Hacker News
First Steps of the PLC Organization – Independent Public Ledger of Credentials
ACCount39
|next
[-]
That's pretty important in a world where the likes of Google can and will just reject your attempt to log in with a valid password on the grounds of "we don't like you", and force you to "confirm" yourself using a phone number that's defunct since 2009.
The issue is, as often is the case, adoption.
rkagerer
|root
|parent
|next
[-]
If you're interested in this but uncomfortable exposing your mailserver to the world, there are proxies that can help (eg. SpamHero) and which could theoretically be swapped out to a competing service if needed while still retaining ownership and control of your domain / address / message history.
verdverm
|root
|parent
|next
|previous
[-]
The PLC makes it easy for Bluesky to be a custodian and onboard new users
FiloSottile
|root
|parent
|next
[-]
I like to insist that the PLC Directory collects and distributes updates to highlight how it's different from a database. The latest state of the account is signed by the key that created it, or by a key that succeeded it. The directory can't inject any values, it's just a low-complexity solution for data availability: the "how do I learn about updates" part.
It could decide to hide/reject updates, but then it could just as well be forked and replaced if it did that. If downstream applications decide to get their account updates somewhere else, that's the directory now, without any loss of continuity for the accounts.
You don't get that from a simple database.
One could argue domain registrations, and so did:web, are more of a database controlled by a (large, international) organization than PLC. Plenty of tradeoffs of course.
someonebaggy
|root
|parent
|next
[-]
We're all watching the first step of enshittification and thinking "this is fine"
verdverm
|root
|parent
|previous
[-]
I believe there is work around did web for an extension that would enable verifiable history
xyzzy_plugh
|root
|parent
[-]
You can always create a new identity, I don't think anything has changed there. If you don't want your new identity connected to your old identity, then don't.
The right to be forgotten is whole separate problem. The only hope here, really, is that entropy takes care of it for you. I don't see how a chain of trust system can fundamentally be compatible with the right to be forgotten unless you relax the rules a bit.
cmjs
|root
|parent
|next
|previous
[-]
PLC is imperfect, like every solution to identity so far, but it's a lot better (in terms of ownership / control of your own ID) than DNS.
idiotsecant
|root
|parent
[-]
someonebaggy
|root
|parent
|next
[-]
ForHackernews
|root
|parent
|previous
[-]
birdsongs
|next
|previous
[-]
ForHackernews
|next
|previous
[-]
verdverm
|root
|parent
|previous
[-]
oh, maybe you mean Sam Altman's World with their eye scanning for identity, that is quite dystopian
tancop
|root
|parent
|next
[-]
I think a model where public really means public and private means private is more clear to users than a closed platform where neither is true. Facebook is actively using your private posts for ad targeting and they can remove your public content at any time for no reason. With atproto that can only happen if you pick a bad hosted PDS out of many.
jdw64
|previous
[-]
epistasis
|root
|parent
[-]
https://overreacted.io/open-social/