The death of privacy front ends?
tux.pizza
tux.pizza
Migrating to services where the data is free and not captive was always the only long-term solution.
Next up: rather than inventing technical solutions to work around walled gardens, we need serious legislative efforts to mandate data freedom. It should be possible to export 100% of one's data stored in a service like Twitter or Reddit in a reasonably-parseable format (a tarball of JSON as one possible example, or maybe a SQLite database, or whatever is appropriate) and import it to a new service. Data moats must end, or we'll be doing this same stupid dance every few years when the next MySpaceBookTokDit enshittifies and takes everyone's social data with it.
And some of those wouldn't be particularly helpful; @tags would lose a lot of meaning as you migrate, especially if others on the destination platform already have that handle.
And regardless, Twitter-alikes aren't the only thing worth considering. Exporting all of one's video data from YouTube, or all of one's comments from Reddit, or all of one's search history (and Google Voice texts, and Docs documents, and etc.) from Google are all usecases that fall under these data moats that are useful to be able to take with you and move to another service. There's probably more usecases I'm not even thinking of, but the point is that by exposing all the data by mandate, we don't have to be limited by the imagination of today, we have the data, we can build whatever future frontends and replacement services and etc. we want.
Microsoft doesn't have such tool for OneDrive, Outlook or their services in general, so downloading 1D docs means going to the website, selecting then and pressing "download". For Outlook emails... well, good luck
As for OneDrive and Outlook exports, if only there were a way to synchronize data to a client. Oh well.
Depends... Under their POV, why would anyone want to import stuff to a Google account en masse if they already have it on their "original" acc?
> As for OneDrive and Outlook exports, if only there were a way to synchronize data to a client. Oh well.
There are OneDrive clients for Windows, Android (and I guess Apple systems too), but it's still less convenient than downloading a single ZIP. Using the official client means I need to copy the stuff to my local drive first, and then compress it if I want to store it in a more efficient way.
I have 3 personal Google accounts, and that doesn't count my work and school Google accounts. It is conceivable that I'd want to move at least a few things around among them.
Also, it is conceivable that someone could write up a utility that prepped arbitrary types of data for import into an arbitrary Google property. Whether it's JSON or XML or whatever, I could see there being use cases for importing data that has not yet been in a Google account at all.
Agreed. The bigger issue is relying on a broadcast-esque provider as your sole storer of video. If your account gets blocked somehow (or locked out) then you're done for. Have a separate, storage-only video account and push to YouTube as well.
Of course I can understand why a service wouldn't want you to be able to post thousands of posts in a matter of minutes, or to fake timestamps, or...
The whole idea of massively importing stuff is complete nonsense.
I could understand why a Twitter alternative might not want you to be able to import a ton of old posts at once. But this is why we need open standards and open source. Some random large Mastodon instance might not want to allow imports, but you should at the very least have the option to spin up your own instance, import all your old Twitter posts, and still participate in the ecosystem.
As others have pointed out, an @tag can still be useful by linking back to the original service. Or the importer can support a username mapping so it can rewrite names from the old service to names to the new service. Sure, all of this requires extra work, but it can be possible if people care enough.
Regardless, export functionality at the old service is the first necessary step. Even if there's no import on the other side now, someone might build one eventually. And even if that never happens, being able to archive your old data is useful by itself.
Regulations on what data can even be collected will solve this problem, and negate the entire reason for using these front ends.
---
Thought that just crossed my mind: what if - a law that mandated any service accessed over the web must not interfere with any attempts to develop or use third party clients?
Not a software license. A law, with actual teeth and massive fines for companies (it's always companies) violating it.
Discord banning folks for using Ripcord? Yeah that'll be $(insert massive fine here) per user banned. Your credit union? Sure, write your own mobile app for it.
Like GDPR, but a hundred steps further.
To give it proper teeth, the fines for willful infringement should be basically company-ending events, because fuck abusing users. No $1000 slap on the wrist. Nah, "up to 5% of company net profit for the year of occurrence, or $X minimum amount, whichever is higher" (to handle unprofitable VC-backed entities) or something truly fear-inducing.
And no, I can't currently think of anything that should be excepted from this. If you think you can write a better GUI for the SaaS version of TurboTax and not land yourself with tax fines, go for it, dude. The law should allow you to do that, too.
You’d make it illegal to take active action against Phishing? That’s uh… bold…
I said "currently" - this means I'm open to hearing worthwhile exceptions, but I do want to have a chance to think about those exceptions and think of how companies would abuse them to in turn abuse their users, too.
Companies aren't going to want to be forced to provide a fully functional API. Not only would that mean a large amount of extra cost to build, test, and maintain but they are also more open to issues from hacks and bots. It's be much easier to kill their web app and tell everyone to use a mobile app instead.
I wouldn't be so sure. This whole industry works on having defaults that most people just accept. It's quite easy to set up an ad blocker, and yet most people just don't.
> The would also be open questions like whether the API must be free to use, could have some legal freemium model, and how a "fair" price would be determined.
I phrased my proposal the way I did on purpose. There's no restrictions on what a company can charge for an account, just that "API access" is always included with it. If a company wants a freemium model, that's fine. If a company charges a subscription for all accounts, that's also fine. If a company bans an account for whatever reason, API access for that account goes away (the arbitrarity and capriciousness of bans is a separate topic though)
> large amount of extra cost to build, test, and maintain but they are also more open to issues from hacks and bots
This is the standard FUD about anything that's "different" or creates a modicum of requirements on companies. They're already publishing APIs for the proprietary apps to use. Nothing changes for "hacks" unless they're relying on the thinnest of obfuscation. And the whole point is that a user using a "bot" should be given the same consideration as a user using a proprietary front end - services should police user behavior rather than being lazy with method of access.
> It's be much easier to kill their web app and tell everyone to use a mobile app instead.
Except most "apps" are also just proprietary front ends to services hosted elsewhere, and thus run afoul of the same bundling.
That's totally possible, I just expect the regulation would kill many services unless the regulation is either full of loop holes or uninforced (or both)
> This is the standard FUD about anything that's "different" or creates a modicum of requirements on companies. They're already publishing APIs for the proprietary apps to use.
That isn't FUD, requiring API access absolutely adds to business costs and overhead. You need to document the API, test it, security audit it, etc. Sure these should be done already but they rarely are. I've seen plenty of companies that largely ignore these tasks when it's an internal API onyl, believing that shipping fast is more important and the obscurity of an undocumented API is itself a layer of security.
I'd be extremely impressed to find literally any company with an internal-only API that is proepryl tested, documented, and audited. I'd be even more impressed if they worried too much about versioning and backwards compatibility beyond the scope of what it takes to update their own consuming code.
There are still huge gray areas to define in anything similar to your proposal, writing laws with loose definitions and purposely building in unanswered questions is worse than having no laws at all.
Is the legal requirement only related to the API surface available? Can I rate limit all unique users, even to say one request per hour, day, or year? Can I code my API in any way I deem fit, like a Soap API or one with an obfuscated API surface that runs through a random RPC protocol? Do I have to follow semantic versioning or similar?
Regulations can't just be thrown together on a whim. That's how we end up with confusing laws and overpaid lawyers trying to game the system in favor of the person with more money. Laws should always be clear on what is being deemed illegal, why, and what the punishment is.
Sorry, but these "questions" are still just FUD.
First, an HN comment is not expected to be a fleshed out legislative proposal, nor is HN a place for fleshing out legislative proposals. So demanding that I readily come up with some perfect implementation details right here isn't good faith discussion, but rather derailing by implying that any law would have to specify a technical implementation (which would indeed be ridiculous). In reality, these details are determined through judgements by the courts, which rubs us software people the wrong way, but does make the problem tractable.
But really the crux of my original comment, which you brushed right past, is that this bundling seems straightforward afoul of the basic concepts of anti-trust. If existing laws do not suffice, a new law still doesn't actually need to specify how exactly something must be made available to the wider market, only that it is. So all of the technical details fall away - whatever technical arrangements a company uses to make its publishing service available to its own in-house app, need to be made available to the wider market. Likely whatever modern web technology they're already using. If that's SOAP then it's SOAP. If that's a bespoke protocol running on bare IP, then so be it.
And if companies attempt to implement this in bad faith and continue colluding between what should be two separate business units, then they should be split up into independent entities.
Legislation sets normative behavior, even if it is not enforced fully or companies find loopholes. It is simply not right for a free society to have surveillance databases that would make the most staunch Stasi agent blush, and we should work towards the goal of ending them by every avenue possible.
Also how do you propose to kick say Equifax to the curb through individual action? There are many services that don't exist via user consent or interaction, but rather just by purported assent through contracts of adhesion from some de facto mandatory industry.
You can do that. You've been able to download, directly from twitter, an archive of pretty much your entire account. It's not quite JSON - it's actually a .js file that declares a single variable, but it's close enough.
Data moats haven't been a thing since GDPR passed and everyone implemented "data dump" features as a result.
The real problem is the lack of federation requirement. Say I'm a competitor to Facebook - what use has a potential customer of mine from an import feature when there is no way for my service to interface with the customer's Facebook friends?
We shouldn't give up, but keep fighting to be able to use services with the software and hardware we choose. The whole "API" concept has always seemed like a power-grab since it was introduced.
What do you mean? Do you mean a public, free API offered by these services?
That's why I like to say that all sites already have an API: HTTP + HTML.
the only point of an API key is to extract information from API users that would otherwise be anonymous.
If the frontends quit working though, I just won't go to those websites anymore.
go to this link (at bottom of main teddit.net page)
https://codeberg.org/teddit/teddit
and look under "instances"
just replace "reddit.com" with the instance name in your reddit url
I actually have a bookmark that does it automatically when I click on it.
javascript: (location.hostname="teddit.net")
or whatever instance you want
> curl -v https://tux.pizza
* Could not resolve host: tux.pizza
* Closing connection 0
curl: (6) Could not resolve host: tux.pizzaSorry, not sorry. Use Gemini, search with Marginalia, socialise with real people and reach your communities with email.
I have some real-life, non-internet-based hobbies for which I come together with other people. All the rest of those people frequently talk about social media, online influencers, DRM-controlled streaming, and WhatsApp groups, and I’m the weirdo because I don’t follow any of that. In fact, it is socializing with real people that convinces me that the world will just go along with tech companies’ nefarious plans, and ultimately it may no longer be very feasible for us nerds to just drop out.
Memes flow. Links get posted.
All is just a setup for the next IRL meeting.
I found the end of the internet in '99.
This is the last few sites that have a low bot ratio.
"office hours" / calls with random people where they can ask for advice, talk about their ideas (or just rant!) worked pretty well for me: https://sonnet.io/posts/hi
Privacy is not piracy. This is piracy.
Producer produces content and RSS syndicates it that can be read by clients IN WHATEVER MANNER OR FORM THEY DESIRE.
That's the whole idea of internet. Now, you go ahead and lament how this is piracy. Its not. YouTube provides RSS feeds. Same do other platforms so as long as they do, we can do whatever the hell we want with the feed
No, the idea of the internet is to create a global scale network of computers.
>YouTube provides RSS feeds.
Which links you to a webpage that includes ads to monetize the video, the RSS feed, and the rest of the site.
> That's the whole idea of internet.
I think it's very hard to assert that anything is "the whole idea of the internet". If you want to go back to its roots, the "whole idea of the internet" was to have a reliable military/government communications system in the case of nuclear war.
These days the internet means different things for different people, and no one person can credibly assert that any particular purpose is valid or invalid.
Certainly the server owners can try to do tricky things to make it so you can only display the data in ways they want you to display it, but there's no natural right that makes it morally or ethically wrong for you to display things how you want.