Live data from Hacker News

Mastodon: Add end-to-end encryption API

github.com

151–160 of 188 posts

Re: Mastodon: Add end-to-end encryption API

#151
post #107

Earlier quoted context omitted.

Instance banning is neither silent nor invisible. Every Mastodon instance has an About page (no login required) listing all instance bans and reasons, anytime. I would be in agreement with you about silent/invisible censorship, but that's not what's going on here. This is a categorically different problem than MITM.

> Every Mastodon instance has an About page (no login required) listing all instance bans and reasons There are instances which require an account in order to see the bans (cyber.space). There are instances which do not list bans at all. There are instances with made up reasons of banning made up instances (mastodon.art). Even that flagship instance lists incorrect reasons for removing instances (claims that certain…

>claims that certain instances shared illegal content when said instances do not allow any form of illegal content

That can be a simple issue of jurisdiction. Mastodon.social is hosted in Germany (IIRC), so they have to adhere to German law. That means, for example, while hatespeech isn't strictly illegal in the US, it certainly is in Germany, it even has a fairly good legal definition. Or take the Japanese instances, which aren't well federated or have media-bans because of differences in media legality. And lastly it can also be simply the case that the instance is not moderating (ie, they write 'no illegal content' but do not care).

Both the statement that an instance shared illegal content and that the same instance was banned for illegal content can be true at the same time.

Re: Mastodon: Add end-to-end encryption API

#152
post #117

Is there a mastodon server that doesn't require email for signup? Throw away providers did not work for me, free email providers require a phone number. It's like signal, the benefits are contrasted against metadata exposure.

I used Tutanota just a few weeks ago for this and they didn't require a phone number. I also found that trying a few providers, sooner or later a throwaway address would work.

But I also think asking for at least an email is not that unreasonable. Sure, I value my privacy, but I also value a good community and keeping the worst spammers out often helps. Talking smaller instances here, obviously, but I think that's where the value is with something like mastodon. Tight knit communities with the option to reach out to others.

Re: Mastodon: Add end-to-end encryption API

#153
post #146

Earlier quoted context omitted.

The federated Mastodon, the one people generally are talking about, is controlled, by a 'democracy' of sorts of the server owners. The technology itself is of course open, but if your content is not approved by the main Mastodon federation, then users will have to be signed into multiple Mastodon federations (if that's what they wish), one to see the main Mastodon federation, and one to see the one that got banned. B…

The definition of "free speech" many people in this thread use puzzles me greatly. If you come to my house and starts yelling things that offend me and I kick you out, I'm not infringing on your freedom of speech. Based on what principles should server owners be forced to federate with third party servers if they don't want to? How is not wanting to federate with anybody "censorship"? I've just setup a mastodon insta…

Main-instance Mastodon (run by the main dev) has made moderation choices that people disagree with. It means conversations here always brings out this same group group of people that disagreed with all these decisions and somehow believe their speech (their bytes) must physically be shipped to everyone else in some network, and must be examined by everyone on the network so that others can decide for themselves whether to listen. I've literally had conversations on the Fediverse where people expected and wanted blockchain-like replicas of their content onto everyone else's computer. And for everyone else to read it.

This group of people have shifted to this position because they no longer have the "de-platform/systemic-censorship" argument that arises when someone is banned from a centralized service, resulting in a total loss of access to the entire platform. Conversely, on the Fediverse they're still there but simply can't talk to some % of users. And that can easily be rectified by being a part of multiple communities and abiding by their rules.

I've tried to write about how ActivityPub (which Mastodon uses) is not a censorship-resistant network and that the point of Federation is to build lots of custom communities and have them politely talk to each other, or ignore the ones that violate community's expectations [0]. Feedback I literally got from here on HN was "I'm disappointed in you", when I think it's an accurate and realistic view. Especially when standing in the shadow of FreeNet.

The same liberty of free-speech and free-association that lets a far-left community thrive, and a far-right community thrive, also lets them block each other (which is a good thing -- it would be ugly otherwise).

[0]https://cjslep.com/c/blog/censorship-is-a-tool

Re: Mastodon: Add end-to-end encryption API

#154
post #150

Earlier quoted context omitted.

> Every Mastodon instance has an About page (no login required) listing all instance bans and reasons There are instances which require an account in order to see the bans (cyber.space). There are instances which do not list bans at all. There are instances with made up reasons of banning made up instances (mastodon.art). Even that flagship instance lists incorrect reasons for removing instances (claims that certain…

You're right, my mistake. In some cases it is not transparent. However, this is not a systematic censorship problem, unlike centralized services with opaque policy language and a complete boot out the door. People are free to run their own instances or have multiple accounts across different instances. Whether you think they're correct is irrelevant to the question at hand. Freedom of speech and association means you…

Do not put words in my mouth. I only replied to the point regarding transparency in your post. I really don't care about the rest.

Re: Mastodon: Add end-to-end encryption API

#155

Earlier quoted context omitted.

I think not. Japanese politicians are preparing for a crackdown on cyberbullying after a wrestler killed herself. mstdn.jp states that it won't likely have the operational capability to deal with the anticipated legal changes, whatever that might be. https://www.japantimes.co.jp/culture/2020/05/26/entertainmen...

Shows how much society cares about anyone that's not popular. There are many people who are suicidal - no named hanging out on mstdn or other internet holes. There are many who get bullied everyday in real life and it's worse because you don't have a block button. Why is everyone so focused on cyberbullying these days? They couldn't solve bullying in school. Only made it worse by putting responsibility on management.…

> I wonder what legal changes they would come up. I am not optimistic.

This. The sad reality, IMO, is that government policing of cyberbullying is never going to work out in practice due to its sheer scale. On the other hand, any legal framework that's going to be introduced would likely be abused by bad actors to suppress speech. So it's either going to be pointless at best, and outright harmful otherwise.

Re: Mastodon: Add end-to-end encryption API

#156
post #150

Earlier quoted context omitted.

You're right, my mistake. In some cases it is not transparent. However, this is not a systematic censorship problem, unlike centralized services with opaque policy language and a complete boot out the door. People are free to run their own instances or have multiple accounts across different instances. Whether you think they're correct is irrelevant to the question at hand. Freedom of speech and association means you…

Do not put words in my mouth. I only replied to the point regarding transparency in your post. I really don't care about the rest.

I'm sorry! Based on context, I understood your post to refute mine to support sneak. And sneak and I have had heated debates about the Fediverse before, and you've stumbled into the latest one. :)

In the future, it would definitely help me and others understand your motivation better if you could even include one more sentence in your communication like "Just here for a correction: some instances are transparent..."

I will strive to be more charitable.

Re: Mastodon: Add end-to-end encryption API

#157
post #120
post #94

Earlier quoted context omitted.

> Why does it matter if any instance decides they don't want to associate with you? It doesn't affect your ability to use the service beyond not being able to interact with folks who probably don't want to talk to you anyway. It prevents people on that instance who explicitly want to follow me from doing so. It also prevents me from following people on that server from my primary account on my homeserver, even if tho…

Then they, and you, can find another instance where you can mutually talk with each other. You are, in fact, allowed to have multiple fediverse accounts for different purposes/groups of people. This doesn't address my point at all that you cannot argue that my server is somehow obligated to process bytes from your server.

Tools that disobey their end users are unfit for purpose. They're bad tools, and should be replaced with useful ones.

Your peers' routers are allowed to drop your packets, but nobody is arguing that that's good or beneficial. There is a difference between "within rights" and "good".

Re: Mastodon: Add end-to-end encryption API

#158
post #117

Is there a mastodon server that doesn't require email for signup? Throw away providers did not work for me, free email providers require a phone number. It's like signal, the benefits are contrasted against metadata exposure.

Surely there's an email provider that doesn't require a phone number? Protonmail, Tutanota?

Or cock.li if you are into edgy domains.

Re: Mastodon: Add end-to-end encryption API

#159
post #157
post #120

Earlier quoted context omitted.

Then they, and you, can find another instance where you can mutually talk with each other. You are, in fact, allowed to have multiple fediverse accounts for different purposes/groups of people. This doesn't address my point at all that you cannot argue that my server is somehow obligated to process bytes from your server.

Tools that disobey their end users are unfit for purpose. They're bad tools, and should be replaced with useful ones. Your peers' routers are allowed to drop your packets, but nobody is arguing that that's good or beneficial. There is a difference between "within rights" and "good".

Oh well. Guess we won't agree on this one then.

Block button go brrrrrr.

Re: Mastodon: Add end-to-end encryption API

#160

Earlier quoted context omitted.

There’s an entire web framework for Elixir called Phoenix. You’re painting Elixir as this obscure language that no one knows and while it’s undeniable that it may not be as widespread as JS, PHP or Python, it is not so marginal. I live in a European city that’s not a tech capital and a couple major startups use it, and I’ve seen it used in major apps across the web. Never used it myself but read how it excels at conc…

It is pretty much obscure, I don't think a couple of major startups is gonna cut it. Elixir never got the kind of adoption that will last for years and years after the hype is gone. Instead it had a nice spike a couple of years ago and i's declining already. Ruby can live for another 20 years based on the 10 good years it had, Elixir never had those years it seems. Yes, it got tremendous attention on hackernews and b…

Some examples of companies using Elixir / Erlang in production: Discord, WhatsApp, WeChat, Bet365, Pinterest (notification system).

This is hardly "obscure" - these are applications used by billions of users all over the world.

Potential developer market for your business or OS project is a factor in engineering, sure. But it's certainly not the only one, and there's a utility threshold for how useful a large developer base can be - maybe I don't care that there are only 10,000 good Elixir in my region if I only need 3 or 4, and I can entice them with good conditions (salary, or a prestigious OS project)

World-class CTOs and engineers choose Erlang and Elixir for their working characteristics as programming languages, a point which you've chosen to completely ignore.

> Even worse, it's functional

I wouldn't consider myself a functional programmer (although if a language offers FP facilities I often use the hell out of them over imperative and OO constructs) but if I built something in FP because I thought it was be the best-suited paradigm for the task at hand, I'd happily weed out people who can't be arsed to learn the rudiments.

Post reply on HN