> I'm not saying it's magic, I'm saying that securing a P2P network is more difficult because the threat surface is much larger and because you have much less control over your stack. At the very least, I (should) have physical security over my own servers, and the intra-DC data links.
With a centralized system you have this:
client1 <-> central server <-> client2
With a decentralized system you have this:
client1 <-> client 2
In the first case, if either client is compromised then the data is still compromised regardless of what happens at the server, because the data still traverses both clients.
And in the second case the "central server" is better than physically secure, it's non-existent. That method of compromise is removed entirely. There are no intra-DC data links to worry about.
> For example, if I find a severe vulnerability, I can immediately patch my own servers. If the vulnerability is in the P2P client, it may be impossible to guarantee that every last client gets patched.
For serious vulnerabilities the solution to this is to push the update with a date check in it that gives people a reasonable amount of time to update their clients, and after that date all of the updated clients refuse to talk to the unpatched ones.
> Because there's obviously an i, wait a reasonable amount of time for everyone to have instnverse tradeoff between control and development speed. Managing distributed state is hard enough when it's on your machines, it's exponentially harder when it's random devices somewhere on the Internet. Your guarantees are much looser.
Only if you're testing in production. If you're the actual developer then you have a test network which is completely under your control, or maybe an isolated group of beta testers who have chosen to allow you to force-update their machines.
> 1. Your data is less local so there is less effective latency.
With a central server the data is on the server and the client has to fetch it every time it wants to do anything. With decentralization you can keep the data closer to where it will be used, e.g. (a copy of) your photos are already on your device.
> 2. You're spending computation and bandwidth that other people are paying for
You're always spending computation and bandwidth that other people are paying for.
If a decentralized system uses 30 seconds of compute time every day from each of a billion devices, probably nobody even notices (especially if you select for idle devices), but do the same on AWS and your boss is going to want to know why the bill is so high.