Solid – Reshape the web as we know it
solid.inrupt.com
solid.inrupt.com
Solid doesn't even seem to work. Following instructions for "learn[ing] how to install and run your own Solid server," I successfully installed a single-user solid server. Great, now I have a single-user setup that is supposed to give me control over my data. So how do I authenticate as the single user? No clue. This thing is so secure, not even I can get my data!
I would have expected something more useful from the inventor of a technology that so many people can use today without having to think much about it.
EDIT: I deleted and started over. I still don't know what happened, but now at least I can create an account and login. Still not quite sure what I can do, now.
Is it actually worthwhile to solicit this kind of “ally” interest? I would think you’d attract mostly onlookers, people who are puttering around thinking about these topics. People who may just gum up the mailing lists.
Is it really likely to attract actual contributors? I’d think that comes more from providing something that solves a real problem for some obscure group of people.
a new, far reaching platform for internet data exchange launching without a basic proof of concept seems like a clear and obvious gap that should have been filled before launch.
A->B != !A->!BSo, it is just "release early, release often". So, the code and the spec has been out there for a long time. I mean, some of this stuff is really old. Us geeks have been thinking about decentralized social networking since the dawn of ages, and it seems like the rest of the world is starting to wake up to its necessity too. So, I think the timing is pretty OK now.
Like, Linux didn't come with a well-polished example either... It wasn't even intended to out-do Minix. :-)
I guess you could say that we could say even more clearly that this is a prototype, and we have a roadmap where it will stay a prototype for some time. But we are seeing people finding it interesting that we're actually not trying to engineer something from the ground, we are seeing what kind of impact we can have with pretty well tested Web technologies. I suspect we have a lot less development to do to have a great social impact than you'd have to do if went full P2P.
At the same time, there is a large graveyard out there of failed decentralized social networks, so we are under no illusion that this is going to be easy. It is going to be pretty hard.
Still, I don't see any reason why we should be sub-surface any longer.
I read the website and I don't really get it. If I give an app read access to my data, they've got a copy. Maybe they don't have the canonical copy, the original, but they've certainly got A copy. How do I have control?
As far as I can tell you've reinvented Facebook with a better API. Why wouldn't someone just embrace and extend to take control? "Oh yes, we made some changes to our PODs so you won't get full functionality with other people's PODs. You can just move your data to our company with a click of a button, CLICK HERE, and everything will work great! Also, we no longer support exports of data, sorry. But we'll take really good care of your data, we promise!"
Maybe I'm dumb and I just don't get it, that's certainly possible. But maybe you're not doing a good job of explaining it.
https://github.com/solid/node-solid-server#testing-solid-loc...
> In order to really get a feel for the Solid platform, and to test out solid, you will need the following:
> 1. A WebID profile and browser certificate from one of the Solid-compliant identity providers, such as solid.community.
EDIT: Seems if you run `solid init` and accept the defaults, it will configure a local WebID provider that you can register to on first use.
I will love standing in line at my local DMV and waiting for my WebID profile to be approved.
In the good old days, only the Church could publish books, so everything that was written down was thoughtful and true.
But we are on the net so nobody knows for sure.
Voting machines and nuclear reactors get hacked with code - which is just something people say on computers.
Hmmm, a centralized WebID eh? No thanks.
Even the "How it works" page [0] indicates how your solid pod becomes your id.
"In order to prove ownership of your data, you need a way to identify yourself. Rather than relying on a third party, you can use your Solid POD to say who you are. So no more “Log in with X” or “Log in with Y” on the Web — just “Log in with your own Solid POD”."
It'd be nice if it didn't replace one type of SSO with another, but proposed a way that SSO wasn't required at all.
“Solid has taken 15 years of development work to finally deliver this.”
I probably missed something, but I didn’t see mention of Solid being taken through a standards body, either (even his own one). Web protocols were standardized early and were royalty free, with working prototypes. That helped lead to quick adoption.
I think Solid needs to start with cleaning up their communications as the whole thing is hard to understand.
The w3.org site describing solid is actually more readable: https://www.w3.org/community/rww/wiki/SoLiD
I, for 1 and super excited to take back my data.
Yes, That is very similar to how I felt when I first found the web. I forget how early it was (1991?), but I was on gopher and saw the docs and a few small sites and had the same thought -- mildly interesting, but not much there. But it took off quickly, and I'd say within 2 years from my first seeing it, gopher was dying, browsers were coming out for Windows and I was trying to explain to people that this was going to change the world.
Will this change it, too? Who knows. But I'm not going to dismiss it just because it is starting small.
It did feel like a new beginning.. combined with a "that's it?", combined with a "how will they ever get everything online?" At the time, no one was really online or knew what the internet was. Protocols like Gopher, Archie worked ok, and there was a BBS world..
Still, the web just felt unspeakably different to what came before in an indefinable way.
If application logic can be separated from data in Solid, this could be meaningful evolution to the web.
Imagine plugging in all of our existing data in one app or database into any other app or database.
One of the more promising initiatives I've seen recently is Patchwork, which is a kind of Facebook or social network that runs on the Secure Scuttlebutt (SSB) protocol.
It's a user-friendly app that you can download, and after getting over the hurdle of adding a 'pub', you can get things going pretty quickly.
What frustrates me is that I can imagine quite a few people would go through the trouble to install the app, non-geeks included, even though it means going to a weird .nz domain and even though simply searching for 'Patchwork' on Google isn't enough. In my experience there's a subset of the general population that will be willing to do this.
But then they get an app that does nothing, and they'll have to figure out that to use the app, they need to add a 'pub' server. Doing so requires a bit of searching and then adding the pubs to the app. I'd say that's a bridge too far for most.
The same goes for developers. Patchwork is written in Node.js and for various reasons there's no easy way to write clients in other languages. Even though I am familiar with Node.js programming, it's enough of a hurdle that even as a fan I just resigned myself to just wait until something more user-friendly shows up (Elixir client plz).
My point is that Patchwork/SSB has been one of the best-implemented things I've seen, and yet it sucks enough that I hesitate to recommend to 'regular' users or developers. And the frustrating thing is that, considering the effort involved, it wouldn't be that much more work to bridge the gap. But doing that is just not interesting enough, and so the whole thing remains a niche that will probably die in due time.
https://www.w3.org/community/rww/wiki/SoLiD
https://www.w3.org/DesignIssues/LinkedData.html
inrupt.com site is just marketing hype and crap experience.
Who needs a product, when you have a presentation.
Does anyone else feel nostalgia for the pre-"web app" days of the internet? I'm talking about personal sites on Geocities and web rings built on communities of shared interest.
The browser was an application for navigating hyperlinked information. Other applications include email clients, news readers, FTP clients, and IRC clients. You never had to download a megabyte of minified JavaScript just to read a 500-word article; you never would, since it took about ten minutes to download a megabyte on a blazingly fast 14.4 modem.
For all the people lamenting the loss of the old internet, most of it is still there(irc,ftp,rss,ncurses email clients) -- you can still use it. You should probably ask yourself why you aren't.
Because there's no gopher client for macOS.
I bet if Google indexed Gopher sites at the outset, Gopher would still be a thing.
Gopher pretty much died long before Google was a thing. Here's a good article: https://www.minnpost.com/business/2016/08/rise-and-fall-goph... (lots of interesting comments below the article from many of the people involved)
They have very little use. There's also a web proxy:
http://gopher.floodgap.com/gopher/gw
Browsing it makes clear why Gopher would not still be a thing, except in the same sense that there are hobbyists who maintain Model Ts and steam engines and whatnot. For a time, Gopher was a miracle and a wonder. That time lasted about a year. The web does all it does and infinitely more.
There is a vibrant international community of people still on gopher, and a lot of us run our own servers. Check out gopher://gopherproject.org
There you'll find a getting started file, and other useful things such as a curated site listing (think DMOZ for gopher) called the Gopher Lawn.
But hypertext is an application, and the web was always about hyperlinked text as well as embedded content. The <script> and <applet> tags and now defunct concepts like VRML demonstrate that the "only static, only hypertext" version of the web you miss were more due to the primitive nature of an undeveloped platform than a state of grace and purity which has since been defiled by the ability to do computation on the web... the intent for the web to host both static and interactive content was there practically from the beginning.
>Does anyone else feel nostalgia for the pre-"web app" days of the internet? I'm talking about personal sites on Geocities and web rings built on communities of shared interest.
I don't. I like being able to watch videos and play games on the web, and buy things, and so on.
And webrings were fun, but modern social media offers a much bigger and more varied set of communities than the old web ever had. I know that's an unpopular sentiment to voice on HN, but as far as most end users are concerned, Reddit and Twitter and even Facebook are useful in ways that IRC and web chatrooms never were.
Most of it is undiscoverable, private, or short form. There are very few people putting up public multi page tutorials or project summaries in the way that they used to.
I don't think there's much structural about Yahoo Answers being what it is. I think it's mostly the population.
Social media is just about as mainstream as the telephone now. Everyone who was on those forums and BBS systems and IRC is probably also on social media.. along with their parents and kids. The web long ago got too big to draw narrow demographic conclusions about. And everything you mentioned apart from BBS is still around.
I mean, my elderly mother uses Facebook and I wouldn't call her "obsessively upvote/view focused." She is obsessed with sharing pictures of her grandkids doing everything, though...
As exciting as those days were, I wouldn't want to go back to dial-up, CRT monitors, no-broadband, no-wi-fi, no-wikipedia, no-dropbox, no-stackoverflow, no-git, no-digital-distribution, etc.
And yes there was broadband in the old days. It just wasn't widely distributed. It was mostly at businesses and universities. As broadband became more common, web sites got needlessly heavier.
On the plus side, future generations will never know the horrors of a RealPlayer "Buffering..." message.
* Unless you really needed punch that monkey.
100% this. About 8 years ago, I had LIGHTNING fast loading times on every page I visited. 800-1000ms was average, on a connection that is slower than mine is today... Now 4-8 seconds is average, and the new Gmail takes 10-12 seconds to load.
I'm nostalgic for the days when the web was faster and more functional than it is today.
As for figuring out how to turn the web into an app platform, Netscape and Sun might have gotten farther in the 90s if it wasn't for Microsoft. There used to be a saying in the 2000s that MS held back technology for a decade.
There's also something about the snappiness of desktop apps on hardware 1/100th the speed of what we're running now that I dearly miss.
I don't understand the premise. Tumblr is / was over ten times larger than Geocities. It did what you're describing. It was still wildly popular with young people just as recently as a few years ago.
With Geocities you could see millions of high school art students demonstrating for the entire world that they don't know the first thing about design or color.
Tumblr is the epitome of a walled garden. The flowers look pretty, but you still have to plant them in neat, orderly rows. Even Facebook's Pieces of Flair offered more of a creative outlet.
You can still make oversized blinking purple Comic Sans text on a black background above an animated "Under Construction" GIF. But you have to do it in CSS.
They've moved to DeviantArt now.
Douglas Adams expressed this well:
“I've come up with a set of rules that describe our reactions to technologies:
1. Anything that is in the world when you’re born is normal and ordinary and is just a natural part of the way the world works.
2. Anything that's invented between when you’re fifteen and thirty-five is new and exciting and revolutionary and you can probably get a career in it.
3. Anything invented after you're thirty-five is against the natural order of things.”
For me the stage that came after this is, "Well, change is going to happen, so either I need to get off the merry-go-round or I need to learn to like it." Geocities and FTP clients are as dead as fan-fold, green-and-white line printer paper, and for the same reason: we found better ways to serve the same needs.
Justifying one's nostalgia by pining for the days of 14.4 kbps modems doesn't make a lot of sense. If they were good, then surely my first modem, a 300-baud acoustic coupler was better. Although I feel a tug of nostalgia when I see one, it wasn't better. Optimizing to save a resource we have in abundance makes as much sense as depression-era grandparents saving bits of string for possible reuse. It wastes that most precious of non-renewable resources: your time.
I also don't find that new smartphones have much touch-based interface latency; but even so, that kind of latency doesn't have anything to do with the internet, nor the halcyon days of late 1998. To my recollection browsing the web in the late 90s was far more exciting but also far less useful than today.
The modern internet has a lot of inefficiency, but I don't see how you could seriously claim it's slower than what we had 20 years ago. Sometimes heavy web applications are relatively slow because they're underoptimized, but that's less of a technology failing and more of a developer failing. Most websites load spectacularly faster, and perform better, than all but completely static HTML websites from two decades ago despite having much larger byte footprints.
Some websites overloaded the 98 web by being an entire page of diced and sliced graphics that assembled the page. Most were mainly text and appeared pretty much instantaneously. Images came slower than the article you could be already reading if you were on dial up.
One of the things I dislike about the current web, is how slow most sites have become - mostly thanks to an absurd overhead of JS and third party SaaS just to display a text article with a few pictures. The number of sites that will unreadbly bounce the content around as various web fonts, icon fonts and other trivia load is pretty ridiculous. It's the main reason I now browse with JS off and white list JS for a tiny few.
It's not just age, it's a sense of loss. I can still go down to the store and buy milk in bag form, just as I could when I was a kid, so I don't feel nostalgic about it even though it's old. I feel nostalgic about the web of my youth because that place is gone now and it'll likely never come back.
In tech circles we like to obsess over new technologies and all of the amazing new possibilities they've brought. We don't spend nearly as much time talking about all we've lost.
This created space for passionate amateurs to create content for their niche. You got wonderfully personalized, quirky sites that didn’t look weird or suspicious and, importantly, actually got traffic (or what passed for a decent amount of traffic at the time.)
The rise of Google, security issues, “walled gardens”, blogging platforms, and YouTube have basically ended the ability of a new amateur site to get a significant amount of new traffic. Internet stardom has moved to YouTube, Twitter or more specialized communities like Reddit, StackExhange, or Wikipedia. The Wikia networks have driven out most need for fan sites. Social networks are a better sharing mechanism than personal blogs meant for keeping friends and family up to date.
This all has had the effect that the internet “feels” far more structured and professionalized than its early days, and IMO is much more a “winner take all” environment for content. I miss the amateur web the same reason I go to high school sports and watch low ranked college football teams- the play may not be as good, but passion is the same, the games feel more human and occasionally you see unexpected flashes of brilliance, beauty, and serendipity that you’ll never see in the professional world.
90% of the web apps that are useful to me would be equally useful as native local apps with local data. As a native MacOS or iOS program they would be hugely faster, without latency, and just as useful out of signal area (still common enough that it happens daily for me).
That would leave me to choose which I wanted to sync either internally or via something like dropbox.
Most of the innovations in the browser that enable apps also promote and enable tracking, auto start videos, and JS loaded ads, and use of the browser as surrogate OS. Mostly I find this a serious misstep. I don't miss bad design and sites that were cut up bits of image etc.
Definitely! There's a lot of that sentiment over at Micro.blog [1], which has built a community of writers & indie software developers (especially developers from the RSS era, if you've heard of MarsEdit or NetNewsWire). There's an emphasis on personal blogging, keeping things simple, and using dedicated desktop/mobile apps (usually made by solo/indie developers) for each task, instead of the website. And as part of the IndieWebCamp [2] projects, there's even people making web rings again [3] as well.
There was also a search engine someone showed on HN recently, that didn't have a crawler - the only pages listed were the specific pages (not domains!) that people submitted to the index. That gave the searches some serendipity, you never found what you searched for but stumbled on something that someone else thought was interesting anyway.
[3] http://th3core.com/talk/traffic/i-made-a-web-ring-5-days-ago...
http://wiby.me is a search engine that indexes pages like the ones you miss. Full disclosure though, I made it.
I think the future is the robust content addressable distributed web. Which could give developers the same flexibility, and users the same friendly experience, but with everything virtualized in a peer to peer mesh. I’d like to see the developer smoothness of Solid married to future-proof content identifiers like this: https://github.com/ipld/cid/blob/master/README.md
I'm a bit outside my wheelhouse, and I don't fully understand what Solid means when they say "You own your data", but with content-addressable strategies, often users _don't_ really have ownership once something is published in the sense that you can't delete or change something if anyone else is serving a copy.
I mean, you own it, but so does everyone else. I think the traditional(?) concept of ownership you are referring to, that allows people to "delete" information is very unnatural and feels akin to trying to reverse entropy. You can't unring a bell, and you can't delete data from the world.
This is important, because for physical artifacts having the right to destroy/demolish means having the right to create new things in its place (if I inherit a historical monument castle and I can't f demolish it to a pile of sand by my liking, than that's a scam, I don't really own it; also I might want to demolish it for aesthetic/informational reasons too, to "wipe" a part of its history from the human collective knowledge base).
And for informational artifacts, the right to "undo" or "take back" is also important, because the fact that what you say/publish is there to haunt you forever will have a chilling effect... lots of interesting things will go unsaid unwritten.
You have to burn books/libraries/things from time to time, otherwise everyone becomes afraid to write new books or build new things!
And on a physical level death has the same liberating effect. You know you're gonna die sometime anyway, so you can enjoy that cigarette, it increasing your risk of an incurable cancer by 1e-3 percent will not have consequences that will haunt you forever... Death and destruction are necessary for true freedom, at least for the kind of freedom I want to have.
Things like block-chain/graphs combined with content adressability bring significant limitations to FREEDOM. Endless responsibility and accountability for everything you've done and said would make life of all creative and disruptive people a living hell. Heck, if you're not free from at least some of the consequences of your actions, then why do anything at all, why even carry on living.
And on:
> You can't unring a bell, and you can't delete data from the world.
Yes you can, if you kill someone, a part of the information that is in their head and haven't been shared with anyone yet will be lost forever. That's a good thing imo. If everyone who's heard the bell is dead and hasn't told about it to anyone... has the bell truly rung? The information that it has is irrecoverable now. And you can thank your friend entropy for that impossibility to recover this data and for the liberating effect that this can sometimes have ;)
There are other definitions of ownership more akin to stewardship. Some circumstances recognise others interests and therefore limit rights and elevate responsibilities.
This, arguably, sensible.
Legally speaking then, you don't own information about yourself like your address or past actions. The government won't let you erase that information. The only way to make your friends and family forget it is to kill them, which is obviously highly illegal.
Even with efforts like Right to Be Forgotten, Europe isn't positing that you actually own information about yourself in the same way that you're doing here. Right to Be Forgotten is a) balanced against public interest, and b) only applies to information access and indexing. Right to Be Forgotten doesn't mean that you can demand a newspaper burn all copies of an article it wrote about you.
The reality is that "ownership" means different things in different contexts. There's not a single definition. When we talk about "owning" data or Intellectual Property, we don't mean it in the same way that you "own" a wrench.
How can you own something that is inside my head?
If I put it there, I own it, and I should be able to destroy all proof that it's not purely a fabrication of your imagination. (Sure, you can still know it and use it to guide your decision, but it shouldn't be legally valid any more, and there should be no way for you to convince others it's true.) Yeah, obviously if it's in the heads of other people too, it would be more accounts in favor of that information being authentic, increasing the probability that I am lying about that in a legal situation. But key thing would be that it's a probability. I can destroy the certainty. That could swing depending on context, maybe I'm more trustworthy than the group of people arguing for the authenticity of that piece of information.
Obviously there's great deal of criminal activities that can be protected by going too far with this, so it's a question of "tweaking the dial" until we get the right amount of informational "light" and "darkness". As Jung said, there are some who need light, and some who thrive in the shadows...
Second, from the inside, this simply isn't how memes work. Memes are designed to propagate and survive on their own. If your ideas are at all good or interesting to society, and they manage to become memetic, then you have zero recourse, just as if you were Patient Zero for some new plague. You shared it, and unsharing is impossible, regardless of how moral you might believe unsharing to be.
Seriously, take some time and think about it: How many of your ideas and concepts are actually original to you? Almost none of them, right? And if you're honest with yourself, pretty much every concept seem inextricably linked to others. Really, what matters is the structure between ideas, and that can't be shared, since it's private to each person's mind.
Anyway, if this doesn't sway you, I'm okay with it; you're purely a fabrication of my imagination.
But this is even more problematic. What if you don't own the thing being used as proof? Do you get to destroy it just because it could be used to incriminate you?
For example, if I take a photograph of a public non-performative event, I legally own the copyright on that photograph. The photograph itself is treated like a creative expression. So should you be able to destroy my photograph? Because the law says I own that, not you.
With Right to Be Forgotten, you might be able to have that photograph delisted from Google images, assuming you had gone through a lengthy court process based on multiple determinations of how public the information was and how harmful it was to you. But you can't come over to my house and make me delete it.
If I go onto a forum later and say, "yeah, I can prove this thing happened; here's a photograph", I haven't done anything illegal. Do you think that should be illegal? I feel like at the point where we're talking about destroying physical evidence of something, maybe this is going a little bit too far?
...and of this: clearly you want just some information to be impermanent or undo-able. I wouldn't want all information about myself to be delete-able. Just pick a class of infos, like "tweets" or "tv interviews" etc. And delete-able shouldn't mean modifiable. If I'd delete a year of my "certified resume" I'd still end up with a "blank year" that wouldn't look good.
There's room for forgettable channels of communication and publishing, from which information can be permanently deleted, and these should also have legal protections ensuring that if someone retains copies of that infos then they are inadmissible in any court, even if they were public at some point. A fully networked society needs such safe-spaces too...
If the information is inadmissible in court, then who cares if there's an immutable copy someplace? We make information inadmissible in court all the time without requiring it to be deleted.
We even make it illegal to ask about age, race, and religion in job listings, and we aren't deleting any of that information. I'm not 100% sure what the problem is.
Yes, that's the root for a lot of information censorship. Society as a whole is still very immature and tends to pretend that not every human is flawed and has a past with mistakes. I hope that we can collectively move past that at some point.
I guessing it would be less likely an issue if your friends / associates have a downloaded copy of your messages for the past year if each week a different key pair was made to decipher a section of the data store or something.
This is important, because getting rid of a content-addressable strategy doesn't actually protect your data. In practice, running application logic locally and having small private swarms is better for privacy than what we have on the web right now.
So say you're hosting your own data at a traditional URL and on IPFS. Well, if someone wants to save your data, they can do it with the same ease on both. They just download your stuff and save it. If you take your data down from IPFS and from the traditional URL before someone saves it, then your data is safe. So, again, same situation.
What IPFS says is, "if someone re-hosts your data, can we cryptographically prove that it's the same data? And can we refer to the data by that signature rather than whatever the host is this week?" So, if your data goes down but someone else found it and rehosted it, stuff like URLs would still work (although in practice, the URL you'd use would be a pointer to the most recent version of your site, so even that isn't necessarily typical).
This is a minor loss to data ownership because you can't literally invalidate a URL if other people are willing to host it. But that's the only thing you've lost. Under the web as it exists today, someone can still take all of your images and rehost them on Reddit or something. If you think it's easy to prevent that, go let the MPAA know what your strategy is so they can end piracy forever.
So the problem with IPFS/DAT isn't fundamentally any different, it just means that URLs break less often, there are fewer Man-in-the-Middle attacks on your website, and there are fewer download links that lie about their payloads.
I'm not convinced it's worth investing time or effort into something that might make it harder to address the problem of URLs in the future. I get "solve one problem at a time", but I feel like URLs are so fundamental of a problem, you have to get them right first before you move on to other problems. And for the most part, we have gotten them right -- build whatever web replacement you're working on on top of DAT/IPFS, unless you have a really good reason not to :)
A decentralized web is a web where content can be re-hosted and verified by anyone.
https://qbix.com/blog/2018/08/28/vision-for-a-new-truly-dece...
In order to have a permissions system, you have to have permissions. For example: read:photos, write:photos, read:running_data, etc
In order to do that, there are a few hurdles:
- You have to define ACLs for every type of data stored in everyone’s POD.
- More complex is to define what parts of what data certain ACLs give access to. For example: I may want to provide heart rate data from my runs, workouts, and temperature data but not GPS. That’s getting very granular
- Since every app will have different or possibly new types of data, having a central standard for data types and ACLs will be tough.
- You’ll also need a mapping mechanism for where the data is stored and how it’s named and the formats that are being used. Even within a single app, you can denotmalize data and store it in multiple places for different purposes.
I like the principle of this but it seems very challenging to adopt. I look forward to seeing someone solve the above challenges.The Web Access Control spec is here: https://github.com/solid/web-access-control-spec . In principle, we could support really granular data ACLs based on that spec, the ACL applies to a URL, and you can give any datapoint a URL, so problem solved. In practice, it may become a bit cumbersome, I suppose it remains to be seen how you'd do it in practice, but I think we have a really good start there, there's lots of stuff that can be realized now.
There's a wealth of academic research that applies to these problems, the problem of the Semantic Web community has been that it has been strong on the academic stuff, but not very focused on truly useful stuff that can be done right now (to quote AaronSw). That's one of the things that Inrupt sets out to change. But the good thing is that we're not setting out to solve really hard problems in the dark, since we have that academic research, we know pretty well what's hard and what should be within reach.
We’ve seen this issue on mobile where users give access to certain capabilities on their phone and then are surprised at how apps use them (camera, mic, location, etc).
The challenge is how to describe these things in the way that the average user can understand and trust.
ACLs, capabilities, etc are generally easy for developers to consume but much harder for the average person to understand.
My main thought is that there will need to be some standardization of data and how it is consumed for this to take off. If a consumer is providing access to their location data in 15 different ways for 15 different apps, how are they even suppposed to keep track and understand that?
Standardization of ACLs/access has become standard on mobile and the permissions are very coarse so they aren’t overwhelming but it often leads to unwanted results. I’ve yet to see someone implement ACLs in a way that is easily consumable by the average user.
As noted, I’d love to see that happen. It’s a tough problem to solve but one that would benefit all users.
(note that URLs can't be a secure handler, since it's just a string that anyone can create. But a URL plus a cryptographic signature could be)
I really want to like this, but if I spend 15 minutes clicking the guides, the “build a solid app on your lunch break” link, and going all over the site, and I still don’t have the foggiest idea of the actual engineering mechanisms, something is wrong.
It is hard for me to believe some consortium of really knowledgeable web architects and inventors made this. It feels like a PR website with attractive purple colors to make me feel cozy. But I want to know really how it works!
I do have most respect for TBH and I would consider everything he thinks and writes about, but this does not sound too good to me either.
The idea of linked data and semantic web has been around for almost two decades now and I have yet to see an application, technique or site that amazes me. On the contrary, most of the things in this space I have seen are bloated, unusable or simply unnecessary - whereas every paper sounds like revolution is around the corner. In that combination, it is the worst of both worlds: academic output, that claims practicality and fails to deliver.
Peter Norvig put it best, when he said: "The semantic web is the future of the web and always will be."
A recent discussion touches upon a few problems: https://news.ycombinator.com/item?id=18023408.
RDF, LDPs, and Linked Data in general are all child projects of the Semantic Web movement, and nigh-on inseparable from it in practice. The venn diagram of their user communities is one circle.
Freebase as a prominent example, was pointless for an average person. There was no reason for it to exist in regards to doing something for millions of people.
Wikipedia, Quora, Stack Exchange, etc. are what people want to consume. Until the semantic Web leads to a dramatic improvement on those types of end user products, it's not going to matter.
The failures of the semantic Web are pretty much the same as the failures of the Web of evil, i.e. the internet: 1. You cannot make people tell the truth. 2. You cannot always determine when someone is not telling the truth. 3. You cannot always make people do things the right way. 4. You cannot always determine when someone is not doing things the right way.
So, you are correct. The true creed of each hard-core technologist is: "Everything would work great if only everyone always did everything my way."
The Semantic Web hasn't "failed" and it's not something that end users need to see, know about, or care about directly. It's those technologists that use Semantic Web tech and data to build applications for the end users.
Freebase as a prominent example, was pointless for an average person.
Likewise Github is pointless to an average person. Because the average person isn't who it's meant for.
Norvig is a smart guy, and maybe he meant something different by that quote than the obvious reading, but at first blush that sounds silly. If he's saying "The semantic web "always will be" the future because it will never happen, then he's objectively wrong. The semantic web is here and has been for a long time.
The key thing to remember though, is that the semantic web is about machine readable data... semantic web technologies are not, by and large, something end users interact with, or even need to know about, themselves. They empower things for developers, but are mostly invisible to the average user.
Google, Yahoo and other major search engines have been extracting semantic data - in the form of RDFa, Microformats, etc., - and using that data for at least 10 years now.
OTOH, if Norvig mean that it will always be the future because it's always evolving, adapting, and growing, then, well, yeah... of course. And that's exactly where we are. Semantic Web tech just keeps getting better and more useful.
Ted Nelson invented the idea of hypertext in the early '60s. It wasn't until the creation of HyperCard in 1987 and the WWW in 1990 that there were practical applications of hypertext that you could put your hands on and use.
Ideas can take a long time to mature.
It’s impossible to find in the impenetrable marketing speak, but presumably the backend here is some off the shelf LDP? Existing LDPs tend towards being profoundly unscalable; typically the number of clients they can handle without choking per second is in the low single digits. All of the implementations I’ve seen are more concerned with adherence to an ill-conceived shitpile of “standardize-first, use-case later” W3C standards than ever tackling the core performance and protocol problems.
And I cannot imagine a worse choice for presenting Linked Data to the modern web than RDF. It’s ugly, dog-slow to parse, and is INCAPABLE of representing a simple ordered list without significantly painful work-arounds that practically by their nature force N+1 queries on to clients. JSON-LD solves a lot of this and has existed for years.
And then we’ve got yet another attempt to pretend the W3C’s WebACL spec is anything other than a lunatic’s fever-dream of a UI and UX nightmare. We’ll apparently just expose it to end users to let them manage their data. That’ll end well.
The Semantic Web Community’s biggest problem is that they think continually recreating “existing thing but with as many of these awful W3C standards as they can shoehorn in” is some kind of Good in and of itself, no matter how bad the resulting user experience would be.
EDIT: at least there's the original outside medium on their project page, but seems like just a static squarespace page: https://www.inrupt.com/blog/one-small-step-for-the-web
What I'd like to see, is every device run a small process which can read the user's data. Html then has a syntax that can be interpreted like
{{ solid://mydata/name }}
{{ solid://mydata/profile.jpg }}
{{ solid://mydata/age }}
etc.
That data is on the user's device encrypted. Apps can never read your data, they can only tell your device to display that data.
That way developers cannot read your data, store them in their own databases, and then accidentally get their own database hacked and we are back to square one.
I'd like the data on your device to be encrypted and have some type of homomorphic encryption such that if an app were to show average age of users, then an app would be able to run some sort of `select average(age) from users` but since the encryption is homomorphic, the app never learns information about any individual user. This would apply for machine learning operations too, so that we could get netflix style recommendations of movies, without a company ever learning what movies we liked, our age, etc.
However, I don't know the first thing about homomorphic encryption so I guess I just have to wait until some great soul builds something like this for us.
What it doesn't solve is the problem how this data is going to be used by those who access it. I wish there was some kind of digital contracts that only allow using personal data in a way permitted by the user.
I have no idea how realistic or how "possible" this technology is for in the near future, but this seems to be a great match for technologies like these.
I mean, in spirit I seem to value the same things as Solid (decentralized, own your data, etc.), but what I don't understand is why it has to introduce so many abstract/new names when it wants to be 'simple'?
Building on top of the Semantic Web concepts isn't going to help either as it has enough disadvantages of its own (e.g., complex standards without adding any real value).
Inrupt is not in Crunchbase. They don't have a business address on their site. They try to get people to sign up without giving terms and conditions first. And they want you to give them access to all your personal information. Right.
https://www.fastcompany.com/90243936/exclusive-tim-berners-l...
From https://www.inrupt.com/blog/one-small-step-for-the-web:
So I have taken a sabbatical from MIT, reduced my day-to-day involvement with the World Wide Web Consortium (W3C) and founded a company called inrupt where I will be guiding the next stage of the web in a very direct way. Inrupt will be the infrastructure allowing Solid to flourishAnd we definitely need a ToS and a privacy policy, etc. The explanation for why we didn't have that is that the code running the sites that we put out there for people to try out is the same code you'd use for your POD on your own box. And most of us are running that code on our own boxes (mine is in a server rack in my basement :-) ), and those installs don't need a ToS. :-) So, you're right, we should have that as an option, so I filed a bug for it: https://github.com/solid/node-solid-server/issues/799
I don't think Solid is going to get any meaningful adoption until the signup and authentication flows resemble those of major current social platforms, which have enjoyed years of usability optimization.
What is a pod and what's so great about it? Something about controlling your data... Storage space... Secure USB stick for the web? So I can mount it and add/remove files from it? Like dropbox or something?
I clicked "Get a solid pod" and it asked me to register, which I did, after which it dumped me into some kind of "home page". Clicking "get started with solid and data browser" brings up instructions for creating notes and calendars and text files in a very primitive interface. There's no link to get back to the "home page" and the back button doesn't work because it's force-forwarding from an interim url.
So is it like a primitive owncloud? What's it supposed to do that's valuable? What am I even looking at?
From the perspective of the end user it's useful because retain control over your data, so there's no barriers to switching to a competitor, for instance.
If people can't run their own POD servers reliably, then they need to use some other cloud POD providers (Inrupt, as mentioned on the website). Which means your data is now with a third-party.
Solid changes the current model where users have to hand over personal data to digital giants in exchange for perceived value
Won't Inrupt become one of those digital giants (in context of Solid) with access to numerous PODs of people who cannot reliably host them ?They didn't fail for not being useful, but because their engineering was clunky and their demands on resources were way beyond the hardware of the time. Also those systems were too complex for the classic programming techniques. Now that we have a better understanding of reactive programming and async dependencies, maybe we can finally build the tools ecosystem to take advantage of homoiconic data, and these systems can take off.
Ok, I like it. Throw in some homomorphic encryption in the future, and maybe we can reverse all this SaaSS nonsense of today.
I love the data stays owned by the user. It's how it should be. I hope the system has some provisions against applications encrypting the data on on user's POD.
Not a great start.
* Ostensibly I've over-written with nonsense details, but a cursory check in another browser, not signed in, shows the same original information.
What a mess.
Given the sign-up asks for both details and I assumed there might be some potential for further use here for a platform created by a trusted party, I unthinkingly stumbled with the minimum.
I usually - which is to say always - don't, but here did.
Not looking for sympathy or sanctimony, just relaying my experience.
I'm curious how this is different.
It looks like Solid has progressed since the last time I really looked into it. But, from what I recall, Solid focuses on standardizing data formats and storage... but not compute. That is, all of your personal data is stored in some central location chosen by you, and then web apps can access that data (if you give them permissions). The web apps themselves still run on their own servers, controlled by the respective developers.
I'm skeptical of this model because:
1) If the code still runs on the developers' servers, there is no way to place technical restrictions on what they can do with your data. They can make a complete copy of whatever data you give them access to, they can store additional telemetry on the side, etc.
2) I think developers will resist standardized data formats because it makes it hard to develop new features. If you want to build any feature that requires storing additional data, it needs to be supported by the format. Perhaps the formats are extensible, but if multiple vendors do not agree on the extensions, then your data is no longer portable, defeating the purpose. I find it hard to imagine that any developer will voluntarily restrict themselves in this way without a huge incentive, and I don't see what that incentive is. (Certainly, not enough people care about data sovereignty for that to be an incentive.)
My opinion is that data sovereignty efforts must focus not just on storage, but on compute. The servers on which code actually runs should report to the user, not to the developer. Developers should build apps, which run on the user's servers. This way, developers are still free to create whatever data formats they want, but the user ultimately controls the storage. Other developers can attempt to develop "compatible" software which can read the same data, but this doesn't hold anyone back from adding new features to their own software.
But my own attempt to create such a platform didn't work out. So, you know, you shouldn't necessarily listen to me...
See the video on qbix.com and qbix.com/platform
We just wanted to focus on developing a general-purpose “operating system” for social networking, so startups and any communities can build their social networks by just installing the system, getting plugins and throwing reusable components on pages (like chatrooms, collaborative documents, group rides, etc.)
That way we can get real user and community adoption and then gradually decentralize things like so:
https://qbix.com/blog/2018/08/28/vision-for-a-new-truly-dece...
To date we have about 5-6 million users download our apps, and around $1M in revenues that we can reinvest into this thing. I would love to speak more to you by email if it makes sense... please look at the above links and let me know your thoughts.
I really believe that the project that will really make this take off will have to work backwards from user adoption (by doing for social networks what Wordpress did for blogging) and then incrementally move towards the decentralized architecture where everyone owns only what they are entitled to. The key is to avoid painting yourself into a corner, so that you can decentralize your own software later without losing features. But until now we focused on actual killer use cases, like this:
And I'm ashamed that I didn't do more to get behind Sandstorm sooner. I suppose this is too little, too late, but I just signed up for the Oasis power-user plan. I suppose if a few thousand of us did that, then you and a handful of other people could work on Sandstorm full-time again.
FWIW, while my current day job (Cloudflare Workers) is not immediately aiming to solve the same "political" problem as Sandstorm, it turns out we have to solve many similar technical problems, in that we are building a massively distributed platform for applications. For example, we'd like it if an application built on Cloudflare can store each user's data in the closest Cloudflare location to that user. That means applications need to be designed to treat each user's data as a separate unit that can independently migrate. If we succeed in getting applications to do that, then it becomes a much smaller technical step to say, OK, now let's store the data on the user's own machines.
It may turn out that this is a much better technical basis for what Sandstorm wanted to do, while making the "political" problem far less ocean-boiling. That's my hope, anyway.
I get that its great when its working and secure, and I can control it. But exploits happen, and now all my data is in one place.
So in terms of security, you can choose to trust a 3rd party with hosting your data, keeping the apps etc up to day or you can host it yourself. I'm not sure what's better!
In fairness, I guess I could have a bunch of pods like financial, social, pictures... or even a pod for each service: facebook_pod, bank1_pod, etc...and host them all with different third parties to try to minimize risk. But this gets incredibly cumbersome.
So instead of posting a photo on Facebook, Twitter, and Instagram, one would (ideally) authorize Facebook, Twitter, and Instagram to read photos stored on the Pod with a "shared publicly" tag (or similar), and then anything with that tag would show up automatically in one's feed on all three sites, and (if also authorized) push reactions and comments back to the Pod.
If I'm understanding correctly, it sounds like a neat idea. I'll be interested to see how well it does.
Exactly the same principle, but it failed to get adoption. Perhaps because users don’t care where their data is stored, and most can barely comprehend it?
Also, having a Solid pod does not prevent the worst kinds of personal data abuse, such as identity tracking and brokering of tracked data. I don't care that Facebook stores my photos, but I do care that they've built a profile around the contents of them.
I do think that the Semantic Web is still a cool idea though.
It also recommends the use of some XML thing so that all your "contact" objects are the same format.
It works for all aspects the digital ecosystem. Clients, Data, Bandwidth, Storage, etc.
Centralized -> decentralized -> centralized -> decentralized -> centralized -> decentralized -> centralized -> decentralized -> etc.
Many years ago, we face the vendor lock-in problem from the software giants, due to proprietary data formats. Thanks to Berners Lee, W3C, XML and open source community, that is less of a problem today.
But now we face the problem of vendor lock-in, not due to proprietary formats, but due to cloud-service lock-in. With all the software giants, Microsoft, Google, Facebook, Amazon, ... offering their services primarily as cloud services, this cloud lock-in issue is going to become more severe in years to come.
It's a new war the software industry needs to fight. It cannot be addressed just by one person, one project, one organization. It needs collaboration from the entire community.
Kim Hamilton Duffy gave an illuminating talk right before me about "Decentralized Identifiers and Self Sovereign Identity Standards"[1]
lmk if any feedback or questions
HTML5 is on the way to become this. You have permissions, local storage, indexedDB, and a ton of APIs. Anything else you need you can just submit it to the HTML5 working group (e.g. shared data)
Or a pod of whales.
"This Solid POD can be in your house or workplace, or with an online Solid POD provider of your choice."
"you never have to sync, because your data stays with you"
If you choose to keep custody of your own "pod", how are you supposed to achieve redundancy without some kind of sync / backup process?
WebID-TLS: https://dvcs.w3.org/hg/WebID/raw-file/tip/spec/tls-respec.ht...
WebID-OIDC: https://github.com/solid/webid-oidc-spec
I hesitate to call it outright bad, but I have no idea what to do after I create a pod. And I'm someone who knows how to write Solidity.
What separates this technology from everyone just making their own websites?
You could even mix data from different schemas in the same document, using something like namespaces.
Like, some kind of extensible markup language, almost.
Solid overall looks very interesting, and I can very much empathize with the "decouple data and applications" magic aspect of it (even though they're not doing a great job describing it). My personal experience has been that with a good linked-data approach, building apps can become a lot easier, as linked (more specifically semantic data) mimics traditional information gathering much better, where you start with a small information point, and then enrich the data by just adding more and more related data points to it. I also found that a linked-data approach lends itself better to adaptive UIs, where one entity might be missing data, that another one has.
All that being said, I feel like Solid made some (non-)decisions that might lead it down the same path as the things that were tried in the last Semantic Web hype:
- Solid is using the same old linked-data formats, that are largely URL based. The problem with URL based systems is that the content behind those URLs might at any point disappear, or change. That makes it especially hard if you try to achieve some semantic conciseness, where the data you entered keeps at one point in time is guaranteed to keep its semantic meaning forever. - In a world where most application developers think about data models on the level of database tables, RDF/JSON-LD is too low level and verbose when trying to use it for building something sophisticated. W3C also standardized a higher level format, OWL2 (which can also be expressed in RDF(S)), which provides a nice abstraction level in its native form.
Those are some of the lessons I've learned while working on Rlay[0], where among other things we've built a content-addressable adaptation of OWL2[1] for the decentralized web. We had to cut some small parts out of the specification so that the semantic stability of concepts is guaranteed when adding additional concepts to the worldwide ontology everyone is sharing, but overall the expressiveness is the same.
Content-addressability has many nice side-effects, but the one I like the most when it comes to Semantic Data is that it allows for a much more organic evolvement of the concepts people are using. If you decide to add a new property to a concept, you can just do that, get a new content-addressing-hash and start using that instead of the old one. No need to add it to the de-facto centralized schema repository that is schema.org.
I hope I didn't go off on too many tangents here. I've been meaning to write a blog post about the topics I touched on for a long time, but never really got around to it. Well at least this comment exists now.
[0]: https://rlay.com [1]: https://github.com/rlay-project/rlay-ontology
....
it adds absolutely nothing besides that.