Bluesky 去中心化身份实为伪命题
推荐指数 38.0 NO. 015 · 2026.06.22
发布2026/06/21Score130Comments118
为什么值得看
ATProto 协议中 PDS 运营商持有用户签名密钥和轮换密钥,可完全冒充用户或转移其 DID 身份。这意味着 Bluesky 标榜的"用户拥有数据"在密钥管理层存在根本性设计缺陷,自建 PDS 才是唯一解法。
编辑判断
这个漏洞的本质是 ATProto 把"身份可迁移"偷换成了"身份由用户控制"——就像银行说你随时能转账,但银行保管着你的密码和 U 盾。真正去中心化的做法应该是用户本地持有密钥、PDS 只存加密后的数据副本,类似 Nostr 的客户端签名模型或以太坊账户的私钥自持逻辑。
如果你正在基于 ATProto 做应用,现在就要评估:你的用户能接受自建 PDS 的技术门槛吗?如果不能,你的产品和传统中心化平台的差异化到底在哪里?这个设计缺陷可能让 Bluesky 生态长期停留在"可选去中心化"的暧昧地带,类似 email 协议——理论上任何人能自建服务器,实际上 Gmail 垄断了 90% 用户。
社区反馈
意见分歧 89 条评论
核心争论:Bluesky 是否已失败:技术缺陷 vs 文化突破与活跃用户争议
Probably doesn't matter for the "40M+ users", most of them have churned at this point and growth is negative. This is good critique for the next iteration of open social protocols, but fundamentally atproto did not fail because of technical reasons. The next iteration should make privacy the default
Based on all the traffic and development activity I'm not sure on what basis one would say "failed"
Source? What I see here doesn't look good. https://bluefacts.app/bluesky-user-growth Never mind the pivot to reddit. https://www.cnbc.com/2026/06/04/bluesky-twitter-rival-reddit...