How I’d Fix the Internet
medium.com
medium.com
In fact, we don't have to change anything about TCP/IP to create fully authenticated Internet services. Without any changes to Internet hardware or programming languages, we can use public key cryptography to allow people to prove their identity to a third party and use that identity to access other services. In places where anonymity is problematic, those services can simply disallow unauthenticated users.
The reason we don't have services like this isn't technological, has little to do with money, and nothing to do with privacy concerns. The problem is that not enough people want this service. If they did, it would exist already.
Meanwhile, the idea that fundamental changes to Internet protocols would alleviate security problems is as old as IPSEC: it was literally the pitch Robert Stratton gave to assembled hackers at Summercon in 1995. The problem with the pitch is that Internet protocols and hardware have practically nothing to do with security; rather, the core security problem is that all programs have bugs, and bugs can be assembled into levers for unexpected behavior. Take it up with Edsgar Djikstra, not Vint Cerf.
the core security problem enabling that is all kinds of widely used computers being fail-open by default down to the lowest levels.
The reason why I don't run up and call random people cunts is the risk that I might get punched.
ID is only one part of that. However bulletproof ID does not yield security. What it does do is allow people/governments to persecute people with much better precision.
The problem of anonymous information sources has been around for millenia. There is a reason you don't trust the shit the drunk bloke spouts at the pub: its mostly bollocks.
The main problem is that normal people, right up to the news producers have suspended their critical faculties.(for different reasons)
"a website I've never seen before, has lots of adverts for escorts and MILFs said that something happened" its not happened.
"a rumour on twitter said..." its a fucking rumour. Find the source and it might become fact. Until then, its the same as hearing it in the fucking playground.
Now, if you're a news producer, I know you want to beat your main rival. But each time you don't bother to fact check, the value of your news drops.
Identification is a tricky issue, influenced by human, social, and political decisions. It's also very easy to trick identification routines.
A very practical example is email addresses for groups or organizations. It's not clear what's identified by such an administrative email address. The people who read it and send in its name? Some more abstract concept? Depends on the situation. I'm too tired to find a better example, but you get the idea...
So the best thing is to say, email addresses identify, well, themselves, and also where to route emails to these adresses.
You can't build technology without clear concepts. Or with too many, incompatible, concepts for that matter. I don't see a better way than layering (i.e separation of concerns).
I for one love to listen to the drunk bloke at the pub. Sure almost nothing he says makes sense, some of it is wildly offensive. The opportunity to listen in invaluable, and I'd fight tooth and claw for his right to a soapbox. Every once in a while he'll say something that challenges my assumptions, and makes me think long and hard.
I model my mind seeking an accurate world view as similar to the simulated annealing algorithm. Without noise in the system it's very easy to get stuck in a local maximum. Without anonymity there's simply too much incentive to stay with the status quo.
Removing anonymity won't fix crap like that.
That said, there are strains of trolling which could be helped by an option to dump anonymously sourced messages. Like the Lindy West troll sending emails addressed from her dead father, or Scott Adams signing up for a thousand sock puppet accounts to drop pro-Adams propaganda in strange corners of the internet...
No thanks.
- All new mobile devices must use IPv6 only. (No more NAT at the ISP level.)
- All IPv6 devices should be able to reach each other if they want to, without going through a server. (End to end voice, video, and messaging without the need for a server.)
- Anything with a big packet buffer must use fair queuing. This includes home routers, interfaces with big buffers, and cable DOCSIS nodes, but not backbone routers. ("Bufferbloat" fix)
- Better ingress filtering at ISPs, to limit bogus source IP addresses to addresses which can legitimately come in via a path. (Single-packet DDOS reduction)
- DNSSEC everywhere (DNS spoofing fix)
- Get rid of the delayed ACK timer in TCP. ("Nagle algorithm" fix)
I don't pretend to know how to 'fix' anything (much less something as complex as the internet), but I do feel like it would be beneficial to have some competition in this space, to whatever degree it's possible.
When there's only one option, a variety of problems associated with monolithic systems and monopolies will inevitably arise--as we've seen with the current system.
It's like I tell mugging victims - you should have stayed on the ID-only sidewalks
Yes, much could be improved about the internet/web. But if we can see misuse in the ideas offered right after reading, the proposed new system would probably be worse than what we have now after some time. It at least took a while to exploit what we have, not 30 seconds.
Does writing on medium.com make you more sophisticated? I don't understand this craziness.
Personally, I cross-post to Medium if I write something that might be of general professional interest. The private notes feature is useful if an editor is doing a copyedit pass and I also think Medium works better if a piece is going to be linked as part of a newsletter or whatever.
Finally, if someone only writes posts once in a while, it may make more sense for them to use Medium than maintain their own blog.
Of course, if you're posting on blogpost or such, it is not your blog —it's Alphabet's. If it were your personal blog, you wouldn't have put this "signal inappropriate content" button, would you?
If an author is willing to move their content if their provider shuts down, that is not much different than migrating their content if medium shuts down.
My own domain name is in .fr, and if it expires I have a chance to renew it before someone else is allowed to take it. There's a few weeks of delay, but truly losing a .fr name requires the owner to be really negligent. I believe .com names are more easily lost, though.
It was strange seeing the mixing of trolls, and bank security concerns.They are pretty different in nature. Im also surprised there was no mention of ip addresses.
I think internet is broken, but more at a technical level, its too easy to have isp accidently break large portions.
ex. Pakistan bringing youtube down accidently in 2008.
Yes, the Internet is broken -- both accidentally and deliberately.
I dunno if they care about govt. orders but if you query their dns for a "blocked" website it answers with an invalid IP:
dig @202.88.149.25 thepiratebay.org
;; ANSWER SECTION:
thepiratebay.org. 65346 IN A 0.0.0.0
And Google DNS at `8.8.8.8` just times out. :/Just finished Cumulus as a similar recommendation to the Circle and hated it. It made the Circle look wonderfully nuanced in comparison. Characters frequently recapped previous chapters, every implication and inference was enumerated explicitly in great detail, etc. essentially no thinking required.
Breaching the security of applications is a very deep problem which is unrelated to the internet. The current computing architecture is exposed to vulns. Both local and remote in a very similar manner.
Regarding the democratic process that have been tampered with, thia is done way before the internet, and will probably go on forever[1]
Indeed. I have some trouble deciding if the author is a troll or a bot.
Edit: source https://wikileaks.org/podesta-emails/emailid/6056
Given the damaging nature of all of the fake news and trolling flying around during the campaign -- including the metric buttload of mountains-made-from-molehills relating to Hillary's e-mails -- I can absolutely understand how someone might think the internet needs some fixing.
I don't agree with the ideas he presents in the article, but I also don't think having a connection to Hillary Clinton's campaign reveals any nefarious intent.
"Its inherent lack of security has allowed Russian actors to screw with our democratic process."
Well, he maybe cares deeply about cyberbullying, to me his arguments feel a bit - dishonest?
I'm not really sure what you're expecting. He's seen something that he felt when horribly awry and he's made some proposals he thinks could improve things.
I agree with the parent, it reads like a political piece to me too that has little to do with technology and such it is nice to have a disclaimer about his affiliation*
*disclaimer: I'm not American nor living in the US