The Default Transparency Trap on Bluesky and the ATProto Protocol
You might know Bluesky? It's one of several Twitter clones born in 2019.
But it's far from "just" a clone, Bluesky was born from research projects within Twitter. It's literally the evolution that Twitter should have followed if the company hadn't been acquired by Elon Musk in 2021.
It was Jack Dorsey (then CEO of Twitter) who announced it in 2019. It was then Parag Agrawal who took the lead on the project before becoming CEO of Twitter.
So, it was a key project at Twitter that aimed to decentralize social networks.
The idea of decentralization was to find a solution to everything that killed Twitter: the concentration of too much power in the hands of a single company.
Bluesky wanted everything to be transparent and open to prevent all the abuses we can see on X with its algorithm widely biased to serve personal interests from being reproduced.
Moderation, recommendations, hosting, everything can be delegated to others, so each user can, in theory, choose what they see, where their data is hosted, and what gets recommended to them.
But this ideal does have some flaws. And that's what I'd like to talk about today.
Decentralized and Federated Networks
Bluesky isn't the first to propose a decentralized network.
But if we're talking about social networks, in the more modern sense of the term, I'd say one of the first is newsgroups that worked on usenet. If it appeared in 1979, I personally used it much later, during my studies (between 1997 and 2001). I mean, in 1979 I was more interested in learning how to properly put food in my mouth than in browsing American university servers.
Oh yes, by the way, since I was talking about my studies, it was during that same period that I started doing fansubs, amateur subtitling of Japanese anime, and that's when I discovered other decentralized social networks like IRC or Direct Connect. Knowing that part of the illegal downloading of subtitled anime was done via newsgroups anyway. The loop was closed.
But for these networks, we're not really talking about federated networks. That is, if you were present on one IRC channel, you couldn't see what was happening on another IRC channel, and the same with Direct Connect.
The first federated social networks appeared around 2008 with Laconica/StatusNet then Diaspora in 2010. But there I have no personal anecdotes to tell about these networks because, I don't know why, but I completely missed them when they came out.
Still, there are plenty of interesting things to say about these two networks. Originally Laconica/StatusNet is a sort of refuge for the free software community against Twitter and besides the first versions of Mastodon ran on the OStatus protocol, itself a direct heir to the work done on StatusNet. So we can talk about a lineage between StatusNet and ActivityPub/Mastodon.
As for Diaspora, it's a bit less cheerful. If the project starts well with a successful kickstarter campaign of $200,000 aiming to create a decentralized Facebook, one of the founders, Ilya Zhitomirskiy, took his own life at only 22 years old which gave a serious setback to the initial project. The Diaspora network then became notable in 2014 for being the digital refuge of the Islamic State. The very nature of the network prevented any central action to combat content created by Daesh, which highlighted some of the challenges of federated networks and had consequences on the design of Bluesky later on.
We had to wait until 2016 to see a new initiative appear with Mastodon and then the ActivityPub protocol in 2018. The network achieved some success with 15M users (but only 1M monthly active users) but it faced several design problems:
- a certain form of complexity in registration (choice of a server)
- identity that is tied to the server which makes moving difficult
Registering is already making a choice since the server can decide who it federates with or not, its internal moderation rules and if the server closes overnight, your account dies with it.
The fact that a server can be autonomous on everything, moderation, permission to leave etc… led several people to say that we left a kingdom instead to a federation of feudal fiefs.
And that's when Bluesky arrived with its ATProto protocol in 2019.
Bluesky is Not ATProto
Bluesky is the standard bearer but Bluesky is only an implementation of a protocol. With this protocol, ATProto, there is one objective: it's that anyone can recreate an application like Bluesky, offer hosting for your data on a server (a PDS), enrich the protocol to add new types of applications. Recreate Facebook, LinkedIn, Instagram, everything becomes possible, with the same user base.
In practice we long pointed out that apart from Bluesky, there didn't seem to be anything else. But that was before. Bluesky now coexists with Eurosky, Graysky or Blacksky for microblogging and with many other applications like Tangled, Sifa.id, Flashes etc…
And to address the moderation questions raised by Diaspora, a user can now choose their moderation services and an application like Bluesky can also hide content.
This makes it possible to quickly address content that wouldn't belong on the network but it's flexible enough to allow you to view it on your own AppView if you wanted to.
As for the problems raised by Mastodon, around identity portability and the risk of choosing a server that changes its rules midway or decides not to federate with servers that interest you, well that's also solved. Identity is not tied to the server but to a directory and all functionality (moderation, feeds etc…) is portable from one AppView to another.
Now that I've sold you the protocol a bit, I need to circle back to my original topic. Why is one of its greatest strengths also a risk for you?
Default Transparency
On the ATProto network, everything is public. That is, you can view the entire network, know the number of users, the active ones, conduct network studies to observe the spread of a specific idea, create tools to identify networks of suspicious accounts.
It's a huge advantage and one of the main criticisms leveled at X since they closed their APIs. In Europe, X had a legal obligation to provide data access to approved researchers to combat misinformation. Musk having a certain interest in not being able to study algorithmic biases on his platform, he is now in conflict with European authorities on the subject.
But that's impossible on ATProto. Except this strength also proves to be a real problem for you.
You may have seen the new "news" tab in mu.social (an alternative client to bluesky)? In it you can indicate your preferences in terms of information:

And you can also select newspapers to follow:

But note the last remark:
I understand my topic and source selections will be published as a public record linked to my account, and agree to share them.
Everything is public.
But in reality, that applies to everything. All my likes are public, all the people I follow, all the people I block.
But it goes beyond that. I invite you to look at my PDS data.

You have plenty of information here:
- I have a profile on sifa.id
- I have "endorsed" people on sifa.id and you can know who
- I have a publication on Offprint (an alternative to Writizzy that I wanted to test)
- I published Writizzy on atstore
- I have a publication on Writizzy (this blog)
In short, all my activity linked to my handle @eventuallycoding.com is publicly available on my PDS.
And that, oddly enough, is a problem.
You don't need to know who I'm subscribed to on standard-reader, and therefore what I read. The same way you don't need to know my political, sexual or religious orientations.
The point of decentralization is, in part, to avoid giving a single company too much information about me by crossing all my data. With my use of ATProto, I just gave this intersection away for free to everybody.
Imagine a forum powered by atproto where I would come to talk about personal problems, an addiction, a complicated family situation. You shouldn't know about it.
Anyway, I really like the potential of ATProto. For example, I admit I was seduced at first when I built my profile on sifa.id: https://sifa.id/p/eventuallycoding.com, a sort of neo-LinkedIn. Well first, technically it's super interesting on one hand and it appeals to the geek in me but that's secondary for the general public. The other point is that I found it powerful to see that sifa.id automatically aggregated my bluesky posts, my tangled contributions, or my blog articles.
But thinking about it, there is a risk. I don't necessarily want to see my vacation photos posted on flashes/instagram or posts on the forums I mentioned earlier arriving in the same place.
Anyway, transparency yes, but up to a point.
What If Information Became Private?
For now, atproto has no concept of private data. But that could change. A new feature is being rolled out with ATProto Spaces.
On paper, it seems promising. It will make it possible to have private information on which I could decide who has access. The use cases we can quickly imagine:
- forums with private sections reserved for members
- native private messages on bluesky (currently private messages are not stored on ATProto)
- member-only content on a blog (Writizzy already handles this case, but by not using atproto precisely)
- private drafts on a blog
etc…
But beware, this is far from sufficient. There is no notion of encryption. Data is private, it's the PDS that will provide access or not to the data but it is stored in clear text. Sure, that limits who has access to the data, but the data exists, accessible to administrators of your PDS.
You could of course host your own PDS, but without encryption I wouldn't make it a safe for sensitive information.
In any case, that doesn't solve a conceptual problem, the fact of associating a handle (your identity) with a bunch of information that shouldn't be mixed.
On the classic Web, we separated our uses through compartmentalization. I created an anonymous Reddit account, a LinkedIn account etc… Here, the promise of portability pushes the opposite effect: a single identity, which brings together all the info on a server (a PDS).
The Solutions?
ATProto is an excellent technical foundation to allow us to build all kinds of decentralized and federated social networks and finally get out of Big Tech.
First we need to wait for some important protocol developments:
- end-to-end encryption on some data. Yes I understand that it's difficult to encrypt Spaces and manage key rotation at each entry/exit, but we could however encrypt DMs between two individuals.
- a mechanism for hiding metadata (for example my news display preferences, my likes, the people I block) like Zero knowledge proof
But maybe the real issue is personal.
What is certain is that atproto, even if it makes it possible to solve the problem of excessive centralization by a private player, should not give us illusions. If it solves the problem of transparency, it doesn't address that of respect for our privacy. I expect more from what it proposes but in any case, the challenge of confidentiality rests with us.
We must put in place a certain form of personal hygiene with respect to these networks by recreating the compartmentalization we had before with a strict separation of identities. Even if it's tempting and encouraged, we must develop the reflex of using multiple identities to separate activities (Public/Professional/Associative etc…). We should have multiple handles. Don't treat the Bluesky login the same way you might have treated the Google login.
Finally, many of us have too easily gotten into the habit of entrusting sensitive information to the internet. Nobody needs to know your date of birth, your location, your marital status and so on. Don't recreate your own panopticon.

No comments yet. Be the first to comment!