• gandalf_der_13te@feddit.org
    link
    fedilink
    arrow-up
    13
    ·
    20 hours ago

    bluesky (or rather the underlying protocol, ATProto) is not actually decentralized. all public identity keys (signature keys) reside with a single entity (some non-profit organization in switzerland, PLC). if they get hacked, the hackers can forge any identity they want to.

    only the messages and media files are stored decentralized, and the user profile personal information (profile picture, bio, etc). but not the crucial signature keys.