This author speaks to me!

> it should just be called “private data”

> the resulting design looks very hard to build on

> Private and public data are basically identical. ... The permission is world-read

Way back before Bluesky decided on their own what permissioned data would look like, when the Atmosphere Private Data WG still thought they had a say in the design, I gave a talk on a ReBAC/Zanzibar style system that aligns with what I think the author is looking for.

https://www.youtube.com/watch?v=oYKA85oZc8U&t=3730s

I suppose we could still build on and run a fork like mine if enough people wanted a more robust IAM system. There are some fundamental issues that I am not sure are resolvable without building them into the protocol core from the start. I have personally given up because of the leadership and am waiting/pondering the next protocol. Another design constraint I'd like to see is incentivizing apps to be federated and installable at the PDS as well as incentivizing small social over public square modalities.

https://github.com/verdverm/atproto

My statement is not super constructive, but yes, I also really liked this article. Local-first, privacy, even the example of managing personal restaurant reviews.

I don't have enough meaningful thoughts here to contribute, but you & OP: I hope we can build a federated protocol for sharing stuff again.

btw, for historical context, the reason it is called "permissioned" instead of "private" is because there were sufficient people in the atmo that were very opinionated the E2EE is the only true private. It became an exercise in bikeshedding every time "private data" came up.

You can find the discussions here: https://discourse.atmosphere.community/tag/private-data/2