Live data from Hacker News

Scuttlebutt, a Decentralized Alternative to Facebook

inthemesh.com

241–250 of 356 posts

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#241

Earlier quoted context omitted.

> Scuttlebutt is fully encrypted.. doesn't that make the API vastly more locked down than Facebook/etc? No, not at all! TOR is fully encrypted, but there are somewhat regular vulnerability reports about various parts of the stack. Including criticial vulnerabilities that can and have been exploited by nation states, for example. > This is no worse than Facebook though This is not at all clear to me. The attack surfac…

> I trust Facebook's security team to audit and patch much more than I trust any random friend. Sure, but I wouldn't choose "a random friend" to run my FB replacement service, I'd choose a trusted friend. And more importantly, no matter how good Facebooks security team are at patching and auditing servers - THEY ARE THE ADVERSARY IN THIS CONTEXT!

> Sure, but I wouldn't choose "a random friend" to run my FB replacement service, I'd choose a trusted friend.

How does this relate to scuttlebutt? There's no scuttlebutt “service”; it's a tool and a protocol, like a pen and the English language.

> no matter how good Facebooks security team are at patching and auditing servers - THEY ARE THE ADVERSARY IN THIS CONTEXT!

I think this is the salient point: if you send data to your friend, they necessarily have that data and can leak it; but there's no need for a stranger with unknown motives (Facebook) to also have that data.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#242
post #98

Okay Hackernews, I get it. Scuttlebutt isn't fully ready for everything yet. I wrote that article hoping that it would sparkle interest to both use it, plus make it happen. This is not your usual startup launch, it's a community project by multiple open source hackers. If something is missing, you can make it happen. And there are so many ongoing developments right now (see list below), that it really doesn't make se…

Nice work...impressive work. Are there any plans to add this to the freedombox? I think it would make a great fit!

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#243

Earlier quoted context omitted.

The whole issue with facebook is that they: 1. Follow you from site to site, scooping up all the data they can on you. 2. Allowed all of that data to be accessible not just by you opening up to a bad actor app, but by any of your friends opening up to a bad actor app. Calling it "overly open APIs" is misleading at best. The point of an A P I is that it is a public interface. If Scuttlebut has proper permissions contr…

How can Scuttlebutt prevent (2) from happening? If you share data with your friends, how can you know that they haven't installed an app that will slurp up that data wholesale? The only solution would to be to enforce reasonable app usage in the client, and then require all your friends to use that client. That seems to defeat the purpose of a decentralised protocol.

Nothing can prevent that from happening. DRM cannot ever work. Facebook can't stop “friends” from slurping data either.

The SSB protocol has other design goals beyond “be Facebook but less evil”; for example it works seamlessly offline.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#244

Earlier quoted context omitted.

What if people get tricked into approving malicious accounts? Who is gonna police that? How are you gonna prevent anarchy?

How are you gonna prevent anarchy? Cats and dogs living together...oh my. Let me clue you in on something. In free societies there's risks and individuals make bad decisions, and we live with it. We don't need someone policing everything.

And this is the crux if the matter.

Ideally, there should only be a select few that determine which apps and programs should run for the masses. We should even control which software users have access to.. After all, giving the people too many choices leads to imminent danger on all fronts and is uncontrollable.

I'm increasingly convinced that there are a great many who relish the idea that the internet, privacy, software, and ultimately life should be state controlled, similar to China or North Korea, as long as It's their people making the rules..

It's 2018 and that would never happen though.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#245
post #196

I think it's fascinating to see distributed social networks from a tech perspective. From what I've seen so far they exacerbate the problems that Facebook has been seeing so much backlash against. 1. The whole Cambridge Analytica issue was caused by APIs that are too open. For distributed systems there are more ways to exploit the APIs and gather data on users. 2. There is a clear issue with Facebook's accountability…

I think your post hints at a general schizophrenia in the latest, culture-war-fueled push against Facebook. On the one hand, the public debate is still significantly dominated by the old guard of anti-Facebook activists, whose objectives can be summarised as "Facebook's power over its users must be reduced". On the other, the renewed interest in doing /something/ about Facebook in the wake of Cambridge Analytica and…

I think grandparent's point was that the first cause you mention - reducing FB's power over users - does nothing for the users if this power instead goes to other 3rd parties, and perhaps even grows.

GP points out that in a distributed social network, 3rd parties can still mine your data, you still have trouble permanently erasing information, and in fact these problems grow instead of shrink. From a user's POV, what matters is the total amount of 3rd parties over them and the leverage they have against these 3rd parties as a whole. GP's point is that shrinking FB's power by going to a distributed social network might actually increase the total power 3rd parties have over users.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#246
post #214

I think it's fascinating to see distributed social networks from a tech perspective. From what I've seen so far they exacerbate the problems that Facebook has been seeing so much backlash against. 1. The whole Cambridge Analytica issue was caused by APIs that are too open. For distributed systems there are more ways to exploit the APIs and gather data on users. 2. There is a clear issue with Facebook's accountability…

The principle is that the network can become federated, which makes it possible to switch providers while remaining on the same network. This allows there to be competition between providers. Presumably, providers would compete based on their ability to protect your data. Facebook, on the other hand, competes almost solely based on the size of their network, which eclipses every other factor like accountability.

Scuttlebutt isn't a service. There are no “providers”, so I don't understand what “federated” means in this context.

It's a tool. The protocol sends data peer-to-peer.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#247

Earlier quoted context omitted.

Personally, I hope (and I think I'm not alone here) that on a network like scuttlebutt, there will be much less "noise" than on facebook. My timeline on facebook (whenever I check it, like weekly) is a mishmash of... * ads (if using a browser that doesn't get rid of them) * "you missed someone's birthday who you didn't even remember you were "friends" with * look at this really popular post in your social vicinity, E…

But if users don’t stay engaged then how would they retain? And if they don’t retain...how would it be useful to anyone when none of their friends are on it?

It's possible for people to be engaged because their friends are interesting; rather than because the service is designed to grab attention.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#248
post #153
post #127

Earlier quoted context omitted.

"You need ... a business plan." I don't agree. What is the business plan of email (by which I mean SMTP, not some webmail provider)?

You're absolutely right! A protocol doesn't need a business plan. Of course, a protocol by itself isn't very useful. You need services using it and systems implementing and supporting it, which do cost money and require some kind of resourcing model...

You don't need services when you can just use tools.

Is Morse code less useful because of the lack of viable Morse code service providers?

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#249
post #120

2018 will be the year of "alternative to facebook" apps that are in no way an alternative to facebook. To be an alternative to facebook, it should at least do 50% of what facebook does, and it should be accessible to all. Anything that takes more than 3 steps to get it running it's going to keep people out. And if you keep people out, you don't have a social network, at least not anything like facebook where your gra…

You can build 'a facebook' in Drupal which is more or less functionally equivalent and people have been doing that for years. But you still have the real work - building the network of users, which is where the value lies and not the software features (which are mundane in the case of fb). What's far more compelling but challenging is open source federated social networking, which is a facebook on rocket fuel and ove…

> What's far more compelling but challenging is open source federated social networking

OK, but that's not this. Scuttlebutt is peer-to-peer, not federated. There are no servers.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#250
post #101

Earlier quoted context omitted.

Actually with a few tweaks, this technology would be much simpler to use than Facebook, for a person like your grandma, simply because it removes that annoying registration process. You just open the installed app, and that's it. It's odd that we got used to the idea that "(1) registration, (2) strong password creation, (3) username selection (in case of conflicts), (4) email verification link, (5) login" is somehow…

I have a question, how would my Grandma signal her identity to SSB from multiple devices? Say she has an iPhone and an iPad and she wants to use the iPad at home and the iPhone when she's out. I imagine it's not as simple as installing the app on both devices in this case? I'm curious how this is approached. Cycle.js and xstream are amazing, as an aside. Thank you.

Using the same identity from several devices is not yet implemented.

Eventually, the client will probably have a “that's also me” button, which you'll press on both devices to confirm.

Post reply on HN