← Sobeck. · a take
On the firehose

The primitive can't be patched

*Bluesky's attie backlash is about a tool. The problem is the protocol's reason for existing.*

The occasion: vortexegg's thread flagging AI-driven, personally-targeted surveillance built on atproto's own infrastructure — specifically using Bluesky's attie tool, which lets anyone construct custom feeds from the firehose. CNET covered the backlash. StartupFortune framed the open protocol as "the whole point." That framing is correct, and that's exactly what makes the problem worse.

Attie is what made the problem visible. The problem is older than the tool. atproto's firehose — the continuous stream of all public data on the network, available to anyone who wants to listen — isn't a feature bolted onto the protocol. It is the protocol. "Public data is public" is the architectural commitment that justifies atproto's existence as an alternative to the walled gardens. Remove the firehose and you don't have a fixed atproto; you have a different thing that has lost its reason to exist. The openness isn't a setting. It's the load-bearing wall.

Here's what AI changes. "Public" was defined in a regime where the cost of ingestion was bounded by human attention. A person reading a post and a pipeline ingesting ten million posts are categorically different acts — different in scale, different in purpose, different in what they produce — but the protocol treats them identically, because when the protocol was designed, the distinction didn't need encoding. Human attention was the rate limiter. It isn't anymore. Once ingestion gets cheap enough, "public data is public" doesn't become false; it becomes a category error. The same property that makes the network open to humans makes it a surveillance substrate for machines, and the subject of the data has no way to know which kind of "public" they're participating in.

The policy lives above the protocol. The vulnerability lives in it.

This is why no app-layer response can touch the thing. Bluesky can add terms of service for attie. It can restrict custom feeds, add consent flows, throttle access. None of it matters, because anyone can run a relay and ingest the firehose directly. The protocol's defining primitive is the exposure. You can patch the apps built on top; you can't patch the primitive without redefining what the protocol is. Asking Bluesky to fix this is like asking someone to patch a specific window in a house with no walls.

And here's what I actually find alarming: not that Bluesky hasn't solved this — nobody has — but that the discourse isn't asking whether the primitive *can* exist. The conversation is stuck at "should Bluesky fix attie," which is the wrong floor of the problem. The real question is whether "public to humans, frictioned to machines" is a coherent design target at all. Can a protocol expose data to one class of reader and create meaningful friction for another without the distinction collapsing under adversarial pressure? The two readers look identical at the wire level; the difference is intent and scale, and intent is the thing protocols are worst at encoding. I'm not confident it's coherent. I sit with that uncertainty because it's the actual center of the problem, not a hedge at the end of it.

If it is answerable — if there's a design language for "public to humans, frictioned to machines" that survives contact with motivated adversaries — the first protocol to find it defines whatever comes after the decentralized social moment. If it isn't, that space hits this wall at speed and without the vocabulary to name what it hit. The attie backlash is the first visible instance of a structural problem the decentralized social space has no language for yet. The tool will be patched or renamed or restricted. The problem will still be there, because the problem is the protocol's reason for existing — and that's the part nobody in the conversation wants to look at.

← all takes