Investor revolt and legal dispute delay Filecoin plans
axios.com
axios.com
> "Obviously it could fail and become worthless. But if it works it could be huge, like Google-scale huge, which is why this became so contentious," a different investor explains.
That anybody put money into such a bleak concept is still beyond me.
(I don't own Filecoin tokens and have nothing to gain by the project being successful, I'm just a fan of that team.)
> The chance of "filecoin" or whatever else existing 12 months into the future is astonishingly low.
I actually think the chance of Filecoin existing in a year is close to 1. It's not due to a prediction of a wildly successful corporate structure. It's mainly about the tech.
I also suggest you check out the latest Arweave x Gitcoin Open Web Incubator Demo Day from last week to see the latest stuff being built. Looking forward to ArDrive, Verto, WeaveID and more.
https://www.youtube.com/watch?v=Slzyw1w5Ric&feature=youtu.be
One further advantage of decentralized UI hosting on Arweave is simply resilience to website outages: https://twitter.com/rleshner/status/1278444807011139585
For the right use cases, that's a bargain.
While it may look good now, there is a non-zero chance it will disappear within 5 years for some reason or other.
So if your data is really important, better make a backup copy of it somewhere safe, like in B2.
I wouldn't assume the money was the cause of the slowdown.
More likely, raising huge amounts of money was the goal in the first place.
From the article:
> But multiple sources say that a large percentage of those tokens had been unilaterally distributed by CEO Juan Batiz-Benet to himself and early employees for less than a penny each, and that he has continued to make such distributions in the years since.
> Sources also say that no tokens were distributed to shareholders and that it often was difficult to get questions answered.
Raising huge amounts of money certainly was the goal but that doesn't mean it couldn't have detrimental effects past their bank accounts.
Releasing an actual product is more of a side product. If you don't develop or release anything, and just buy yourself Porsches, it's textbook embezzlement. But if you spend the money in a plausible way, you're mostly safe, even if the product turns out a major flop.
Unless you get greedy and start doing too shady stuff, like issuing yourself tokens under the table, that the founders apparently did.
It could turn out to be a flop, but the only people that would lose would be accredited investors who, according to regulations, should know better. I would say Filecoin has at least as good of a chance of succeeding as any ordinary VC investment.
https://ipfs.io/images/ipfs-applications-diagram.png for some examples of applications using IPFS. Visit https://ipfs.io/ for more info.
This is a good indicator of a technology's novelty, but it has zero correlation with the product/market fit.
Internet = Once curiosity, small, for geeks
Internet = Success
Filecoin = Is curiosity, small, for geeks
It is untrue that automatically follows Filecoin = SuccessIPFS doesn't really have a killer app people actually care about as long as we're not actually interplanetary - the internet connection from any point to another on the planet is generally good enough.
I've personally used it for storing large binaries outside of git. My build process requires using some binaries and fetching them by hash is much better than fetching them from some url.
Here is a subforum dedicated to discussing use cases of IPFS. https://discuss.ipfs.io/c/ecosystem/applications-of-ipfs/16
I don't understand the basis for this accusation. I thought the reason for Filecoin was essentially to provide an incentive layer to run IPFS nodes. The problem with IPFS was that it largely drew from volunteer efforts and therefore if you want to actually want IPFS to be a high-performing and low cost service you need to provide a market incentive structure to run a node.
Of course you can build something super distributed and fractional on top of that. Maybe d.tube and lbry are such things, but the more venture capital is involved the less I tend to trust such efforts.
Filecoin turns file storage into a marketplace, which is a significant improvement. Currently S3 charges a large premium because you wouldn't trust many other people to reliably hold on to your data. I expect this will cause the cost of file storage to plummet.
Your venture capital heuristic is a good one, but I think the rest of what we know about Filecoin overwhelms it.
Libp2p is the best peer-to-peer utility I’m aware of (please share if you know of comparable others). This in it self is a massive undertaking.
Multiformats is brilliant. A few simple tweaks to the way we form address open so many doors.
IPLD is supports json, cbor, protobuffers, git and more. All of which tie together really nicely in to the multiformat addressing and utilized by IPFS.
Literally everything they do is open source and free to use how ever you want. If you find a bug, fix it. If want support for something new, propose it.
Their projects are frustrating sometimes with regard to understanding the nuances of decisions that were made (such as /p2p vs the overloaded /ipfs) but they’re not building pay per use service like AWS S3, they’re building an open source community and they deserve at least a look at their source code before writing them off.
Isn't that fundamentally impossible? There's nothing preventing someone from setting up an archive site dedicated to storing/serving deleted content.
Take the example of a traditional website or web application like Facebook. When I post content I can select who will be able to access that content and there is no way for anyone NOT in the groups I select to pull down that data even in an encrypted form.
If Filecoin operated this way, then there would be no way for anyone to archive the data, because they could not access it in the first place.
In the Filecoin case, I would still think that it should be possible to guarantee that a particular object is not being actively served by a node on the network at any particular point in time and penalizing nodes (loss of Filecoin) that do not pass this check.
The concern I have is about malicious actors being able to access the raw objects held on the Filecoin network. They won't be able to do anything with the encrypted objects immediately, but I don't know that you can claim that will always be the case decades from now.
Yes, it is. If you delete the keys, nobody has access at all to the data. The ciphertext is irrelevant.
Said another way: you are trying to fit a centralized-shaped peg into a decentralized-shaped hole... wrong tool for the job.
If your use case does involve this situation somehow (?) then the only real solution is to encrypt it, as others in this thread have pointed out. There is simply no other option in an open-membership P2P network... otherwise the RIAA and MPAA would have long ago crushed BitTorrent.
Other networks have implemented mechanisms for the network nodes to delete files as detailed elsewhere in this thread and I think it is entirely reasonable to say there is more that could be done at the network level to help mitigate exposure. Dealing in absolutes is a dangerous proposition.
But all that would do would be to push people to do it off-network instead.
What the parent posters are saying is that there's no way to trust that your (encrypted) data won't end up landing on the hard drive of someone who chooses to capture everything that passes through said hard drive.
Whether the node itself keeps the data is kind of immaterial, if there's no technical limitation preventing the owner of the node from keeping your data.
But also, as an open-membership decentralized network, there's also no real way to incentivize node implementations to obey deletion requests.
It's helpful to think about peer-to-peer networks as if every node was programmed from scratch by the person or organization running it, to do exactly and only what that person/organization wants it to do. (Not true, obviously, but the incentives behind there being a free market of p2p node software work out similarly to if it was.)
In such an environment, why would a given node owner want to add a "read a deletion-request log, and actually-delete everything mentioned in it" feature to their node in particular? Especially if they weren't a party with their own private data stored that they were interested in ever deleting, but instead were only on the network to make money hosting other people's stuff; or because they wanted to insert public data sets onto the network?
The threat model I'm thinking about is a malicious actor requests an IPFS object that he/she knows holds data that is valuable, but that they can not decrypt. They then hold this object for a period of time till at some point they are able to break into it using improved computing power or exploiting some flaw in the implementation.
Now, you raise a good point about Filecoin being an open membership network. In my particular example, the malicious actor could just decide to run an IPFS node and start holding any data that comes to it for future malicious purposes and maybe they start pulling down specific files that they want to target directly. I don't have a solution to this other than to think that having some reputation built into the IPFS node network could help mitigate that risk. You might imagine that nodes with high reputation are trusted and it is harder(requires a lot of time/money) as a node operator to become part of that group. People might decide to only trust the highly reputable nodes with their private data and utilize all nodes for public data.
Then 3 years later all the snapshots end up on a torrent site, after you paid that whole time to "delete data".
However, I assume when a file is "unpinned" in IPFS you stop earning Filecoin for storing it? I'm not sure but I can't imagine why it would be any other way.
There's maybe a reason for the owner of a "Filecoin node" to want to delete data "on the network." But that data ends up stored on many IPFS nodes, some (many?) of those hosted by people who've never even heard of Filecoin, but are just running on the public IPFS network for other reasons (usually the same reasons someone would donate to the Internet Archive, or host a public-access Debian APT mirror.)
When you look up a file "on Filecoin", you're really looking it up from the IPFS network. Filecoin just incentivizes the insertion process. But data inserted "into Filecoin" is now on IPFS. So you have to think about what an IPFS node would (want to) do with your data.
Why would these "pure" IPFS nodes that have your data, care about deleting it in response to requests? That's not what IPFS is "for." These nodes aren't participating in the filesystem-like storage paradigm that Filecoin represents. They're participating in a "content-addressable storage" paradigm. Deletion would be a violation of the ideology that likely motivates them to run their node.
Using S3 at least means you’re in a contractual relationship with Amazon, who thus has a monetary incentive from all its customers to “do what it says on the tin”, lest they all lose faith in its claims and boycott/switch to some other object-storage provider. Amazon can do this, because it's a single coherent closed-membership hierarchical organization, rather than an open-membership p2p network which people could join for reasons at odds with the network's "designed" incentives.
Without a "Proof of Deletion", adding a deletion-request system to Filecoin would only be a mitigation against ciphertext-recovery at best—something that increases the probability that your file will be fully erased from the network—rather than a true guarantee that the entire system will attempt to achieve an explicit consensus state where the ciphertext has been purged from it.
So, if you're a system architect, why would you choose to store private data on a service (Filecoin) that can only offer a high probability of erasure, rather than one (S3) that can offer a guarantee of non-recovery?
And if it's clear that there's no reason to make that decision in favour of Filecoin, then turn that around: why, as the Filecoin or IPFS node-software authors, would you bother to add this feature, if it would be the game-theoretic dominant strategy for software architects that have this use-case to ignore Filecoin/IPFS in favor of some other solution, with or without the added feature?
-----
All that being said, I'm ignoring a distinction here that's fairly important: there are two types of private data — timely and timeless private data.
• Timeless private data would have just as much value if it was obtained years from now, as it would have if it were obtained today. (Someone's Bitcoin-wallet private keys, for example. Or compromising photos of a politician.)
• Timely private data has high value to its owner upon creation, but that value erodes over time; until, at some point, even the creator themselves doesn't much care if it gets leaked. (Apple's next iPhone design, for example. Or the source code to Super Mario World. Or military intelligence.)
There's actually far more timely private data in the world than timeless private data. And encryption, all by itself, basically solves the protection needs of timely private data. Cryptanalysis seems to only really advance in power alongside Moore's law; so anything encrypted using modern encryption technology, won't be brute-forced for a number of years yet. So you can take your timely private data, encrypt it, and stick a printout of the base64 ciphertext in the public square, if you like. By the time anyone can decrypt it, there'll be no value in doing so.
Filecoin/IPFS works just fine to hold timely private data. And since that's most private data, it actually supports the needs of most system architects just fine.
It's quite the rare use-case that requires decentralized storage of timeless private data. The fact that this type of data is so rare, though, is another strike against IPFS or Filecoin node-software developers being interested in introducing a feature specifically meant to help that use-case. Filecoin/IPFS would still be a non-dominant strategy for the timeless-private-data case, so there'd still be no point; but on top of that, it's a niche-within-a-niche.
Why do you want this? The files are encrypted and thus illegible. To anyone without the key they look like random noise.
If you're defending against your own government, they already control the network and could hold on to your S3 network traffic until they can decrypt it.
If you're defending against an individual how would they know where to download your file from? I assume the network doesn't broadcast a connection between real life identity and the data you're storing. And if the individual can monitor your physical network, then they can again decrypt the network traffic eventually.
If you're defending against the server hosting your content, they would have to host your old data for years past you stopping the service before they could decrypt the content, which would be a massive investment.
Finally, do you have reason to believe that our current encryption algorithms will be cracked anytime soon? The last big innovation I heard was SHA-1 generating a hash collision in 2017, but even that took thousands of dollars in compute resources, and SHA-1 was known to be defective for a long time before that. I imagine if we use our best algorithms they'll hold up for quite a while longer.
So my understanding is that in the example of a decentralized app that uses Filecoin to store an IPFS object on the network the IPFS object id could be sniffed on the localhost by something like Wireshark. This way an attacker could identify the encrypted objects that are of interest to them and then independently request them from the IPFS network.
In terms of threat, I'm primarily thinking of larger criminal organizations that might target things like files containing SSNs, credit history, etc.
SHA-1 is an example, but my biggest concern comes from the potential of quantum computing to render what we consider secure today obsolete. (https://www.technologyreview.com/2019/05/30/65724/how-a-quan...)
Data retention for ciphertext where the keys, stored and distributed elsewhere, have been deleted/zeroized, is a complete non-issue.
Basically, how do you know what we are encrypting today, won't be able to have the encryption broken 30 or 50 years from now?
Basically any project I've seen started by Protocol Labs ends up a mess of a project so I'm not surprised Filecoin is where it is now. It's quite clear that Protocol Labs is extremely incapable of managing a project of scale.
How so? I don't have much experience with IPFS, but I've heard great things about it
Testground was an initiative started by Protocol Labs to create a solution that would be used for testing of IPFS at all levels of the protocols, while also giving developers an SDK that can be used to write new testground tests. The reason this was needed is because the before the Testground project was started, the last few releases of go-ipfs (the reference implementation of IPFS) introduced new bugs, and regressions. Why? Primarily because of the poor planning, poor test coverage, and overall poor project management.
So Testground development started and went on for about 5 months until the developer in charge of Testground development makes a post on a GitHub issue (https://github.com/testground/testground/issues/42#issuecomm...)
Tl;dr of that comment? Poor project management lead to a lot of wasted development time on Testground.
Irony of the whole situation aside, if this was an isolated incident it might not be so bad. But it's not an isolated incident, it happens all the time, and with every single project managed by Protocol Labs.
Interestingly enough this latest post from Axios caused me to come out of the woodworks with my own series of posts about how Protocol Labs has failed both IPFS and Filecoin. I briefly detail a few more of the problems here (https://bonedaddy.io/blog/ipfs/posts/failure-ipfs-filecoin-p...)
https://siasky.net to get started
Adding a "distributed" network in there is extra points of failure, not less. But in crypto, price tends to not care about actual efficiency or utility at all, and is really just a roulette wheel of ticker symbols. Disclaimer: founded a crypto.
> Sources also say that no tokens were distributed to shareholders and that it often was difficult to get questions answered.
I think this highlights where it's really difficult to be a young founder. Giving your investors news you know they won't want to hear isn't a fun conversation but it's necessary. And the longer you avoid those difficult conversations the harder it is to recover the relationship and the closer you get to running afoul of your duties.
Right now backblaze b2 charges $0.005 (half cent) per GB. This is probably an upper bound on what decentralized storage services can charge. I sampled some computers on bestbuy and found that most of them come with 1TB storage (this excludes computer with SSDs, which have less). This probably translates into 500GB of free space that the average person can rent out, which works out to... $2.5/month. If we factor in a modest electricity consumption of 30W for 24hrs/day, 30 days/month, that's 21.6kWh, or $2.16 in monthly electricity costs (assuming 10 cents per kWh). So best case, you're going to be making $2.84 per month per computer, which doesn't seem worth it. In reality it's probably worse because sia's currently paying $3.68/TB, which works out to a loss of $0.32/month.
Makes me wonder how the distribution on other filesharing/torrent networks looks like.
Another line of questioning I have is about the possible effects of this system should it become popular. Cryptocurrency mining caused huge spikes in graphics card prices - will the same apply to high-capacity harddisks, due to people trying to run mini-datacenters for profit?
How much storage will the Filecoin network be able to provide? How would a hypothetical large storage supply interact with pricing models of other providers? And on a more optimistic note, will it enable individuals to develop a new class of programs using lots of storage which aren't possible currently, technically or economically?
I think the key difference is in filesharing networks, there are tens/hundreds/thousands copies of data, and each peer can jettison the data at any time without penalty. In contrast, storage networks (I'm using sia as an example here) only have three copies (by default), require upfront commitment (6 months by default), and you stand to lose your collateral in the event you delete the data prematurely. The latter two properties exist to counteract the unreliability associated with only having 3 copies if peers can randomly drop out at will.
>will the same apply to high-capacity harddisks, due to people trying to run mini-datacemters for profit?
Theoretically no. Presumably because every gigabyte of storage that's being bought for the storage network, is every gigabyte that someone doesn't have to buy to store their data.
if you really think the first adopters are going to be sharing cat pics you're being incredibly naive.
can filecoin do that? obviously not. the whole point of being decentralized is that that kind of action is not possible. why wouldn't that be incredibly beneficial to any distributor of any type of illegal content that would otherwise be removed from the centralized storage systems?
Sorry, what? How do you imagine that works? Wouldn't it actually constitute destruction of evidence, which is a felony?
In the situation that you somehow get the unique hash for the encrypted CP files before the FBI can tell that you host them, I don't know what would be your legal responsibility. But naively thinking about it, I would expect a good citizen to delete them, therefore not contributing to spreading cp around.
edit: As to your second paragraph, I'm not a lawyer but I'm pretty sure that would technically be felony destruction of evidence (odds of prosecution being another question entirely).
Exactly. In your initial post, you claimed it was a foregone conclusion that they would decline to press charges. And I don't know about you, but having my electronics confiscated for an indeterminate length of time would be more than bad enough. How are you even going to pay your attorney, if you can't do your job without a computer?
I'm pretty sure that in the end, you wouldn't be liable. But you might have to prove it. For example, it's perfectly legal to run a Tor exit node in the US. It's still strongly advised that you don't do it from your home, however.
I do however see how the fear that one's servers might be used to store CP or equally problematic content could stop Filecoin and similar systems from getting adoption.
point is there will be illicit content being shared, and why would I want to spin up a node and be roped into some FBI investigation because my computer has bits and pieces of the illicit content they are looking for?
whatever tiny reward they offer isn't worth it
You could have just said that, or 'pirated movies', but neither are as inflammatory are they? Instead you chose to make the most offensive assumption you could think up.
Paedophilia is not like theft, it's only attractive to a small subset of people.
So for any service that's going to put random files on an end user device it's very relevant to ask the particular question "how are you going to ensure that child porn does not get put there?", with the explicit focus on child porn - it's acceptable if the service has no solution for pirated movies, because if pirated movies get put on someone's PC without their knowledge, that's not going to them in jail, but for child porn at least some answer is mandatory. For example, at the very minimum, censorship of known bad file hashes, such databases exist - of course, that's circumventable by e.g. encryption, but it would help from the legal perspective.