
All of the social stuff (issues, PRs, comments and so on) is on ATProto, and on ATProto you also have a "repository" object, linking to a "knot" object containing the address of the knot.
What's stopping an E2EE DM implementation to use ATProto to point to something like an "accepted matrix server" for all parties, and each having a "matrix identity" ATProto record ? (I don't know about Matrix so idk if this is exactly possible but you get the idea)
by LelouBil - This author speaks to me!
> it should just be called “private data”
> the resulting design looks very hard to build on
> Private and public data are basically identical. ... The permission is world-read
Way back before Bluesky decided on their own what permissioned data would look like, when the Atmosphere Private Data WG still thought they had a say in the design, I gave a talk on a ReBAC/Zanzibar style system that aligns with what I think the author is looking for.
https://www.youtube.com/watch?v=oYKA85oZc8U&t=3730s
I suppose we could still build on and run a fork like mine if enough people wanted a more robust IAM system. There are some fundamental issues that I am not sure are resolvable without building them into the protocol core from the start. I have personally given up because of the leadership and am waiting/pondering the next protocol. Another design constraint I'd like to see is incentivizing apps to be federated and installable at the PDS as well as incentivizing small social over public square modalities.
by verdverm - My statement is not super constructive, but yes, I also really liked this article. Local-first, privacy, even the example of managing personal restaurant reviews.
I don't have enough meaningful thoughts here to contribute, but you & OP: I hope we can build a federated protocol for sharing stuff again.
by citelao - I've followed the ATProto space (and seen you around the space) a bunch over time, and honestly for the private data portion of it, I'm quite bearish on the idea of an ATProto shaped thing winning here.
I do think "small social" is winning in almost every definition of the word. There's Discords for everything, each non-technical person I know is in 10s of group chats, folks on Instagram or Twitter seek their "communities" on these apps. HN and Reddit are somewhat platforms of yesterday, valuable only for the sheer volume of conversation, not really of any particular use, often used to doomscroll on the toilet or in the supermarket line.
But ultimately I don't see why you need a protocol for small social. ActivityPub could do it fine (even though it's largely used as a glorified JSON HTTP API), Matrix or IRCv3 can do it fine, email works and is being used, heck you could even roll a bespoke HTTP or Websocket RPC (de-facto ActivityPub) to fix the problem anyway. ATProto is useful because it's a protocol for socializing In the Large. I think user experience matters for this much more than a protocol. I know Bluesky users want it, but I'm not convinced that an ATProto derived solution is the answer.
by Karrot_Kream - btw, for historical context, the reason it is called "permissioned" instead of "private" is because there were sufficient people in the atmo that were very opinionated the E2EE is the only true private. It became an exercise in bikeshedding every time "private data" came up.
You can find the discussions here: https://discourse.atmosphere.community/tag/private-data/2
by verdverm - I've been building a board game community on ATProto. The idea revolves in trying to build the feeling of local clubs but online, instead of "PLAY NOW" being on the landing page (although you can play now if you want) it's organized around clubs. I also wanted to move away from one game oriented community. I play Go and Chess and I would love clubs to be for mixed games. You can create leagues, or tournaments, etc.
As an extension of that I've been building a small language to build games (with a nice time traveling debugger and automatic replays) inspired by Elm. Go and Chess are both built on top of this and you could fork them and modify the rules. Want to code a new Chess variant? Go ahead! Want to code a whole new game you want to try? Go ahead!
What I'm very excited with ATProto is that because all games are broadcast on it and each shares a core system of turn-based replays (and review system with branching) software can be built on top to do AI analysis, or a replay view. The idea that my application can be extended without me adding an API is very exciting and very much in the direction I want to take the system (community is the core tenet).
by MarceColl - How do you prevent a player from manipulating game state outside of the app view?
There is a subgroup in the Atmo working on games, have you found them yet?
by verdverm - Reading articles like this one, I do think people are trying to put a square peg (their applications) through a round hole (ATProto). The ATProto was designed around all data being public. You write public data to a user's PDS and then any application can read that public data and do something with it. If all data was private (encrypted?) by default then that would defeat half of all of ATProto's goals.
Imagine someone starts startup A on-top of the ATProto. They raise some money, get some users, some people love it, but ultimately they die. If the data was private to that service, that data dies with the startup. But if the data is all public future startup B can read that old data and do something with it. As a user that's brings me a ton of utility and comfort trying out new services.
If you're trying to built a local-first, mostly private service I just don't think the ATProto is the right tool for the job.
by ekosz - > The ATProto was designed around all data being public.
I might turn this around to say that ATProto was the square peg trying to fit into the round hole (the vast majority of people want privacy)
by verdverm - If the primary user concern is "all data is public", then the utility of ATProto is extremely narrow and will likely lose to something with a different philosophy.by jshen
- > If all data was private (encrypted?) by default then that would defeat half of all of ATProto's goals.
Yeah, this is the reason why I don't understand why they succumbed to the idea ATProto must handle private and has started on work trying to figure it out (https://atproto.wiki/en/working-groups/private-data). Instead, focus on just really great public data archiving and displaying, at scale.
- atproto permissioned data [1] will solve the dilemma you're describing. Ultimately all the data is in the same place (your PDS) and you can always read and write any data there. If startup A goes away, startup B can read that old data and do something useful with it.
[1] https://github.com/bluesky-social/proposals/blob/main/0016-p...
by jakelazaroff - > If you're trying to built a local-first, mostly private service I just don't think the ATProto is the right tool for the job.
I agree! I think the "permissioned data" working group is aiming to solve the middle ground – where you want to broadcast something "publicly" but to a specific audience instead of the whole world (e.g. invite-only event, membership club). It's "private" in the sense it's not open to all but not in the sense that only you can see the data.
Nick Gerakines has been sharing some good examples of what you could build using permissioned data:
- Private Events: https://ngerakines.leaflet.pub/3mqxalpvn4k2e
- Bookmarks: https://ngerakines.leaflet.pub/3mqu653us3k2p
- Community content: https://ngerakines.leaflet.pub/3mqzsstcsok25
by billdybas