Ask HN: You have one shot to redesign the Internet – what do you change?
How are you going to make the Internet better?
How are you going to make the Internet better?
- 48-bit static IP addresses. 70 trillion should be enough. 128 bits was overkill.
- Nodes, not interfaces, have IP addresses, so you can use multiple paths.
- IPSEC available but initially optional.
- Explicit congestion notification, so packet loss and congestion loss can be distinguished.
- Everything on the wire is little-endian, byte oriented, and twos complement.
- You can validate a source IP address by pinging it with a random number. If you don't get a valid reply, the IP address is fake. Routers do this the first time they hear from a new address, as a form of egress filtering. This contains DDOS attacks.
- Routers will accept a "shut up" request. If A wants to block B, it sends to a router on the path, the router pings A to validate the source, and then blocks traffic from B to A for a few minutes. This also contains DDOS attacks. Routers can forward "shut up" requests to the next router in the path, for further containment.
- Fair queuing at choke points where bandwidth out is much less than bandwidth in.
- Explicit quality of service. At a higher quality of service, your packets get through faster, but you can't send as many per unit time.
- No delayed ACKs in TCP.
- Fast connection reuse in TCP.
- Mail is not forwarded. Mail is done with an end to end connection. Mail to offline nodes may be resent later, but the sender handles that. Mail, instant messaging, and notifications are the same thing. Spam is still possible but hard to anonymize. If you want your mail buffered, use an IMAP server at the receive end.
- One to many messaging uses a combination of RSS and notifications.
- Something like Gopher should be available early. The Web would not have fit in early machines. but Gopher would.
The least significant 64 bits in IPv6 are used for link-layer addressing, which is how IPv6 supplants older L2 protocols (ARP etc) with NDP etc, thereby fixing (or at least improving) some significant issues with larger IPv4 subnet scalability/reliability
What is crucial, combined with the fact darkr points out that since they include the link layer the IPv6 protocol deals with more of the network architecture, is that IPv6 headers are much simpler, with only 8 fields, the 6 non-address fields all in the first 64 bits, while IPv4 has 14 fields, with the 12 non-address fields taking 96 bits, and they are better designed with attention to what routers find most important. This simplicity offers routing subsystems increased flexibility in the way they can be put together and handle their workloads.
Go one further, mail is pulled, not sent. One such approach is https://tonsky.me/blog/streams/. It'd be hard to prevent moats and people might still coalesce into a few popular middlemen, but at least spam would be reduced. Spam is the primary reason client-side/self-hosted mail is left to the tech-savvy.
This shifts the DoS threat from servers to clients. How does the router know that the request from A to block B is legit? Just because the router can ping A? Behold, a system where you can shut down your enemies for good by paying botnets to send requests to block B.
Full quote: "- Routers will accept a "shut up" request. If A wants to block B, it sends to a router on the path, the router pings A to validate the source, and then blocks traffic from B to A for a few minutes. This also contains DDOS attacks. Routers can forward "shut up" requests to the next router in the path, for further containment."
Operating systems would quickly develop "multi noding"; binding multiple node identities to a host, and then partitioning those among the interfaces.
Separate IPs for different adapters is a good idea, and needed for NAT: e.g. a home router being 192.168.1.1 inward-facing, and having some external IP. I
What if humanity becomes a Kardashev type-2 or an interstellar civilization? In that case the population of humans, much less computers, could easily succeed 70 trillion.
I experimented with this one over 10 years ago, pre-Wireguard. The idea was to first establish a peer-to-peer connection, e.g., via L2 overlay, then have each peer run their own smptd. A supernode runs on a publicly reachable server at a hosting company and is only necessary for extablishing a peer-to-peer connection, not for routing traffic. Each peer has an Ethernet interface, e.g., a tap device with a private address for the L2 overlay, and each peer runs their own smptd. As for spam, the trick is to limit the size of the overlay network. Users might belong to several L2 networks, e.g., work, home, school, etc. If it networks are kept small and the peers do not give out their email addresses to people not on the network, then it's possible to have a small, spam-free email network among the peers. If end-to-end email on small disparate networks became the norm, spammers would have to find all these small overlay networks and infiltrate every one.
As I understand it, this was the original intended design of email: smtpd's directly communicating with each other. This still happens but users do not run smtpd's. Instead they were asked to run pop clients.
This is an invitation to silence unwanted users by certain governments.
Isn't this difference academic/software? What is the crucial point here that can no longer be implemented as an abstraction? (Not a networking specialist so this might just be my ignorance speaking.)
> You can validate a source IP address by pinging it with a random number.
Good idea, but I suspect this is the type of feature that might quickly fall prey to implementation laziness/incompetence, or in other words, enough implementers would both ignore it and not use it until it became unreliable.
> Routers will accept a "shut up" request
I like this idea but couldn't this system be abused by a malicious man in the middle to much more easily hinder connectivity to a targeted system? The man in the middle can fake the validation too...
> Mail is not forwarded
I don't think this is a good idea. People would quickly invent a forwarding protocol if one didn't exist. I mean, I see what you're trying to do here, but I don't think you would succeed on this one.
> I like this idea but couldn't this system be abused by a malicious man in the middle to much more easily hinder connectivity to a targeted system? The man in the middle can fake the validation too...
I think of it more as a "I'm just ignoring these, you mine as well stop sending them" request. After all, a man-in-the-middle can already just drop the packets.
Some MITM can only inspect and forge traffic, not drop it (e.g. NSA tapping fiber)
SCTP has multi-path routing, no?
a static IP per device is google and facebook's wet dream. yeah apple, keep your IDFA for yourself.
also, imagine getting banned and not being to use google anymore, at all. asking your kids to google something for you and getting them banned too.
IPv6 addresses are a major PITA, not only are they too long, they're impossible to write and get even most technically competent people to understand. They're almost as hideous and unusable as x.400 email addresses...
1. Everything being 'free' by default drives us to ad-supported centralized services. Economics aren't a separable concern.
2. Too few IP addresses. (At least one of the pioneers, I forget which, said he pushed for longer addresses but was overruled. So the technical constraints probably did not force this.)
I'm not sure how to fix #1, but here's an approach from the 90s: https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.16....
I hate this argument. I've been online for a long time and the internet existed just fine without, for example, facebook. We don't have to accept ads but we do have to be willing to not use certain things out there.
I know this is a holywar topic and many would disagree simply by seeing `blockchain` word used here. But to my mind this exactly the place where this technology is beneficial. We need automated algorithm controlled currency to have this type of smart internet subscription.
The problem of how to fund actual web application development is not much different from the problem of how to fund media development in general. Newspapers, television, and magazines alike long ago settled on some mix of premium-tier subscription services augmenting a more open, ad-funded free tier.
This is so much more of an issue today than 30 years ago not because of anything specifically about ads to fund media, but because ad profitably has been driven sky-high by individual consumer profiling that relies upon privacy invasion and surveillance of your customers. Ads back in the day would improve via voluntary focus groups and that was fine. Today, they improve by tracking every digital action a person ever takes in order to more accurately correlate interacting with an ad with making a future purchase. Volunteers for focus groups are pretty much okay with giving their opinions in return for cash. Every person on the planet is not nearly as okay with having every digital action they ever take recorded and analyzed.
This doesn't mean it'd kill advertising. It wouldn't even kill all of the forces encouraging me to put my 'content' on centralized services even though I'm nothing like a media corp. But I suspect the right changes could've helped a lot towards a healthier computational ecosystem now.
This early architectural decision that costs are out of band didn't fundamentally make anything impossible. But when you see a lower-level problem addressed by higher-level workarounds, and you're getting to redesign the system, isn't that exactly what constitutes an opportunity?
I also don't want to be nickle and dimed to death, given the transaction fees there's a huge push to subscriptions and other models. Where if I could instead just pay exactly what a generic ad I'd _never_ click on anyway pays to get placed (like 0.00001 dollars for all the ads on a webpage stuffed with them) I might actually pay instead of using adblock for all of the security, usability, and bandwidth saving reasons.
Quite frankly, if they didn't allocate full /24 to single entities (including localhost...), we might still have enough addresses left.
Even if we hadn't wasted /8s on huge allocations to single companies, and things like 240.0.0.0/4, we'd still be basically where we are today, with v4 address space being scarce and traded as a commodity.
For how long?
IPv4 is just inefficiently allocated in general. Why does the world need 10.0.0.0/8 in addition to 192.168.0.0/16? Isn't 65k addresses enough? Is there a private organization in need of 16 million addresses?
Not to mention AMPRNet (amateur radio) owned the entire 44.0.0.0/8 up until 2019 (a portion was sold off to Amazon). That may have seemed reasonable in 1980 but now it's just plain crazy.
Plenty of mobile phone networks have well over 16 million subscribers, and they typically don't have enough public IPv4 addresses for everyone. This has led to really hacky stuff, like using DOD IP ranges as psuedo-private space, or re-using private IP addresses in different regions (which can't be fun to maintain.)
Some networks have fixed the problem by using NAT64 - forgoing IPv4 altogether internally, and translating to public v4 at the edge. (Works surprisingly well, T-Mobile US has been doing it for the better part of a decade.)
This is why 192.168.0.0/16 is often used for services like libvirtd, kubernetes and docker. And the use of the range by those services makes it even more unwieldy to try and put some other LAN in there.
You can work around these considerations if you want, but many people won't. When you're the network engineer responsible for designing a company's networks, you'll be wanting to keep things simple and robust. When you're called in at 3am on a Sunday because the network is down, you better hope your ability to recover doesn't require making a bunch of subnet calculations because you decided to try and use the pool of available IP addresses efficiently.
Just before the Internet was opened to commercial use in the mid 90s, would've made a perpetual prohibition of advertising over the Internet. Ads are what have ruined everything.
Take just about anything unpleasant about the Internet today and it is either directly a consequence of ads, or an indirect consequence of someone trying hard to make you see ads.
There would also have been no google, no amazon, no android, no kindles. I'd still be ordering everything from the Sears Catalogue, waiting 6-8 weeks for it to arrive.
1 The number of people who became wealthy from this behaviour is relatively small, but news of their "success" is widely disseminated.
google as it exists today, an advertising company hoovering up private data while masquerading as various services, all in the name of pushing more ads, is not a net positive to the Internet. Having it not exist would be wonderful in this alternate universe.
Of course there would be search engines though. There were plenty search engines before google, before ads, and those would've evolved along a different path from where they were in the mid 90s.
The Internet and the web could have grown in this way indefinitely with large e-commerce sites paying their ISPs proportionally more for traffic but reaping the benefits of not maintaining brick and mortar storefronts.
The first search engines had no ads. They were public services to a large extent. Modern Google is a distributed crawler/indexer and inverted search tree for queries (last I heard). Something quite similar could have been built and sharded across ISPs.
DNS is still ad-free, supported only by the ISPs and Registrars that benefit from it. So is email. The PKI is free again. BitTorrent or ipfs could localize the costs of content distribution if media companies weren't bamboozled by DRM.
Oh no!
Anyway...
Sears could still have their catalogue on the internet. Just because something is online does not mean that it needs advertisements everywhere. It's about time we realize that.
But I don't see how we could actually forbid ads on the internet and the legal basis for it.
Even Google landed on advertising as a monetization technique but existed before it and easily could have been a sustainable business without it (though not the behemoth it has become).
I had supposed without Ad's you wouldn't have had the dotcom boom of the 90's. No dot-com boom means venture capital wouldn't have flowed as readily. Amazon still would have started, but they burned a ton of cash in the late 90's. Without burning so much capital I don't believe they would have become as huge or if they would have even survived.
I remember old amazon being cheaper than retail most of the time, they must have been eating that loss. In the end it worked out for them.
Digital communities would have been really hard - a lot of online forums, I know, depend(ed) on advertising to pay for the then-expensive hosting costs. I'm a believer that Facebook now is long past its prime, but I remember how exciting it was in the early days when it was connecting me with family members and friends. Advertising is how all of those things were able to become accessible to everyone.
Maybe a better solution would have been to ban personalized advertising? A lot of the really gross behaviors with ad exchanges, data brokers, ISP interception, etc. are all to allow for highly targeted and personalized ads. Maybe you could only target ads towards "interests", which could be set at a browser level, and a user could configure if they wanted to see more relevant ads.
Not without something to monetize. Just no advertising.
Commerce sites would exist largely as-today in this alternate universe.
Early on there was a lot of interest in micropayments for funding sites with interesting content. That pretty much all dies because it was a harder problem to kickstart off the ground than just stuffing every page full of ads.
But, with ads prohibited, the Internet would've evolved differently and we'd probably have a very convenient way to pay some fraction of a penny to any site we frequent, all with zero ads and none of the toxic consequences of forcing people to view ads.
Take just about anything unpleasant about the
Internet today and it is either directly a
consequence of ads, or an indirect consequence
of someone trying hard to make you see ads.
I largely agree but would solve it a slightly different way.The ad-supported model became the overwhelming default because payments/micropayments were hard and scary so we spent a whole bunch of years conditioning users to believe everything on the internet had to be free.
Payments/micropayments still are hard/scary to a large extent. Large swathes of internet users literally would not dream of paying for content or community membership. Thus, nearly everything online remains riddled with ads or the consequences thereof.
So rather than banning ads I wish we'd made somehow payments/micropayments easy, safe, and transparent and baked that right into the internet somehow.
Think about how Patreon and Kickstarter (which are not without their flaws) have allowed people to support creators more or less directly. Now, imagine if we'd somehow baked something like that in to the internet itself.
The last big things to secure are DNS (can be done with DNSSEC), and possibly somehow mandate TLS for connections (although you definitely don't want that all the time).
One big glaring problem is BGP, which we don't really have an answer for. Whereas "just use DNSSEC" pretty much solve the last big security hole above, BGP is still difficult because you have to basically have a system to attest the path for each BGP node. AS1 can't say "I have a path of length 5 through AS2 AS3 AS4 AS5 AS6 to AS6" unless that message can be attested to by each node, but then this comes into a bootstrapping problem (e.g. how do you reach those ASes to get some sort of key without going through AS2 first?) or trusting some authority as we do for ssl certs. God knows the first thing I do on any fresh install is uninstall those root certs from any sketchy government I don't trust.
Having worked on SDN in its heyday for some of the big players in the space, there are definitely good ideas in the space, but getting to adoption is damn difficult, bordering on impossible. I don't know what it will take to oust BGP, so we're kinda stuck with it for the foreseeable future.
I see what you did there :D
If people decided to take this away by adding some security directly into the IP layer (i.e. such that communicating without it is impossible, such as mandatory IPsec), I don't think the tradeoff would be worth it. Now you would have to manage all the normal stuff that comes with keys (e.g. expiration and renewal), and you may find your device gets wedged if you don't do the delicate key expiry dance correctly (i.e. you can't even connect to the site to get updated keys).
It's very easy to say "those DARPA morons not designing security was a big mistake!", but I am not convinced that the tradeoffs of solving it at the internet level (i.e. L4 and down) are worth the bootstrapping / flexibility hits.
I remember my dad scraping enough money to buy us a computer in '97 with unlimited internet (aol was still selling the internet by the minute back then). As a kid who hardly ever had enough money to buy a comic let alone magazine, and who's local library was lacking, it was life changing being able to just lookup and read about anything for free.
Maybe it would be better to fund more useful things, like sites that give children access to knowledge through direct contributions. Like how Wikipedia is funded.
We have that problem now, apparently. Every consent decree that happens to some monster ISP includes a "low cost service for poor people" mandate.
(Even Xanadu is very arguably not a single concept - it's evolved significantly over time, and although Ted doesn't miss much, the power and development pace of personal/portable computers and smartphones seems to have surprised even him - we don't see many roadside Xanadu stands with the big flaming X...)
escript cscript mscript ascript
Maybe if something like webassembly had come along earlier, we could have avoided all that "javascript as bytecode" nonsense.
[1] https://books.google.com/books?id=3b40AwAAQBAJ&pg=PT32#v=one...
The worst that happened to the internet is Google becoming evil. The internet circa 2000 was mind blowing.
Exactly, it became evil!
The problem is that it's the 60s. My first thought was "security", but unless you an also teach them about elliptic curves, they're going to use the security of the 1960s, which as we now know isn't very secure.
Maybe at least having security baked in would help make it easier to switch to better security later, like how ssh can use different protocols as old ones are broken. But you'd have to make sure that you were very clever about how it was implemented so that it could be switched without major changes.
Another thought is "more IP addresses", but again you are in the 60s. The computers don't have enough memory to deal with IPv6 length addresses. So again the best you can do is try to set them up with easy upgrades.
Which makes me think the best suggestion would be to teach them about Moore's Law, which of course would have a different name, and try to push for every protocol being extensible as technology grows -- make sure that more octets can be added to IP addresses without them breaking, that security is baked into everything but everything has a way of negating a protocol so that they can be upgraded, that there are no hard upper limits that are assumed and can always be changed.
Basically, teach them what we now know are software best practices -- constants shouldn't be hard coded in the software, they should always be in a separate config.
Don't you think that would have slowed down the growth quite a bit?
Obviously it wouldn't apply to everything, but back in the 60s future growth was clearly not thought about the same way as today.
This could perhaps have been implemented in VLSI back in the 80s in such a manner that 32-bit IPs ran at full speed, 64-bit at half speed and 128-bit at quarter speed.
In fact, you can even ping any 32 bit unsigned integer and it will turn it into an ipv4. Try it: `ping 134744072` will ping `8.8.8.8`
So why not 64 bit? 32 bits fit in 64.
Instead we now have 2 concurrent protocols.
ps. 8*256^3 + 8*256^2 + 8*256 + 8 = 134744072
So the only real option is creating a new protocol with a new protocol ID in the header. And if we're making a new protocol anyways, we might as well design it to fix more problems than just address space exhaustion.
And that's what IPv6 is. The Wikipedia article has a lot of details on the kinds of changes it makes and why: https://en.wikipedia.org/wiki/IPv6#Comparison_with_IPv4
For example, if an old router got a packet for 1.2.3.4.5.6.7.8, where would it send it, if it didn't crash just trying to read that address?
The address is not the real issue. An IPv4 header contains 32 bits for the source address and 32 bits for the destination address. That's what needed to be extended. IPv4 implementations expect the destination address to be 32 bits after the source address.
Any fix you can think of to extend the address fields in the header will fall into the situation of having an additional protocol. Because changing the v4 header and calling it a v4 header would probably get your packet dropped as bad. Or have it being sent to somewhere else. Or some other undefined behavior.
So your best option is to have it identify as a new version. Yes, v4 implementations will reject your packet, but that's what you want in this case.
This idea reminds me of the Evil Bit: https://datatracker.ietf.org/doc/html/rfc3514
I am hoping that the same technology that transported me back in time and made me director of DARPA would help me solve those issues.
Others here seem to be redesigning the entire intarwebs. I'll just pick one thing I might have been able to digest.
DNS is brilliant - but insecure, and centralised. The dependence on registrars was a huge mistake. The competition for names is an unintended consequence; the DNS created artificial scarcity, which resulted in commercial businesses that produce nothing of value.
So something like GNS, I guess. https://tools.ietf.org/id/draft-schanzen-gns-01.html
A) Establish the expectation that websites "close" in the middle of the night for ~5-6 hours, local time / for each timezone. I don't know if would best be done via cultural influence -- giving talks, writing essays, personal communication, testifying / making inroads with politicians -- or via creating some sort of protocol. The idea is to prevent the unhealthier aspects of internet binging and screen addiction.
B) Establish the expectation that internet comments are transcriptions of voice recordings. I.e. to leave a comment, you have to call a phone number and leave a message which then gets transcribed as "the comment." In order to respond or reply to a post or a thread, you have to listen to the message and tone of voice of the person you are replying to. I don't think this would solve every internet dialogue, but it'd promote healthier interactions and less division.
In my book, the largest problems with the internet are techno-cultural, not technological.
You can read a bit about how it works in practice on the web.
https://www.huffpost.com/entry/ultraorthodox-jews-are-co_b_1...
http://www.hareidi.org/en/index.php/Hareidi.org%27s_Kosher_I...
Background: https://www.journals.uchicago.edu/doi/pdfplus/10.14318/hau7....
I see this is as a problem of the medium of discussion more than anything else.
- An "influencer" gets her photo on a Wheaties box. After that, the influencer doesn't have to do overt advertising to promote the cereal, their fortunes are bound together.
- In politics, as the former US president so amply demonstrated, attention is a currency.
- What about the exchange of ideas? Can one talk about the contents of a book without selling (or discouraging the sales of) the book?
- Is any mention of brand names to be prohibited? If you can mention a brand, unless all the brand's marketing has been completely ineffective, you are selling the brand. Don't like it? Pass the Kleenex.
AUPs lasted only a very short time after O'Reilly showed their Global Network Navigator site at Interop showcasing the capabilites of a new graphical web browser from NCSA called Mosaic that could - gasp! - display inline images along with the HTML hypertext! (Probably hard for the younger crowd here to believe, but early browsers had to open images in a separate window, sometimes with a separate image viewer helper program. Yeah, really. Mosaic was a game-changer, that made the vision of the modern web obvious to at least 1% of the people who saw it.)
This one would be hard to enforce. Still a good idea.
- Get rid of ARP - just append the LAN address to the network address like other networks. By default LAN addresses are random. (Note IPv6 enables this basically.)
- Support encrypted DNS and authenticated BGP.
- Let DNS return other metadata including the port as well as the IP address.
- Let DNS caching work. Don't misuse short DNS timeouts for load balancing.
- Ingress traffic filtering - reject source IP addresses from outside the current prefix.
- Not IP per se, but let multipath work in the LAN (and give Ethernet a TTL so that packets don't loop forever if things go bad.)
- Eliminate (or minimize) broadcasts. Use unicast/multicast for DHCP, service lookup, etc..
- Support relocation/forwarding of TCP connections so they don't break when your IP address changes.
- Fix TCP congestion control so that the data rate doesn't decrease as latency increases.
- Second adding congestion notification to TCP to differentiate between packet loss and congestion.
- Encrypt the host name in SSL/TLS.
A whole bunch of other changes to reduce latency in general - no one really quite realized how important latency was back when this stuff was designed, but in all fairness, it's almost, "how could they?"
Lastly, extend DNS to provide not only encryption and non-repudiation, bu most importantly, more info, or just absorb Project Athena's Kerberos and Hesiod into DNS at first opportunity. This also allows AFS or other global distributed filesystem support, which in turn could have changed database architecture and semantics for the better. Imagine how different the net would be with a scalable global federated name and directory service that could do everything that Yellow Pages did in the 90s.
(N.B.: When I was at Chevron, we built our own version of YP that was hierarchical and multi-domain. It worked really well ("really well", as in damn near flawlessly from the Monday morning we turned it on after a coffee-fuelled weekend hacking session by one of the three true geniuses I've ever met!), seamlessly syncing the info that was in Hesiod/Athena, YP, and DNS to make as much of it as made sense available to clients of each. I've never seen anyone else ever do anything like that, even in all my consulting exposure to other big companies' network services architectures.)
I have a theory that NAT killed the open web. There was this idea at the beginning that everyone could host their own website, email, etc. But when you're behind a router, you suddenly have to be quite technical in order to set all that up on the computer in your room. So only (bored) technical people bother. It's possible this is the reason platforms came to dominate.
In an IPv6 world you could have a free program you download that gives you an interface like Squarespace except you can host it for free on the very computer you're using to make your site. Could be totally accessible to nontechnical people. Same goes (much more powerfully) for distributed protocols like Matrix. You could have encrypted messaging platforms like Signal that don't even need a handshake server; devices talk exclusively to each other. Etc. It would be a radically different internet.
It’s always been a somewhat niche, difficult thing to run most standard servers. (Web/mail/ftp/gopher/nntp)
Such a government could then require app stores to remove "dangerous" technologies like Tor and messaging apps that support end-to-end encryption.
Perhaps ISPs would be allowed to support "legacy" devices and OSes, but with a special "Evil Bit" set on packets, so that websites could (and in some cases would be required to) refuse access.
The other problem you run into is ease of use. Most users of the internet can't understand PKI based certificates so I don't know how an interface could look that would provide a strong guarantee of identity but also allows my mom to use it and not get phished.
The original idea was that protocols would allow any one to participate by simply making their own webpage. But dynamic IP addresses, the DNS system, and even just HTML design were out of reach for most people so that got lost and monsterous websites under centralized control became the mediators for most people.
So if we could find a way to bake that decentralization into the protocols even more strongly while making them accessible to non-technical people, that's the change I would make.
The aim is to create a world where central platforms are not dominant, but any user can easily participate in the communication protocols with out there being a central point to collect all the data or force changes from.
...of course, I have no idea how one would go about doing that, and there in lies the rub.
Have you heard of Holochain?
"Holochain is an open source framework for building fully distributed, peer-to-peer applications.
Holochain is BitTorrent + Git + Cryptographic Signatures + Peer Validation + Gossip (data propagation).
Holochain apps are versatile, resilient, scalable, and thousands of times more efficient than blockchain (no token or mining required). The purpose of Holochain is to enable humans to interact with each other by mutual-consent to a shared set of rules, without relying on any authority to dictate or unilaterally change those rules. Peer-to-peer interaction means you own and control your data, with no intermediary (e.g., Google, Facebook, Uber) collecting, selling, or losing it."
Centralization has been greatly enabled by it being legal to hoover up all kinds of user data and monetize it by selling ads or using it for ML training. Huge moats, unassailable by anyone trying to charge money directly and discouraging interest and participation even in free, volunteer efforts (since the commercial ones are already no-charge...) while encouraging players to jealously keep their users captive, avoiding open protocols and certainly not developing new ones (notice how application-level network protocol development and support started to dry up fast as FB and Google's money-printing machines really started to get going?).
I'd say the shortest path to fixing the Internet is making that illegal, especially since that activity is also horrible and dangerous for other reasons. Ideally, the same law would hamstring the credit reporting agencies and also keep banks and other financial institutions from using/selling your data.
Now, it could've been done in a better fashion, more deliberately, or more broadly, but there are at least two notable early protocols with decentralization/distribution in mind: email (consisting of several protocols) and nntp. Now an individual may still access a, to them, centralized authority for sending/receiving content, but the protocols themselves were meant to support a distributed architecture.
Failing that, Flash should have become open source and part of the W3 web standards, but opened up such that we could observe the code that's running.
(see http://www.youtube.com/watch?v=bpdDtK5bVKk&feature=youtu.be&... by Jaron Lanier, also see Ted Nelson)
" Refusing to accept the authority of previous philosophers, Descartes frequently set his views apart from the philosophers who preceded him. In the opening section of the Passions of the Soul, an early modern treatise on emotions, Descartes goes so far as to assert that he will write on this topic "as if no one had written on these matters before." "
Anything that allows me to send files to a device of a person I know on a direct connection without a service in between and regardless of our locations in the world. Still an unsolved problem AFAIK.
Having thing given for free to be then exploited for various purposes is reason why these services are shit - because you are not the client, the guy who pays for your data or advertising space is.
How this increadible technical potential got translated into social reality says more about society than the technology[0]. If the stack of applications that has been built on top of it has become dystopic it is because society had dystopia in its dna. The technology simply allowed it to be expressed, so to speak.
By the same token, any technical tweak that maintained or improved this scalability would simply have led to an alternate dystopia. It may be counterintuitive but maybe the only internet that would actually be "better" would have been a more local / less scaling version. A more gradual transition might have given society time to adapt, develop some defense mechanisms and not be dominated by the lowest common denominator
[0] Keep in mind that all communication technologies of the 20th century (phone, radio, TV) quickly degenerated and never delivered the utopia initially projected
2. Make use of DNS SRV records for all services. Why HTTP must be on port 80? Why not consult DNS to resolve the port too? Pretty much related to my first point.
Basically: servers focus on serving their data, and then it's up to the user to figure out which "renderer" they want to use to display it. Ofc defaults would be provided.
But, say, you wanted to view tweets in a table form: no problem.
Or maybe, you want to have a really wacky "whip the llamas ass" UI for podcasts: go for it.
-----
The big benefit of this is that it would allow for artistry in websites, rather than the boring old blue, black, white, grey material design.
I'd add some kind of built-in, frictionless, privacy-respecting, user-friendly, transparent payment/micropayment system. Built on open standards so we could have multiple competing UX's and the best one(s) would win.
Basically, think about how Patreon and Kickstarter (which are not without their flaws) have allowed people to support creators more or less directly. Now, imagine if we'd somehow baked something like that in to the internet itself.
The web is 99.9999% garbage and one of the biggest reasons is because we spent nearly two decades training people that everything on the interwebs was free which meant that it had to be ad-supported which means that nearly everything has been forced to pander to the absolute lowest common mass-market denominator.
Even with some kind of "good" micropayment system, sure, most stuff would still be free/ad-supported lowest common denominator crap. I have no illusions. Just look at every other form of media that has ever existed.
However, just imagine how books or movies or whatever would look they were de facto forced to be free for the earliest part of their existence.
I think we failed to appreciate how much the average user would need centralized services (Search & Social) to use the Web. Both of these services are around discoverability of content. Humans want a water cooler to visit and chit-chat, or an organized library to look for information.
Additionally, because accessing the Web was seen at first as "free" (outside your ISP), people would gravitate towards "free" centralized services like Facebook and Google.
This created a recipe for what we see today with the incredible power of these companies over so many aspects of our lives.
So what would I think should be different? I would have been more thoughtful about regulating these centralized services in the way the FCC regulates the airwaves & media companies. Which is even more proactive than antitrust law. It's OK that they're profitable. That's good! But we ought to avoid single companies owning the entire search / social space.
For good reason, though. Who says what information is "verified", the government, the news media, the publishers? And what governments, media, and publishers get a say?
Perhaps it'd be nice for browsers to show a little indicator to confirm that a website is hosted by a government (although .gov and .mil are only valid for American governments, government could use a given domain as their government basis). There's a big difference between what's right ("climate change is real") and what the government is saying ("who knows, maybe drinking bleach is a good idea?").
Dividing the net goes straight against the idea of the internet. I don't think using a special browser for special domains is very tempting. We'd probably end up with the alt-net version of onion.to to proxy all different kinds of sites to a single application.
Now you wrap the adress of me: Individual > Household> Street > City> Airport into encrypted shells, that only reveal the next destination upon arrival within the data-organism.
These of course are valid only, if a public ledger certifies their longterm existence.
Your reply will take time, it will travel on land, air, water and, by all means possible. But it will reach me, i promise you that. To add plausible deniability, all you need is hostile apps, who participate within the meshnet, without the users consent. To add motivation to participate, just allow the transfer of crypto-currency - a currency backed up by the promise of data-transfer, no matter were, no matter what.
The web is a different story, especially social media. I'd like to make social media, and the web in general, more forgetful. "Digital natives" (second-flight millenials and Gen Z) are going to get screwed with the persistence and easy archiving of social media data. This is partially a result of the natural shift in cultural expectations that occurs over time, as well as a consequence of having their awkward-for-any-generation blunder years recorded forever. This is definitely more a legal change than a technical one, but I would mandate (1) a time span (such as 5 years) where public social media posts must revert to author-only private unless consent is otherwise obtained and (2) a prohibition against public mass archiving of social media posts from people who aren't public figures.
This type of mass archiving for the use of closed-off academic research libraries is acceptable, but merely going and hoovering up every public tweet or Youtube comment or Reddit post and and putting it up with a public search engine shouldn't be permitted. Treat it like many countries treat the census, and only allow publicly opening up these archives far into the future (for example, the raw underlying questionnaires used for the Canadian census are not released to the general public until 92 years after collection). Different story for public figures such as politicians, but we shouldn't archive everything that everyone has said in perpetuity.
Consequences:
* There is no live user tracking.
* Access control can be user/password or ssh keys
* You always have an archive of what you read
* You always have an archive of chats
* Everything is in principle decentralized (whether it is in practice depends on whether people keep files.
* Clients are in control.
One of the primary uses cases for Web Package is to let two users exchange content while offline, perhaps via a usb stick or what not. This isn't part of the specification, but we could begin to imagine sites that have a list of the web packages they have available for download. And we could imagine aggregating those content indexes, and preferring to download from these mirrors over downloads from the origin's servers.
I'm hoping eventually we get a fairly content-addressed network, via urls.
https://com.ycombinator.news/item
Having just checked, I see that ycombinator.news has already been registered, so maybe the lesson is that everyone should register "palindromic" domains, like com.ycombinator.com for example.
com.ycombinator.news/item
On the other hand, you could do an incremental query perhaps and cache the path length.
But I wonder about having the protocol name in there. Couldn't DNS return the ports for the supported services and then you could pick whichever one you want?
Also I like that ycombinator becomes "ycombninator".
That and probably mandatory native layer 3 encryption
- A general idea: Arrange so that sending packets costs way more than receiving, just like snail-mail. (At the moment, a large website or spammer pays very close to $0 per message, individuals pay much more per byte to receive junk.) This would encourage decentralisation, nicely small web pages, and discourage spam.
- And "disappear" XML. It might be "ok" (just) as document markup, but it's a terrible for structured data and config, and for transfers.
As a coworker of mine pointed out, it's a little bit ridiculous that URLs on the web look like this: `more.and.more.general/more/and/more/specific`. They should really be `more.and.more/specific`, just like bang paths[1] were.
I expected Xanadu. Centralized, omniscient namespace, two-way links, micropayments, etc.
We got The Web. Which eschewed all of that.
Much as I hate The Web (repeating myself), I grudgingly accept that it probably succeeded because it wasn't Xanadu.
Even if Xanadu launched, like a better AOL or Prodigy, I suspect most people wouldn't have grokked it.
Another triumph of Worse Is Better. Like PHP and JavaScript and so many others. Then hot patch it towards something less offensive.
It'd be like my brain broadcast just multi subscription stream, bunch of inputs and reacting to those events.
Encourage the development of browsers for kids. Parents can configure their kids' computer to only run "KidFox" browser which has all the security features turned on. Only allows white listed sites that has been vetted by various agencies, denies escalated privileges, turns off all webcams, prevents remote hackers taking over their kids computer etc.
Lastly, it is more of mindset. Developers should take the attitude that every client computer, server, and database has been compromised to some degree. That is we should have defense in depth and not rely solely on one mechanism to protect us from the bad guys.
Target goal: No cleartext password authentication. (No telnet as it was, no ftp as it was, no smtp as it was, etc., yada, and so on....)
Fallback goal: Get HTTPS right far sooner, with cryptographers working on SSL 1.0 from the beginning, with funding, and eliminate HTTP as soon as possible.
I'm push as many examples of capability based security into the academic world as I possibly could, in the 1970s.
Alternatively, push a version of Pascal with a standard library, and drown the insane practice of ending strings with a null instead of knowing their lengths.
Pondering the implications is left as an exercise for the reader.
As in, if you need ad revenue & marketing to support your website, you simply don't exist. You can have a website, but no advertisements or "user engagement" nonsense. You're either free or you're offline.
So so many protocols (history), but how few could we get away with, and what would they look like?*
Why don't we have constructive computational contracts for computational work?
How do we make the Internet easier to understand?
How do we manage the agency problem? We yield far too much agency as a matter of daily life, our data is not our own, our decisions are shared with barely knowable third parties.
How do we design human computer interfaces with health, especially mental health, as primary constraint?
How rapidly can the EU coalesce around a combination of a RISC-V general purpose CPU (with suitable trimmings) and a SEL4-influenced-kernel, perhaps in Rust (https://gitlab.com/robigalia)?
How do we standardise on constraints of discourse such as those pertaining to offensive language or hate speech? How do we make it easier for people to communicate with kindness? Autohinting everywhere? Like a shellcheck for human bashfulness?
VR and AR are coming very soon and without care they will be shatteringly destructive of human life. Humans addicted to computationally modeled utility functions mediated by multi-sensory computer games?
How do we embed the lore in the experience? How do we make available all the references as delightful marginalia?
What areas of Mathematics and Physics do we need to study to get ahead of our problems? Category theory is beyond trendy, what's trending? How about rigorous dimensional analysis to match the type theory, or sumthin? How do we invite the world's smartest financiers to apply and share their thought more generously?
Can we settle on a basic curriculum? What functional minimum of linguistic, mathematical, physical, visual, and other skills do we need? Is lisp or a variant the first language we should learn, and if so how should we be able to learn it? If not lisp then what? APL? Fortran? Compiler forbid, Haskell?
How do we ensure that code and documentation are always in sync? How much time will this require?
How do we guarantee a standard of professional attainment and delivery of ICT expert that is globally effective? How do we standardise how we do, not just what we do?
How best can we help each other make our Internet an even better place?
(much spelling, apologies)
*4
1. Encrypted onion routing on layers that betray source/dest IP. 2. eSNI on all TLS connections. 3. Privacy-focused DNS.
The problem is how laws destroy fair competition by favoring those with the most $$.
Fix that, and you fix everthing else (not gonna happen).
Or, if we're talking about the ground work, specs the cookies such that browsers must implement the cookie consent and therefore sites can't build it in js.
The problem is that these MTAs get hacked or people just hijack domains.
Heck, the barrier to buying a domain is so low that this is a legit way of spamming too.
This suggests that one way of making spam unprofitable would be to require any domain which sends email to put up a bond of $100 which is forfeited if any of the big four email providers decide that the domain is sending spam.
To make this acceptable to public opinion, the forfeited bonds would to go directly to popular charities, and all existing domains would be automatically grandfathered in, so there would be no extra cost for any current business or user.
Yes, but the customer will blame you when e-mail from a misconfigured MTA doesn't arrive (from my experience running one).
If only we'd had DKIM from the start, preventing thousands of broken servers from being set up in the last twenty five years...
S/MIME seems to work pretty well, but the paid certificates pretty much doomed its uptake. I think I still have a Startcom certificate from back in the day that has long since expired.
There's really just a difference in thinking, "private by default for email" vs "public by default." Or "untrusted network" vs "trusted network." However you want to think about it.
i passed the course.
How we distinguish warm va cold, idk
The only things broken on the internet are smartphones and closed IoT firmware.
I feel like starting with IPv6 would make a dramatic difference in adoption rates today... I.e. IPv4 never gets created. Imagine a world without a single NAT device or port translation algorithm.
I would change the web.
I would remove JS and design browsers to natively run python instead.
A centralized internet will inevitably do more harm than good.
And no JS. ;) /jk
As an alternative:
- Private and federated. Everyone has a personal server application which spans multiple personal computing, storage, and peripheral devices and supports federated access at varying levels of security.
- The server stores and manages a user's private data and anything else they feel like storing or sharing. (This requires unobtanium level security, but since we're imagining let's pretend this is a solved problem and see where it takes us.)
- Sharing of all kinds is user controlled and is opt-in across multiple competing federated networks. This includes social networks - with the difference that anyone can start their own network, for any purpose.
- Networks are decentralised and peer-to-peer, and do not store personal data, track, or profile users. This is a user=centric network where users own and control their data. Not an industrial data silo network.
- Users can share different interest profiles and personal details across different networks with varying levels of security and implied credibility.
- Ads are opt=in not opt-out, and defined by voluntary and informed profile and interest sharing, not involuntary and uninformed data harvesting.
- Anonymous microtransactions are a thing. Anyone can sell at scale with as little friction as possible.
- There are no cryptocurrencies and no blockchain tech, because generating random numbers with the equivalent of your own electrical substation is fucking stupid. There is a low-energy secure equivalent. (See unobtanium. Or is it?)
- A common kit of essential server apps is open sourced and community-maintained.
- Commercial and/or professional apps are available by hire or subscription. Servers have a multi-profile multi-layer security model which controls which layer of personal and/or server data outsider apps have access to.
- All paid-for apps supply full details of the schemas and file formats they use, to guarantee that users can freely transfer data to a competing app provider so apps and services hold personal data hostage and have to compete on service quality, not on retention gaming.
- Hacking, malware, virus creation, phishing, and so on, are punished by deletion of personal server data and reduction to the most basic server hardware and software. For serious and repeat offenders, this is for life.
- IoT devices are treated as personal server peripherals with no external data sharing (except by opt-in.)
- Government and military networks use an expanded version of the same system. Municipal, military, and internal gov services run on separate private subnetworks which can only be accessed through authorised devices with extra ID verification, not through general public logins.
Basically it's a combination of device security, private ID (probably biometric), sacrosanct personal data protection, high user-controlled privacy, super low cost of entry for entrepreneurial service provision, squashing of local, national and international scales, and strong forcing of anti-monopolistic competition - the opposite of the current model, which seems to be about herding users into virtual pens owned by monopolists, applying various psychological patterns to control and trigger behaviour, monitoring behaviour and sentiment through minimal privacy, and having to deal with very leaky and insecure devices and systems.
(html (head ...) (body ...))
You leave it the hell alone! <g>
You leave it the hell alone -- because if you don't, upon returning to 2021, you'll discover that in addition to your wanted change -- there will be all kinds of unwanted "butterfly effects" in the world, resulting from that change, and not limited to the Internet, either! <g>
Like, propagating in and through actual reality -- not just constrained to a computer screen or virtual world!
Unwanted/unforseen/unexpected (but mostly unwanted!) "butterfly effects" (imagine just how scary these could be if you were unprepared for them -- the scariest Stephen King novel wouldn't do them justice!) resulting from Chaos Theory (which programmers know to be actual fact -- make a small change early on in a program -- get vastly differing results later on, as the program moves through TIME...)
So if it one day happens that you magically appear (through time travel, or other plot element) at DARPA in the 1960's -- then you take a quick look, like Clark Griswold in "National Lampoon's Vacation", when he takes a brief look at the Grand Canyon (all of a few seconds!), and you appreciate all that DARPA and all of the other earlier Internet researchers did -- and you leave all of it the hell alone! <g>
Yup, sorry, nothing to see here, nothing to change here, no changes for me! Just passing by, not going to touch a single thing! <g>
You also appreciate the fact that while today's reality is a mess in many ways (and it is!) -- it could also (with Time Travel/Butterfly Effects/Chaos Theory) -- have been a much, much bigger mess(!) -- with Butterfly Effect horrors beyond your wildest understandings! <g>
https://en.wikipedia.org/wiki/The_Butterfly_Effect
https://en.wikipedia.org/wiki/Butterfly_effect
Disclaimer: The above was written for thought-provoking and possibly (depending on the reader's viewpoint!) comedy purposes only! <g> (Though it also works if read from a serious viewpoint...)
You can still strip identification for things like posting in public forums, but for everything else knowing where shit came from is critical. From spam email to well everything. It baffles me that spoofing callerID is not only possible but that some people think its important.
Along these lines I have a pet idea that a subset of IPv6 be geo-located, meaning your latitude, longitude, and possibly altitude are encoded in the IP address. This allows routing without the huge tables in the routers. Combined with the ability to verify that a packet came from its advertised location this is very powerful for security.
One way to verify the origin of data (email for example) is not to send it, but to send something akin to a URL (preferably better than that) so we have to at least be able to request the data from somewhere rather than have it sent to us anonymously.
Unfortunately being able to verify the source of data also enables end-to-end encryption fairly easily and nobody in power wants the public to anything like that...
I don't think it would solve all problems but it would be useful for cutting down on bots and spam for certain types of websites. Many people don't realize that a large chunk of content on sites like Twitter and Reddit (and probably HN) are propaganda from marketing agencies or hostile foreign governments. That argument that you had with someone on Twitter - you could be trying to chat it up with a Chinese paid internet troll. How would you even know? There is a complete lack of good faith on the internet now and verifiable identity, it would be nice to think of how the internet would have been different with it. Unfortunately, we also have a huge number of people/groups/companies that depend on lack of verifiability so I think this is why the idea has become so controversial.
For example, 2d langs for HTML, CSS, JSON, others: https://jtree.treenotation.org/designer/
A 2D lang that replaces Markdown: http://scroll.pub/
You can have 2D langs for TCP/IP, DNS, HTTP, et cetera. A grid is all you need.
I figured the math out 8 years ago, https://medium.com/space-net, and slowly getting there. Still in early days, but good annual growth rate. I'd be surprised if it doesn't happen. The math makes too much sense.
2D languages have none of those. They imagine all programs as laid out on a grid. Think of a spreadsheet. For trees, you use indentation. There is not a single computer language in all the world that cannot have it's semantics represented with just that 2D syntax. This realization has long fascinated me. It knocks me off my feet, the same way I feel about binary notation.
Here is a talk I gave in 2017 about 1D vs higher D languages: https://www.youtube.com/watch?v=ldVtDlbOUMA
Here is a video that makes the connection between programming languages and spreadsheets clearer: https://www.youtube.com/watch?v=0l2QWH-iV3k
I don't think I fully understand your concept
I also noticed your example grammar often contains a lot of js code. So it's not intended as different language but as data model with built in JavaScript? Kinda like a more modern XSLT?
You hit the nail on the head. The extendibility is the key thing. In Scrolldown every little piece of content is in its own little scope. It's like every block is it's own little file written in one of many different grammars. These all compose effortlessly. This is the early days, but I expect there to be thousands of little "micro-grammars" for use by people using Scroll. For example, you might have a microgrammar for making flow charts, or making interactive observablehq/worrydream/jupyter like documents, or quick sims, or blueprints, or audio content, or slide shows. It's sort of like web components done right.
> I also noticed your example grammar often contains a lot of js code.
The idea with Grammar is to keep refining the language and hoisting as many patterns into pure 2D/Tree languages as possible. But I have to use resources judiciously, and strike a balance between research and deliverables. Folks have started Tree Notation implementations in languages like Kotlin and Swift, and when/if there turns out to be a need to have something like a Kotlin Grammar interpreter, then at the time it would make sense to iterate on Grammar so the `javascript` blocks are instead a DSL. You can see that is a bit in progress with the `compiler` nodes; but have gone with the hacky `javascript` bits in many places just for pragmatic reasons.
> So it's not intended as different language but as data model with built in JavaScript? Kinda like a more modern XSLT?
Grammar started out as a POC but evolved into something pretty practical. Sort of an ANTLR for 2D languages. But sometimes I still just hard code the parser/compiler for a language from scratch. They are generally pretty simple.