Live data from Hacker News

Scuttlebutt, a Decentralized Alternative to Facebook

inthemesh.com

311–320 of 356 posts

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#311
post #103

Earlier quoted context omitted.

Why should “a service” silence anyone? How about letting people make their own decision who they want to talk to, without a third party saying “I forbid it”.

Can I use an analogy from biology to shed light on the valid point you have? Human beings exist as part of a society--a larger organism. Imagine if a cell were permitted to send any proteins or RNA it wanted to its neighboring cells. As long as the signals are benign or simply "nuisance" level, it's fine. But if the signals subvert the very organism of which they are a part--for example, by tricking neighboring cells…

Your analogy breaks down right away because people are not mere cells in the organism of a state. That is a dangerous mentality that can lead to Totalitarianism.

In your own example you alluded to cells refusing to commit apoptosis. By your analogy, it should be just and proper for people to be regularly savrificed for their state — their very lives may be required to be given up for the state to function.

I do not think we base our human societies on the law of the jungle — and certainly not on the inner workings of an organism! I doubt you are able to take this analogy very far without coming up against horrendous human rights violations.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#312
post #12

Earlier quoted context omitted.

Diaspora is federated, which for non-technical users is worse than FaceBook itself. The individual nodes (to which thousands of users are connected) will have far fewer resources to secure themselves than a behemoth like FaceBook. Also, uptime, badwidth etc. ScuttleButt is peer to peer, somewhat like torrents but for data feeds.

> Diaspora is federated, which for non-technical users is worse than FaceBook itself. The individual nodes (to which thousands of users are connected) will have far fewer resources to secure themselves than a behemoth like FaceBook That's a weird argument - it doesn't even make sense no matter how you look at it. 1. Security is more or less centralized as per core code and core protocol. 2. Why do you imply big monol…

It's more than the app (whose code and core protocol you've mentioned) - it's keeping OS up to do, firewalls, opsec, watching for suspicious activities: These are all things that facebook (the company) does that need to be taken care of on every pod/node.

If it's federated, it means thousands of accounts are likely going to live on each server - and many of those servers will be easy to hack. It is in that sense the facebook does a better job securing it (and they have shown that they can do opsec) -- not any theoretical "centralized vs distributed" argument.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#313
post #239

Earlier quoted context omitted.

You know, I'm pretty sure when they said "legislatures" they were implying the imperfect-but-normal ongoing political process. The one which stretches across dozens of different countries and with some influence by the billions of non-legislator citizens. Instead you seem to be a hurry to travel down a road that sometimes ends with the word "Statist" getting thrown around as an epithet against heretical outsiders. >…

Let's apply the same logic to non-digital goods and services: Do you believe it is fundamentally wrong for a government -- even with significant public support -- to interfere with one anonymous man's Galtian quest to sell radium toothpaste by mail? Amazing...even after I point out his janky biology analogy, you go ahead and try one yourself. You people can't help but to double down.

> You people

Yeah, that's what I suspected, we're done here.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#314

Earlier quoted context omitted.

But if users don’t stay engaged then how would they retain? And if they don’t retain...how would it be useful to anyone when none of their friends are on it?

It's possible for people to be engaged because their friends are interesting; rather than because the service is designed to grab attention.

But how the tool they use to do so is designed matters!

If there is too much friction then people simply won't adopt it

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#315

Earlier quoted context omitted.

What if people get tricked into approving malicious accounts? Who is gonna police that? How are you gonna prevent anarchy?

How are you gonna prevent anarchy? Cats and dogs living together...oh my. Let me clue you in on something. In free societies there's risks and individuals make bad decisions, and we live with it. We don't need someone policing everything.

we certainly don't need to police everything...but there is a middle ground between that and no policing at all! And that will be hard to do in decentralized networks.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#316
post #193

Earlier quoted context omitted.

> Scuttlebutt is fully encrypted.. doesn't that make the API vastly more locked down than Facebook/etc? Encryption has nothing to do with it. The whole issue with CA was that they (just as many apps before them) were using Facebook social graph data that was available for them to access via the API. Encryption on any layer has nothing to do with it - if you have access to the API, you get the data. In distributed sys…

You very definitely don't need to expose the social graph to the api. We are doing exactly that in Peergos [1][2]. Your social graph is only stored in encrypted form in your own storage space (in IPFS). The source of a follow request can't be deduced by anyone except the recipient. If you start integrating Tor/i2p hidden services, even global passive network adversaries will struggle to figure out the social graph fr…

From what I understand, in Peergos the friend list is stored on certain node. Which means software running on that node can see your friend list - which is essentially what happened in CA case, except maybe Peergos does not allow to run third-party apps on private node, but even if they didn't currently, I see nothing preventing from this happening in the future. What happened in CA case, AFAIK, is that users allowed the software to access their social graph data, and that software compiled it into a database that was used for purposes the users didn't intend to. If we assume that the users can run third-party plugins on a Peergos node, why isn't that possible with Peergos?

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#317

Earlier quoted context omitted.

If the recipient can access it, then the recipient can grant access to a third party- which is what happened with Facebook/CA. People unwittingly shared the information their friends had shared with them with a third party.

That is clearly fundamentally true of any information. The question is what is shared by default. We don't even share your friend list by default, so the exposure is much less.

Default are powerful, but you are always one "Please click this to enable new exciting ways to play Candy Crush" away from any non-default setting. It may be true that FB users value their privacy, but reflecting these values in minute-to-minute behavior is a much more complex question. People are not always vigilant or realize what exactly is the consequence of their actions.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#318

Earlier quoted context omitted.

Ah i think i may have misunderstood how the system is made. It is purely peer to peer. So any issues could be if the software has a security vulnerability, but I'm not sure how that ties in with things like "as-use" open source licensing. This post explained the network fairly well I found: https://staltz.com/an-off-grid-social-network.html As far as GDPR goes, you're right because you're specifically choosing people…

> having a mechanism to delete your messages on other people's systems when they sync would probably go a long way. It is my understanding at the moment that it's not scientifically possible to do this. If I'm mistaken I would love to hear a proposal for doing this, but I don't understand how full read access can be revokable once you have the data and a way to decrypt it. DRM doesn't count/work.

Not technically possible currently (well, last I checked). A client could be configured to send a "please delete message id 29342" type post, but other clients would have to know how to understand that and to honor it. The functionality would be similar to "sender has recalled this message" in exchange.

Also, the way the protocol works is that clients discover the most recent log entry number, and then request all "missing" ones. So that delete message would be more like a "please overwrite message id 29342 with zeros or something".

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#319

I really love the concept of this. I travel a ton and am without internet for days/ weeks at a time. Scuttlebutt allows me to keep up to date with friends and communities while offline and when I do eventually get online, just grab the newest updates and download them locally. This is such a cool thing in my eyes for parts of the world with little / no internet access. The creator of the project (AFAIK) sails around…

What is this "offline" you speak of?

When I'm on a plane and Gogo is moving about dialup speeds, while blocking protocols that would make dialup usable.

Re: Scuttlebutt, a Decentralized Alternative to Facebook

#320
post #196

I think it's fascinating to see distributed social networks from a tech perspective. From what I've seen so far they exacerbate the problems that Facebook has been seeing so much backlash against. 1. The whole Cambridge Analytica issue was caused by APIs that are too open. For distributed systems there are more ways to exploit the APIs and gather data on users. 2. There is a clear issue with Facebook's accountability…

I think your post hints at a general schizophrenia in the latest, culture-war-fueled push against Facebook. On the one hand, the public debate is still significantly dominated by the old guard of anti-Facebook activists, whose objectives can be summarised as "Facebook's power over its users must be reduced". On the other, the renewed interest in doing /something/ about Facebook in the wake of Cambridge Analytica and…

It's not as binary as you make it seem; It's more a question of oversight than it is power.
Post reply on HN