<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kevinak</title><link>https://news.ycombinator.com/user?id=kevinak</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 26 Sep 2026 02:36:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kevinak" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Twinkleplop – plop some twinkle in your code (ultrafast syntax highlighting)]]></title><description><![CDATA[
<p>Article URL: <a href="https://twinkleplop.pngwn.at/">https://twinkleplop.pngwn.at/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49804730">https://news.ycombinator.com/item?id=49804730</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 22 Sep 2026 17:16:12 +0000</pubDate><link>https://twinkleplop.pngwn.at/</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=49804730</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49804730</guid></item><item><title><![CDATA[Tablinum – Local-first database for the browser]]></title><description><![CDATA[
<p>Article URL: <a href="https://tablinum.dev/">https://tablinum.dev/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49437847">https://news.ycombinator.com/item?id=49437847</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 25 Aug 2026 17:49:51 +0000</pubDate><link>https://tablinum.dev/</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=49437847</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49437847</guid></item><item><title><![CDATA[New comment by kevinak in "Show HN: Bramble – Local-first password manager"]]></title><description><![CDATA[
<p>Very cool! I like it!<p>What about using Nostr relays to also back up your data passwords? I built a library called Tablinum around this idea. Local first but backed up to Nostr relays using NIP-59 gift wrapped events.<p><a href="https://tablinum.dev" rel="nofollow">https://tablinum.dev</a></p>
]]></description><pubDate>Fri, 03 Jul 2026 22:23:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48780719</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48780719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48780719</guid></item><item><title><![CDATA[New comment by kevinak in "We moved our Bluesky data to Eurosky"]]></title><description><![CDATA[
<p>That's a lot of information about something that does not really matter in practice. It's not until ew get to the very end of your comment that we get to the actually relevant part for the discussion.<p>> So let's talk in practice: when you sign up for Bluesky, they store the private key for you. This way, for users that don't care about any of these details, they do not have to think about it at all. It's saved with the rest of your account data, you don't have to worry about backups or anything.<p>> However, at any time, any user can register a rotation key with the PLC directory. To do this, you generate a new public and private key, and then store that private key wherever you'd like. All the usual caveats here apply. You can then use your existing private key to add this new public key to your account. Once you do that, it shows up in your DID document as a rotation key. You can use that rotation key to add more keys, remove the Bluesky owned keypair, whatever you want. Now it's not stored by Bluesky.<p>> The majority of users have not done this, it's true. But they can. Whenever they'd like.<p>The Bluesky PDS stores (and has access to!) your private keys. They are in full control of your identity. It just so happens that 99.99% of users are on the Bluesky PDSs AND 99.99% of users will choose the path of least resistance and in practice NEVER register an external rotation key. This is exactly the problem. It is massively centralized and a rug pull from Bluesky would effectively just kill off the network.<p>It's insane that this is just hand-waved away because "you can just self-host" or "you can just register an external rotation key". If you think users will actually do this I have a bridge to sell you.</p>
]]></description><pubDate>Wed, 01 Jul 2026 10:57:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48744849</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48744849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48744849</guid></item><item><title><![CDATA[New comment by kevinak in "We moved our Bluesky data to Eurosky"]]></title><description><![CDATA[
<p>Where are your rotation and signing keys stored? Who can access them? Talking here about the majority case.</p>
]]></description><pubDate>Tue, 30 Jun 2026 20:37:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48738846</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48738846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48738846</guid></item><item><title><![CDATA[New comment by kevinak in "We moved our Bluesky data to Eurosky"]]></title><description><![CDATA[
<p>Nope. When I’m talking about identity I’m speaking strictly of the keys that sign your messages and the pub key derived from it. In every other cryptographic system that is your identity. It is absolutely correct that the PDS has complete control over your keys when it comes to 99.99% of users. I challenge you to prove the opposite.</p>
]]></description><pubDate>Tue, 30 Jun 2026 19:47:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48738260</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48738260</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48738260</guid></item><item><title><![CDATA[New comment by kevinak in "We moved our Bluesky data to Eurosky"]]></title><description><![CDATA[
<p>That’s a very narrow definition of decentralisation. In any case - both atproto and fediverse are massively centralised compared to something like Nostr, and it’s not even close.<p>The fact that the PDS in practice owns your identity in the vast vast majority of cases is such a dumb trade off that it’s honestly laughable. Should Bluesky decide to splinter off of the network there would be like 50000 people left.<p>Stop telling people that it’s decentralised in any meaningful way and be honest about it instead. That’s the issue. The dishonesty and tricking users.</p>
]]></description><pubDate>Tue, 30 Jun 2026 17:46:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48736390</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48736390</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48736390</guid></item><item><title><![CDATA[New comment by kevinak in "We moved our Bluesky data to Eurosky"]]></title><description><![CDATA[
<p>You won’t have decentralisation on Atproto because the protocol itself incentivises centralisation.</p>
]]></description><pubDate>Tue, 30 Jun 2026 16:33:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48735193</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48735193</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48735193</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>The end of the article explains why this isn’t necessarily better than a centralised service. Yes - you can self host but no one (yes, there a few exceptions) does in practice. Your PDS host can pretend to be you on any atproto application.</p>
]]></description><pubDate>Sun, 21 Jun 2026 21:08:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48622610</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48622610</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48622610</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>The point of the article is that 99.9% of users will not take custodial control of their identity - not that they can’t.</p>
]]></description><pubDate>Sun, 21 Jun 2026 20:27:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48622308</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48622308</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48622308</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>Yes - the trade off is centralisation.</p>
]]></description><pubDate>Sun, 21 Jun 2026 20:10:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48622180</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48622180</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48622180</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>Atproto is not decentralised, it’s faux decentralised. You can technically be sovereign, but incentives and the way things have been done results in massive centralisation - 99.9% of users are on a Bluesky PDS and have not registered a higher priority rotation key. And they won’t, ever, because that’s how humans work.<p>The day Bluesky decides to enshittify there’s a very real possibility that they might also just stop allowing people to extract their keys and splinter off the network. The enshitification begins when VCs turn upp the heat it they start getting low on cash.</p>
]]></description><pubDate>Sun, 21 Jun 2026 20:09:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48622168</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48622168</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48622168</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>It’s great that tings like this exist but as long as this is how identities work on ATProto it’s unfortunately going to be a niche thing.</p>
]]></description><pubDate>Sun, 21 Jun 2026 19:59:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48622076</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48622076</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48622076</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>You can just read the documentation: <a href="https://atproto.com/guides/overview#account-portability" rel="nofollow">https://atproto.com/guides/overview#account-portability</a><p>“The signing key is entrusted to the PDS so that it can manage the user's data, but rotation keys can be controlled by the user, e.g. as a paper key. This makes it possible for the user to update their account to a new PDS without the original host's help.”</p>
]]></description><pubDate>Sun, 21 Jun 2026 19:27:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48621811</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48621811</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48621811</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>Yes you can but the vast majority don’t, and that is what matters. When Bluesky goes rogue because of profitability issues or VC pressure, the vast vast majority of users lose their identities on the wider network. Users will choose the path of least resistance. It’s all about incentives.</p>
]]></description><pubDate>Sun, 21 Jun 2026 19:21:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48621773</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48621773</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48621773</guid></item><item><title><![CDATA[New comment by kevinak in "Who owns your ATProto identity?"]]></title><description><![CDATA[
<p>Correct, but it’s not decentralized in any meaningful way, which is what a lot of ATProto proponents want you to believe.<p>No one (not literally of course) self hosts their PDS. Like 99.9%, if not more, are using the Bluesky PDSes.</p>
]]></description><pubDate>Sun, 21 Jun 2026 19:17:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48621742</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48621742</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48621742</guid></item><item><title><![CDATA[Who owns your ATProto identity?]]></title><description><![CDATA[
<p>Article URL: <a href="https://kevinak.se/blog/who-actually-owns-your-atproto-identity-hint-its-probably-not-you">https://kevinak.se/blog/who-actually-owns-your-atproto-identity-hint-its-probably-not-you</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48619140">https://news.ycombinator.com/item?id=48619140</a></p>
<p>Points: 171</p>
<p># Comments: 152</p>
]]></description><pubDate>Sun, 21 Jun 2026 14:09:07 +0000</pubDate><link>https://kevinak.se/blog/who-actually-owns-your-atproto-identity-hint-its-probably-not-you</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=48619140</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48619140</guid></item><item><title><![CDATA[New comment by kevinak in "Penguin 'Toxicologists' Find PFAS Chemicals in Remote Patagonia"]]></title><description><![CDATA[
<p>Looking at the studies on the site I’m only seeing comparisons vs placebo and activated charcoal - why not compare to non modified regular beta glucan that is in most oats?</p>
]]></description><pubDate>Sat, 11 Apr 2026 09:16:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=47728937</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=47728937</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47728937</guid></item><item><title><![CDATA[New comment by kevinak in "I'm betting on ATProto"]]></title><description><![CDATA[
<p>Not parent but I wrote an article about how PDSs (the thing that hosts your data) control your signing and rotation keys. It's technically possible to self-host but as always, the default becomes the norm. 99.999% of users on ATProto host their data on BlueSky servers.<p><a href="https://kevinak.se/blog/who-actually-owns-your-atproto-identity-hint-its-probably-not-you" rel="nofollow">https://kevinak.se/blog/who-actually-owns-your-atproto-ident...</a></p>
]]></description><pubDate>Wed, 01 Apr 2026 19:57:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47605737</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=47605737</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47605737</guid></item><item><title><![CDATA[New comment by kevinak in "Colibri – chat platform built on the AT Protocol for communities big and small"]]></title><description><![CDATA[
<p>There is - <a href="https://flotilla.social/" rel="nofollow">https://flotilla.social/</a></p>
]]></description><pubDate>Sun, 29 Mar 2026 12:04:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47562436</link><dc:creator>kevinak</dc:creator><comments>https://news.ycombinator.com/item?id=47562436</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47562436</guid></item></channel></rss>