Live data from Hacker News

Re-decentralizing the Web, for good this time

ruben.verborgh.org

261–270 of 295 posts

Re: Re-decentralizing the Web, for good this time

#261

Earlier quoted context omitted.

Gmail basically took over email through centralization. A lot of companies and people use it because the price is fair and the spam filter works better than almost anything else. I have tried FastMail and I like the company, but the spam filtering is not good. But good luck even trying to replicate FastMail anti-spam if you roll your entire email stack yourself. I have run my own email server even well before Gmail w…

I disagree vehemently on the difficulty of running your own email server. I have been running a pretty standard postfix + dovecot email setup for myself and close family for almost a decade now. It definitely is necessary to once set up proper DKIM, SPF, DMARC and TLS by default (thanks to Let's Encrypt), but after that the setup is pretty much hands-off. Spamassassin filters my spam down to at most one mail a day, a…

I'm pretty sure FastMail uses Spamassassin, so why is an email company so bad at configuring that software? Their spam filtering is simply not nearly as good as Gmail, it's not even close.

I used Spamassassin back in the day and it was effective for a bit, and then pretty much all spammers figured out how to avoid it.

Also, I'm not talking about the obvious VIAGRA large caps spam, which I think is fairly easy to solve. But spam has become much more nuanced and Gmail is the best at it, and the false positive rate is still amazing.

Re: Re-decentralizing the Web, for good this time

#262

Earlier quoted context omitted.

Mastadon meets Dropbox, with a content navigation interface thrown on top?

Yes, that's the thing. We know how it should be used because people are already using such systems. We need that no part of the system is owned by a single organization.

https://project.hubzilla.org/page/hubzilla/hubzilla-project

This is what hubzilla can do, along with using the Zot protocol for distributed identity.The main issue really is having an easy wizard-based installation/configuration for new users wanting to host.

Re: Re-decentralizing the Web, for good this time

#263
post #254

Earlier quoted context omitted.

And the biggest issue of them all, keeping it absolutely secure while doing all that. It would be a killing blow to the venture if someone got their data stolen.

The existing centralized systems set a pretty low bar for that, to be honest.

I do not think current big centralized systems are a low bar, the attacks get more and more sophisticated, but mom&pop/volunteer/etc. systems still get exploited in the most banal ways possible.

Re: Re-decentralizing the Web, for good this time

#264
The point about the decentralised web allowing the permissionless creation of centralising systems reminds me of the paradox of tolerance, where tolerant societies are thought to be taken over by intolerance if they tolerate that intolerance.

Maybe this is a lesson that we need to be less tolerant towards the creation of centralised services because those with money and power will seek to bring decentralised systems under their own control.

Re: Re-decentralizing the Web, for good this time

#265
post #205

Earlier quoted context omitted.

Basically all home routers block incoming connection because so many shitty IoT devices were built to trust anything that is able to connect to it. My router doesn't even have an option to turn off the block. Can only unblock ports 1 by 1

I guess the route around this would be for the maker of these devices to partner with router companies. Alternatively, they could also be routers. That would potentially make quite a lot of sense...

I can see a lot of value in routers becoming mini home servers + IoT device hubs. There should also be some standard way for devices to let the router know if they should have access to the outer internet so things like lightbulbs only have access to the iot hub and then the hub has access to the internet.

Re: Re-decentralizing the Web, for good this time

#266

Earlier quoted context omitted.

> why shouldn't browsers do it on a website's first launch? Because users would riot, and would use browsers or plugins that suppressed these notifications.

I would love it, personally! And websites would riot, and then reduce the number of permissions they requested, just like apps do/did.

It would be just like the cookie notices are, now that the data misuse is displayed with a banner, people rage and hate those. Websites haven't really removed third party/non-essential cookies.

Re: Re-decentralizing the Web, for good this time

#267
post #226

Earlier quoted context omitted.

I found it interesting they highlight the decentralized nature of email. And yet the decentralized design meant spam was basically unsolvable. It wasn’t until Gmail came along that they largely solved the spam problem. There are so many abuse related issues on the web and I’ve seen no decentralized effort that works unfortunately. Cloudflare brought cost effective DDoS protection to the masses.

Gmail "solved" the spam problem not by making email centralized, they did it by making a good spam filter.

Gmail's spam filter is one of the worst. About once a month some gmail user tells me that he found my mail in the spam folder. Of course it is easy to keep down spam when you don't care about false positives.

Re: Re-decentralizing the Web, for good this time

#268
post #117

Technology won't help with this, regulation will. We have parallels from other platforms - specifically the fixed and mobile phone networks. There used to be monopolies in local phone service. There were new competitors, but to change provider, you had to change phone number. Even changing cell phone provider required a number change. This obviously had strong network effects pulling you to stay with your provider. Y…

If you have ever seen any attempt by any government to regulate software you would know this to be a Lovecraftian nightmare, and not a solution.

The way this usually works, is there's an entrant into the market who decides it is cheaper to use the government to gain access to a network instead of building their own (Number Portability, Local Loop Unbundling).

The government then says "You have to allow competitors access to X, and you have to do it by date Y".

Then the companies get together and agree on how to do it because they agree that government dictated standards suck. There is usually some jostling around with someone wanting to run a centralized database for a nice per-transaction fee. Typically this is tossed out in committee, but not always.

Re: Re-decentralizing the Web, for good this time

#269

Earlier quoted context omitted.

> How could decentralized applications/services be sustainable funded? If not advertising, how? How any other open source is funded (e.g. corporate/individual donations, grants, crowdsourcing, support, ancillary products, etc). I don't believe, at least for an MVP, that much funding is needed compared the scope of some of the successfully funded open source projects that exist. > Most importantly, why would users car…

Please, show me a list of self-sustaining open source projects that cover developer time and administrative overhead just in donations. The only one I can think of right now would be Font Awesome 5 (via Kickstarter), which already was a very popular product with big name recognition and had a professionally run Kickstarter. Pretty much ever open source project only survives because developers donate their own time, o…

Those, then, would seem to be valid ways to organize such a project. Lord knows there is more than enough volunteer time available to achieve any project - if properly organized.

Re: Re-decentralizing the Web, for good this time

#270

Earlier quoted context omitted.

I really, really sympathize with the goals here but when I read through these proposals a few months ago I literally facepalmed. They seem about as realistic as praying for some kind of deus ex machina. Ultimately I think there are technical solutions to making the decentralized web more attractive than the walled gardens, but at this point they will need to be ridiculously polished and shiny to even get a look, and…

I found it interesting they highlight the decentralized nature of email. And yet the decentralized design meant spam was basically unsolvable. It wasn’t until Gmail came along that they largely solved the spam problem. There are so many abuse related issues on the web and I’ve seen no decentralized effort that works unfortunately. Cloudflare brought cost effective DDoS protection to the masses.

I would argue that the problem of ‘spam’ has not been solved, since that would mean an agreement on what constitutes spam—that spam has some inherent properties that subjects it to easy classification, and that spam is not evolving.

But that’s beyond the point that I originally wanted to make: spam and email have very similar parallels to security and the Internet. In another universe, it’s possible that the issue of spam and security could’ve been incorporated into the protocols themselves. But for some reason I’m sure is rational, those issues were moved outside, to the hosts — to be left to be solved with middleboxes as firewalls and Google’s spam filter.

I would argue that this was the smarter choice and that both of these involve the same problem: spam and security are ill-defined and constantly evolving.

Post reply on HN