Challenges in building a decentralized web
educatedguesswork.org
educatedguesswork.org
I host a static nginx webserver from home and just use a text editor to look at my log of POSTS to participate in p2p web techs like indieweb's webmention.
The big reason to ditch the modern web entirely, though, is DNS - you pay a centralized thousands of dollars for rights to a name - if That's not centralization I don't know what is.
Truly decentralized means anyone hosts google.com, only difference is you pick which certs to trust. Probably by consulting your regional office/town hall, or similar.
Not to mention that I want my phone's battery to last as long as possible, and hosting websites off it will have an opposite effect.
Too bad, Android and iOS don't allow background apps to be sending/receiving continuously.
Too bad also that NAT over IP4 basically means you can't run a web server from a smartphone, even if you wished to do so.
The other thing we need is some trust/take it with us models. Servers signing their content, local not distributed blockchains.
Federated + pingback + logs. Paul Frazee had some good threads a bit back on kind of replacing distributed but concensus blockchains with local contract logs, where we could inter-transact, but check to see whether someones really being honest & doing the things they said/following their interface's contracts... ugh where was it.
Could well be wrong but I dont see consistent hash rings or other open p2p content stores as being likely to ever scale storage or availability sufficiently.
It would be extremely confusing. Didn't we invent HTTP and IP and the web to let computers shoot messages to each other directly? What happened to that?
NAT did.
There are many people advocating to keep using network address translation, refusing to let go of this workaround for a problem that IPv6 solved long ago.
Inevitably they either think that NAT == firewall, or that carrier-grade NAT is needed for their privacy. (I mentally translate that last word to "illegal activity".)
Most NATs do allow a hole to be punched, but it's a manual step that most users aren't even aware is an option. The process is unique to each model of NAT device, and there are hundreds if not thousands.
Because of address sharing, there can be only one port 80 or one port 443 per NAT. Of course, SNI and similar technologies can work around this, but this is also a relatively high hurdle to get over.
This is difficult enough at home, but in corporate environments it's no longer doable at all. Gone are the days of some early adopter running a webserver on a box under his desk for a decade! I mean, you can, but between the firewalls and the NAT(s) in the way, there is little chance it'll be accessible even internally, let alone externally.
There are other issues also: For technical reasons typical ISPs provide much more downstream bandwidth than upstream bandwidth. Residential-grade connection public IP addresses change semi regularly. Some ISPs are now so low on IP addresses that there is second layer of carrier-grade NAT in front of your home WiFi NAT. Home users have no chance of defending against even a DoS attack, let alone a DDoS attack, which would then also take out their personal Internet, not just their web site. Most people run Windows at home, which would be fine except that the consumer editions limit IIS connections to 10 concurrent requests. Etc...
Meanwhile professional, centralised web hosting can be had for $5/month, little more than a cup of coffee.
You could have a retort for every point, but fundamentally self-hosting makes no sense. For example, you could say that people should just use a separate machine running Linux instead of Windows to host their site. Okay... what's the cheapest decent turnkey machine you can buy? $200? That's the same cost as 40 months of hosting on a cheap provider, and you still have to worry about your dynamic public IP, NAT punching, certificate management, HTTP security headers, NGINX configuration, etc...
After all: what if you only really "carry" your digital identities with you and nothing else?
What if ubiquitous login to any platform would always just work? What if you could easily move all your data from one cloud platform to the next?
Solving the question of Identity is one piece of the puzzle, for sure, but only just that.
1. https://keet.io (a p2p chat and file transfer app). DHT is used to map your public key -> IP address. Currently in open Alpha. How is this better than Jitsi? Jitsi Meet uses a server to coordinate and merge WebRTC video streams, but it is fully E2E encrypted and decentralized as you can run your own instance. Much like Nostr versus other truly P2P alternatives.
2. https://www.impervious.ai (a browser with build in P2P functions). In closed Beta at the moment.
3. Holepunch is a platform for creating apps that don’t use any servers whatsoever. See also: https://www.bloomberg.com/news/newsletters/2022-07-28/tether-s-holepunch-takes-on-big-brother
4. Synonym (pun on "nym", maybe?) is also trying to solve identity: https://bitcoinmagazine.com/business/synonym-launches-architecture-for-self-sovereign-economy-around-bitcoinThe "truly decentralized" web, under this angle would only contain small fish. But the very success of the web means that giants will emerge.
Well... umm... okay, if that makes sense. But it doesn't for most people most of the time.
People as a rule like centralised services, because they can innovate and iterate faster. Centralised services have efficiencies of scale, round-the-clock support, and other perks that decentralised systems generally cannot afford to replicate many times over, at least once for each instance.
We need to find games that people will want to play.
I personally think it's just a matter of cultural practice. A large fraction of the world got on the web after the web as publishing platform was privatized. If it was the norm back in the 00s that every household, town and school first bought a box to function as the home server for it's members (which doesn't seem that far fetched imo. If Usenet and IRC were a little more accessible...), there's no reason that in this alternate history, most of the Facebook groups, Discord servers or Reddit subreddits would have had their own domain name or something like that. There will always be space for public soapboxes like Twitter and algorithmic feeds but that's only a fraction of how social networking is done. I like to think as the public consciousness is waking to the harms of monopolized publication platform that's always looking to grow it's stock value, we'll see the federated web return to the norm.