Radicle: Peer-to-Peer Collaboration with Git
lwn.net
lwn.net
I'm also suspicious about moderation. Even with tools to blacklist peers, it seems like this design is vulnerable to "hostile takeovers" where a repo is forked but the new maintainers don't change the repo's did, instead just get more nodes to follow them than the original.
A DID is a public key. If you don't know the corresponding private key you won't be able to make any updates. All you'll be able to do is mirror it.
instead just get more nodes to follow them than the original
This is like saying "but I can fork Verisign's Root CA certificate and get more nodes to follow me than Verisign!". No, you don't have the private key that goes with that root certificate. So everybody will ignore you.
Cryptography is not a popularity contest.
So, anyone can make commits and seeds will accept the commits from anyone, but the "canonical branch" will only update (on a given seed) if it's signed by repository delegates. The "next strictest" level of control is private repositories, which simply means that Radicle will only send its commits to a peer in the repository's allow list.
My next big moderation-related question is what redaction looks like. Obviously an unwilling peer would diverge from the signature chain at this point, but does Radicle provide any tools for, say, permanently redacting an issue comment? It's obviously possible (but painful!) to do this in regular git for commits.
Link: https://radicle.xyz/
Previous HN discussion: https://news.ycombinator.com/item?id=39600810
https://lwn.net/Articles/967157/
Update: A reply has been added since posting this.
https://github.com/MichaelMure/git-bug
https://github.com/dspinellis/git-issue
https://sciit.gitlab.io/sciit/ (this one has a list of alternatives here https://sciit.gitlab.io/sciit/#other-distributed-issue-track...)
Overall it's very disappointing that Github didn't decide to embed issue tracking (and also PR discussions) inside the repository (in another branch perhaps). Issue discussion is part of documentation IMO, and not distributing it alongside the repository causes lock-in
https://github.com/MichaelMure/git-bug/issues/749#issuecomme...
They really don't want you to leave their walled garden.
Git by itself is decentralized, and peer-to-peer technologies existed long before too.
> Radicle does not use any blockchain or cryptocurrency technology.
Which is also my experience from playing around with it recently.
> Git by itself is decentralized
This is true, but people very rarely lean into that. I personally run my own cgit for all of my public repositories, and I have collaborated with people who run their own git servers by managing multiple remotes - fetching from their remote and pushing to mine to share. I've also collaborated on projects that use email-based workflows. This works really well, but it also requires us to have the infrastructure to do that. Radicle reduces that infrastructure requirement to running a daemon on your desktop (as is common with p2p technologies).