17 karma · joined April 22, 2022
It does work tolerably well, people are building stuff on it, but I think it's too widely-hated to build a network effect. (Source: search for urbit on HN and click on literally any thread)
It had so much going for it, but it was DOA from launch for two reasons: first, the implementation is so bizarre that the kernel documentation is frequently mistaken for an elaborate joke, and second the founder's racist blog went viral at virtually the same time as the public launch. It's not technically failed I guess as it's still being developed and does work, but a network without a network effect can only go so far.
I honestly think the "personal server" idea would be incredibly useful, and it would also be very profitable (not the software itself, but for cloud providers) if every suburban family rented a $15/mo VPS. I post about it here from time to time in the hopes that someone will fork it or re-implement what is basically a great idea, but in a non-ridiculous way and without #cancelled taint of the founder. Bezos, if you're reading this, please put a small team on it just to see if it goes somewhere, I'll be your first customer.
But there's also probably some new and interesting criticisms one could make? Perhaps about the actual project described in the article? And maybe after having read it and understand it? That doesn't seem like too high a standard.
I know I'm shouting into the void here, and under a pseudonym to boot, but this is an active FOSS project that real live people work on in their spare time because they hope it'll be important and useful. I like to think it's a convention here not to shit on such people for comedy value.
As someone who thinks urbit would solve an important use case but is too hopelessly weighed down by the stench of its founder to go anywhere, a good fork seems is a reason for optimism, so best of luck Plunder team!
But more generally, if it's true that the only way to make a provably secure app is to design the OS and language around that purpose, then the problem you describe is general too - it will always be a challenge to find auditors.
I'm not arguing with you, just trying to answer your questions. If you want to make really damning accusations about how awful urbit is, it will help to learn more about how it works :)
That has nothing to do with the thing you quoted ("network identity and keys are already baked into all your interactions with the network"), which describes how urbit nodes talk to each other. Whatever identity you run an app under, all traffic from that app will be cryptographically signed by that identity.
What is Urbit?
Urbit is a virtual machine OS for server-side applications. If you imagine a future in which it is common for non-technical people to rent cloud server space on which to host server-side applications (say, a small blog, a mastodon node, a minecraft server, etc), Urbit aspires to be a good platform on which to host them.
Urbit features:
1. All input events (http request to an urbit-based api, signed message from another urbit, keystroke from console, etc) are transactions which change the OS state (or don't, if they fail). As a result, it should be impossible for a transaction to fail halfway through and leave the urbit instance hosed.
2. Exactly-once messaging between nodes. This is possible because nodes have persistent connections; disconnection is indistinguishable from long latency. This may sound minor, but it is a huge part of what makes urbit novel and (theoretically) stable and secure.
3. Built-in identity and auth. An urbit instance can't boot without an identity, which serves as username, network-routing address, and also as the public key with which all outgoing messages are encrypted. In practical terms, this means no urbit app or service needs to deal with logins or passwords or crypto.
4. There are only 2^32 first-class identities, which makes urbit a de facto reputation network. This is to minimize malicious behavior; if an identity costs $5, and you can only make $2 from spamming before that identity is blacklisted, no one will spam.
5. The urbit network is hierachically federated, and hence resistant to censorship. (Of course, this is a misfeature if you want to be able to censor people off of the networks you participate in)
6. It's not there yet, but the urbit kernel aspires to be so small and simple and formally-provably-correct that at some point it's done. As in, done done - no features to add, no bugs to fix, done. A lot of the design decisions (some of which are wildly unperformant) make no sense unless you take this goal in to account. More on that here: https://urbit.org/blog/toward-a-frozen-operating-system
Main Criticisms:
1. The founder has objectionable politics/beliefs. For its first decade, urbit was the solo project of one Curtis Yarvin, who moonlighted as an alt-right-ish blogger, and flamed out of polite society as a result. I've read a tiny bit, it was pretty dumb. The tl;dr is that he wants to get rid of democracy and bring back feudal monarchies. He also said some pretty racist stuff from time to time and that's the main reason everyone hates him. He left the project several years ago, which accomplished absolutely nothing in terms of anyone hating it any less.
2. The language is very strange and possibly bad. By "language", I mean both the programming language (hoon, the native language you write urbit apps in) and urbit's terms for core concepts, almost all of which have new, made-up names. More info here: https://hooniversity.org/urbit-and-hoon-glossary/
3. A lot of people think it's a shitcoin of some kind. AFAICT this is objectively not true. There's no way anyone will make any amount of money speculating on urbit unless it works in the sense that it's a good OS that millions of people want to use. Besides, if it were some kind of scam, it would've fallen apart when the founder left under a black cloud. That didn't happen; it is still chugging along. There are competent programmers who understand it and have worked on it for a year or two and still think it's genuinely good technology and continue to work on it for that reason.