What's preventing the dream of decentralization from taking off? We have the technology.
What's preventing the dream of decentralization from taking off? We have the technology.
And around the time when home connectivity became good enough that people considered home hosting was also around the time Slashdot was created.
I had a members.aol.com/benibela site or something
Examples: Let's Encrypt (Certs), Internet Archive (Culture), Quad9 (DNS), Wikipedia (Knowledge), OpenStreetMap (GIS), Python Packaging Authority ["PyPi"] (as part of the Python Software Foundation)
EDIT: Seriously, start non-profits whenever considering implementing technology infrastructure you're unlikely to want to extract a profit from and are seeking long term oversight and governance.
Generally speaking, much like for profits, it is the people that run it that decided its culture, not a legal structure.
The average developer isn't interested in showcasing their social/political views, starting a revolution or building the future of the internet. They just want to get the job done as quickly and effectively as possible and go home.
All being equal, though, we should try to avoid technical systems with unnecessary trust relationships and critical concentrated dependencies, though.
And if we must have a concentrated dependency, we should do our best to pick very trustworthy ones-- both based on their track record and their likely future interests relating to organizational structures.
If you don't trust the code itself – it doesn't matter where it is hosted. Validation/audits etc. are essential in any case.
If you don't trust the reliability/uptime of the central service — it's trivial to create a private mirror containing the packages you want. Every internal build system I have seen does this already.
NPM's had its share of catastrophes and controversies that have made things tougher and caused harm to downstream users. It has also saved lots of effort.
Focusing on e.g. mirroring misses the point, IMO: One's dependency on something fundamental like package infrastructure isn't to survive one deployment or minimum sustaining, but to be an ongoing part of your technology stack. Yes, you can move on, but it'll be costly. If the component decides to start to suck, you're going to feel pain.
The post if I remember was mostly ignored, but received a few downvotes and maybe a couple of negative comments.
Based on that, it seems that what's preventing decentralization from taking off is ignorance and apathy.
A day or two later the guy announced npm, Inc. if I remember.
There are actually a lot more developers that have accepted a federated services worldview than a peer-based fully distributed one. But there are package registry projects along both of those lines.
https://github.com/orbs-network/decentralized-npm
https://blog.aragon.one/using-apm-to-replace-npm-and-other-c...
https://github.com/entropic-dev/entyropic
But again, ignorance, apathy, and the status quo remain the most popular options.
Time and money.
I think this is probably a good thing in general, and should maybe lead to some interesting enhancements, and maybe even finally solve the distribution of binary modules at a better level.