Live data from Hacker News

Our experience with the Fediverse, and why we left

infosec-handbook.eu

71–80 of 224 posts

Re: Our experience with the Fediverse, and why we left

#71
I am one of the people that got a lot of shares on Mastodon for being critical of Signal.

I think this article greatly misrepresents the main arguments going around the Fediverse about Signal, and the arguments for alternatives.

1. Signal holds the only set of signing keys to the only published binaries allowed on the network, compiled by them, that in turn control all signing keys. If pressured they could push a malicious update with unpublished code. The published server code has not been updated since April last year, so either they have made no changes since then or they are already comfortable pushing updates without matching public source code.

2. The bulk of metadata protection on Signal comes down to trust in SGX, which indeed is an entirely broken technology and keys can be extracted from it via a number of side channels if there is sufficient motivation, such as a government trying to track down dissenting views, or a future owner of Signal that secretly is willing to cooperate with a state actor. Intel also could, if ordered, also issue a microcode update intentionally compromising the RNG used for keys, etc. Signal places a huge centralized target on its back so I think these risks are plausible and worth being aware of.

3. Signal forces all TCP/IP metadata to one stack, which if combined with heuristical analysis, I strongly suspect it would be possible to work out which IPs communicate with which other IPs even without aid of SGX contained metadata.

4. Signal is actively hostile to any third parties that compile and sign signal network compatible binaries and release them via open source app stores, and vows to fight them and get them removed from the network. Moxie repeatedly says he prefers the install base tracking proprietary stores like Google and Apple afford.

5. Signal has built their entire social graph on phone numbers which require ID to buy and are actively tracked in 200 countries, and many carriers will sell out their customers to bounty hunters etc. This is directly at odds with their stated goals of furthering privacy.

When asked what alternative I suggest, I say Matrix.

Those that really need privacy can use a pseudonym via Tor on a server of their choice hosted by people they trust and avoid revealing PII to the messenger at all, unlike Signal. The most private metadata is that which you are not required to reveal in the first place.

The server and remaining metadata that must exist, like sensitive channel memberships, easily be hosted in a server you own on property you own. Sensitive channels could stay on that server and not reveal any metadata or group participation to the wider network giving you granular control of your own metadata and where it lives.

If you really wanted to you could even use generic tools that exist for SGX to do FDE on the database disk with the key in SGX and in turn also run a lean binary like Dendrite in SGX. I don't think this is worth it, and I think SGX is largely security theatre at this point but this is what freedom looks like.

You can run your own server and maintain it according to your own threat profile, instead of using a one size-fits-all threat profile a centralized walled garden forces on you.

If you still think all the arguments above are totally unreasonable and you don't like hearing a lot of opinions critical of popular centralized services like Telegram, Signal, and Whatsapp... then indeed the Fediverse may not be for you.

Most users care a lot about keeping digital sovereignty which is why they joined the Fediverse in the first place.

Re: Our experience with the Fediverse, and why we left

#72

As a regular fediverse user, the main detail I'd be curious about is: Which server was the experiment done on and which servers were federated with? I don't have anything against this article per se, but it's worth noting every fediverse encounter is different. My main take on this article is that it's like walking into a McDonald's and being upset they don't serve pizza and then condemning all fast-food as being ter…

Show me the Mastodon server with the moderation policy that fits the author's use case. It appears I can't even search mastodon instances by the criteria of moderation policy. (But if I'm missing something obvious please correct me because I'd love to be able to do this!)

There an abundant history of examples of centralized, publicly accessible forums where the quality of the discussion matches what the author desires. Plenty of FOSS mailing lists too, many of them extant. (On the topic of security, the cryptography list comes to mind.)

Mastodon's only value is in its utility to deliver discussions that are at least as functional as those I've participated in on these ancient services. If the author and I cannot easily (or ever) discover how to engage in discussions like that, it doesn't matter at all whether the underlying infrastructure is centralized or not.

Edit: clarification

Re: Our experience with the Fediverse, and why we left

#73

Earlier quoted context omitted.

I guess problem lies in this part mainly. Choosing host is more important than it should be. Mainly because hosts are trying to do 2 things at the same time: being identity provider and being some kind of content host in federated environment (moderation etc). Because of this when you choosing a host, you are investing too much. Their future policy changes etc will effect you, you cannot afaik move to another host. (…

This is why I recommend self-hosting via pleroma if possible. Mastodon is a huge resource hog compared to pleroma, which can run nicely on a raspberry pi. But yes, the issue gets outsourced to the user, and you have to trust a random individual instead of an entity like twitter.

I don't know much about pleroma, I will definitely check.

But when you self host your Mastodon, aren't you losing the benefit of local. What is the point of local if I will be alone there?

Re: Our experience with the Fediverse, and why we left

#75

Earlier quoted context omitted.

Fidonet used to provide the federation across message boards in the BBS era, so there is literally nothing new. Really the new thing was smartphones opening up microblogging to average people who want to track celebrities and pretend what they had for lunch is worth sharing. (Edited to clarify fidonet was in the BBS era)

Fidonet boards exchanged messages overnight so the propagation delay was much longer. Also, the topology was different. I don't think the idea of each user publishing a public stream of messages that others subscribe to was a thing back then? Instead you would post messages in forums.

I was replying to a post claiming the only novel part of mastodon compared to old message boards is federation. I’m merely pointing out that many old message boards did have federation.

To your points (1) yes, everything was slower back then (2) people could and did post streams of their work within the BBS framework, everything from multi-part posts to “owning” a message-board topic, to text/ansi e-zines, but back then the focus was much more on following topics than people.

Re: Our experience with the Fediverse, and why we left

#76

Earlier quoted context omitted.

This is why I recommend self-hosting via pleroma if possible. Mastodon is a huge resource hog compared to pleroma, which can run nicely on a raspberry pi. But yes, the issue gets outsourced to the user, and you have to trust a random individual instead of an entity like twitter.

I don't know much about pleroma, I will definitely check. But when you self host your Mastodon, aren't you losing the benefit of local. What is the point of local if I will be alone there?

I have a single user pleroma instance and I don't check local or federated timelines. I think I even disabled them. If I want to discover new content or users I go to the instances that interest me and explore their timelines.

Re: Our experience with the Fediverse, and why we left

#77
I was looking to find an insightful article about the problems with Fediverse.

But I only found an article that rants about the toxic humanity.

This article has nothing to do with so called "Fediverse". It's so unrelated that the title almost reads like a click bait.

Re: Our experience with the Fediverse, and why we left

#78
This just reminds me that the problem with discourse isn't centralization, control, lack of privacy or security, or any other thing.

The problem is that people act in bad faith online, a lot.

Give a bunch of people a platform to broadcast their thoughts, and a lot of people will be lazy about those thoughts. A lot of people will turn it into a competition and be more concerned about creating a following rather than spreading truth and fostering healthy discussion.

Sure, I'd take a Fediverse over a Facebook or a Twitter any day; lack of corporate control and the ability to run your own instance and federate are just plain better from a "health of the internet" perspective. But that doesn't solve the social problems inherent in any community where people most don't know each other personally and don't have to interact face-to-face.

Re: Our experience with the Fediverse, and why we left

#79
post #64

Earlier quoted context omitted.

I guess problem lies in this part mainly. Choosing host is more important than it should be. Mainly because hosts are trying to do 2 things at the same time: being identity provider and being some kind of content host in federated environment (moderation etc). Because of this when you choosing a host, you are investing too much. Their future policy changes etc will effect you, you cannot afaik move to another host. (…

Users have to make the same choice with any other social media service.

There is only the choice of whether to use the service or not. If you get banned for wrongthink on Twitter, it does not immediately affect you on Facebook.

Twitter and Facebook only ban the more extreme or inconvenient forms of wrongthink. Mastodon servers on the other hand often are Subreddit style echochambers.

Re: Our experience with the Fediverse, and why we left

#80
post #64

Earlier quoted context omitted.

Users have to make the same choice with any other social media service.

Sorry maybe I couldn't explain my point clear. Think Mastodon instances (hosts) as reddit subreddits. Basically you are creating an account in not universe (reddit) but on instance (subreddit) And this subreddit is deciding, which other subreddits you can see with your account. (fediverse)

I am questioning the presupposition that one chooses to make any account at all.

Using your analogy:

I don't need to create an account to view a subreddit or reddit. I don't need to create an account to view federated instances.

When I publish content on any social network I am always thinking about who it is intended for. I don't post the same things on Facebook that I would on Instagram, for example.

Users have to make the same choice of what to publish with any other social media service.

Post reply on HN