Fiatjaf/nostr – a censorship-resistant alternative to Twitter
github.com
github.com
followed by
> To publish something, you write a post, sign it with your key and send it to multiple relays (servers hosted by someone else, or yourself). To get updates from other people, you ask multiple relays if they know anything about these other people. Anyone can run a relay.
Sounds pretty much like P2P techniques to me.
We need to realize our problem is not with censoring people, it's with who does the censoring.
We don't like it to be the gov, because we don't feel like the gov is 'by and for the people'
We don't like it being large corporations because that's doubly the case.
The point is that it won’t be effective since messages are pushed to/pulled from multiple relays.
These are all questions we've already seen from USENET; in fact, it's not entirely clear to me what the benefit to this protocol is over USENET, except it's new.
No, the problem is with censoring people.
You make it seem like censorship is a given. I disagree and feel no need to have a third party prune unwanted ideas for me. This will seem like a strange idea for some but I don't need a priest in between myself and God. I don't need a doctor in between myself and good health. Why would I need a censor in between myself and information?
No need for governments, no need for corporations, just me and my silly brain will decide what to digest. What a concept!
-
We need to realize our problem is not with censoring people, it's not with who does the censoring, it's people that try and normalize censorship.
No, it’s who/when/where the censorship occurs.
If you want to come into my living room and shout Nazi propaganda, your ass is getting censored and banned from my house.
If you think that level of censorship is a problem, then we have a fundamental disagreement, and the bad news for you is 95% of people will disagree with you.
If you agree on that level of censorship, then we’re just arguing where the who/when/where line should be.
No it wouldn't. As big as Facebook is, they still only moderate their own platform, and there is only one instance of Facebook. Separate vBulletin instances do not constitute a single, collective "vBulletin platform." The narrative of "Big Tech" as an organized leftist conspiracy orchestrating censorship over all social media is simply right-wing propaganda.
That's my point. The reason vBulletin forum moderators aren't equivalent to Big Tech censorship is that you can run your own vBulletin, independent of theirs. Censorship of Facebook is bad because that isn't an option.
Case in point: a number of Youtubers fed up with the platform demonetizing and delisting their content are advertising their content on other video platforms, or just hosting their own like Corridor Digital.
The web is one of the few examples of the free market actually working, but people have fallen for the defeatist and nihilistic narrative about the "centralization" of the web and "control" by sinister forces, insisting that competition with any big platform is simply impossible.
They said that about MySpace too and look what happened.
The term moderation itself often came from debate and discussion venues where moderators would police speeches.
This isn't true, it's just that the spatial constraints IRL mean there's never been a need to scale moderation of town squares beyond intuitive methods. Go to your physical town square and start screaming slurs and threats of violence at passers-by, and see how long it takes before the community "censors" you.
In developing and developed countries I've had (ostensibly) mentally ill people shouting epithets at passerbys and they're just ignored. So I think this is more about cultural norms.
Moreover, the case you mention is simple. If a spammer joins a forum and starts spamming, there's usually broad support to kick them out. Once the argument becomes ideological, that's when sentiment is a lot more mixed
I censor myself all the time. There's numerous things I simply don't want to read or see, but I've made and own that decision for myself.
Here's a devil's advocate point of view:
Free speech/free press is an asset within a group when the following are true: A) members are acting in good faith which typically requires value systems to be not too divergent, B) members agree on how to arrive at the truth, and C) members are not confusing science (designed to be true), opinion (designed to be neither true nor false), and entertainment (designed to be false).
When one of these is not true, it creates liabilities that need to be managed. Social breakdown is the result of not managing these liabilities.
Probably an initial response will be: "well who decides X" ... if we've figured this out for engineering problems where lives are phyisically on the line we can figure it out for this. Any authoritative action whether it be laws or standards make some portion of people unhappy.
I'm wondering where exactly you think all of this "information" you would be digesting would be coming from, absent the "censorship" of structures and systems needed to collect, validate and disseminate it?
Good luck reconstructing the last 8000 years of human progress and knowledge from first principles, naked and alone in nature with some crystals and potions before you fucking die of parasites and tetanus I guess.
Back to the original point - You're assuming that a doctor, government or corporation will make a decision for me that's in my best interests. In reality they're much more likely to make a decision for me that's in _their_ best interests. Lots of examples in the past few year+ with the pandemic.
Racism/sexism is a lot murkier of a topic. There's a lot of nuance there that I think we culturally haven't fully figured out. The whole "cracker" situation on twitch, for example.
+1. When I was younger I used to browse 4chan somewhat regularly. I saw snuff videos and other awful content that I still think about to this day. My life would have been better had I not seen it.
Do you really want to censor racist comments, for instance? Wouldn't you rather know how many racists there are out there?
The real problem is possible use of a channel like this to support bad actions, not bad viewpoints. For example, someone could advertise to hire a hit-man to kill someone. Or a group might use the channel to organize a mob to go around burning down jewish businesses.
In the scheme described, owners of individual servers could block such messages, if they recognize they're there (a possibly hard problem). Perhaps this would be sufficient, while still leaving viewpoints uncensored, since there are, we hope, very few people in favour of serious criminal activity, while many favour free speech even for those they detest.
I'm not taking a stand against the content itself, but as long as there are bullies that can be moved to action by bits on a disk, our protocols will need to either support censorship, of be zero-knowledge to the point where nobody knows which bits are on which disks.
The difference with nostr is lots of redundancy -- you post your content to like 5 servers so that if one goes down you're not really censored, people still get your content and -- in your list of relays -- you replace the censorious one and then your followers update where they follow you at.
The link to the content isn’t global it’s still relay/post the client just searches for a given post within its list of relays.
The content is then served through a specific relay which hosts it so basically directly from a server.
So this isn’t a supernode topology or server P2P of any kind.
GNUTELLA supernodes were used to limit the number of peering connections that each client on the network had to maintain and organize the network into a manageable topology this is necessary from a technical perspective and any P2P network solves this problem in some manner that turns a fully meshed network into some sort of leaf and spine topology.
This is basically needed to ensure that any client on the network can reach any other client reliably and to ensure that the network can support large number of clients without needing to coordinate peering globally across the entire network.
If you build a P2P network where peering is just a randomized best effort mesh between all clients it would rather quickly break into a bunch of rather isolated networks as peninsulas and then islands would form.
These days, I have the feeling there are only two kinds of platforms left:
The clean ones with strong moderation, where any form of edginess and possibly controversial topics including breastfeeding, violence or discussing human rights can be banned globally or in certain countries.
And the other ones, where the Nazis, lunatics and scammers hang out.
I‘m still not sure what to take from that.
Comparing "speech" pre and post social media is like comparing "weaponry" between knives and nuclear weapons.
I‘m still not sure what to take from that. "
Probably because the Nazis, etc have been pushed off the mainstream networks and had to find alternatives and the rest of the people didn't and those new/smaller networks haven't been required to censor yet.
Sounds like these anti-spam measures are not actually implemented yet.
Personally, I don't mind having to manually filter/ignore non-conformant behavior in order to prevent that possibility for myself and any other minority group online.
You can find my pubring on my bio after following me. There's no ability to discover others at this time!
Nostr relay registry hosted here (https://nostr-registry.netlify.app) by fiatjaf.
Exciting times!
It isn't too hard to improve upon the status quo in various ways when you just drop a key usability requirement (in this case, the need for human-memorable 'handles').
It is worth reading 'Why Johnny Can't Encrypt' (1999) [0], 'Why Johnny Still Can't Encrypt' (2011) [1], and 'Why Johnny Still, Still Can't Encrypt' (2015) [2].
[0] https://www.usenix.org/legacy/events/sec99/full_papers/whitt...
[1] https://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.22...
E.g. a "name/profile to key/value" service would be useful for more than this.
If people want mastodon style handles, for example, it's easy enough to create a mapping that can leverage DNS for example to let you query for a matching pubkey in a cacheable and easily scalable way and without the need for that to be built into the messaging protocol.
> E.g. a "name/profile to key/value" service would be useful for more than this.
At which point you've reintroduced a global namespace SPOF that is vulnerable to censorship, etc.
You can push the complexity around like food on a plate, but getting rid of it is another matter entirely.
(and in fact on reading the protocol specs, they do have a way for relays to publish mappings [1] . EDIT: and that would seem to make it possible for crawlers to crawl relays to assemble non-canonical catalogs fairly easily).
There are downsides to having multiple namespaces, such as e.g. that there's no guarantee that your client will be able to map a given pubkey back to a human-readable name and/or dealing with collisions between mappings from different sources, of course, but this is reasonably well thread ground.
That's fine. But it's entirely independent of whether or not you provide a lookup mechanism for names.
The point of having the mapping of a name to a key is for users to use it in place of the underlying key in their interactions with the system.
Users just need a catalog which includes the keys of people they care about. The relays can backfill this information. You have little reason to know mappings for users whose messages you're not seeing, and if the messages are not censored the mappings won't be either.
Usability and convenience are two different things. A system that is difficult to use might be easily understood by the user and vice versa.
it's not obvious to me though how you find people to follow.
I assume this is so a relay can't manipulate your messaging by picking and choosing which messages to forward; they'd have to forward messages [0-N].
Edit:
> sig: <64-bytes signature of the sha256 hash of the serialized event data, which is the same as the "id" field>
Signed hash rather than a mac - might be vulnerable to an extension attack
But I'm an idiot so who knows.
There are many examples but the most recent ones that come to mind are people trying to get their friends to use Murmur/Mumble instead of Discord with basically near-zero success. I've seen this in a few gaming forums. Anyone attempting this is basically laughed off the platform with the responses like "All my friends are on Discord" and "Discord can do x,y,z can your app do that?"
So in practical terms how would one make such a platform widely adopted?
This is really the wrong focus.
Everyone should be focused on how to "mainstream" this in the minds of content creators, organizations, institutions, and media. The audience will find these subjects because they have a certain gravity to attract followers.
This is why, in my mind, if the federated open web wants to "succeed" (spoilers, it hasn't failed at all and it's a spectacularly organic ecosystem. Everyone's just using the wrong definition of success), it needs to start demanding for these mainstream content creators to publish to the open web by way of standardized protocols. Especially any groups that take public money or hold special permission to use public airwaves (licensing).
Why would a content creator, org, institution, and media use a new app with no users? All of the above publish to twitter because Twitter's "bizarre techniques to keep you addicted" and "doesn't show an actual historical feed from people you follow"
I remember back in the 90s there was a time when no one had their own web site, but you couldn't listen to 15 minutes of news without someone telling you their AOL "keyword".
Things are very similar today, in a way.
You need to do something better that makes people go "oh, this is neat". I had never heard of Murmur/mumble before, so I spent about 5 seconds checking it out. Nothing about the home page appealed to me... so I closed it.
One way is to port over interesting content from existing platforms. They already have an RSS relayer here: https://github.com/fiatjaf/rsslay
Not saying that this is like a genius new idea, but I think they're aware of what people may want.
But yeah, it's kinda hard. We must keep building though.
I’m not sure if can be…
- Developers working for free generally build things that they themselves want to use. If you look at HN’s opinions on eg Discord vs IRC (or Dropbox vs rsync+cronjob), you can see how the venn diagram of “nerd goals” (e2ee, distributed, federated) and “everybody else goals” (I want to communicate with my friends) is almost two separate circles.
- If you get paid by the users, nobody will use it (Remember app.net? Me neither)
- If you get paid by advertisers, you have the same economic incentives that created Facebook
As you yourself pointed out, neither RSS nor nostr do anything to help people find an audience, so this is completely irrelevant to the question of how these things compare.
Ok. So still delusional. Have a good day.
Luckily, relays are very lightweight and easy to run so maybe it will eventually get decentralized.
This could be reasonably censorship resistant if the first place people checked for the updates of users they follow was a hidden service that is innate to every client. Ricochet Refresh and Bisq are great models of this -- every messenger or trader client launches a local daemon accessible only by a hidden service that corresponds as its identity. Any kind of relay or pub system needs to be an offline-only gossip protocol that is only checked if the publisher's hidden service is inaccessible.
Secondly, this just does not scale, at all. The twitter firehouse is petabytes of content a day. If even a single city adopted this and used it like people do Twitter, running relays would be a financially and logistically significant enterprise. This is obviously nonviable. There are great ways for lowering the cost of UGC, namely serving it on some sort of DHT. You could use BitTorrent, or you could use IPFS. You are using neither, which means you haven't done basic napkin math on what being a Twitter alternative would mean.
But basically a real useful and actually decentralized and censorship resistant protocol would not be dependent on pubs or relays. If you want to contribute to something in development which actually has a viable model, I recommend Identia: https://github.com/iohzrd/identia
This proposed service has not confronted a single one of the actual problems of censorship or centralization in the subset of social media. You maybe should actually talk with people who have done significant anti-censorship work and ask them what the actual problems are and what needs to be done to solve them.
I think the good thing about Nostr is that all the network / account / content seems to be stored in the data, not on the servers, so if the relays become a problem at some point it would be trivial to add new channels to distribute the data.
>Secondly, this just does not scale, at all
I think it does very nicely, in the sense that because the network IS in the data you could have different relays only distributing some of the data for some of the users and by connecting to different relays you could still rebuild the complete conversations in your client.
This also solves one of the annoying things of modern internet: when a video or an article gets taken down all of the websites that reference it get a broken link that is very difficult to recover. This is one of the reasons many accounts respond to screenshots of tweets rather that no tweets.
With something like Nostr should be easier to recreate all the references in a post as long as at least 1 person has archived them.
It's also ridiculous that you cite attacks at the infrastructure level that were not used to censor anyone so far -- because censorship happens always at a much higher level -- and then you just proceed to recommend an IPFS solution that is also subject to attacks at the infrastructure level, because everything is!
Do you have any examples of this? The only deplatforming I'm familiar with is the removal of accounts from websites, though yes that may include a cloud provider's website. I'm not familiar with any IP address related or BGP based filtering by any actor that isn't nation-state funded (for which a system like Tor is necessary.) There's also the GNU Name System as a DHT based domain name system.
This is very simple. Why hasn't anyone done it before?
TBH this sounds like UUCP without routing, I'd say people _have_ done it before...How does it handle a relay tempering with the content of posts or altering the meta-data? Or a relay who'd be sending out fake posts?
Author signs every post with their key.
So the client does the verification? Or is it the relay?
Also, I didn't mean impersonating a specific author, I meant generating posts that no one truly posted to it. So when your client lists the chronological most recent posts you get a bunch of fake manipulated content that was mass generated by the relay itself for example.
From the README:
> A relay is very simple and dumb. It does nothing besides accepting posts from some people and forwarding to others. Relays don't have to be trusted. Signatures are verified on the client side
---
> So when your client lists the chronological most recent posts you get a bunch of fake manipulated content that was mass generated by the relay itself for example.
From the README:
> Each client can decide how to best show posts to users, so there is always the option of just consuming what you want in the manner you want — from using an AI to decide the order of the updates you'll see to just reading them in chronological order.
Not sure how it allows you to find new people or responses to comments. Seems like it should be a key part.
I guess some level of interaction will be needed to replicate the things people look for in Twitter. I guess a very basic functionality that that would cover this would be posting in your timeline "responses" to other posts by including the key of the other author and the cryptographic signature of the post. From that a client would be able to obtain the "parent" post and build a thread.
Yes, that's interesting. You don't want to replicate the addictive part of Twitter but you need at least to replicate some of the network effects.
There should be at least the possibility to reply to posts, so if you follow a guy regarding a topic you can find what other people interested in that topic think somehow.
Social problems need to be solved by social arrangements and supported by technical tooling.
Obstructing the truth by misinformation, spamming, etc is the actual problem. It is a much more effective way to target uncomfortable infos. During one of the Russian elections, voter fraud was caught on camera and was uploaded to Twitter, with #villageName. It quickly caught on and censoring was impossible at that point - so Russian bots instead started spamming #villageName posts with no sane content so anyone clicking on the hashtag to learn what happened was left wondering.
Granted, there seems to be no censorship on Hacker News. :thinking:
That's a good thing in general, though I suppose the example cited is an example of moderation most of us would consider poor or undesirable.
follow the site through RSS and you can see a huge amount of flagged, dead/removed posts