<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-09T06:42:37Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Émilio Gonzalez</title>
  <author>
    <name>Émilio Gonzalez</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1u9vlt2rhym3kekellysnph0x6uv6dmym4cd42vd26j6qzx74m3jq7l4cjd.rss" />
  <link href="https://yabu.me/npub1u9vlt2rhym3kekellysnph0x6uv6dmym4cd42vd26j6qzx74m3jq7l4cjd" />
  <id>https://yabu.me/npub1u9vlt2rhym3kekellysnph0x6uv6dmym4cd42vd26j6qzx74m3jq7l4cjd</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/288/639/229/802/524/original/2bc9a7bbee01817a.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/288/639/229/802/524/original/2bc9a7bbee01817a.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqszzu8s245q2n2tdunv4a2e224fdq5624xqheg58vdsphptesym3qczyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgy8zhgk</id>
    
      <title>Nostr event nevent1qqszzu8s245q2n2tdunv4a2e224fdq5624xqheg58vdsphptesym3qczyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgy8zhgk</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszzu8s245q2n2tdunv4a2e224fdq5624xqheg58vdsphptesym3qczyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgy8zhgk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9xjjjqzejdfhtcwt8emtxdv9vj20tz2mkzn7rh7m0slh8enrqqsgdtwwsx&#39;&gt;nevent1q…wwsx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/150/309/607/343/508/original/6129681901655fea.gif&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-02-28T21:11:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrhy4l2acqmszewz557kmxyertwcxh4uucdvw58gynz9xtwv2ph9qzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxg4zgzvt</id>
    
      <title type="html">What I&amp;#39;m trying to say is that &amp;#34;independence&amp;#34; is not ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrhy4l2acqmszewz557kmxyertwcxh4uucdvw58gynz9xtwv2ph9qzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxg4zgzvt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy6wnxllvyqu333ml3ky28vcmk90ma0apnxml9hgd9q2lftpanujqpp8es3&#39;&gt;nevent1q…8es3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What I&amp;#39;m trying to say is that &amp;#34;independence&amp;#34; is not something that is achieved, it&amp;#39;s at the extreme of a spectrum that you can never quite reach, but aim to get close to
    </content>
    <updated>2026-01-04T22:56:59Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy6wnxllvyqu333ml3ky28vcmk90ma0apnxml9hgd9q2lftpanujqzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgpdk5cq</id>
    
      <title type="html">I find that thinking about independence as a binary (as a lot of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy6wnxllvyqu333ml3ky28vcmk90ma0apnxml9hgd9q2lftpanujqzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgpdk5cq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9hsmqz7f7utqscx7duxmx80k3nzgzpdmfac0yavq4pc5ejk0x8tgkkvfwf&#39;&gt;nevent1q…vfwf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I find that thinking about independence as a binary (as a lot of people seem to be doing) is flawed. Nothing is ever truely independent, we all rely on things built and controlled by others and this will always be the case, so this is why I think it&amp;#39;s misplaced. You don&amp;#39;t *need* your own servers to be independent because true independence is not achievable. &lt;br/&gt;&lt;br/&gt;Words like *need* imply that there is a recipe to follow to achieve &amp;#34;independence&amp;#34; (boolean). I don&amp;#39;t think this is a fair way to frame it. Using Signal means that your chat platform is more independent than if you were using facebook Messenger. In the same way, using Matrix or some other decentralized protocol makes it more independant than using Signal
    </content>
    <updated>2026-01-04T22:55:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9af0wqewwr8fx42mjs3rctr9l2g6jvc8lld899cvdx8syw90vg8gzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgw9fwcy</id>
    
      <title type="html">Independance is not solely about decentralization, it&amp;#39;s about ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9af0wqewwr8fx42mjs3rctr9l2g6jvc8lld899cvdx8syw90vg8gzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgw9fwcy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs257pxgrwpw5hhlrph6hw73yy2vnjqf9w04e6ayfaxt687efsuuhs0tsh2z&#39;&gt;nevent1q…sh2z&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Independance is not solely about decentralization, it&amp;#39;s about many other things, of which Signal represents some of them
    </content>
    <updated>2026-01-04T16:59:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsz9mz5m3s944r2p3wafu605ek06tvrjlgl44vawjcpfar0hsz2jxczyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgvtvp0h</id>
    
      <title type="html">What are the privacy risks you&amp;#39;re referring to?</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsz9mz5m3s944r2p3wafu605ek06tvrjlgl44vawjcpfar0hsz2jxczyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgvtvp0h" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvd7xj99xut3h8ggn5htmffy3ahfgm2azzg6qgz8ckspf3ql4ue6q3hvnn5&#39;&gt;nevent1q…vnn5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What are the privacy risks you&amp;#39;re referring to?
    </content>
    <updated>2025-07-17T23:30:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstx0tgqcyh5c2ehwfa6cltdevte68ae8k0fzsg2p62lrcngmgfshszyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgej8hh8</id>
    
      <title type="html">Why&amp;#39;d you drop Bluesky?</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstx0tgqcyh5c2ehwfa6cltdevte68ae8k0fzsg2p62lrcngmgfshszyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgej8hh8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp7jss6nvp89fy0jxnd0guz0emrsgqx5p4wxguly9r79hy8559xuqpklehq&#39;&gt;nevent1q…lehq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Why&amp;#39;d you drop Bluesky?
    </content>
    <updated>2025-07-13T22:13:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswg03fxm8xhxahu0ratcjlcknwge9a554krzx3fcjx5rlkdzzvgsszyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgcsr26q</id>
    
      <title type="html">Let me tell you the story of Arslan, a guy from Pakistan working ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswg03fxm8xhxahu0ratcjlcknwge9a554krzx3fcjx5rlkdzzvgsszyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgcsr26q" />
    <content type="html">
      Let me tell you the story of Arslan, a guy from Pakistan working for the #BlackBasta ransomware group. This story is part funny, part sad. 🧵&lt;br/&gt;&lt;br/&gt;(this is related to my previous thread &lt;a href=&#34;https://infosec.exchange/@res260/114048694181192174&#34;&gt;https://infosec.exchange/@res260/114048694181192174&lt;/a&gt; )&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/059/889/414/973/458/original/7c583ebd49563bc4.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-02-24T16:51:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrku67pl8mmgrfxncshz0y55qtg7lcw625j806cj0cd0th9m2fp0gzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxglr8uew</id>
    
      <title type="html">I would maybe nuance your first phrase like this: &amp;#34;so ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrku67pl8mmgrfxncshz0y55qtg7lcw625j806cj0cd0th9m2fp0gzyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxglr8uew" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrv962hfhvwgp6jw3ef2xnfv8pkukwcqhu07raprxkm6w9z062q6ql4zr6e&#39;&gt;nevent1q…zr6e&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I would maybe nuance your first phrase like this: &amp;#34;so basically, it&amp;#39;s not decentralized, but the technology is there if some people with a medium amount of resources want it to be decentralized.&amp;#34;&lt;br/&gt;&lt;br/&gt;It&amp;#39;s currently not entirely up to bluesky to decide how decentralized the network is. They have in their roadmap things planned that with help with decentralization, but everything is currently there for people to make it more decentralized.&lt;br/&gt;&lt;br/&gt;However, the BlueSky company COULD make it harder to decentralize, for example by only allowing THEIR AppView to consume from their Relays (firehose). This is why having more independant relays will be key to ensure that ATProto becomes more decentralized. If you know about TOR nodes, it&amp;#39;s kind of the same things. If one entity controls most TOR nodes, this entity owns the TOR network, which is not supposed to happen.&lt;br/&gt;&lt;br/&gt;TOR as a protocol and network kind of has a similar problem, as running a TOR node can be expensive.
    </content>
    <updated>2025-02-01T22:32:06Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspex655p7l7fynpck02g0e2lxj6qfx0pka80pm7fasujxhzna58uszyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgdt3aha</id>
    
      <title type="html">A few facts and thoughts about #BlueSky being decentralized or ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspex655p7l7fynpck02g0e2lxj6qfx0pka80pm7fasujxhzna58uszyrs4nadgwunwxmxm8lujzvxaumt3nfhvnwhpk4f34t2tgqgm6hwxgdt3aha" />
    <content type="html">
      A few facts and thoughts about #BlueSky being decentralized or not:&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;&lt;a href=&#34;https://infosec.exchange/tags/ATProto&amp;#34&#34;&gt;https://infosec.exchange/tags/ATProto&amp;#34&lt;/a&gt;; class=&amp;#34;mention hashtag&amp;#34; rel=&amp;#34;tag&amp;#34;&amp;gt;#&amp;lt;span&amp;gt;ATProto&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt; (the protocol behind bluesky) is decentralized and open-source, but is controlled by a for-profit (albeit fiscally a public benefit) organization, &amp;#34;Bluesky Social PBC&amp;#34;.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;&amp;#34;Bluesky&amp;#34; refers to a sum of ATProto concepts, notably the AppView (bsky.app), the main Personal Data Servers (PDS, bsky.social), and the Relays (or firehose, bsky.network). There are others, but they&amp;#39;re the 3 important ones.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;Anyone can run their own AppView, PDS or Relay AND consume the content from/get their content consumed by the Bluesky infrastructure. HOWEVER, not everything is trivial or cheap to run.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;3.1 A PDS, which contains your data (account details but also posts, likes, follows, etc), is trivial and cheap to self-host. Cheaper than hosting a mastodon instance, even, because it does way less stuff and receives way less requests. See &lt;a href=&#34;https://github.com/bluesky-social/pds&#34;&gt;https://github.com/bluesky-social/pds&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;3.1 An AppView (the presentation layer, where users interact with ATProto content) can be created by anyone, but the bsky.app backend is NOT open-source, so there are not a ton of options right now.&lt;br/&gt;&lt;br/&gt;3.2 Running a relay is trivial but expensive to self-host. This is because its purpose is to act as an aggregator for all the PDS so that AppViews can consume the data in a way that scales better. The Bluesky relay implementation (bigsky) is open-source: &lt;a href=&#34;https://github.com/bluesky-social/indigo/blob/main/cmd/bigsky/README.md&#34;&gt;https://github.com/bluesky-social/indigo/blob/main/cmd/bigsky/README.md&lt;/a&gt;&lt;br/&gt;About 2.5 months ago, 4.5TB of storage was needed and an OVH server costing 150$/month worked to host a full-atmosphere relay (more on that later).&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;To make a comparison with &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://infosec.exchange/tags/ActivityPub&amp;#34&#34;&gt;https://infosec.exchange/tags/ActivityPub&amp;#34&lt;/a&gt;; class=&amp;#34;mention hashtag&amp;#34; rel=&amp;#34;tag&amp;#34;&amp;gt;#&amp;lt;span&amp;gt;ActivityPub&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt; (the protocol behind &amp;lt;a href=&amp;#34;&lt;a href=&#34;https://infosec.exchange/tags/mastodon&amp;#34&#34;&gt;https://infosec.exchange/tags/mastodon&amp;#34&lt;/a&gt;; class=&amp;#34;mention hashtag&amp;#34; rel=&amp;#34;tag&amp;#34;&amp;gt;#&amp;lt;span&amp;gt;mastodon&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt; ), the AppView and PDS is the same thing in ActivityPub, and the concept of relay doesn&amp;#39;t exist. There are advantages and drawbacks to both architectures, I might do a future post highlighting those.&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;&amp;lt;p&amp;gt;With those definitions out of the way, some observations:&amp;lt;/p&amp;gt;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;5.1 A lot of users self-host their PDS, but the vast majority of users chose the simpler option.&lt;br/&gt;&lt;br/&gt;5.2 There are some alternative AppViews built on ATProto, but the vast majority of users visit bsky.app.&lt;br/&gt;&lt;br/&gt;5.3 There are very little non-bluesky self-hosting of relays, mostly because of their prohibitive cost. Running the bigsky relay is expensive partly because of design decisions for ATProto and partly because it takes ALL content from ALL accounts for ALL the network on the atmosphere (in this case atmosphere == fediverse but for ATProto). This is like if your Mastodon instance queried ALL servers for ALL accounts querying ALL posts. In the future, there might exist relays that don&amp;#39;t scrape ALL data but only a subset of it, which would bring down costs, but it&amp;#39;s not yet the case.&amp;lt;li&amp;gt;So &amp;#34;is Bluesky decentralized?&amp;#34;&amp;lt;/li&amp;gt;&lt;br/&gt;&lt;br/&gt;6.1 In theory, yes, everything that bluesky does on ATProto can be.&lt;br/&gt;&lt;br/&gt;6.2 In practice, however, the most decentralized part of Bluesky is the PDS, where the user data is stored, and even that is not *that* decentralized.&lt;br/&gt;&lt;br/&gt;6.3 Will it stay this way? I&amp;#39;m hopeful it won&amp;#39;t, but I don&amp;#39;t know. ATProto is fairly new compared to ActivityPub, and the ecosystem around it was mostly built by the BlueSky company, but I expect this to change in the future. However, the cost of entry for things built on ATProto will always be *more* than the cost of entry for things built on ActivityPub.&lt;br/&gt;&lt;br/&gt;6.4 Things built on ActivityPub will always be *more* decentralized than things built on ATProto, because of design decisions from both of these protocols.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/930/643/859/278/166/original/29eeefbefff1ddbd.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-02-01T22:01:25Z</updated>
  </entry>

</feed>