Achtung: Decentralize, decentralize, decentralize
drewdevault.com
drewdevault.com
As a counterpoint, see, for example, [1], that quotes the Supreme Court Hobby Lobby decision[2]: “Modern corporate law does not require for-profit corporations to pursue profit at the expense of everything else, and many do not.”
The argument in the OP article stands without this — it is nearly as bad that companies have incentives to misbehave, as if they were legally obligated to — but there is also room for improvement at the margin, if employees and customers understand that corporate actions are management’s choice; their hands are not tied.
[1] https://www.nytimes.com/roomfordebate/2015/04/16/what-are-co...
[2] https://caselaw.lp.findlaw.com/scripts/getcase.pl?court=US&v...
Hobby Lobby or a car manufacturer might find a way to combine civic duties with corporate profits, social media will never be able to. Their entire business model is based on squeezing as much value as possible out of the limited attention span of consumers.
Google isn't a paragon, and it's alarming (to me) that Google is building a universal panopticon too. But these two companies, despite the similarity in their business models, appear very different with respect not just to how they collect data, what they collect, how much they sell, and what breaches or not-breach breaches have occurred, but also how forthcoming they are about all this, and whether they act like they've got something to hide. Facebook used tricks[1] to run their iPhone app in the background when requested not to, and only backed this out when the new iOS “battery shaming” feature outed them; they uploaded Android call history with text that mislead the user into thinking they were just uploading contacts. Google has made mis-steps and knows a scary amount about us, but I don't recall this kind of systematic boundary-pushing and post-discovery obfuscation and denial.
Or contrast Lyft and Uber.
These differences in behavior aren't from a difference in business models. They are from differences in “corporate DNA”, or culture. Zuckerberg was a teen when he wrote these messages[2], but most people I know don't speak or act like that even at that age. Some people advance to a different moral stage even at the end of, or after, their teen years; it looks from a longer pattern of evidence, only some of it recent, like Zuckerberg and his company may not have done so. Yes, business incentives are a factor, but explanations don't begin and end with “money made me do it”.
[1] http://pxlnv.com/linklog/facebook-background-data/
[2] http://www.businessinsider.com/exclusive-mark-zuckerbergs-se...
Corporate culture is a structure build on-top of their business, nobody has ever changed their business to adapt to their culture, they just get a rebranding and hire a PR team if the two happen to run into conflict.
That's clearly incorrect. Both Walmart and Costco are in the same retail business, but their corporate cultures are quite distinct.
Companies aren't individuals. They are aggregates, and (absence some major force, e.g. like Gates in MS or Jobs in Apple, or some important founding principles) aggregates tend to go to some mean, which in the case of companies includes profits above all.
There's a difference between "we did it because we were legally obligated" and "we did it because Zuckerberg wanted to". The myth of profit maximisation being an absolute legal duty is much too kind to Facebook here; they're not just a victim of our late capitalist system.
> It simply would not be a billion dollar business otherwise.
Right. Which is why their largest shareholder and CEO is going to ensure they do it, not because he's being forced by the spectre of shareholder lawsuits.
> Hobby Lobby or a car manufacturer might find a way to combine civic duties with corporate profits, social media will never be able to.
Certainly not if we continue to give them a pass when they fail to do so.
the company does whatever those that control the majority of the shares want it to do. Absolutely no one else, unless the company engages in illegal activity has any say. Corporations are democracies with the rules of majority that are spelled out in their documents.
The sad specter of case law dating at least as far back to Dodge v Ford [1], is that legally the only relationship that has to matter to a (US) business is its relationship with its shareholders. Consumer protections have only ever barely been carved out with regulatory action.
> How do non-ad-buying users matter as customers to Facebook
They are literally all Facebook has, eyeballs.
Snowflakes don't matter, if only one Facebook user cares about their privacy, then Facebook shouldn't care. Is it a perfect system? No. But it is democratic.
But I also think that Facebook is already on its way down, people seem to have moved on. At least according to their numbers they still seem to grow or at least remain stable but I would guess that this is mostly due to expansion into new markets and if people there go through a similar trajectory it is only a question of time until the last new market starts and eventually stops using Facebook.
Here in Germany MeinVZ [2] was the dominant social network until people started moving to Facebook and now MeinVZ is just a ghost town. And it pretty much feels the same with Facebook now, actually already for the last five or so years, people come back and engage more and more infrequently until they eventually disappear. It is much slower as compared to MeinVZ but I am pretty sure it is essentially the same thing.
I am not sure where they are all going, maybe Instagram for the younger generation, maybe just WhatsApp for friends in my age, so Facebook the company might just be fine for some more time even if Facebook the network dies. But things have certainly changed from this madness of, I don't know, somewhere between five and ten years ago, when Facebook became inevitable, when it was constantly in thew news, when every ad poster featured a Facebook link.
I would neither be surprised if it turned out that Facebook was an essentially quite short-lived onetime phenomenon and people were not that interested in a global community as the social media proponents would want you to believe, nor would I be surprised if every generation had its own Facebook even if just to set themselves apart from the older generation. Why would we even assume that social media is more than a fluke and does not die away just like many things before?
Only if enough of your friends were on it to make it worthwhile, the danger is that many of your contacts would disappear, which would lessen the value of facebook for even more people, leading to a vicious cycle. And even if it didn't happen to your social circle it would stem the inflow of young people even more than is already the case).
Then it's not much of a business, period.
In my ideal world, we'd only have businesses where the costs are open and direct (e.g. no "user is the product" or selling of personal data, or even "ad-based").
If they can't make it in this way, then, sorry, they don't have a business model.
Well, if there are no buyers, then why have a product?
That's only a myth in that it's not mandated. But it's still very much what almost every company will do, so it's a de facto (if not de jure) thing.
But it didn't used to be like that – not even that long ago, either. In 1970 Friedman released his essay "The Social Responsibility of Business is to Increase its Profits". Look at the corporate behavior he was criticizing:
> The businessmen believe that they are defending free enterprise when they declaim that business is not concerned "merely" with profit but also with promoting desirable "social" ends; that business has a "social conscience" and takes seriously its responsibilities for providing employment, eliminating discrimination, avoiding pollution and whatever else may be the catchwords of the contemporary crop of reformers.
In other words, companies at that time WERE concerned about social responsibility, and not purely focused on profit. Friedman didn't like this; he called it "pure and unadulterated socialism".
Since that time this parasitic mentality was spread to and propagated by top schools like Harvard, dominating the world view of that next generation of businessmen/women. But it was never "a defacto" thing, and many are starting to catch on to the damage it has caused.
I agree with your implication in using the word "myth" that fiduciary duty as a concern is overblown in the collective world of public corporations (the decision in Dodge v Ford was hugely problematic and its shadow haunts us all), but it's not a myth in that it doesn't exist.
> Companies like Facebook, publicly traded, have a legal obligation to maximize profits for their shareholders. Private companies with investors are similarly obligated. Nowhere in the equation does it say that they’re obligated to do anything for you - the only role you serve is to be a vehicle for exploitation.
But I see an exception to this rule: Self-financed companies where the founders are still the shareholders and where the founders are in the company for the long run, and where the company is financed by the users.
If your company is financed by the users, then in order to make the business sustainable you need to optimize for the users. If the users demand privacy, then you optimize for privacy.
I'm aware that slow, sustainable growth is not popular in silicon valley, but that's probably a question of culture (in many european countries a lot of startups still follow this path).
But will they change? Zuckerberg, as far as I can tell, started Facebook because he wanted to be master of the (internet) universe. And then he hired a lot of really smart people with the same motives.
Are you hoping that at some point in time he is going to have a great moral conversion and decide to forego power and wealth and become a sort of saint who will give it all away? Seems to me far more likely Zuckerberg will pretend to reform, but keep pursuing the same goals.
What you are saying seems to be that we should not push decentralization and instead just wait around for something good to happen. Which in turn makes me wonder about your motivations.
The article is about why we need to decentralize. This is an important issue, and so we need to have a discussion to decide whether or not this is the right course of action. And we have this great resource, an internet comment section, in which to discuss it. And you are a netizen, so you should think about it and add in any useful comments you might have.
Instead you made a comment that derails the conversation off onto a track that it seems to me isn't useful. I see this happen a lot here at HN. There is a lot of useful discussion, but so often there are also people who make comments that derail the discussion, provoke an argument that isn't really relevant. I wish every commenter would first think out what is the basic issue at stake, and avoid making comments that lead to disputes that are off track from what needs to be discussed and decided.
Also, while I do like the expression "if you're not a customer, you're a product", it does not change the actual definition of the word customer.
> a person or organization that buys goods or services from a store or business
You may be confusing the word "customer" with the word "user"?
> 1. General: A party that receives or consumes products (goods or services) and has the ability to choose between different products and suppliers. See also buyer.
https://en.wikipedia.org/wiki/Customer
> In sales, commerce and economics, a customer (sometimes known as a client, buyer, or purchaser) is the recipient of a good, service, product or an idea - obtained from a seller, vendor, or supplier via a financial transaction or exchange for money or some other valuable consideration
I think to me the customer is the one receiving the product, whether or not they have actually spent money.
Also for consideration, "paying customer" and "non-paying customer" are common(?) phrases.
If you want to decentralize the servers then you MUST also decouple user accounts from the server they signed up with. Today, if you switch to Masterdon (or perhaps someone you know is running a diaspora node), everything appears to go well until a year from now when the volunteer who was providing the server loses interest or moves on, and your account/photos/journal/social network vanishes. So you start over by creating a new account with another server... tick tick tick, gone. Rinse repeat.
Centralized services don't have this problem - even myspace is still up today, meaning this killer problem isn't on our radar when we evaluate things like Masterdon, or promote it. We don't realize this is a temporary arrangement with a clock ticking down to complete account destruction.
Hubzilla is the only decentralized social media project I've encountered that tackled this problem and sort of solved it (they call it "nomadic identity"). I hear that needing an architecture able to solve this problem was why when Friendica was gaining popularity, the guy behind it realized the whole concept was a lost cause and subsequently started again with what would later be called Hubzilla.
Regardless of whether Hubzilla itself is your cup of tea, separating user accounts from volunteer run servers is necessary before centralized social networks can be challenged, otherwise you just inoculate people against ever leaving the central networks again.
(not to suggest this is the only necessary thing, or only hard nut to crack)
> If you want to decentralize the servers then you MUST also decouple user accounts from the server they signed up with.
I somewhat disagree. Email is a decentralized service that works well and its accounts are coupled to the server you signed up with. It merely requires you to do some research when picking a node² or running your own.
Ideally there would be some provision in the protocol that allows you to transfer your content and notify your friends whenever there is an address change. You could do this with a digital signature. You could also bolt on a decentralized identity that's on the blockchain, e.g. register a domain with namecoin (which is completely decentralized) and point it to your current social identity. Problem solved¹.
--
¹ to be fair, registering a domain with namecoin is not trivial at the moment.
² perhaps pick one that requires payment, that creates an obligation to provide the service
Additionally, there are features in email that you won't expect from these nodes like a useful (to muggles) data export. I can pull down my email with IMAP or POP, close that account, and still have access to all of my old email. Hell, I could _reply_ to one of those old conversations using my new account/provider and keep right on trucking.
* Identity management via blockchain (one of the use cases where IMHO this is a good, or at least defensible choice).
* Metadata storage in a DHT
* Content storage in torrent swarms
None of this depends on any single peer/server.
Y'all got any more of them "examples"
I'm now aware of two social media alternatives that aren't dead accounts walking. Twister is in beta, but that looks interesting enough to play with and keep an eye on.
On twister, you could regularly see people having their "oh shit" moment when they published a post with a typo or such for the first time. You get used to it.
I chose twister as an example because its decentralization contrasts nicely/clearly with the federation being discussed in the parent.
Mastodon is working on migrating accounts between servers so that in the exact case you describe people can take their data and move elsewhere.
Of course, you'll need permission (though sometimes asking for forgiveness can be good enough)
You do not want to start there, Facebook's MO is exactly that.
Facebook's MO is "store all the shit and never delete it", an archival project should have an MO of "archive everything we can get and delete it when somebody complains".
Otherwise you'll never be able to archive any significant portion of the internet or fediverse.
Companies have an {obligation, fiduciary duty} to maximize value for shareholders, therefore they have no choice but to do horrible things to {users, customers, the environment, civic institutions}
Presumably, decentralization, federation and open source will eliminate the profit-maximizing corporation, thereby stopping all the horrible things.
The problem with this reasoning is that it only addresses one side of a two-sided transaction. The corporation doesn't transact with itself. The other side of the transaction is the user.
What if every user was willing to pay $5 per month for a "clean Facebook" without ads, without surveillance, without psychological profiling, without selling private data to malevolent third parties?
If every user paid $5 a month, Facebook could continue their current business with the best computer science talent and a global network of data centers.
If every user paid $5 a month, Facebook's shareholders would do fabulously well.
But of course, that's a ridiculous proposition. Only an infinitesimal number of Facebook's 2.2 billion users are willing to pay for the service.
Since a social network only has value to a user when all the user's friends and family are also on the network, a Facebook that only has a few people willing to pay won't be very useful.
Advocates of decentralized social networks need to explain (1) who will pay, and (2) how to get enough users to make the network valuable to a typical user.
Until we figure that out, we're stuck with social networks that are free for users, monetized with advertising, and regulated by the state.
The formerly decentralized services are no longer so decentralized since "free of charge, paid for by data and ads" has shown itself to be a viable business model that users love. (Until they understand what's happening, at least.)
People keep saying this but to my knowledge email still isn't centralized. While there are a lot of gmail users in the US but that's not the case in many other countries, many people also have a .edu email and a few years ago I ran my email server myself (I even handled signing papers when I switched jobs over it.) Google even contributed to and pushed for dkim and spf which solved a huge spam problem that threatened their ability to forward mail from smaller outside domains to their users. A lot of people might use one of the big services but as long as you don't have to in order to interact with them it's not "centralized."
There is no control within Facebook's ecosystem. Similar with AOL, if you don't use Facebook, you're necessarily out of the loop, and I don't feel comfortable with that.
Not to detract from your point, just thought you might be interested to know that USPS actually has a legally-protected partial monopoly on the right to carry letters (18 U.S. Code § 1696).
An exemption was added in 1979 allowing private carriers to deliver "extremely urgent" mail. This is why UPS and FedEx express mail envelopes bear that text on their front.
Apart from this exemption, USPS, FedEx and the like are only allowed to deliver 'parcels', not 'letters', though I'm not sure where the distinction is legally defined.
More info: https://en.wikipedia.org/wiki/Private_Express_Statutes
But it is absolutely federated - I have the choice of running my own server and can communicate with every other e-mail address on this planet.
Unfortunately, it isn't easy to setup - average Joe has no chance to get his own server. On the other hand, for IT people it isn't extremely hard either. Once setup, it is nearly maintenance free...
I'm running my (and a company) e-mail server since 2001 and I don't want to miss it. I only once had a problem with being blocked by big sites, after moving to a new server where the IP range has gotten on some blacklists, because of the previous owner. Also never a problem with spam filters.
I hope e-mail will never be replaced - or at least there's some new way of communicating federated where every internet user is reachable.
This is what happens as technology progresses. I don't think the solution here is to abandon imperfect technology in favor of old, but to improve upon it.
If we need e-mails and phone numbers to sign up for social media, then we don't actually need the social media. We can go back to simply using the numbers and e-mails.
Better to extract the value of Facebook and move forward by eliminating the negative, than revert to something many people find less convenient.
I disagree that we currently do. And only agree for email in 1998 when its decentralized nature costed more to the users than the benefit of being decentralized, hence the transition.
Nowadays, any kid can get online. The range of intelligence and character has expanded dramatically.
> But of course, that's a ridiculous proposition. Only an infinitesimal number of Facebook's 2.2 billion users are willing to pay for the service.
Well, at least some tens of millions of users seemed to be happy about the idea to pay USD 1 a year for WhatsApp.
They were running this operation with something like 50 engineers so it should have been really profitable.
Then came Facebook...
All chats I've been in on Telegram and Whatsapp over the last few years could be stored in a few gigabytes of disk space.
How would I know? I've had a look at what Telegram and WhatsApp stores on my phone.
The problem is that, to a sufficient degree, they're not. Likely because the value proposition (or its assurance) is a hard sell. And that hard sell limits network scale (and hence, value).
Mind, even free alternatives have exceptional difficulty in competing with scale. Viz, G+.
Simple -> Start the app and commicate (on all devices)
Minimum features -> Feed, Chat, Groups, Events, Friends
Fast -> No one will use a slow App
Ownership -> All self-owned data can be removed from everywhere
Decentralized -> And no one else can remove your data
Privacy -> With simple sharing control
So far, I've not seen anything that has all of these.
- Handle DMCA notices and law enforcement requests for taking down illegal content.
- Hackers compromising accounts.
- Private data being compromised because of Wordpress like security bugs.
- Spam / Bots spreading junk and fake news.
- Permanently deleting content.
- Concerns around terrorism, grooming, child pornography etc
These problems will become major headaches at scale.
But only on instances they are administrators off.
So while I can take down illegal content on my instance I can't go to the japanese instance and ask them to stop posting all those anime girls. They follow their own rules and if I don't like them I can just not allow their content on my server.
If you want to follow both my server and the japanese server you'll have to find an instance that doesn't ban either of us or run your own.
(Though I trust that there are a good number of lightly administrated instances that it'll be easy to find one before you're forced to run your own)
Instances may decide they'll ignore the DMCA or allow japenese content that would be illegal as CP elsewhere or don't give a damn about hackers compromising you.
So here's the rub: 1) you post stupid stuff, but by the time you realize this, you've already forgotten your password and the account recovery doesn't work, 2) someone gets hold of your account, posts stupid stuff, and 'throws away any means to recover the account', 3) someone posts stupid stuff that is determined to violate law, how do you take that down?
This is where Google+ and all the others failed.
I HEAVILY disagree with this. Content generated by people obtains, at one point, historical value. Self-owning should end with personal details, anything involving someone else has to be kept because I think social media has no point if someone else can just now delete basically what are part of my memories. I know Facebook doesn't do this well either, but they aren't making it easy to scrub everything clean either.
I think a line has to be drawn on the part of private ownership when it comes to privately created content.
Person A: "I have a problem X that I need help with"
[deleted]: [deleted]
Person A: "Thanks that worked!
> Decentralized -> And no one else can remove your data
How do you expect to be able to do that? Decentralization implies your are passing data to peers you do not control. They'll only remove data you ask them to if they are well behaved, but there is no guarantee of that.
It's like wanting to be able to delete emails that have already be sent,
You have chards of data on more than one endpoint that sync between eachother - to forcefully remove it you would need to remove it from all of those hosts manually.
But with, let's say, an access/crypto key - you can do it on all of them. Systems like Storj already do this i believe?
Or do Mastodon people say it's strictly for broadcasting and encourage people to use proper end-to-end encrypted messaging apps for private communication?
Facebook has a disincentive to sell data: if they sold user data, they no longer have exclusive control over it and somebody else can profit off their efforts in its collection. The value of Facebook is they have lots of eyeballs and they have lots of data on what those eyeballs like to see. If they simply sold this to an advertiser, why would the advertiser want to come back and pay them in the future? What they actually do is let advertisers target on this data, but the advertisers never actually have direct access - they can only assume that the users they target are ones that have the attributes they requested.
So what is Facebook selling? The same thing any other media platform, from newspapers to TV, is selling: your attention. Are you the product? Kind of. But just like any other marketplace, Facebook knows that if their platform doesn't provide value you're not going to come back and then neither will the advertisers.
Personally I think Google has played this balance far worse, by comparison: their interaction time with their users is so small that they have gotten more and more spammy to wedge into the little bit of your attention they get. Facebook gets a lot of user time and thus can be far more judicious on when and how they show you advertisements.
That's what this whole uproar is about: they're allowing wholesale data access, not aggregated targets through their API.
Google, whom you criticize, is the one actually only selling aggregates.
Second, Google grants just as much access to your data via API, if not more, than Facebook. Using Google’s APIs, you can grant full access and control to your email, calendar, contacts, etc. If you think companies aren’t currently abusing that in ways that make Cambridge Analytica look like children, you would be mistaken.
But as the article points out, in order to get people's attention it does things like allow fake news to be posted, and allow apps to collect your personal data.
There is no promise that a company can make to its users that outweighs the fiduciary duty that obligates them to maximize profits by any means.
Not true. [1]
[1] https://skeptics.stackexchange.com/questions/8146/are-u-s-co...
But fortunately we don't have to worry about that, the people writing laws are not all idiots and it would be a pretty stupid idea to put requirements into laws that are essentially impossible to fulfill due to a lack of psychic powers and time machines.
I think too many implementations are focused on the wrong things. Too many implementations are hung up on the distributed storage part. These can be plugged into abstractions as new ones come about. In the meantime, just because it says "decentralized" doesn't mean that pieces can't be centralized on some people's computers. I think when most people say that they mean off the cloud and into the home. Also, too few implementations care enough about anonymity.
Check it out - matrix.org
PS: Even more importantly, the Host Identity Protocol. The US army has been using it for over 10 years. If that doesnt speak volumes ...
Plus, the author talks about Mastodon, which solves an entirely different problem than matrix to begin with.
Matrix doesn't even support ActivityPub, which is basically the W3C approved standard for federated social activity, it should be easy for Matrix to integrate into the fediverse.
Until then I won't consider matrix as a serious solution to anything.
I do agree that mastodon and matrix - of which I'm a fan of both - solve for different scenarios. Mastodon replaces twitter; sort of short social media bursts/broadcasts. While matrix replaces slack (and other chat platforms like xmpp). I've always seen matrix as a modern-day irc; also allowing expansion and enhancement via plugins, and programmability like good ol' irc is/was.
ActivityPub was only recently approved, so can't expect every project to instantly support it; though to be fair it has been on many projects' radar well before its approval by w3c. I truthfully haven't followed the latest matrix news, so not sure if support for activitypub is coming soon. I do feel that supporting activityPub really make it that much more powerful of a protocol AND platform...but i'm sure that's not a trivial matter.
If you haven't played around with clients for matrix (such as the Riot clients), i suggest you give it a try. Riot keeps getting better and better with each new release.
I can't in good faith recommend Mastodon.
Also, lack of encryption allows for selective censorship on the fly.
Either offer it properly or do not offer it at all. It's irresponsible otherwise.
Twitter by default broadcasts everything you write to the entire world!
Why should open source solutions be held to a higher standard?
To be fair, at least your connection to twitter is encrypted. This means that an observer can't tell it's your IP that's posting on twitter as you.
That is, your location.
Thus twitter is actually better. A court order would be needed for them to disclose IP addreses, at least.
What!? Are you talking about TLS? Because this is true for Mastodon as well then.
Mastodon is a microblogging service, it's perfectly fine to not sign all messages (though ActivityPub does support signing)
Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
Note it IS signed. It's just not encrypted. It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Additionally... should I be some location and post something, I'd be broadcasting my location, even if that isn't intended. All because it's not encrypted, where it should be.
>Mastodon is as trustworthy as your instance administrator, so you'll have to find a place where you can trust your admin.
That'd be true if it was peer-to-peer encrypted. But it is not; all messages are plaintext on the wire.
Can you tell me how and where you would broadcast your location via Mastodon? There are no geolocation features in Mastodon.
>It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist.
Has anyone attempted to encrypt a message to 64,000 recipients yet? I don't think restricting a message to followers is an applicable model for e2ee. Direct messages yes, I can see the point in that.
For a network observer, your IP address, associated with your account name.
>I don't think restricting a message to followers is an applicable model for e2ee
But requiring TLS between clients and servers, and between servers (for the federation), is applicable.
>Direct messages yes, I can see the point in that.
The average joe expects direct messages to really be private. If they're not, that's bad.
>The average joe expects direct messages to really be private. If they're not, that's bad.
They're not "really private" in Twitter DMs and Facebook Messenger and PMs on phpBB and Discourse forums, they were not "really private" in ICQ, AIM and XMPP (unless you installed the OTR plugin on the last one). E2EE is cool but most private messages on the internet do not use it and they are still called things like "private" and "direct".
Citation needed. I was told it's optional in a recent thread.
>They're not "really private" in...
Doesn't address the argument you quoted:
>The average joe expects direct messages to really be private. If they're not, that's bad.
If you use TLS they aren't.
>should I be some location and post something, I'd be broadcasting my location, even if that isn't intended.
you broadcast it to your mastodon instance. In P2P you would actually be broadcasting your position to any network observer. In Federation only your instance knows.
Connect to post something without encryption means your location is revealed to anybody observing the network.
This is indeed dangerous.
Where are you taking this from? You think connecting to your Mastodon server you have an account on somehow broadcasts to the whole network?
- Your message
- Your account name
- Your ip address (thus location)
- The time at which this happens
If the message is sent through an encrypted connection, but the federation connection between the servers is unencrypted, a powerful enough observer could still deduce the above.
Most Mastodon servers have TLS, exceptions usually included instances deployed to localhost.
Mastodon doesn't technically require it but all clients I've seen do and the web interface relies on some features that are only available in a trusted context (HTTPS and localhost)
I don't really see the problem though, which instance you sign up to is up to you. You can sign up to a HTTP-only instance if you want.
The privacy of your data is in the hands of your local administrator more than any powerful observer (and servers you send messages too, like with email, for which all your complains are valid too since it functions similarly).
That's a serious issue. If plaintext is allowed, then expect getting people to downgrade to plaintext will be trivial, because "it just works".
It's a serious mistake, but a well understood one by today. Mastodon is relatively new, and they should have known better than to do this.
So yes, Mastodon did know better but it's not an inherent property of ActivityPub to use HTTPS.
Why not? Not a fan of the 60s?
Aggregators would be where you go to set up your friend list and see your feed. It could look and feel like Facebook does now. It would have an open standard protocol that content hosters would use if they wanted to be aggregated. This could still be an add driven business, but subscription, self hosted, and DIY solutions could exist too.
Content hosters could either charge a monthly hosting fee, or they could serve up their own adds. Self hosted and DIY solutions could also exist.
The big benefit to this would of course be the competition. Since it's an open standard anyone could be a content host, and anyone could be an aggregator.
To make extra sure there is competition, and this could come in a phase two after the initial splitting up of Facebook, there should be open standards for exporting and importing friends, follows, likes, etc. to and from aggregators, and open standards for importing and exporting content from the hosters.
Speaking of follows and likes, there could also be aggregator aggregators (AAs). People could opt in to publicly and anonymously share their likes and follows and the AAs would consume those and report on trends that cross aggregator boundaries. Anonymity could be much more protected this way while still giving us that interesting information about what is trending.
One tricky part of this is how do I as a content author only allow my friends to see certain posts of mine? It would have to be with encryption. My content provider could keep public keys of my friends and only my friends (well, their aggregators) would be able to decrypt my posts using my friends' private keys. I can see some challenges and holes in this, but it doesn't seem any worse overall than how Facebook protects privacy now. Open implementations and peer review could get us to better-than-Facebook privacy quickly.
Is there a connection between any recent event and German(y) that I missed?
Some words, phrases and symbols from foreign languages can become internationally-famous so almost everybody can understand them and also gain meme-like semantic self-emphasize.
¡No pasarán!
ॐ
PS: I have also heard it's quite popular among French metal bands to use German in their names to sound scarier (e.g. Blut Aus Nord).
Yes, decentralization would be the right solution. But this will always be discouraged by governments and corps alike, basically by everybody who has already lots of power and wants to have more power over your life.
As always you as a single person can choose to either be part of the ant swarm, giving someone else all power over you, but by that sharing in the ant swarms gains and luxuries as long as you are loyal, or by being self reliable but therefore also really be required to build everything by yourself that you really need and want to have.
If you decide for the first part there is really no reason not to give the person who has power over you also access to all your data. It's part of how a group works. And if the people at the top don't like you anymore then they will find ways to kick you out no matter what you do or keep secret. On the other hand its also part of the deal that the people above you don't use their power to peek into your life as long as you stay loyal and support their goals.
So FB either needs to accept to only live on the fringe instead of being the market dominator, or they need to accept that the government has bigger power and yield to them.
The only thing I feel one needs to be wary about is parasites who wants to keep the whole cake without sharing even a little bit with people below them. Trump is one such example. With these people you can't do either of the two paths, there's only the battle for who's stronger. And if you are like most people you don't really enjoy being in a constant struggle for survival.
It might very well be that Zuck is fighting against Trump here, and then that's the parasite situation and all Zuck could do is move out of the US, give up that market until Trump is gone again.
Instead, we should make the developer tools EASY to create P2P (not federated) decentralized apps. This is what we are working on:
http://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wit...
Also, d.tube is a pretty good decentralized YouTube clone, worth a mention.
Also I'd like to hear the author's thoughts on GPG's viability, as discussed below:
https://moxie.org/blog/gpg-and-me/
Eventually I realized that when I receive a GPG encrypted email, it simply means that the email was written by someone who would voluntarily use GPG. I don’t mean someone who cares about privacy, because I think we all care about privacy. There just seems to be something particular about people who try GPG and conclude that it’s a realistic path to introducing private communication in their lives for casual correspondence with strangers.
I stand corrected. I'll have a look at Mastodon.