Inrupt, Tim Berners-Lee's Solid, and Me
schneier.com
Inrupt, Tim Berners-Lee's Solid, and Me
1–10 of 183 posts
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#2Re: Inrupt, Tim Berners-Lee's Solid, and Me
#3Re: Inrupt, Tim Berners-Lee's Solid, and Me
#4The domain name analogy scares me rather than reassures me. Sure, DNS was created in good faith to be as distributed as possible, but is it? There are recent stories that show that individuals do not have as much control on domain names as one would ideally like. See these stories -
- Sinkholed: https://susam.in/blog/sinkholed/ (domain name hijack by German authority by accident)
- The duck tape holding the internet together: https://medium.com/thisiscala/the-duct-tape-holding-the-inte... (loss of control on domain name due to registrar error)
While the idea behind Solid sounds solid but the moment they talk about outsourcing pod hosting to third-party pod hosting providers, I get worried. Would it lead to walled gardens of pods? (Example GMail for emails) Would they add non-standard convenience features to create vendor lock-ins (Example GitHub for Git)? Would they abuse their power due to vendor lock-in (Example Sourceforge for SVN)?
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#5Projects like this never seem to pan out. It solves a problem people should care about but most aren't motivated to act on.
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#6The idea of pod reminds me of the self-hosting movement: people -including myself - host a bunch of services to avoid sharing fundamental data, like email, GPS-history or contacts.
Still, "self-hosters" interact with all the big personal data hoarder out there (FB, Google, the many ad and tracking companies) which expose them to the same abuses as any other internet user.
Basically, I don't really see a company like FB play ball with these guys, for two reasons:
1) the privatization of data would be a existential threat to their business model
2) the majority of internet users are oblivious to the data collection tactics employed by half the internet and I can't picture folks raising pitchforks for "pods" to become a standard.
But I also hope to be dead wrong!
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#7Projects like this never seem to pan out. It solves a problem people should care about but most aren't motivated to act on.
They basically admit, outright, that their proposed solution doesn't solve the problem:
The ideal would be for this to be completely distributed. Everyone's pod would be on a computer they own, running on their network. But that's not how it's likely to be in real life. Just as you can theoretically run your own email server but in reality you outsource it to Google or whoever, you are likely to outsource your pod to those same sets of companies. But maybe pods will come standard issue in home routers.
Imagine you're an average user: you don't know much, but you've maybe read one of the billion news articles about how Google reads the context of every inbox on their service. Now some guy comes up and tells you that you should put all of your data in the hands of Google.
Totally a good idea.
And can you imagine how bad it would be if this came standard in home routers?
Congratulations, it's 2058 and there are over three billion routers & modems released in 2025 that haven't been patched since, but instead of just being a minor issue like it was when routers and modems did relatively little back in the 2010s, they're containing all of their users' personal data. And that's not even getting into how bad of a concept it is to have a family sharing a single access point for their data.
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#8> Even if you do hand your pod over to some company, it'll be like letting them host your domain name or manage your cell phone number. If you don't like what they're doing, you can always move your pod -- just like you can take your cell phone number and move to a different carrier. This will give users a lot more power. The domain name analogy scares me rather than reassures me. Sure, DNS was created in good faith…
Don't forget that millions of domain transfers happen every year without going wrong. There are cases like the ones you linked to, but those are the exceptions rather than the rule, thankfully.
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#9> Even if you do hand your pod over to some company, it'll be like letting them host your domain name or manage your cell phone number. If you don't like what they're doing, you can always move your pod -- just like you can take your cell phone number and move to a different carrier. This will give users a lot more power. The domain name analogy scares me rather than reassures me. Sure, DNS was created in good faith…
Re: Inrupt, Tim Berners-Lee's Solid, and Me
#10Even if the “pod” is a virtual one in a data center, as long as the webmail provider is a different company to the pod provider, the data access is granular enough, and the terms of service enforce that the data is stored in a way that’s readable by me, this can only be a good thing.
Perhaps legislation could help here? What if the service company starts encrypting the data they store on my pod and refuses to give me the key? It would be good to wield the power of a regulator against bad actors who do this and any other shady rule bending.
Very exciting.