Why ActivityPub is the future
blog.joinmastodon.org
blog.joinmastodon.org
Now, some would say that, these services had the goal to make money and that's why they attracted capital and could hire top talent, but it doesn't change the fact that they had to have a strong product mentality to get to where they are today.
Most decentralized software I see have a project mentality based on idealism, but idealism is not enough. That's why desktop Linux failed to capture significant market share even if it costs zero to Joe Average to install it: it stayed at the level of idealism, of a project, while proprietary platforms like Windows an OSX had serious money and talent behind them because they weren't just projects.
On the other hand, Firefox and the Linux kernel are good example of successful open source softwares with a strong product mentality. Mozilla had a vision and they realized they need a strong product to fulfill that vision, so they needed to be able to pay their developers well, meaning they had to generates money. Same thing with the Linux kernel, which is backed by a lot of big companies.
So I guess what I'm saying is; if ActivityPub is to be the future, then there should be more than idealism behind it.
We need products on ActivityPub that beat real products
Hotmail had more users after 18 months than the total history of all email services on earth combined for the first two decades of email. If email was still as annoying to use as it was pre AOL & Hotmail, the general public still wouldn't be using it today.
OP's point is not whether netscape or mosaic is better, but that the graphical web browser was what brought the web mainstream. Doesn't matter if it's mosaic or netscape (or several other graphical ui browser competitors that existed during that time)
You've gotta build a really compelling service first and foremost (otherwise, why bother), and then add federation later. The danger of that is it's really tempting to just skip the federation part if you get big, but it's a critical part that shouldn't be forgotten, but only after you've got a great app people are using.
I'm watching Mastodon to see if this belief is wrong and it ends up taking off, but I think there's a real danger is designing for nerds and getting small time success and validation with nerds and geeks (this is not derogatory fellow nerds), because what we want is not what matters to most people and you risk biasing your community (the Google+ effect, though it happened there for different reasons).
The idealism has to be matched with hard pragmatism. Maybe one of these projects will do that.
Too many 'hacker/techie focused' projects focus on grandiose visions and philosophical points at the expense of a real purpose.
I did some work on PubSubHubbub based federated social networks back in the FriendFeed days. Technically it worked really well, and we had a few nodes sending posts between sites with only seconds of delay.
But no one wanted to use it.
After I while I worked out it failed for exactly the same reason FriendFeed (and Google Buzz) did: federation is actually a weakness when there is a major player.
FriendFeed gave up and took the FB money (smart). Google Buzz gave up and was replaced with the completely different (and non-federated) Google Plus (which failed for different reasons).
The only argument for it working this time is timing. I've come to appreciate timing based arguments a lot more over the last few years, so maybe there is an opportunity, but I'm sure not putting any effort into it.
Desktop Linux's failure is a matter of perspective, but there were more than a few products built around it... they just failed. It turns out, that was the wrong vision.
It's really not.
https://www.statista.com/statistics/218089/global-market-sha...
Firefox is arguably better than Chrome and has a much nicer ideology as well, but it's not so much better than Chrome that the majority of users is switching by default.
Non technical people need a reason other than ideology to switch. The product needs to provide a new value that doesn't exist or be so much better that it's obvious to everybody who tries it.
It's not even that.. often it's just distribution. Often consumers don't really want to make a conscious choice, so taking it away from them in the distribution channel is the way to go. I remember doing studies on search engine switching rates. No matter how awful we made the default search engine, the vast majority of users would not even try using Google. It was AMAZING.
I would argue that the browser wars have, to a much larger degree than we're prepared to acknowledge, been driven by distribution. Users don't want to make a choice.
So that means you just need a strategy for winning the distribution channel game. Product design be damned.
Like most standards, its success hinges on the success of products/projects/whatever that employ it.
The article is talking about how ActivityPub is the future, but without strong products, how can that future be possible?
Idealism alone won't convince people to switch to Mastodon instead of using Twiiter or Peertube intead of Youtube.
Just curious, according to you, is democracy an idealism that happened alone or with a product?
Edit : so, maybe Mastodon will never be as big as Twitter, but the goal isn't to migrate everyone from Twitter to another platform. The goal is to propose alternatives. The title of the submission is a bit click-bait
Both Mac and Windows is successful because retail. People do not want to troubleshoot issues themselves.. They also want something they know. Apple is good at marketing and Windows is something we all know. Linux has just a bunch of small shops and does not have the same brand recognition. It takes much longer for Linux desktop to reach that level of trust. Especially when Microsoft uses their considerable capital to lobby against Linux adoption. Linux adoption is continually rising though.. It is at about 3% right now.
ActivityPub is like the Linux kernel. It is the foundation that other software can use. It took a long time but eventually the idealism behind Linux made it work. It became an important infrastructure that saved money and thus an edge. ActivityPub have the same possibility. It could become the infrastructure of social media.
If enough sites start supporting it, you could get many of the benefits of RSS with the few benefits of massive silos like Twitter and Facebook.
But when you start having global monopolies in various industries that don't care about automatically banning the "little guy" from which they make little money to begin with and when you have governments that are increasingly more interested in let's say "curating" the internet, then that anti-censorship benefit starts to become a lot more appealing to a lot more people.
It's why I'm glad Firefox is not only finally a decent competitor to Chrome but also starting to adopt all sort of anti-censorship protocols and technologies, too (and hopefully there are more to come).
The rank of benefits is, of course, highly subjective. I'm speaking for myself.
How did it do that? It threw away all the technical and usability benefits it had over Chrome, so I guess it's "a decent competitor" instead of "a clear winner" for some purposes, like it once was. Is that what you mean?
The article is either pitching abstractions like "compatibility" or solutions to non-problems like the risk that Facebook might vanish.
Though I'm not convinced aggregation is a big problem.
Does this scale properly and how does it compare to existing solutions like XMPP Pubsub (https://xmpp.org/extensions/xep-0060.html) that is basically built to deliver content, in real-time (trough TCP sockets) and can handle thousands (millions?) of delivered packets per seconds?
I'm building a federated social platform that is fully relying on XMPP (Movim https://movim.eu) and I'm wondering about the limits and different usages of this fresh new protocol.
current-gen AP servers do have an implicit dependency on HTTP and DNS. i've spoken with several people about creating a proof-of-concept AP server that supports gossip-based replication and a few other ssb-inspired features.
Or to make my question more precise : would the gossip model be used only for data distribution and we would still have to register on a node, or would it allow to keep and reuse our data and identity should our usual node disappear?
the idea is to move the key that AP uses to sign JSON-LD objects to the client and do all of the crypto operations there.
a server in this model is an always-on relay for replicating data. you can submit a message to any relay and expect to have it show up on all interested servers.
unfortunately, this will also break compat with HTTP/DNS-based AP servers, but hopefully this is something that the maintainers will be open to supporting.
relevant threads:
https://b.9chan.lol/notice/279590
https://b.9chan.lol/notice/226866
I find it rather disappointing (in ActivityStreams in general), by the way: on the first sight it's a part of the Semantic Web, but the approaches seem to differ from common ones, and the specification itself mentions that there's merely compatibility with one of the serialization formats (JSON-LD).
> but transport and actor resolution are not well specified
There's this for ActivityPub though: "Publicly facing content SHOULD use HTTPS URIs", and bits such as "The outbox accepts HTTP POST requests, with behaviour described in Client to Server Interactions", "clients MUST discover the URL of the actor's outbox from their profile and then MUST make an HTTP POST request". Authentication is not specified, but apparently de facto it will be some hacks on top of HTTP, too.
Putting those two together, it seems to mostly aim the popular nowadays combination of HTTP and JSON (just RDF/semweb-friendly).
You can be certain that regardless what happens
with Mastodon, the network will live on and
flourish. Newer and better software will be born
within this ecosystem, but you will never have to
drag all your friends and followers someplace
else again–they’ll already be where they need to
be.
What is a 'friend' here? A follower?If mastodon.social is shut down tomorrow, a user - say joe@mastodon.social - would lose all his followers, no?
First of all the followers that were on mastodon.social too - their data is gone just like Joes data.
And the ones not on mastodon.social - yes, they would still exist. But Joe would have to make a new account somewhere else and ask each and every one to follow him again. And he would have no proof that he is the same joe that they knew under the account joe@mastodon.social.
Or am I missing something? Is there some public key that is Joes real identity and only he knows the private key?
But it's the same with gmail and everything else like that, I don't see it being a problem of ActivityPub or Mastodon. There's keybase or having your own domain with some index.html where you can direct your followers to a new account is not that big of a deal nowdays. If having to host it somewhere is too much for you - use dot tel tld (https://en.wikipedia.org/wiki/.tel). People that really want to read your ramblings will find you anyway.
Great products though.
Ivy - Naturally grows and spreads and often is seen climbing walls. Maybe in this case it climbs and covers a FB wall :-P Also a play on FB being started at an ivy league school.
Greenfield - Maybe a reasonable name for the protocol that those apps can be built upon? "Ivy's built on the greenfield protocol"
Anyway, that's what I came up with in 10-15 minutes of brainstorming and I would pose that those are much easier, approachable, and just better names than these others that simply don't elicit any sort of emotion (or negative ones).
Names matter, a lot. You need to be able to tell a story that moves people to action. That's what marketing folks do that adds a ton of value. Most open source projects don't have marketing folks so... :-)
A mastodon is a massive, hairy, smelly beast. It's also an extremely well known heavy metal band. For a Twitter clone it makes absolutely no sense. "Toot" as well has some existing connotations I wouldn't think they would want to associate with...just seems like a total non-starter.
Wouldn't this happen as well if the instance my account was created in shuts down?
Also, the stuff that has already been tooted lives on in the fediverse in other servers, so it's not like the toots also disappear from other servers after an extinction event, just like an email server going down doesn't delete the email from everyone else's inbox.
Couldn't Keybase.io solve this? It could track your identities on these servers, and it would exist outside of any instances or federation, but be the source of identity that would go along with any federated instances you are a part of
The issue with distributed systems that rely on public keys is the lack of options to turn to if the keys are lost or compromised. And yes, people will lose keys. Systems that rely on keys for identity need to figure out what options people have at that point to re-establish their identity.
How about backing up accounts in other servers? These could be encrypted with a key which only the user controls. Or perhaps the backup could be done encrypted in cloud storage like S3 (this would involve a paid account, obviously) so the user's presence could be resurrected in a different server?
It might also be dandy to have "failover" agreements, where one server can agree ahead of time to failover users for another server, in case of failure.
If you own your domain name you can have a provider die, and you'll still be able to re import your data on a new provider, assuming you're able to set up a DNS
And that's where you lose most non technical users I guess?
Compare to email, where the MX record provides a layer of indirection. ActivityPub technically has a feature like this using a .well-known file, but it leaks into the user interface n unpleasant ways.
That said, it's wise to maintain a backup account on a different instance. Right now one of my instances is down for unknown reasons, but almost everyone who follows me there also follows my other account.
1. You can readily extract your information.
2. And re-import it elsewhere.
3. You can run your own instance.
(I've had a couple instances die and / or fade on me, which is why I maintain a few presences.)
Maybe my way of using Twitter is particularly weird, but I'd be more disappointed if I'd lose the thematic lists of interesting Twitter accounts that I have collected over several years at this point than if I'd lose my followers.
The above is also the main reason my pasts attempts to switch from Twitter to Mastodon have failed. There's quite much people and content in the Fediverse now, but still not enough that matches my particular combination of interests.
People think it'll resolve or at least mitigate the issues of digital privacy, digital harassment, and digital overpopulation, but in reality will just create ever more wasteful and unaccountable digital sprawl while inevitably recreating the exact same problems (e.g. HOA discrimination, nosey neighbors, hiding all non-conforming traits lest your cohabitants judge you, etc).
Self hosting a service will of course mitigate all of the issues you listed. The control shifts from a company like Facebook into the hands of the server owner.
Of course, the forces are now politically/socially based rather than fundamentally racially based, but the principle remains the same. It's another digital White Flight by any other name.^1
---
1 https://www.technologyreview.com/s/419843/did-whites-flee-th...
And it's probably better for society in general that communities work that way. You don't want millionaires and oorporations controlling discourse, and in many cases, there are groups and communities who simply physically cannot use the same platform (those on complete opposite sides of the political spectrum for example).
I was on an emulation forum for several years in the early 2000s that had people from every walk of life, every stripe of politics, on essentially every continent of the planet, yet the number of regular users was still within Dunbar's number, for years. That's not going to happen nowadays. If you can reasonably attract ten users, you can and probably will attract several hundred, or more, in much smaller timelines.
This is borne out by looking at Mastodon instances right now--there are ~200 out of ~3000 that fall within reasonable estimates of Dunbar's number and there's no guarantee that any of them will be stable even in the short term. It's a Great Filter for comprehensible human communities.
Secondly, the notion that by federating or centralizing, you can avoid or generate discursal control is pretty unfounded. The 2016 US Presidential election and Brexit are more than enough evidence of that. People can and will use any capacity within their reach to influence discourse, regardless of who owns or doesn't own the infrastructure.
I'd argue that federating generally allows for more pernicious discursal control by monied and corporate interests, solely through the lack of singular points of control. If you can automate contact and distribution, which is already trivial, you can spread whatever you want as far as you please as much as you like, knowing that if 90% of administrators remove it, you still have 90% possible impressions and 10% of instances that haven't removed it. If the content is even remotely infectious, it'll immediately spread back to the 90% by the 10% of users, anyway. Chain-letters are great examples of this in action (and in their more modern forms "upvote this if," "retweet this if," and "like this if").
Control isn't binary. Facebook can exert much control over discourse while still being vulnerable to powerful actors.
The idea that I'm primarily disagreeing with is that Facebook, Twitter, et al. can be hegemonic in a user-populated space. I don't think they can. They can certainly exert large amounts of influence and constrain it, but it's not monolithic and they don't control it. Federation only makes that influence more invisible. It certainly doesn't remove it.
Just because not all problems can be solved with Mastodon, and the like, does not mean they are not worth pursuing.
Are humans in large numbers capable of interfacing with individual human beings without engaging in pernicious behavior? The answer, as anyone online in the last twenty-five years is a resounding no. Are humans in large numbers capable of behaving immaculately when it comes to preserving their own or their customer's privacy? Once again the answer, as anyone online in the last twenty-five years (and several decades longer if you include proto-business networks) is a resounding no. If you add progressively more humans to anything, does the output improve? If the metric is human satisfaction, the answer is no. If the metric is the rate of return in a Ponzi scheme, then yes, okay, you've got me there. The cause of almost all problems is solutions.
As far as social media goes, it's literally designed to use people to promulgate human-motivated pseudo-information for as long as humanly possible. It's not for "socializing" or "meeting people" in the same way that TV shows and movies aren't there for entertainment. It's to sell the viewer's attention to people that have anything but their interest in mind. Moving to federated enclaves is just further deregulating an already throughly pernicious industry.
Once I got doxxed by bloggers from one end of the political spectrum who thought I was a blogger from the opposite end. (We have similar names, but the doxxers put out all of my info. I generally try to avoid making extreme political statements publicly on the internet.) Even after I got my info taken down, someone archived it and the archives got passed around on Twitter, prolonging the mess. Even now all that stuff shows up if you google my name (which I could see being an issue in employment and housing searches, for instance).
I'm not asking anyone to care about what happened to me, I just want people to think about the consequences of a system that can't be moderated. If some bad actors can continuously re-inject false information about normal people into the internet, it can have negative effects on the lives of those individuals. Advocate for an uncensorable internet all you want, but you should also be honest about the potential ramifications.
Ever since quitting social networks I've been looking for a way to push content to close friends and I really had to fall all the way down to email before anything worked. So I'm hopeful for some slightly more tailored technologies to step in.
You can host your own instance, of course, but that requires time/money for maintenance, and not everyone will do this.
For example:
joinmastodon.org gives me two dropdown boxes at the bottom of their frontpage. One asks what my interest is, the other asks what language I speak. Then it ajaxes in some links to different instances which (I suppose) are geared toward the interest I chose.
Does this mean that for each interest I must sign up on a different instance, controlled by a different entity with their own terms of service?
Edit: clarification
there's added value to the local timeline, especially in smaller instances when you've just joined, because it allows you to find like-minded people. If you could do without that the easiest option might be to join a large instance or start your own, but both come with discoverability issues.
In short, no, you don't need to, but you could (just like you can make multiple emails) if it helps you separate stuff
>I don't expect any major changes are needed for compliance, which is why it's been pretty low priority. it's just a matter of getting a document together that better informs admins.
Mastodon has all the features needed for compliance, and does not collect or store any data that's not for its primary purpose.
edit: I didn't see that this was in the context of GDPR.
Also, doesn't ActivityPub allow closed groups?
It's specific to the use case and what guarantees you have, and not a strict property of a protocol.
personally, i don't care about GDPR since i'm not under EU jurisdiction. even so, none of my servers store logs and i don't require an email address to register.
So maybe we should talk about the downsides of ActivityPub?
However, most of Google’s petabytes of video are inane "cat videos", people’s personal uploads that only ever attract one or two of their friends to look, or shills, and would it really be such a shame if their content couldn’t be hosted somewhere?
And, not everyone has the necessary stuff to be able to seed a video like that. A very large part of the world has their phone as their primary computing device. You're not gonna be able to seed a video from a phone on a cellular connection.
These are made for things like that.
The idea with a eG is, the owners are also the customers. For example, if there is need of appartments, people found a eG to pool the money to build multi-appartment houses where they self live in later.
Since the customers are also the "stock owners" they elect the board.
I think this fits perfectly for these federated social networks.
I've commented about this before, email is federated, and we saw what happened there: Everybody moved to gmail. Federation will lead to all the same systemic issues.
A better approach is to use P2P/decentralization, rather than a hosted instance owning your account/identity, you own your account/identity and you can reuse it across any/all services. Even if those services die or go away, you will always exist.
This isn't just "talk" though, we've spent the last 4 years of our lives working on giving away truly Free and Open (MIT/Zlib/Apache2) software to help people build stuff like this:
https://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wi...
Now there are dApps in production that have pushed terabytes of daily traffic. We're still working through some scaling up kinks, but we're making fast progress.
What are the systemic issues? Why did everybody move to gmail? I liked the ability to just let my email collect and search it. I liked the spam filtering. That's why everybody moved to gmail.
The systemic problems I saw with email had to do with server security and spam. How is it that those problems aren't solvable federated, but solvable P2P?
It is true that people switched to gmail because of what you say. I don't disagree.
The point is that even with federated services, consumers will choose the most convenient one (and they should!).
But that still means users are dependent upon that service. Imagine if Facebook became ActivityPub protocol compliant.
They (like Google with Gmail) would have more resources to make the most convenient/amazing Mastodon experience. Is this itself bad? No. Is it that companies have more resources, that is bad? No.
It is simply that the following is better:
If you have a P2P/decentralized protocol, even if Google/Facebook were to create a killer app/experience for it that everybody "switched" to, there...
- data
- account
- identity
- friends
- etc.
Would and could still exist regardless of the backend (federated, centralized, or not). This is not true with ActivityPub / Mastodon.
Imagine if you could have switched to gmail and automatically "kept" all your emails? And then you could just as easily switch to a different competing email interface, and it "kept" all the emails/data you had in gmail?
That is the kicker here, by "kept" I do not mean "migrates from one to the other", by "kept" I mean the application interface just reused the same existing underlying data.
Extra point:
Very few people are going to switch for encryption/privacy alone. But if gmail/activitypub/facebook/mastodon was P2P/decentralized (like is possible with our system), then you can have competing apps (analog: gmail vs hotmail) that are still end-to-end encrypted (analog: neither gmail's or hotmail's servers would be able to read/decrypt your data) because that is happening in the app (the "client") not on the federated server (like with activitypub/mastodon) or the centralized server (gmail/facebook).
Everyone moved to Google because they offered (I think) a full gigabyte instead of the mere megabytes that was standard at the time. And it also had a really slick web interface that didn't require setting up software. People could finally use it for work, or to send pictures without managing space or an email client. "Never delete anything" was the big selling point.
Every mail host has a web interface now and provides lots of space, but it took too long. Inertia keeps GMail dominant, not centralization.
In other words, if you don't explicitly take action (i.e. follow) nobody can send you a message on Mastodon? I thought that was how it was implemented, but please correct me if I'm wrong.
I'd argue activityPub isn't the future, until it root causes the reason for anemic adoption.
Also, the best use case might not be in transferring an existing centralized app onto activity pub
https://gdpr-info.eu/art-20-gdpr/
A regulator / court would have to look at what is "technically feasible" for Facebook to implement, but given that there are multiple interoperating projects supporting ActivityPub (with much smaller resources than Facebook) I think it would be hard to argue that Facebook couldn't add ActivityPub support.
At a stretch, Facebook might argue that data portability only requires them (as data controllers) to publish your Facebook posts to specific accounts on other services, and doesn't require Facebook to accept inbound posts from competing platforms, but I don't know whether Facebook would want to be in a situation where their competitors have access to data on Facebook but Facebook doesn't have similar access to data from their users.
If you ran the Facebook page for a club or society, then much of the metadata about the events you created for it would likely not be covered by the GDPR; but for a personal Facebook page, if you were publishing information about an event that you were organising and were planning to attend, it is more likely that a useful amount of metadata would be covered.
I don't know whether ActivityPub has a standardised way of handling event invitations and RSVPs, but the existence of things like the iCalendar format and its various implementations might go some way towards making the "technically feasible" argument.
I think I can name a single person I would follow who is on Mastodon, honestly can't think of a #2