Don’t record your social life on an append-only social network (2022)
ctrl.blog
ctrl.blog
As opposed to Mastadon, your identity is tied to your pubkey rather than the instance that you created your account on. The difference to Scuttlebutt is the differentiation of relays vs clients, and the lack of chaining messages together in the "blockchain"-like structure.
The result is a fairly simple protocol which is fairly low latency and seamless for many applications compared to other decentralized solutions.
[1]. https://nostr.com/
https://github.com/nostr-protocol/nips/blob/7d792055372ce1af...
Then clients and relays SHOULD act as if the referenced event is deleted. This is different than MUST, probably because there’s no way to guarantee it happens. It’s also possible the delete event doesn’t make it to everywhere that received the initial event.
See also: the Streisand effect
Only if someone cares enough about your social media to be watching for deletions, which I'd imagine is pretty rare. If no one's watching now, now is the right time to delete something.
> See also: the Streisand effect
I think it's important not to overstate that effect, as there are lots of scenarios where deletion will not draw more attention to something. For instance: you're a rando deleting something that's not interesting, not currently being observed, or something no one will notice when it's gone.
The trope namer got hit by it because 1) she's a celebrity, and 2) removal would result in a noticeable gap.
A better way to think about it is: do you have good reason to think someone is actively watching you or will go through the effort to collate your social media posts against some archive (that will be incomplete unless you're an active target)? If you don't, delete away.
If you're still concerned, delete some old stuff randomly to distract from the stuff you really want to delete.
> even if that somebody is some Internet archival robot
Those can't even scrape everything people actually want to keep, let alone comprehensively scrape every social media post from everyone. There are huge gaps.
I actually was peripherally involved in some volunteer efforts to archive a bunch of stuff around the Hong Kong protests and the Afghanistan withdrawal. IIRC, they didn't even try to scrape Facebook posts (because FB was doing so much to thwart scraping, and there may have even been problems with Twitter). There are well-developed tools for YouTube, through.
It would, if someone were looking in detail, but that isn't what the Streisand Effect is. That effect is the demand to stop/remove something that draws attention to it, not the actual removal (if it is indeed removed at all).
If the photo of her property had been quietly removed by the photographer I and most others would likely never know anything about it, much like you and most of the rest of the world wouldn't know I deleted a post on my blog that was so full of embarrassing typos that I couldn't be bothered to correct it. I know about it because of the heavy-handed demand that it be removed from that collection.
Sideloading has to become a default, somehow without us returning to antivirus era. Problem is that no one knows how to make that happen.
> Relays are like the backend servers for Nostr. They allow Nostr clients to send them messages, and they may (or may not) store those messages and broadcast those messages to all other connected clients.
I still haven't wrapped my head around these two words from the nostr site. How can it be truly censorship-resistant when used are entirely dependant on what their relays decide to store and share?
Hopefully someone, like a Raspberry Pi cluster on a derelict Soviet military space station on an international orbit, will take your message and relay it, :shrug:, and those messages can still be authenticated by the key.
That’s how I understand that part; Nostr uses DNS for blue badges and relay connections so “truly” indeed sound a bit of crypto talk though.
If it's all through a relay it probably isn't very censorship resistant at all. My messages may be signed locally but if the network trends towards mob-based bans and censorship like Mastodon as soon as I get on the wrong side of the network I'll be the only one seeing my signed posts
What I believe that "censorship resistance" actually means in un-cryptocurrencified talk is, it lets relay operators filter out locally illegal but not globally unethical contents(e.g. political speeches, pornography, certain URLs and strings) without banning users and/or fragmenting the network. And that is an improvement over Mastodon/ActivityPub architecture.
But boy those crypto guys knows how to hype it up...
However the main issue with peer to peer is not everyone is going to be online all the time, relay serves as a temporary storage place until one of the user/client goes online and get the message.
Well on their page they said" To publish something, you write a post, sign it with your key and send it to multiple relays (servers hosted by someone else, or yourself)."
If you really want to prevent that then it is to also selfhost.
The claim is that it enables social network/s that are resistant to censorship. It doesn't say that it is a social network that's impossible to censor.
It's a protocol that everyone is free to implement. Valid implementations of the protocol should be compatible with each other. Meaning you don't have to go to soshl.com or use the Soshl app. Relays can choose whether or not to store/broadcast your messages, yes. But they can't stop you from sending them and they can't fake or modify your messages. They also can't revoke your identity. I assume a relay can't force other relays to delete things, but I'm not sure of the details.
A relay choosing to retransmit your message or not could be considered censorship, but it is not the same censorship as a court ordering Youtube to take a video down, which is not the same as Twitter silently burying your posts, which is not the same as the police arresting protestors, etc...
In Mastodon each server makes their own decision on who to censor. Functionally it's grown into a bit of a hard mentality with entire servers being censored if they don't go along with the larger group
And the idea of using nano transactions for upvotes has long been an attractive approach in this community for mitigating bot swarms from influencing conversations. In fact, the proof of work system that bitcoin was based on was originally proposed in the 90s as a solution to fight email spam. A micro cost of computation power (or a nano transaction) is neglegible to most legitimate users, but adds up quickly for spammers who depend on sending out thousands of emails for a single hit.
Neither financial ledgers nor contracts are things we should want to be persistent and immutable - as the crypto and smart contract folks have repreatedly demonstrated
I have seen way too many systems that model something that happens somewhere else and provide no way for correcting discrepancies between the system and reality, built on the assumption of either infallible humans or infallible integrations, when the truth is that all humans and all integrations will eventually fail to input data correctly and need the ability to correct anything (no field should ever become fully read-only in such a system, and no status should become fully unreachable from any other status).
You just enter a new operation correcting the issue. If you can't do in in the external ledger, you do it on your own side and then cancel your correction using a new operation when the external ledger is finally corrected.
The point is auditability. You want what's inside the system to reflect what's actually happening.
The latter would be interesting for areas where conversations should be on the record, however in cases that people want their conversations off the record they’d just use a side channel. The UK govt communicates using WhatsApp for Christ’s sake.
So it’d need to be something where both parties fundamentally benefit from the ability to verify that a post, or a conversation, took place. Where would that even apply?
I think the problem it's trying to solve is: "How can we mix social networking with blockchain?"
The traditional alternative is logical clocks, but a malicious participant could forge those, so they're not suitable for a fully distributed system run by random users.
(SSB is blockchain in the strict sense, but there's no proof of work or anything like that. Each feed is its own append-only chain with its own private key.)
For SSB, the aim was to be able to gossip feeds via untrusted intermediaries, with patchy network connections all round, and be sure that the intermediaries haven't added, changed or removed any posts in the feed.
The protocol's designer lives on a boat in New Zealand, and other collaborators live in remote areas in different time zones.
One adjustment to the protocol that seems to me like a quick win (but presumably has some technical hitch I can't see, since I don't recall anyone suggesting this) would be to not include the post's body in the “block” (in the message itself that gets hashed and signed by the next message), but rather as a “blob” (essentially an attachment) which others don't need to download in order to verify the feed. That way old messages could be effectively forgotten if all peers co-operate (and no-one took a screenshot, etc).
There's nothing to prevent you from taking this route, you just sign a blob hash instead of an entire message object.
I work on an experimental SSB-like-protocol in my spare time that does exactly what you've suggested: https://github.com/evbogue/bogbook
I don't know if this makes the network forget more, but the aim is to reduce the time it takes to sync and get started.
why would that need a blockchain (even without proof of work), as opposed to simple signed, timestamped, indexed posts and having the reading client app check the signature and post indices?
> why would that need a blockchain (even without proof of work), as opposed to simple signed, timestamped, indexed posts and having the reading client app check the signature and post indices?
It depends on how the message is signed. If the message format's this:
sign_message(message + timestamp + index) + message + timestamp + index
The 'index' can be manipulated: The signer (malicious or not) can resign an old message & effectively overwrite a previous message.
sign_message(new_message + old_timestamp + old_index) + new_message + old_timestamp + old_index
This means that in the event of such a resigning, it's the app's responsibility to prevent resigned messages from overwriting old messages.
Blockchains prevent this at the data structure level because signature hashes are effectively random, meaning they're near-impossible to tamper with:
whole_message := prev_message_hash + sign_message(message + timestamp) + message + timestamp
wherein prev_message_hash := hash(prev_whole_message)
In contrast, this here, which is the only thing the blockchain struckture really adds:
> The signer (malicious or not) can resign an old message & effectively overwrite a previous message
… is a rather radical shift of the goalpost, as the only capability the blockchain really adds is to protect against modification not by untrusted intermediaries (which was the purpose and which would already be covered without a blockchain) but by the legitimate owner/editor of the feed.
In other words: The only thing the blockchain adds is that it makes it impossible for YOU as the user to edit YOUR OWN posts. I'm not sure that's something most people in the social network context (as opposed to, say, a financial transaction ledger) would see as a feature and not an anti-feature.
Yeah, that's exactly what SSB does, plus each post includes a hash of the previous post.
I think that's so that even the holder of the private key can't retroactively replace an old post with an altered version of that post (but with the same index number and similar timestamp).
Feels like people are really just trying to play into "everyone has a number that can be banned" for the Internet/social life in general.
The problem of justifying the existence of blockchains.
Getting funded by people thinking it will be next big thing.
That sounds like it could be useful in legal and policing contexts. One complaint I’ve often heard about body cameras in policing is the possibility of footage that was created and did indeed exist being “lost”, with the implication being that legal entities intentionally destroyed evidence of either the footage existing, or its contents.
To the extent that this centralized authority issue applies to textual data or metadata, decentralized records of messaging times and contents would potentially be an invaluable tool of transparency and promoting systemic confidence in a visible shared audit trail.
The same as every other blockchain application: the problem that no-one has found a practical use for Blockchain despite 14 years of effort, but that blockchainers continually need the next wave of hype so that their coins don't lose value.
I would say the main interesting problem to solve is how to have a social network with a shared state without requiring a all-powerful central party like the existing solutions. Blockchain solutions allow a consensus about what is in the network without this.
If you don't care about the social network state diverging endlessly that's not a problem, but part of the "social" part of social networking is that users expect to see broadly the same messages or at least that all messages are drawing from a common well in the sense that I can choose not to follow a particular person or conversation, but if I do follow them/it then I see the same set of messages as others who are following. This is how we have a shared conversation.
Edit: Not saying this is the only or best way to do this, but it is one way and I believe this to be the problem blockchain social networks are trying to solve. eg these guys are building a blockchain social network and it's explicitly one of their goals https://www.projectliberty.io/
Edit, amend, add, delete, schedule, etc., all from a single text file. I haven't worked on it in a few weeks but I intend to get back to it soon.
[0] https://post.mw
I guess it would be fine if indexed separately. Edits to data past a certain age are fairly rare.
Haven't been posting as much as I want to yet, I'm working on the editor from https://markwhen.com to hopefully port it over to https://post.mw as well
Did you know HTML and CSS are basically text files with some special organization that allow you to make really snazzy colors and marquees and stuff?
It's just a text file you can POST, too!
Super simple, use the same tools you use now.
Well, you'll need a browser to make it look pretty, but that's not the point right?
There are certain privacy features like self-deleting messages that you can only get in a closed ecosystem. Does this mean you shouldn't use any kind of web-based social media, since everyone you communicate with can easily and automatically archive everything using a browser extension or userscript?
Let's suppose that you posted something publicly to an append-only social network, and it was completely OK at that time. Then, laws changed (and you could not predict this), and this post is no longer legal according to the new rules. What the lawyers say is that the very fact that the message is still online is now a crime. Yes, there is a universal notion that laws do not apply backwards in time (retroactively), but here they indeed don't: the message is still online AFTER the law got into existence, and so this is a lasting crime that started when the law was enacted.
Normally you would be required to delete the post between the moments when the new law is announced and enacted, but you can't, and it is still yours for others to find and read, so you go to jail.
P.S. It would be interesting to know the opinion of lawyers from other countries.
However, you always risk someone else (like a scraper) storing messages including your signature forever. Deleting is virtually impossible for practical communication purposes. Best you can get is “I promise you I deleted my copy and thus wont distribute it further”.
To me public communication has the trade off between trusting the communications platform (like most social platforms today) vs trusting the end user (signed messages). If you have trusted end users, scraping a third party repo of “forever history” becomes more plausible, as they can both prove that you(ish) signed it and are unlikely to respect your request to delete their copy. Is this different from what you’re saying?
Take instead the example of sending content encrypted with shared session keys over a live mesh network, where you send session keys to your specific friends to decrypt instead of revealing an identity to them.
Any "friend" could prove that they had some content at a specific time, but they could never prove that they didn't just make it themself since you gave them the symmetric key that let's either of you make shared content. This is a simple way to fail to achieve irrefutable though other properties as well..
If for example you are accused of a crime with no statute of limitations and a friend has since died, there should be a distinction between whether their hard drives prove something or their hard drives are hearsay without something else, like their testimony that they didn't tamper with contents in some long forgotten practical joke.
For the strongest guarantee of non-repudiation, there’s OpenTimestamps:
"Promise" as in committed somehow or wishful?
It sounds like you are describing a UI for simuating mutablity (like declarativd photo edits in Google Photos) , not actual data mutability.
I can’t speak to hate speech (other than seeing reactions to it showing up a lot in trending topics) as I’m liberal with my use of block to keep Twitter as non-toxic as possible.
If the mass exodus has caused any major user count decrease, people should be talking about "Why would you still using Twitter?" than "Hey, I've closed my Twitter account, cool uh?"
The entire neighborhood gather to see a fire destroy my house
Me: wow, I never had so many visitors before
Anyway it seems clear that usage has shifted and reportedly Twitter is now running low quality (and less expensive) ads.
Also, I wouldn't call the Snapchat UI terrible. I would call it difficult for first time users. This creates a "buy in" effect with users... Lots of powerful tools have this concept, similar to the Bloomberg terminal.
Yeah, that sounds like a really positive user experience. Hard pass.
Crypto keys aren't supposed to collide, but on a set of billions this could happen. -- If it does have a contingency for replacing the PKI part of the identity. This also covers loss of key material, etc...
Identity is ephemeral and in flux.
An indexed web of trust, who knows who, etc might work.
I'm not familiar with SSB. And, to me, this article's headline is five words too long (harumph)
Question though: Does this imply that I can follow someone without them knowing about it if their address hash gets leaked? If so, in what way could it meaningfully be described as being private? I assume there's some way to control who you broadcast to, or approve someone who follows you, and this description is just not mentioning it.
You can broadcast encrypted statements: https://ssbc.github.io/scuttlebutt-protocol-guide/#private-m...
~Everyone can tell how many of these you sent, when, and how large were they, but not to whom (incl. how many recipients they had unless there were too many and you had to send multiple copies[1]) or what was in them.
[1] The copies will still be unlinkable, but if someone sends 5 messages of ~same size within a second, it's a pretty good guess that they're sending 5 copies of the same message.
Like a tripcode?
>Instead, your username is a meaningless cryptographic hash that consists of random-looking numbers and letters.
Ah
I still have vision for what Haven could be, and supporting self-hosting remains important but I think I'll end up with something like the Matrix/Element model where there is a (free?) centralized server you can use, or you can host your own with full interoperability.
[1]: https://havenweb.org
Good luck with that. Even the Firefox plugin requires some additional setup. Frictionless it ain't. By a long stretch.
Sigh.
Otherwise just have a blog or whatever.
Here's some fun keywords to whet your whistles if you wanna:
Camp Williams Boundless Informant ICREACH MAINWAY DCSNet BULLRUN/Edgehill - NSA breaking encryption by intentionally weakening encryption schemes and stealing master keys.
To rewrite the Beatle's lyric.
twetch.com