Live data from Hacker News

Achtung: Decentralize, decentralize, decentralize

drewdevault.com

71–80 of 174 posts

Re: Achtung: Decentralize, decentralize, decentralize

#71
Facebook should split into Facebook the aggregator and Facebook the content hoster. You could talk about a third piece that is Facebook the content provider, which is for providing things like gifs, templates, memes, emoji, games, and other stuff like that. Because Facebook hasn't completely broken from open web standards those types of content providers already exist today.

Aggregators would be where you go to set up your friend list and see your feed. It could look and feel like Facebook does now. It would have an open standard protocol that content hosters would use if they wanted to be aggregated. This could still be an add driven business, but subscription, self hosted, and DIY solutions could exist too.

Content hosters could either charge a monthly hosting fee, or they could serve up their own adds. Self hosted and DIY solutions could also exist.

The big benefit to this would of course be the competition. Since it's an open standard anyone could be a content host, and anyone could be an aggregator.

To make extra sure there is competition, and this could come in a phase two after the initial splitting up of Facebook, there should be open standards for exporting and importing friends, follows, likes, etc. to and from aggregators, and open standards for importing and exporting content from the hosters.

Speaking of follows and likes, there could also be aggregator aggregators (AAs). People could opt in to publicly and anonymously share their likes and follows and the AAs would consume those and report on trends that cross aggregator boundaries. Anonymity could be much more protected this way while still giving us that interesting information about what is trending.

One tricky part of this is how do I as a content author only allow my friends to see certain posts of mine? It would have to be with encryption. My content provider could keep public keys of my friends and only my friends (well, their aggregators) would be able to decrypt my posts using my friends' private keys. I can see some challenges and holes in this, but it doesn't seem any worse overall than how Facebook protects privacy now. Open implementations and peer review could get us to better-than-Facebook privacy quickly.

Re: Achtung: Decentralize, decentralize, decentralize

#72

This article like so many others perpetuates this idea that Facebook and others are selling your data. You can more or less disprove they are doing this with a little critical thought. Facebook has a disincentive to sell data: if they sold user data, they no longer have exclusive control over it and somebody else can profit off their efforts in its collection. The value of Facebook is they have lots of eyeballs and t…

How does that distinction changes the OP's thesis?

Re: Achtung: Decentralize, decentralize, decentralize

#73

Weird... I always thought Google was inescapable, but I cannot get a single data point to display on that tracking map. I should note I am currently (and frequently) signed into Google and Google maps normally seems to know where home is.

Same. At /maps/timeline it says "Location history is off", so I guess that's something that needs to be enabled.

Re: Achtung: Decentralize, decentralize, decentralize

#74

Earlier quoted context omitted.

I'm not sure many people require those to move from FB.

No, but some of these may be legally required in order to operate as a competitor to Facebook.

I don't think anyone is saying the alternative should operate as a business competitor to facebook. I think the idea would be for the service to be fully decentralized, where no one has the power to remove anything

Re: Achtung: Decentralize, decentralize, decentralize

#76
post #29

The post repeats the myth “There is no promise that a company can make to its users that outweighs the fiduciary duty that obligates them to maximize profits by any means. The only defense of this is legislation and consumer choice.” As a counterpoint, see, for example, [1], that quotes the Supreme Court Hobby Lobby decision[2]: “Modern corporate law does not require for-profit corporations to pursue profit at the ex…

Its not about law, its about investors. Big investors have outsize control of the boards of most companies, and they pretty much only care about profits. The public doesn't blame them either because we don't talk about how decisions made by those on the board shape the entire company. Investors have little to fear from unethical decisions, so they make them.

Re: Achtung: Decentralize, decentralize, decentralize

#77

This article like so many others perpetuates this idea that Facebook and others are selling your data. You can more or less disprove they are doing this with a little critical thought. Facebook has a disincentive to sell data: if they sold user data, they no longer have exclusive control over it and somebody else can profit off their efforts in its collection. The value of Facebook is they have lots of eyeballs and t…

Except you're exactly wrong in that Facebook has been directly selling data while Google has not. Cambridge Analytica was crunching specific user data, not just buying aggregate targeted ads.

That's what this whole uproar is about: they're allowing wholesale data access, not aggregated targets through their API.

Google, whom you criticize, is the one actually only selling aggregates.

Re: Achtung: Decentralize, decentralize, decentralize

#78

Tangential, but what is it with people using German words, randomly? "Achtung" here, I saw some (US, afaict) people on Twitter try to establish "#forwärts" yesterday.. Is there a connection between any recent event and German(y) that I missed?

Pourquoi-Pas?

Some words, phrases and symbols from foreign languages can become internationally-famous so almost everybody can understand them and also gain meme-like semantic self-emphasize.

¡No pasarán!

PS: I have also heard it's quite popular among French metal bands to use German in their names to sound scarier (e.g. Blut Aus Nord).

Re: Achtung: Decentralize, decentralize, decentralize

#79
post #46
post #38

Earlier quoted context omitted.

>Why does it need to be signed and encrypted? We have PGP, Signal and Co. for that Note it IS signed. It's just not encrypted. It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist. Additionally... should I be some location and post something, I'd be broadcasting my location, even if that isn't intended. All because it's not encrypted, where it…

>should I be some location and post something, I'd be broadcasting my location, even if that isn't intended Can you tell me how and where you would broadcast your location via Mastodon? There are no geolocation features in Mastodon. >It needs to be encrypted, too, because it's the reasonable expectation when private messages and followers-only messages exist. Has anyone attempted to encrypt a message to 64,000 recipi…

>Can you tell me how and where you would broadcast your location via Mastodon?

For a network observer, your IP address, associated with your account name.

>I don't think restricting a message to followers is an applicable model for e2ee

But requiring TLS between clients and servers, and between servers (for the federation), is applicable.

>Direct messages yes, I can see the point in that.

The average joe expects direct messages to really be private. If they're not, that's bad.

Re: Achtung: Decentralize, decentralize, decentralize

#80
post #48
post #39

Earlier quoted context omitted.

Note metadata includes where someone is posting from. Connect to post something without encryption means your location is revealed to anybody observing the network. This is indeed dangerous.

>Connect to post something without encryption means your location is revealed to anybody observing the network. Where are you taking this from? You think connecting to your Mastodon server you have an account on somehow broadcasts to the whole network?

If a message is sent through an unencrypted connection, anybody sniffing the network gets:

- Your message

- Your account name

- Your ip address (thus location)

- The time at which this happens

If the message is sent through an encrypted connection, but the federation connection between the servers is unencrypted, a powerful enough observer could still deduce the above.

Post reply on HN