Thimbl - Decentralized Microblogging with SSH + finger
thimbl.net
thimbl.net
Thanks Hacker News! Nice to see this pop up here, even if I wouldn't have posted it here just yet ;)
As long as we can get a better peek into their implementation... I am curious, like others, why they're not using public key authorization, etc.
from="proxy.thimbl.net",command="finger-wrapper" ssh-rsa AAAA...
Very doable.
Based on what tricknik has said so far, this strikes me as an HTML5 WebSocket spawning SSH. Similar to what was discussed here:
http://news.ycombinator.net/item?id=1694607
Great idea, I had awesome .plan files way-back-when and spend most of my time in my shell.
Updating my micro-blog with cat >> .plan ... ^D would be enjoyable. I am looking forward to your work!
But the main problem that this completely lacks any technical description.
* I have to trust thimbl.net and/or you that you aren't storing anything.
* Even if you released your codebase on github (or similar) there is no guarantee (to outside users) that it is the same one that you are running on your servers.
* Your site is not https, meaning that my ssh password is going plain-text over the internet.
* Even if your site is 100% not doing anything funny, there is the possibility for someone else to sniff the passwords flowing through your site.
1. thimbl.net provides its public key.
2. You add it to ~/.ssh/authorized_keys (or whatever your SSH server uses).
3. ...
4. That's it (remove key if you don't trust thimbl anymore or thimbl may even remove it by itself, at the end of setup process).
I could have multiple keys, all w/ different access levels, all on the same user account. There is no way to do this with a password, other than to just have separate user accounts.
- As soon as you started the connection, it would try to connect to all group members via their ports. If the group list is old, or if some are offline, maybe some/all wouldn't work.
- Whoever has the fastest response time, if their group list is newer than the existing group list, the client requests an updated group list from (just in-case it is out of date). If no one is online, obviously this doesn't happen. The user of the client trying to update must ok the changes to the group list (to keep someone from gaming the system). You could also specify who to get the grouplist from.
- At this point the client must be ok'd by the others if his IP/port has never been accepted into the group before.
- If accepted, at this point the client is flagged as someone who has a group list to share.
- At this point the client can communicate with others in the list, and if you want it to be microblogging or just IM'ing, anything goes, depending on the client.
That it resurrects finger? ...So?
Of course, that's the problem - there isn't really anything here to talk about, just some 90s Wired magazine fodder of a slideshow and a plea for community help.
From your slideshow: "THIMBL will succeed with a community. join us and help make a free, open social network"
"and a bunch of blogs with fees"
What "fees" for running free blogging software on my server?
"Interesting that you bother to post a comment"
It's called having an opinion. If you can't deal with skepticism after publishing PR material without having anything more substantive handy, rethink your strategy.
First hint: I at no time said that I found this "not worth talking about". Those are words you tried to put in my mouth to distract from my noting that there's not much here to go on.
Second hint: People say "community, come help us succeed" in order to blame the lack of community help when they go nowhere.
Anyone care to enlighten me further as to how it works?
I changed my default SSH port to avoid brut-force, do you think I'm going to trust anybody with an actual password ?
Note: This is by making the handling script the thing that runs for a certain ssh key, I don't think it works with a password though.
https://docs.google.com/drawings/edit?id=182y8FZDPvY1R-SQnYC...
(For anyone working on the site that might be reading this, there's a "where" that should be a "were" and an "it's" that should be "its" in the first paragraph; I stopped reading there.)