Who Owns Your ATProto Identity? Hint: It's Probably Not You

A security analysis of the ATProto protocol reveals that Personal Data Server (PDS) operators hold significant control over user identities and signing keys. This centralization risk allows operators to impersonate users across multiple decentralized applications.
Why it matters
The findings challenge the assumption that decentralized protocols inherently protect user autonomy, highlighting critical security vulnerabilities in current implementations.
After writing my previous article about Bluesky's centralization risks, I got into the weeds on how the PDS (Personal Data Server) works. The more I looked at it, the worse it got. I was originally worried about Bluesky going rogue and deleting accounts or locking people in. It's actually the least scary thing your PDS operator can do to you.
The article provides a technical critique of a protocol's architecture rather than a political or social argument.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in