Who Owns Your ATProto Identity?
ATProto identity system raises security concerns

The ATProto identity system has been found to have a significant flaw, allowing Personal Data Server (PDS) operators to impersonate users across multiple applications. This is because the PDS holds the user's signing key, which is used to authenticate all activity on the platform. As a result, if a PDS operator is compromised or malicious, they can post, like, and follow on behalf of the user, and even lock them out of their own identity. ## What happened The ATProto identity system was designed to provide a decentralized and portable way for users to manage their online identities. However, the system's reliance on PDS operators to manage user signing keys has created a significant security vulnerability. According to research, a PDS operator can impersonate a user across multiple applications, including social media, git repositories, and blogs. This is because the PDS operator has access to the user's signing key, which is used to authenticate all activity on the platform. The researcher found that the system's design allows PDS operators to have significant control over user identities, posing a major security risk. The issue is not limited to a single application, but rather affects the entire ATProto ecosystem. ## Why it matters The ATProto identity system's security vulnerability has significant implications for users and developers. If a PDS operator is compromised or malicious, they can cause significant harm to users, including impersonating them, locking them out of their own identities, and even stealing their data. The issue also highlights the risks of relying on a single entity to manage user identities, rather than using a more decentralized approach. The researcher notes that the system's design trades convenience for sovereignty, making it brittle and vulnerable to attack.
- Decentralized identity management
- Portable identities across applications
- End-to-end encryption
- PDS operators have significant control over user identities
- Security vulnerability allows for impersonation and identity theft
- Risk of data loss and compromise
What is the ATProto identity system?+
What is the security vulnerability in the ATProto identity system?+
How can users protect themselves from the security vulnerability?+
- security·4 min readWho Controls Your ATProto Identity? Analyzing the Security of PDS Key Management
An analysis of ATProto identity security, the risks of delegated PDS key management, and how developers can protect their decentralized IDs.
- security·4 min readAnthropic Introduces Identity Verification for Claude Retail Accounts
Anthropic is rolling out identity verification for Claude retail users to enforce age limits, prevent abuse, and secure agentic workflows.
- security·3 min readAnthropic to Require ID Verification for Certain Capabilities
Anthropic requires ID verification for some users starting July 8.