upvote
How does this compare to Persona? https://en.wikipedia.org/wiki/Mozilla_Persona
reply
did:web is closer to owning your own identity, this is a central database controlled by an organization

The PLC makes it easy for Bluesky to be a custodian and onboard new users

reply
Sort of.

I like to insist that the PLC Directory collects and distributes updates to highlight how it's different from a database. The latest state of the account is signed by the key that created it, or by a key that succeeded it. The directory can't inject any values, it's just a low-complexity solution for data availability: the "how do I learn about updates" part.

It could decide to hide/reject updates, but then it could just as well be forked and replaced if it did that. If downstream applications decide to get their account updates somewhere else, that's the directory now, without any loss of continuity for the accounts.

You don't get that from a simple database.

One could argue domain registrations, and so did:web, are more of a database controlled by a (large, international) organization than PLC. Plenty of tradeoffs of course.

reply
Data flow: all the internet's creators ----> Jack Dorsey ----> all the internet's consumers

We're all watching the first step of enshittification and thinking "this is fine"

reply
one of the other feature of PLC compared to did:web is that it presents the identity history, but this is also problematic for some people (dead naming and right to be forgotten)

I believe there is work around did web for an extension that would enable verifiable history

reply
IMO perfect is the enemy of good here. If your personal email account you use for literally everything is firstname.lastname@mailprovider then you're already in the same situation. This isn't any worse, but it is strictly better.

You can always create a new identity, I don't think anything has changed there. If you don't want your new identity connected to your old identity, then don't.

The right to be forgotten is whole separate problem. The only hope here, really, is that entropy takes care of it for you. I don't see how a chain of trust system can fundamentally be compatible with the right to be forgotten unless you relax the rules a bit.

reply
Nobody owns a domain name. You rent it, subject to the whims of the registry. Miss a single payment and you loose it forever. Even if you always pay up on time, despite price rises etc, they can still decide to take it away: https://neil.fraser.name/news/2026/09/03/

PLC is imperfect, like every solution to identity so far, but it's a lot better (in terms of ownership / control of your own ID) than DNS.

reply
Doesn't did:web suffer from the same flaw as e-mail on your own domain - not being able to actually own a domain?
reply
it's a shame the way handshake and crypto went, that was an actually great use for blockchain
reply