Live data from Hacker News

Mastodon: Add end-to-end encryption API

github.com

111–120 of 188 posts

Re: Mastodon: Add end-to-end encryption API

#111
post #79

>An additional layer on top of it is so-called message franking, which allows encrypted messages to be reported to content moderators without compromising keys or message contents ahead of time while also preventing fake reports. That sounds like the encryption isn't deniable. Personally I would prefer deniable encryption to ability to report wrongthink.

It sounds like you have never worked on a platform frequented by mobs of abusers (situations where abuse is targeted and high-volume enough that the "victim should just block" alternative is untenable for the victim).

Or a platform used by children.

The alternative, which you're welcome to use, is a fully decentralized/unmoderated platform. That alternative doesn't work for a lot of people. For them, the ability to report is often critical, quite literally, for their physical safety.

Re: Mastodon: Add end-to-end encryption API

#112
post #61

Earlier quoted context omitted.

I left Mastodon because the big "traditional"/sanctioned instances started banning other instances they didn't like, specifically Gab (instance full of right-wing people that allows basically anything that isn't illegal). I had high hopes for Mastodon but whatever, this whole social network thing isn't worth the trouble. Now HN and Youtube are the only websites I visit for entertainment.

I don't understand this mindset at all. It's not so much "I want to be able to say whatever I want", it's "I want everybody to listen to whatever I say". Go post edgy xenophobic stuff in your dedicated online community if you like it so much but stop acting surprised when other communities want nothing to do with you.

More or less “I’m not going to pay for your freedom with my privileges”.

De-federation and Gab blocking are mostly for instance operators and app developers to avoid hosting illegal content and avoid being seen as sympathetic to extremists respectively.

What people fear is either could be used as grounds to charge them as child molester or colluding terrorists or to revoke your Apple/Play Store developer accounts for life.

Re: Mastodon: Add end-to-end encryption API

#113
post #58

Earlier quoted context omitted.

No one controls Mastodon -- setup an instance and you're off to the races!

The idea of preemptive banning of federating with other instances is extremely common in Mastodon-land. This means that unilateral actions by admins, invisible to their userbase, restrict what their users can read, or who can read their users. It would be fine if the users opted into this, but it happens silently and arbitrarily by admins, oftentimes based on speculation or gossip, not even real abuse. It’s all of th…

While I don't agree with you, there is an interesting discussion to be had here about digital "commons" (something like the "public utility" concept in the US), I think.

If a company with a near-monopolistic network effect (Google, FB, etc.) censors speech or who-can-talk-to-who/see-what on their platform, it seems that most folks agree that this is bad, whether or not they're willing to do anything about it.

So, instead, we have decentralized services (and semi-decentralized ones, like Mastodon). At what point does a Mastodon community operator's decision to censor speech or who-can-talk-to-who/see-what on their platform become problematic? When a community achieves a large size? If new community members aren't made aware of the censorship? Is the difference between these communities and an ultra-ubiquitous one like "having a Google account" or "being connected to friends on Facebook" a difference of degree, or a qualitative one?

It's simple to argue an extremist position of "all speech between any set of parties must not be suppressed for any reason, even by the parties themselves", but I don't think most people want to live in that world. Similarly, it's pretty hard to isolate a line past which an operator of a community-service should be held to a different standard of conduct because of how ubiquitous/depended-on their community is, but a lot of people seem to think that this line exists.

Re: Mastodon: Add end-to-end encryption API

#114
post #8

Pleroma does what mastodon't

Was it wise to start this project in Elixir? Note - I have no idea what this project does, it may be a tremendous success, I just think it's a pretty wide gamble to start it in a language that has such a tiny user base and steep learning curve.

Elixir is, more or less, a thin shell on top of Erlang. As long as Erlang is maintained, Elixir can be pretty easily carried along with, as far as maintaince goes.

Re: Mastodon: Add end-to-end encryption API

#115
post #108

Earlier quoted context omitted.

Please don't put words in my mouth, personally I don't have anything worthy of being heard. I really wanted Mastodon to be where I can find everyone. To be free of censorship, ads and algorithm-induced bubbles. I am lucky to have the "right" mentality (in regard to the tech industry), so I am not often suppressed, but everyone is different. I don't want to impose on someone a "correct, healthy community". Blocking an…

Sorry, didn't mean to put words in your mouth. However, it's very presumptuous to say: "I really wanted Mastodon to be where I can find everyone." That's Facebook and Twitter. And even then you can't find everyone. People go to the Fediverse to build the community they want, not be subjected to "everyone". It's this clash of collective rights vs individualism that seems to drive so many of these ridiculous arguments.…

Hmm, maybe I should see the fediverse as multiple loosely-connected Twitter clones, rather than one place maybe? I seemed to have a malformed expectation regarding Mastodon. Thanks for clarifying that for me.

"Mastodon is a decentralized network! Remember, regardless of server choice you can talk to and follow anyone on Mastodon!" -- mastodon.social

I was perhaps misreading the developer's intentions.

Re: Mastodon: Add end-to-end encryption API

#116

Earlier quoted context omitted.

Was it wise to start this project in Elixir? Note - I have no idea what this project does, it may be a tremendous success, I just think it's a pretty wide gamble to start it in a language that has such a tiny user base and steep learning curve.

Elixir is, more or less, a thin shell on top of Erlang. As long as Erlang is maintained, Elixir can be pretty easily carried along with, as far as maintaince goes.

How many web developers know Erlang though? this project is mostly web based no?

Re: Mastodon: Add end-to-end encryption API

#117
Is there a mastodon server that doesn't require email for signup? Throw away providers did not work for me, free email providers require a phone number. It's like signal, the benefits are contrasted against metadata exposure.

Re: Mastodon: Add end-to-end encryption API

#119
post #117

Is there a mastodon server that doesn't require email for signup? Throw away providers did not work for me, free email providers require a phone number. It's like signal, the benefits are contrasted against metadata exposure.

I'm not aware of one. Unfortunately any server not requiring e-mail confirmation for sign-up would be overrun by spammers (we don't want to add CAPTCHAs because 1) they are unpleasant for real humans and 2) they require loading external resources which is minus points for the user's privacy).

Re: Mastodon: Add end-to-end encryption API

#120
post #94
post #71

Earlier quoted context omitted.

Why does anyone have a requirement to talk to your instance? What if, due to your ideological stance on issues, I don't trust that your server won't decide that mine is distasteful in some way, and that you'd cause your server to disrupt mine in some way by flooding it with messages, for instance? I have legitimately had this happen and it nearly brought down my instance. Some script-kiddie decided to fuck around and…

> Why does it matter if any instance decides they don't want to associate with you? It doesn't affect your ability to use the service beyond not being able to interact with folks who probably don't want to talk to you anyway. It prevents people on that instance who explicitly want to follow me from doing so. It also prevents me from following people on that server from my primary account on my homeserver, even if tho…

Then they, and you, can find another instance where you can mutually talk with each other. You are, in fact, allowed to have multiple fediverse accounts for different purposes/groups of people.

This doesn't address my point at all that you cannot argue that my server is somehow obligated to process bytes from your server.

Post reply on HN