Minimal web-of-trust governance for did:plc #4002
Replies: 3 comments 2 replies
|
Similar ideas explored by @ngerakines here: https://bsky.app/profile/ngerakines.me/post/3lsmypfzmnc2g
I’ll close this thread once Nick & co. have opened a new one, since I lack a deep enough understanding of the DID space to avoid certain phrasings and misplaced concepts that could easily derail the conversation. |
|
Huzzah! 🎉 https://bsky.app/profile/bnewbold.net/post/3lz6kko5bnc2l https://docs.bsky.app/blog/plc-directory-org
I still think a multi-org setup would be well worth exploring as a continuation of this critical first step, and Bryan has already alluded to some such possibilities here: |
|
Talking to someone from NLnet at public spaces conference they still see the foundation in Switzerland as centralized under the control of Bluesky PBC. I support all initiatives toward removing a single point of failure for the plc directory. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
It’s been nearly a year since this foundational discussion about proper PLC governance:
https://atprotocol.dev/bluesky-and-did-plc/
I’ve touched on this subject a couple times before..
#2821
#2705 (reply in thread)
..but I’ll try to clarify what seems to me like a minimum-viable v1 of a sufficiently co-operated (distributed) PLC directory, with mainly social rather than digital technology.
To get us started, Bluesky could make a rigid federation (hand-picked & limited) of a few ‘trusted’ alt-PLC directories for the first 6-12 months. They all agree to point to each other as equally valid record-holders.
Bluesky starts as the sole arbiter of additional PLC keepers, but over time this group will be socially pressured by the public to establish a pluralistic governance model.
Every alt-directory would be approved via Bluesky as a valid PLC operator. These should be institutions-of-service; that is, institutions that are no strangers to web-infrastructure servicing.
So in the US, maybe Let’s Encrypt would make a good first partner. In the EU, the first such institution that comes to mind is https://nlnetlabs.nl/
As for some companies to partner with, email companies pair very well with atproto-oauth (and the PLC that comes with it), since it gives them the same OAuth magic as Gmail and its Google Login.
So..
Openly run companies like that.
Let’s say all those five orgs agree to participate as long-term-reliable PLC directories. Then we’d have a bunch of mirrors like this:
did:plc(bsky)did:plc(letsencrypt)did:plc(nlnetlabs)did:plc(proton)did:plc(mozilla)did:plc(iroco)It’d even be fine if all the alts would effectively have to register new PLC identities through Bluesky in the first iteration of this. So a bsky plc is always generated for new atproto signups, but a small cohort of pre-approved partner institutions can be relied upon for seamless storage of backup/rotation keys.
I think this is the best way to grow the atproto network to >100M participants, namely by commodifying the great atproto complement that is the PLC-based identity.
In summary. I just wanted to convey that:
All reactions