Viral.js – Peer-to-peer web app distribution
pixelscommander.github.io
pixelscommander.github.io
Security : how do you guarantee that a client peer is not tinkering with the code it distributes further?
Unreliable: browsing sessions come and go. Before forwarding the app maybe the browser is already closed..
Bandwidth: nobody loves bandwidth thieves
And so on...
But there's still no way you can make this faster than traditional CDNs (at the minimum you'll need an extra round trip to check for peers). As a matter of fact if my torrenting speed is any indication, it will be abysmally slow.
You probably won't be penny pinching over bandwidth cost when every 100ms of page load time costs you 1% in sales. http://blog.gigaspaces.com/amazon-found-every-100ms-of-laten...
This could be great for a small niche of applications, but even for those, these points are still important.
Particularly on the consumer end, turning my device into a provider as well as a consumer of data is typically not my intention. It's forced seeding on all clients in a torrent sense, which not everyone wants to be a part of. Or for that matter, can be. In a world of data caps, turning my phone, tablet, or hotspot connected devices into a CDN has moral and fiscal implications that have to be considered.
I don't think anyone is going to use this stuff any time soon in production but I do think the general idea is one that a lot of people have thought about and it's nice to see someone take a wack at it.
You could make a system involving digital signatures (EdDSA), but then "how do you trust which public key?" type questions mean this doesn't improve much.
Wilkinson, S. R. & Almeida, J. S. QMachine: commodity supercomputing in web browsers. BMC Bioinformatics 15, 176 (2014).
http://bmcbioinformatics.biomedcentral.com/articles/10.1186/...
"Modern web browsers can now be used as high-performance workstations"
https://github.com/qmachine/qmachine
"QM is an open-sourced, publicly available web service that acts as a messaging system for posting tasks and retrieving results over HTTP. The illustrative application described here distributes the analyses of 20 Streptococcus pneumoniae genomes for shared suffixes. Because all analytical and data retrieval tasks are executed by volunteer machines, few server resources are required. Any modern web browser can submit those tasks and/or volunteer to execute them without installing any extra plugins or programs. A client library provides high-level distribution templates including MapReduce. This stark departure from the current reliance on expensive server hardware running “download and install” software has already gathered substantial community interest, as QM received more than 2.2 million API calls from 87 countries in 12 months."
So for the time you spend (actively) on a website, instead of being shown ads, you "rent" your device's CPU etc in exchange for the content.
We have to wait for fully homomorphic encryption[1] to realize this, or a clever implementation of zero-knowledge proofs. Your proof of concept may work now if you can implement partial homomorphic encryption, perhaps something similar to CryptDB[2] or ZeroDB[3]. I read more about this in a recent Zdnet article that gives a brief summary[4].
[1] https://en.wikipedia.org/wiki/Homomorphic_encryption
[2] https://css.csail.mit.edu/cryptdb/
[4] http://www.zdnet.com/article/encryptions-holy-grail-is-getti...
0. https://www.quora.com/How-is-WebTorrent-different-from-PeerC...
It would be awesome if something existed to use this tool while ensuring users do not modify the files
That should be possible with subresource integrity.
https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Haven't used it, but same premise.
One point i might add to questions of NAT...what if the first types of apps to be distributed this way were games (then later other catgories of apps), and using ipv6? I think that would do 2 things: avoid some (though not all) nat-related issues; and help increase adoption of ipv6 overall. (I suppose my question should not need to be specific to this viral.js.)
And also I agree that there were a lot of problems to work around and benefits are not that obvious if application size is 3 Mb. However it becomes closer to real life with every additional megabyte of application size. E.g. for video content it definitely worth and it also could work for web games and VR experiences. Other cases? Sure there are some. Let`s consider this as first Viral JavaScript implementation.
All I can think of is high resolution porn which is currently not cost effective to be purely ad driven. Or hosting illegal videos/music that you can't really make enough real money off of to pay for server costs.
But definitely not for "distributing web apps" like the author mentioned unless your js is so bloat it is tens of MBs.
Case Study 1: Google Maps and Offline Mode
Alice navigates her iPad to http://maps.google.com and looks up the geography of the city she lives in, Boston. Alice knows that she’s going to be traveling later that day and might not have access to WiFi, so she clicks the “Save for Offline” mode button that is either part of the browser or website interface.
The interface presents a permissions menu: “Maps will need to use 500MB of space and will add https://maps.google.com” to your offline hosts” Alice agrees and the download begins. Google Maps saves a copy of its client code, the necessary map data, and a light nodejs server implementation into a browser cache.
When the browser senses a connection has been lost, and Alice navigates to or is already on maps.google.com, the nodejs server spins up and requests are forwarded to that server. Alice notes that the browser indicates that the connection is offline and sets her expectations accordingly for what she’ll be able to do. When the connection is regained, the server shuts down and the browser forwards requests to maps.google.com’s true IP address.
One day Alice leaves the big city to go camping. She has downloaded maps of the campgrounds onto her iPad as is her usual practice. She moves into her cabin with her friends, and they all realize they have no connection and forgot to grab the maps. They have all brought their phones. Alice activates the promiscuous mode of google maps and the nodejs server becomes active on a mesh network and declares itself the secondary access point to the primary maps.google.com. The phones all mesh network with each other and the iPad. When one of her friends goes to maps.google.com, and looks up the camp grounds the phone asks the friend if she’d like to acquire a copy of the maps server from the iPad with a version number and date of acquisition. She agrees, and the phone downloads the copy of maps offline. As all the friends get the copy of maps offline, the servers distribute the requested map tiles using bittorrent.
The friends can now go explore the woods without depending on a single device (though they probably should have brought a paper map).
Until we have fast, fully homomorphic encryption, I don't see how peer-to-peer apps are going to be useful in the industry.
1. Opened website
2. Clicked "Demo" to see what this was all about
3. Read "Please, login via Facebook..."
4. No thanks. Closed tab.
I only use FB maybe twice a year, and apparently it's not frequent enough to rid this old and overly concerned fear i have.
Alas, no login via Facebook for this mentally old man, apparently.
That feels deceitful to me. They try to create the impression of a public profile, but then put up an artificial boundary in the middle of your content beyond which you must be real-name identified and tracked to read.
It just feels wrong to me. Like they are hijacking the content I licensed to them (for free!) and using it as a carrot to compel people to provide them with personal information.
I understand it's completely irrational, but i have yet to link my FB to a single thing due to this irrational fear. I'm sure if i used FB more i would have worn away this fear, but there is honestly no page on the internet that makes me feel more old than FB. I go there and all the buttons and overload of "things" makes me feel like i'm looking at a AOL sign-on page from way back.
Mind you i'm 32, so not that old.. but still, there is some type of age and or usage issue going on in my head.
I say this not as a complaint, but more as a curiosity for fellow developers. I'm sure i'm a small minority of FB users, but it seems as if i'm a fringe user who had their trust broken and is very tough to get back.
I'm totally willing to go to FB (albeit, infrequently), just unwilling to link stuff via their API.
Also, to be clear, when i mentioned the trigger word "Privacy", i did not mean Privacy from Facebook. I was referring to spammers/scammers/etc.
Bottom line is that I already use Gmail and a fair number of other Google services. I don't use Facebook at all.
It's not so much about trusting Google over Facebook, but rather an unwillingness to share my personal info with yet another company...and Google beat Facebook to the punch. If Facebook had offered a comparable set of services and had offered them first, the roles would be reversed.
That said, I've been looking at ways I can divorce myself from Google because I trust them about as far as I could throw Larry Page.
Yes. Google's place on the internet, particularly in search, and it's greater openness means that Google is more heavily regulated (see the 'right to be forgotten' cases). Making demands and even suing Google is rather straightforward. Their door is open formal complaints. But even finding an email address for a Facebook rep can take years.
Happy to argue this ad infinitum but, basically, nothing (let me repeat that - NOTHING) is private once handed over to Facebook.
And that extends to data your friends upload about you.
I'm not talking about anonymous, aggregated data. I'm talking about actual personal private data.
It doesn't help those who actually (unlike you) did not consider X to be a dealbreaker, interacted with the actual service and now want to discuss the other parts. And those who haven't interacted with it want to know about the meat of the product and how well it does what it does, not the superficial color of the bike shed out front. We have to scroll down past ALL the replies to you, and replies to replies.
I recently posted on HN a link to a project I open sourced which I spent 5 years of 10-40 hour weeks working on. I built it for myself, but happened to put effort into open sourcing and documenting it so others can use it. The top comment was: "Saw JS was required to see the website. So I left."
It may be valuable to the person who built the site, but no one else. It's like being invited to a party, and then saying "your door was painted yellow, thats enough for me!"
The issue isn't that a person posts it, but why is it always the top comment?
Maybe it's the polarizing effect. The comment wasn't for or against FB but it somehow resulted in FB vs Google subcomments. I've seen the same happen with languages, IDEs, operating systems. I don't get it...
But I'm guessing the snowball from that is why they end up on top.
That wasn't the intention, but there are three other comments on the OP mentioning the same issue so it caught other people off guard for some reason.
If you wanted to point that out and avoid the snowball, what do you think the best approach is?
"Area Man Constantly Mentioning He's Not On Facebook"
1. Looked for some cool indie (bootstrapped, proof-of-concept) experiments on HN frontpage
2. Found it. Enjoyed page and experiment
3. Came back to look for interesting constructive comments
4. Stumbles on pointless bullet point comment complaining about bootstrapped parts of an indie experiment.
The landing page has three paths:
- Github
- Article About
- Demo
The other two provide valuable and intriguing info.
Making your demo more accessible might help. I'm not sure how that's "trash".