It is going to happen, and they can go kicking and screaming, or try to get something that works with them.
Mastodon has the unfortunate adolescent problem of being not Twitter but not yet fully matured into its full potential. Teenagers and Mastodon alike rebel agaist their parents in order to discover who they are. Before they sort this out they try a bunch of contrary behavior and eventually they discover what makes them them.
Is Mastodon Mastodon because it doesn't have full text search, because it doesn't have an algorithm feed, because it is decentralized, because it doesn't have quote replies, because it has a different user base with different relations?
All of these, and not all of these. Mastodon will, eventually figure out which ones make it itself and which ones don't. Maybe in that process it reinvents itself countless times or maybe it coalesces around a strange attractor in social-feature-space. We dont know the results without running the experiment and figuring out what full text search means to Mastodon is running the experiment.
Different folks have very different expectations and wishes if you ask them about the ideal social media site. Imo it's paramount to bring back trust. This could be done not through dubious "fact-checkers" or by banning anyone certain people dislike, but simply by having the option for accounts to have all their submissions posted to a blockchain so that they can't be deleted nor altered. This could be used by media, politicians and anyone else who wants to signal reliability. Users could then go back in time and decide for themselves if the account is honest and worth engaging with, there would be cryptographic proof if they keep lying or misrepresenting things and this in turn could easily be linked to.
Ideally, not only that but users should be in control of their data. This is kind of true with Mastodon but the majority of users don't run their own server and won't ever, because that's just unrealistic. It's better to outsource this with financial incentives to ensure decentralization and user control.
I have my own measure of success and Mastodon meets it well enough, but I wouldn't say treating it as an objective measure adds any value, and why should it? I really only care about n=1.
It was certainly a fiery post, but this is how the web has worked since forever. Whether it's robots.txt or #nobots, opting out is required. After all, you're putting the content out there. In the end, this should be addressed by modern clients: "Do you want your posts to be searchable and your following list to be used for recommendations? Yes, No" and add #nobots if they decline.
Anyone who is putting content on the internet is explicitly "opting in" to the content being on the internet, with all the rights, privileges, advantages, and disadvantages thereof. They can elect to make their wishes about content sharing known by using things like robots.txt and #nobots, but those are merely weak guidelines, and by then it's too late anyway since they've already opted-in by putting their content in an easily accessible location. Kind of disingenuous to stand on a street corner with a bullhorn and then get pissed that someone heard you and remembered what you said.
This happens literally all the time with music: broadcast is not a license to redistribute or otherwise commercially use content.
i have no problem when the people i intended to reach save and index my email. yet i think i’m reasonable in being upset whenever i discover a new party i didn’t know/expect is doing it (e.g. NSA).
SMTP sniffing, SNI sniffing, DNS sniffing: these are all instances where ingesting “openly available” data is beneficial to the party doing it but costly to me (it limits my ability to speak freely with a consenting party without consequence).
fediverse is clearly split on this. some people have expectations based more in personal correspondence, and don’t want to end up in the same situation as email where the adversarial relations and negative externalities are just de-facto/accepted. others have expectations based in mass-media, where the further your comms travel the better. but for most users, they use the protocol for a mix of both, and that makes for a messy and difficult to reason about situation.
some of this is solvable with protocol upgrades. but that’s going to take a lot of time, and it’s not clear that every social norm even can be enforced technically.
The rule I was taught was "email can be stored indefinitely and read by every node in the network the email is routed through; act accordingly."
A lot of Mastodon users want Mastodon's #1 priority as a platform to be harassment prevention, even if it requires major compromises in usability.
(Another example of this is the lack of a quote-tweet (quote-toot) feature.)
Ironically, the community's response to the author of this blog post when he debuted his search tool could probably qualify as harassment - he was absolutely walloped on there.
I brought this up because I specifically run my own server and I license my content in a way that prohibits its indexing for full-text search. Am I a "Mastodon people"? Who can say for sure.
My experience comes from using Mastodon from 2015-2018 (where I got to witness the free speech instance wars) and ultimately distancing myself from it.
With the recent influx of Twitter refugees the user community on large instances has, as one would expect, trended to the mean, and I would say this statement doesn't have much merit now.
I don't think Mastodon or anything else on the Fediverse currently uses public key encryption at all, though.
Google Plus had the option of sharing publicly, with a specific circle, with all your circles, or with your extended circles (your circles and their circles). This gave very good granularity in controlling who could read what. It sounds like some people at Mastodon could really use something similar, and the only way to accomplish that on an open, federated network, is through encryption.
Though it may be a bit much to encrypt it separately for 100 different people. It really blows up the overhead. So maybe don't encrypt the entire message with publish keys, but with a secret key, which gets encrypted with each public key of the allowed recipients, all of them attached with the same message. Still some overhead, but a lot less.
I don't know ActivityPub well enough to know if they already have something like this, but it might be a useful addition.
If you want end-to-end encryption then the key management needs to be on the client and the client software needs to be securely distributed, which makes it more like a mobile or desktop app than a web app.