This will happen one day, and I hope more will follow Sandstorm's path.
This will happen one day, and I hope more will follow Sandstorm's path.
It's what you describe. They're working on it, hopefully to be released some time this year. You upload something, it gets distributed to random nodes on the SAFE network. Minimum of 4 live copies of your data, and if any of them get taken down, another copy is immediately created on another machine. This completely eliminates the need for hosted servers for most types of apps. You can upload any files, including javascript, which means you can essentially run entire SPA and other applications using this network.
I guess what I meant to point out is that the convenience of having a server in a data center is probably pretty significant for most people.
Physically, this is true. But politically, a well-designed personal server ecosystem is more robust than it looks against this attack.
The key is, as Kenton points out, server mobility. The server that's your whole network identity has to be able to migrate easily, even automatically, between hosts public and private.
One way to think about how mobility makes a personal server more private -- even against a global adversary -- is the epidemiological concept of "herd immunity."
For any global network, the percentage of users who demand absolute privacy is small. It works better to host your machine in the cloud. But the costs and pain points of closet hosting are acceptable for this specialty market.
What's not acceptable is a situation in which the pro-privacy users form a small isolated network which can only talk to itself, losing on Metcalfe's law. Instead they need to be externally indistinguishable from normal users. Moreover, they need to be able to switch back and forth from absolute to relative privacy -- cloaking and uncloaking, as it were.
Normal users care only about relative privacy, ie, security against all non-sovereign adversaries. Excellent relative privacy is available from an ordinary data center. "Linode hacks" happen, but less and less often.
But actually, just as the privacy-conscious users can blend into the herd of normal users, the normal users benefit from the small minority of privacy-conscious users.
Any global adversary has to assume that anyone with something to hide has probably hid it already. So cost-effectiveness concerns decrease the adversary's motivation to search in data centers. Why would anyone with anything to hide, not hide it at home? Home searches are much more difficult.
Moreover, most people computing at home probably have nothing at all to hide -- they are just normal people who care about privacy. So as long as they stick up for their digital rights, the global adversary remains politically quite weak.
A related and somewhat more tangible point: Having the majority datacenter users using the _same platform_ with the _same apps_ as the pro-privacy users means that the pro-privacy users will have a much better selection of apps to choose from. Whereas today, non-SaaS apps are rather neglected due to their inability to reach a large userbase, but those non-SaaS apps are the only things the privacy-critical users can use.
I think I've heard of some approaches to conceal the actual algorithm from the computing unit (by obfuscation, or by distributing the actual calculation between multiple units), given that the software we're actively using doesn't do anything secret - and is likely to be a free and open source software, it doesn't make much sense to protect the executable code besides integrity checks.
Otherwise, if we talk about - just for example - a receiving mail server (MDA) that has encrypted mailbox storage like [1], then it really depends on how much mail you receive. For a typical personal mailbox, where the steady rate is less than an email-per-minute (and usual email size is some kilobytes, not megabytes), encryption overhead is negligible. Such server would sleep most of time anyway.
[1]: https://grepular.com/Automatically_Encrypting_all_Incoming_E...