Live data from Hacker News

On the Twitter Hack

schneier.com

91–93 of 93 posts

Re: On the Twitter Hack

#91
post #54
post #32

Earlier quoted context omitted.

> "ownership of your own social graph" What would that mean? > If these platforms were forced to act more like email Who decides who's "following" who? Say I decide to use a competitor. Do I then get to "take" my Twitter followers and can still broadcast to them on Twitter from a different app? Under what conditions can Twitter block your activity? Either they will have to let a lot of spam in or they'll have to ban…

All this is actually worked out in some detail (search keywords federated/indie web). Check out the PubSub model, and the ActivityPub protocol as an example, and Mastodon as a working proof-of-concept. As a starting point, imagine email & RSS and work forward from there. I'm not saying it's trivial, but it's also not insurmountable.

I did actually do a lot of reading on ActivityPub yesterday and it's exactly the mess I would have imagined it to be.

The standard doesn't define all that much. Arbitrary undocumented JSON fields are perfectly fine and used heavily. Just following the standard you wouldn't get too far, would need to follow Mastodon's implementation to be truly compatible [0].

Many instances have already banned each other, some client apps have outright hard-coded blacklists in. So again would the government forbid that? But then what do you do about unruly instances?

The whole model IMO is pretty wrong in favoring instances over individuals. Twitter is a free-for-all, this model is completely different in optimizing for small groups of like minded people.

Secure private DMs are pretty much impossible in AP.

Rate limiting, spam protections etc are left completely up to the implementer. So would the government define that under an anti-trust scheme?

Now if one considers it to be just some low-level building block for distributed social then okay, maybe it's fine. The idea is basically social-related stuff in JSON over HTTP. Okay. But it doesn't really solve much of anything in practice. It offers a strictly worse experience in name of decentralization. This is exactly why I'd be afraid of the government stepping in and forcing these kinds of decisions on companies.

[0] And then it only gets you compatible with other Mastodon-style instances (and most seem to use the exact same implementation, just different themes). There are other ActivityPub apps that operate under a completely different UX/UI scheme. Which is both nice and weird in that the standard has obviously been written with Twitter-like stuff in mind.

Re: On the Twitter Hack

#92

Earlier quoted context omitted.

> I think anonbcpolitics was ignoring DMs. Yes, because there's no evidence of anyone using DMs to govern. We don't know if a politician uses Signal, Twitter/IG DM, or other 1:1 communication apps, we have to handle those cases when we catch them, like Hillary was caught with her private email server. If she was actually punished it may have deterred people from circumventing FOIA. I would be directly opposed to such…

In my jurisdiction, at least, the intent "to govern" doesn't make much of a difference in whether an item is a public record or not. My public records training would cause me to assume that Twitter DMs created or received by the government entity I work for, irrespective of their intent, are public records. It would be nice if elected leaders at all levels of government were held to the law w/ respect to public recor…

You focused on the wrong part, I could have left out "to govern". My point was there's no evidence of anyone using DMs, we're talking about public tweets. And there's no use talking about private communications because the scope expands from Twitter to the individual's actions (sneaking around using Signal or similar, etc.).

Re: On the Twitter Hack

#93

Earlier quoted context omitted.

In my jurisdiction, at least, the intent "to govern" doesn't make much of a difference in whether an item is a public record or not. My public records training would cause me to assume that Twitter DMs created or received by the government entity I work for, irrespective of their intent, are public records. It would be nice if elected leaders at all levels of government were held to the law w/ respect to public recor…

You focused on the wrong part, I could have left out "to govern". My point was there's no evidence of anyone using DMs, we're talking about public tweets. And there's no use talking about private communications because the scope expands from Twitter to the individual's actions (sneaking around using Signal or similar, etc.).

I work in IT in local government. Even with the public records and ethics training our employees receive we still encounter plenty of times when we must advise other offices re: the public records-related concerns associated with their employees using personal phones, email, and third-party hosted services in the course of their job duties (let alone "sneaking").

I would assume that, at every level of government, significant numbers of public records are being lost to free third-party hosted services.

Post reply on HN