Live data from Hacker News

Diaspora Developer Release

joindiaspora.com

101–110 of 202 posts

Re: Diaspora Developer Release

#101
post #16

Earlier quoted context omitted.

You're unfortunately right. I say unfortunate because I really, really like the name: it sounds good and conveys their mission very well, but ease of spelling is probably paramount.

I'm not so sure about the name. I understand how it conveys their mission exactly and it does that really well: leave facebook(or twitter or wherever), come here. I can see how setting themselves up from word 1 as opposition to facebook has a huge amount of importance but what happens to that branding on the off chance they win? (I know this is like planning where to put the swimming pool in your 1 bedroom apartment…

I think the name is quite perfect, really. I can't think of any other single word that sums up what they're trying to do so well, at least not so evocatively.

The whole idea is to allow the Facebook-bound multitudes to leave that particular kingdom and spread -- along with their data -- across the Internet, as a decentralized system.

The name is therefore the goal, the intended result. It's a high bar, but it's an ambitious project.

Re: Diaspora Developer Release

#102
post #13

Sweet Jesus. Please publish a security reporting page at the earliest possible convenience, because this will have private info on it within a day from now, and that is a very bad idea right now.

If you're smart enough to get code from github working on your own box, paranoid enough to worry about facebook's control of your data and be interested in an alternative, and savvy enough to get wind of such an early release, I don't think you're going to put anything that sensitive in this network!

Re: Diaspora Developer Release

#103
post #71

Earlier quoted context omitted.

Security issues don't belong in a public bug tracker.

In an established product, no. At this stage, I think keeping 'em public is a good idea.

There's no marginal benefit beyond what putting a security warning message on the download page would get you. In fact, filing a public bug would probably be less effective in preventing harm than such a message would be. The marginal cost is significant.

There's actually more of a case for disclosing security bugs in established products if the vendor doesn't respond quickly enough. If people are relying on a product for critical uses, having information that lets them minimize their risk could be helpful. I don't see the benefit in this case.

Re: Diaspora Developer Release

#105

Here's a public server for trying it out: http://openspora.com/ Running stock Diaspora code, but it's got a LOT of problems (which is to be expected from pre-alpha software I suppose.)

The Images aren't uploading, are you using heroku?

Re: Diaspora Developer Release

#106
post #3

I'm impressed and surprised that they have released code. I worried that the initial flurry of money and hype would derail them. Many projects never get this far, and for this, they deserve to be commended. They've built something and dealt with a lot of external pressure at the same time.

I think it speaks to the support network available for entrepreneurs in NYC. Charlie O'Donnell of First Round kicked it off, from what I recall, with this post advising Diaspora on how to make it through the immediate chaos and get to building. Many people spoke up via blog posts and tweets to suggest simply getting to work as quickly as possible and to not set the vision too high yet.

http://www.thisisgoingtobebig.com/blog/2010/5/13/what-diaspo...

I saw them shortly after at MongoNYC where they were getting a lot of attention. In spite of that, they just focused on learning what they needed and hearing the talks about people's experiences.

This is exactly the kind of focus that's needed to get the job done, so not only should it not be surprising, it should be expected. In spite of that, I'm stoked to see it.

Re: Diaspora Developer Release

#107
post #13

Sweet Jesus. Please publish a security reporting page at the earliest possible convenience, because this will have private info on it within a day from now, and that is a very bad idea right now.

What? Correct me if I'm wrong, but it looks like they're just releasing the source code, not taking new users for "the" Diaspora or sharing access to any kind of central database of users. It's just a ruby web app you can download and run locally (or on a web server if you're that dumb...), right? And in that case, how is this any worse than the hundreds of other bits of (unsafe, untested) social networking code floa…

There is no argument against having a policy for receiving, reviewing and patching security reports. It is that simple.

"hundreds of other bits of (unsafe, untested) social networking code floating around the interwebs" is not a benchmark that this project should aspire to.

Re: Diaspora Developer Release

#108
post #105

Here's a public server for trying it out: http://openspora.com/ Running stock Diaspora code, but it's got a LOT of problems (which is to be expected from pre-alpha software I suppose.)

The Images aren't uploading, are you using heroku?

Nope.

Re: Diaspora Developer Release

#109
post #15

It seems to be AGPL licensed. I'm wondering how that will affect adoption.

I think that since the community funded this project that the code should have a more liberal license so that the community can do what they want with it.

The project also depends on MongoDB, which is also AGPL licensed, which raises the question of if paid hosting of a diaspora instance is 'commercial' and if it requires a MongoDB license from 10gen, I would think that it does.

They should BSD/MIT license their own code, and build more storage options outside of MongoDB. I am surprised that donors didn't insist on a license as part of the kickstart funding.

Re: Diaspora Developer Release

#110
post #47

Earlier quoted context omitted.

For a lot of people, their name’s strongest connotation is Jewish persecution. To me, this is so awkward as to rule out the name for use in serious software.

It's like at my work when I proposed that we could get some benefit from an "interim solution" until we could finish up what we were planning. Of course people started (innocently, ignorantly) calling the original plan the "final solution". Always made me cringe.

You either work with uneducated simpletons, or closet nazis and crypto-fascists. There is just no way anybody with a modicum of culture would hear "final solution" and not cringe, much less use the phrase passively in everyday non-historic conversation.
Post reply on HN