Who Owns Your ATProto Identity?
ATProto identity system raises security concerns

The ATProto identity system has been found to have a significant flaw, allowing Personal Data Server (PDS) operators to impersonate users across multiple applications. This is because the PDS holds the user's signing key, which is used to authenticate all activity on the platform. As a result, if a PDS operator is compromised or malicious, they can post, like, and follow on behalf of the user, and even lock them out of their own identity. ## What happened The ATProto identity system was designed to provide a decentralized and portable way for users to manage their online identities. However, the system's reliance on PDS operators to manage user signing keys has created a significant security vulnerability. According to research, a PDS operator can impersonate a user across multiple applications, including social media, git repositories, and blogs. This is because the PDS operator has access to the user's signing key, which is used to authenticate all activity on the platform. The researcher found that the system's design allows PDS operators to have significant control over user identities, posing a major security risk. The issue is not limited to a single application, but rather affects the entire ATProto ecosystem. ## Why it matters The ATProto identity system's security vulnerability has significant implications for users and developers. If a PDS operator is compromised or malicious, they can cause significant harm to users, including impersonating them, locking them out of their own identities, and even stealing their data. The issue also highlights the risks of relying on a single entity to manage user identities, rather than using a more decentralized approach. The researcher notes that the system's design trades convenience for sovereignty, making it brittle and vulnerable to attack.
- Decentralized identity management
- Portable identities across applications
- End-to-end encryption
- PDS operators have significant control over user identities
- Security vulnerability allows for impersonation and identity theft
- Risk of data loss and compromise
What is the ATProto identity system?+
What is the security vulnerability in the ATProto identity system?+
How can users protect themselves from the security vulnerability?+
- security·3 min readAnthropic to Require ID Verification for Certain Capabilities
Anthropic requires ID verification for some users starting July 8.
- security·2 min readForcing Real ID for Internet Traffic
New ID rules for US air travel
- security·3 min readUS Government Suspends Access to Fable 5 and Mythos 5
The US government has issued an export control directive to suspend access to Fable 5 and Mythos 5, citing national security concerns and a potential jailbreak method