Building Permanent and Censorship-Resistant Blog with Ethereum ENS and IPFS
pawelurbanek.com
pawelurbanek.com
https://news.ycombinator.com/item?id=27551619
One thing I realized is how expensive Ethereum domains are. The domain price is equivalent to a regular domain and then you still have to pay the gas fee, which makes it more expensive than a casual .org or .net
The other drawback of these censorship-resistant blogs is that they all require plugins to access the non-HTTP domain, which all but rules out most non-technical people who don't even know what HTTP is.
And while it can still be accessed over HTTP, the bottlenecks become the same companies that might comply with censorship requests.
As the OP said, you're just back to relying on a centralized service
I'd struggle to explain what IFPS is but I can follow the link just fine.
But the rate of growth of this space and with browsers like Brave gaining some traction, I won't be surprised if Firefox starts natively supporting Web3 tools at some point in the future and that would make Google and Apple think about it as well.
Definitely will take time but this seems like the logical next step given how far this tech has already come in the last 5 years.
All .eth addresses are resolved by cloudflare with the .link tld, so hn.eth could be visited as a normal site with hn.eth.link
Skynet is different from IPFS in that everything is hosted by paid servers, and it uses direct routing instead of a DHT, so you get a lot better latency. Skynet's IPNS equivalent (called SkyDB) is also a lot faster, p999 on the order of 200ms to update something.
The other nice thing about Skynet is it's all http accessible. Anyone can run their own Skynet portal, and that portal by default serves over http. You can grab any content from any Skynet portal, and there's even an upgrade in development that will automatically find alternate portals for you if requests fail.
> In addition to the cost of the domain ($5/year), you have to pay the gas fees.
Who does the $5/year go to? What incurs gas fees? Registration & updates? Updates are mentioned below:
> One downside is that each data update costs money, ~$1.5 at the time of writing.
Are initial gas fees higher?
This is something that bothers me about the state of dapps right now. The way many of them connect to the blockchain is via Infura (a centralized service); even Metamask uses Infura to connect to the blockchain. There’s this abstraction that you trust, that you’re working with something totally decentralized, but right now the technical constraints necessitate single points of failure or censorship.
Of course, the data is still there in the blockchain, decentralized over many nodes, but the way we access that information seems very, very brittle.
Likewise with ENS, all the data is stored locally on your local copy of the chain, so it doesn't matter how many users are making queries because each one is only querying their own node.
Also users are serving files to each other in an offline-first ecosystem. From that perspective it could be faster and more reliable as well.
This is why they call it web3. web1 had the same initial problems. Use Brave.
Secondly, you need specialized software for HTTP, it's called a web browser. There are browsers that have (or will) have native eth/ipfs support. I think Brave already does out of the box. People will download whatever app their friends are using, even if they have no idea what's going on underneath.
The HTTP gateways for all this stuff are only so "legacy" tech can communicate to that world. It's a bridge, not a destination.
For permanent storage you should check out https://www.arweave.org/ rather than IPFS + centralised pinning services like Pinata. With Arweave you pay a small upfront fee to have the network store your file forever.
It's the promise of IPFS+Filecoin but actually live and being used (eg by the Internet Archive). There's some decent tooling & docs for it too: https://github.com/ArweaveTeam/arweave-deploy
Edit: Filecoin is also live and being used, I was out of date. https://docs.filecoin.io/store/
"This Arweave+IPFS bridge allows you to have truly permanent backing of your data using Arweave, while also making it available in IPFS." [1]
[1] https://arweave.medium.com/arweave-ipfs-persistence-for-the-...
How are the economics of this sustainable? "Forever" hosting for a small upfront fee seems like it must be a lie.
Can you only upload small files, so you end up paying 1000x+ S3 prices, with the hope that Moore's law outpaces cost of keeping the file online?
Are reads monetized, so unpopular files will inevitably lose the forever guarantee?
Seems like an obfuscation of the economic problem that doesn't solve it.
If you were to store 100 TB on the weave tomorrow (the weave is currently 10TB), the block reward would remain the same, but the endowment payout would trigger much sooner.
The endowment fees are sized with the assumption that the endowment will have to pay out immediately and until the end of the 200 year period.
That shifts my expectations from "economically infeasible lie" to "small fee may not be so small, but feasible with proper stewardship and valuable for certain use cases."
In the crypto/DeFi space, superlative marketing copy is more likely to be interpreted as 'potential scam' than other domains IMO.
I'm always curious, though - there are some things that we want to censor for good reasons. The usual poster child (sorry) for this is kiddie porn. But there's other stuff - revenge porn, libel, etc that we as a society might want to censor. How do we do this on infrastructure like IPFS?
In no way shape or form am I defending the nasty stuff or saying that it should be allowed, but when defending privacy and liberty, there's a real question about how we deal with hidden lawlessness that uses the same tools people use for legitimate purposes, or, more importantly, how people use these tools in a way that a government views as illegitimate or a thought crime but are in the defense of liberty.
I think there's a notion of policing that comes out of this discussion that is not part of the technology but rather a complement to it. I don't know what shape that would take.
We similarly have a complete ban on violence, except for the state which has a monopoly on it. This does get abused sometimes, the system isn't perfect. But it's better than allowing anyone to use violence whenever they want to resolve disputes.
I agree that there's a discussion that we technologists need to have about policing and censorship, which we're currently not having.
An analogy can be made to WhatsApp. It's known to be used to coordinate terrorist attacks in Europe yet not a single government intelligence agency has managed to legislate Facebook into opening a back door. Because a backdoor makes encryption quite pointless.
Similarly, the case with Apple. Whom categorically refuses an unlock ability to authorities, and so far has won.
There's no public outrage. The public seem happy to be protected from the prying eyes of their governments. And I guess the public implicitly accepts that as part of this protection, some very nasty stuff goes around these same platforms.
That's why I believe we should separate content extermination (which is fully impossible) from hiding said content from view. The latter is doable and common.
For example, terrorist videos are almost immediately removed from social media platforms upon detection. This stops it from spreading and its damage and shock effect is contained. However, should you specifically seek out such videos, they can still be found in several places, and you don't even need to go to the darkweb.
Censorship, in the practical sense, should be seen as hiding from view. Not deletion.
I think the larger picture here is that censorship really doesn't impact how pleasant a place is to live in. I currently live in Berlin, and there's a whole heap of sensitive history here, but that doesn't really affect you if you just want to live a normal life.
Even more worrying is Cambodia's recently introduced internet censorship decree, which "requires all internet traffic in Cambodia to be routed through a regulatory body charged with monitoring online activity before it reaches users."[2]
[0] https://freedomhouse.org/article/death-press-freedom-cambodi...
[1] https://www.aljazeera.com/news/2017/9/22/cambodia-switching-...
[2] https://www.hrw.org/news/2021/02/18/cambodia-internet-censor...
As I said in that interview, there are a lot of cultural factors at play, and it's not nearly as clear-cut as it has been made out to be.
Wow.
Because if the answer is "it stays accessible" then this technology is fundamentally broken and we need to stop using it or promoting it immediately.
I do get the need to prevent governments snooping on journalists and protesters. But I think there's also a valid need for access to evidence for our justice system to function properly. If we can't convict people without evidence (rightly), and we can't force people to incriminate themselves (rightly), then we must be able to access evidence somehow.
Anyway, the child issue is also a problem vs sanction. Anyone hosting the data in a normal judicial system want will it be ?
In the normal hosting business, content like this is taken down by the hosting provider. For IPFS, a key question has to be "who gets to decide when content should be removed, and how does that happen?". If that person isn't a government because no-one trusts the government, that's fine. But someone needs to be able to make that decision and act on it. Then the usual legal channels can be followed for taking content down if necessary.
Before the internet, all of that stuff could be (and was) published using traditional printing presses and distributed like everything else that was printed. We dealt with the outliers then the same way we ought to deal with them now: find and prosecute (or sue, in the case of libel) the people that were responsible for publishing them, not try to outlaw the printing press itself for not having a "no bad stuff" backdoor.
Because, really, if somebody comes up with a truly uncensorable distribution platform, the point of whether or not it can be used to distribute "bad stuff" will become moot: it will be uncensorable by definition, and we'll have to go back to the "old way" of handling the edge cases.
Bitmessage is also pretty awesome already...
But I guess as long as that data is centralized it could be censored.
In essence, only valid queries would be transmitted and replicated across peers.
It would not be a single ledger, it would be a collection of ledgers. Data that is often queried would have higher short term redundancy, that would face over time. Any data submitted would be have at least 10 or 25 copies across all clients, and data would be found through a DHT.
I guess public data would be encouraged since visible by everyone, but private encrypted data be limited. Trust and data moderation are also problems.
The fundamental problem is that when a page is created, we don't know what address the comments will get (since it will be based on their content).
We can easily look backwards, from a comment to all of the previous thread, e.g.:
Page <- 1stComment <- 2ndCommentB <- 3rdComment <- ...
The problem is those arrows only point one way; we need to know a name/URL for a comment, rather than the page. To solve this we need a mutable reference, like DNS, IPNS, some third-party service, etc. If we have that, there are lots of things we could use to accumulate and render comments (like WebMention).> IPFS seems to have no method of creating “references” to other hashes
Such references would be arrows pointing the other way.
It's simple, It's effective (for most non "web scale"/commercial use cases), and it's legally safe.
It was very easy to set. No code. My site is: https://klaudioz.eth.link/
Also i bought the eth domain when the gas was a very low price.
"requires cloudflare"
Banned from a server? Post on another one or your own server from where subscribers will pull your posts. Digital signatures for validation.
Publishing the specs will suffice. As developers can come up with various implementations based on it.
We built an alternative platform called Skynet, which allows anyone to host decentralized webapps like blogs, or even more advanced things like chess tournaments. There's a design pattern called a DAC that makes it easy for multiple frontends to use the same data, without anyone needing to learn a data spec.
Is IPFS really resistant to censorship? It seems like any state-based actor could easily block access to IPFS nodes if they were serving a specific CID.
A state actor would need to block all IPFS hosts as soon as they begin to serve a specific CID. This is a game of whack-a-mole that would be difficult to maintain.
It will get cheaper to "save" but more expensive to access
A few papers exist that describe byzantine fault tolerant DHTs, but they make assumptions about the percentage of evil nodes, which requires some method of authentication / Sybil resistance to be effective. Also the network cost blows up substantially, and DHTs already aren't very fast in terms of loading things like web pages.
This has never worked for me
Is there supposed to be some advanced setting not on by default in Metamask that allows .eth domains to resolve?
https://internetofbusiness.com/bitcoin-blockchain-contains-i...