Sandstorm's security track record, and what it means for self-hosting
sandstorm.io
sandstorm.io
I sincerely hope the future is one in which lots of families, people, etc, self host their own "cloud apps" rather than delegating it all to facebook, gmail, etc, and sandstorm looks like it could be a winner here. (Or maybe owncloud, or that thing that HN blogged about a week or two ago, or...)
Given the variety of applications one can host on Sandstorm, it's hard to have an all encompassing 'Sandstorm app'. And for what the core of Sandstorm does, the web interface does it well on mobile.
At present most of our apps are focused on productivity tasks (e.g. real-time collaborative document editing) with I think is the kind of thing people still mostly do on desktops. You can totally open Sandstorm and Etherpad on a phone browser, though, and I commonly do this when demoing it to people.
In any case, we obviously have a lot of work still to do, but I hope that doesn't stop anyone from trying out what we have so far. :)
I tried the grain's url, the "share with others" url, etc...But none work via rocket chat's clients. I did find the following discussion: https://github.com/RocketChat/Rocket.Chat/issues/1352 ...Again, I'm just not understanding what url i can share for my family to use - via for example mobile device - to connect/chat on this grain (whether i kill my browser sessions or not).
Sorry i didn't mean to make this almost a support inquiry. Maybe a simple note displayed upon creation of the grain like the following would help: "Hey, you just created a rocket chat grain, if your users are going to connect using one of rocket chat's clients, they need to enter this following url: xyz12300d64bnfnskdfnfgi3o45titj34.oasis.sandostorm.io/whatever/rocketchat/whatever/2342342r". And you can imagine if you look at your "abandon logs"; how many other users try your service, can't figure out how to connect to it for a particular app (again we're talking typical, non-techie users), and then never come back? Again, my comments are coming from a fan of yours. ;-)
Clicking through it seems like they are saying "security non-events" meaning if you self-hosted an app yourself you would have been vulnerable, but because you managed the app through Sandstorm, you were never vulnerable. This is definitely very interesting!
This page describes individual CVEs and how they were mitigated: https://docs.sandstorm.io/en/latest/using/security-non-event...
This page has a more general overview of the concept: https://sandstorm.io/how-it-works
(It's funny how many people initially react to this idea with something like: "How is that not obviously wrong?" Guess what? It works. And no, it's not inefficient -- our managed hosting service runs a healthy profit margin.)
But I 100% agree with your premise, providing dependable security (even at a reduced functional footprint) is a key deliverable for Sandstorm and adds tremendous value to the platform. I assume you have found that adoption is hindered significantly by people "nervous" to try it? The premise is if you can make Sandstorm feel more safe, easy, reliable, it could it become mainstream. So security benefits are a huge bonus.
It also looks like the Sandstorm authentication design has really paid off. I think it's part of the initial complexity of evaluating your system, which is unfortunate, but it's great to see it providing real-world protection for a lot of your apps.
For apps like Etherpad, on the other hand, Sandstorm has blocked several serious security vulnerabilities with zero loss in functionality -- in fact, Etherpad on Sandstorm has more robust sharing / access control than Etherpad stand-alone. :)
I see you have an App Market -- is anyone selling apps for Sandstorm, or are they all free? If there was a way to monetize, I'm surprised someone wouldn't invest the time to make Wordpress support comments and then sell it on your market?
To me this is a really interesting monetization model... can a few small developers write a Sandstorm app which potentially 1M+ users could one day be deploying and self hosting, while charging some nominal annual fee to fund the development?
When I saw the YC W16 startup on the front page a few days ago selling the pretty box to enterprises who wanted to self-host, first thing I thought of was Sandstorm. Why sell hardware? You are making the platform which makes managing the apps possible for 90% of businesses, that has to be where the value is.
It's natural to wonder why everyone isn't doing it, if it's this easy. Or where the innovative part lies. Whenever someone claims a major advance, some skepticism is probably correct.
Sandstorm just took this well understood security model and the innovative storage abstraction and applied it to any language with Cap'N Proto bindings. Pretty cool.
The reason most people aren't doing it is beacuse most people don't really understand capability security, despite its simplicity. They've been raised and trained in the access control list model and it's deeply ingrained at this point.