Live data from Hacker News

Interoperability Can Save the Open Web (2023)

spectrum.ieee.org

41–50 of 66 posts

Re: Interoperability Can Save the Open Web (2023)

#42
post #33

I am nobody. I have little impact. I want my programs to be safe from government intrusions, from age checks, from encryption backdoors, from corporate surveillance. How do I win this battle with big tech? I am deeply in self-host. For the self-host to succeed it needs to be better, unregulated, and free. It needs to be easily distributed. The data should be easily distributed. Import and export should be fast and ea…

I would say: 1) Use HTTP (secure is not the way to decentralize). 2) Selfhost DNS server (hard to scale in practice). 3) Selfhost SMTP server (also tricky). 4) Know and backup your router (dd-wrt or iptables). JSON over HTTP is the way. XML is not bad for certain things too; even if I understand the legacy of abuse.

> Use HTTP (secure is not the way to decentralize).

This doesn't seem like useful advice. If you're going to use HTTP at all there is essentially zero practical advantage in not using Let's Encrypt.

The better alternative would be to use new protocols that support alternative methods of key distribution (e.g. QR codes, trust on first use) instead of none.

> Selfhost DNS server (hard to scale in practice).

This is actually very easy to do.

Re: Interoperability Can Save the Open Web (2023)

#43
post #42
post #33

Earlier quoted context omitted.

I would say: 1) Use HTTP (secure is not the way to decentralize). 2) Selfhost DNS server (hard to scale in practice). 3) Selfhost SMTP server (also tricky). 4) Know and backup your router (dd-wrt or iptables). JSON over HTTP is the way. XML is not bad for certain things too; even if I understand the legacy of abuse.

> Use HTTP (secure is not the way to decentralize). This doesn't seem like useful advice. If you're going to use HTTP at all there is essentially zero practical advantage in not using Let's Encrypt. The better alternative would be to use new protocols that support alternative methods of key distribution (e.g. QR codes, trust on first use) instead of none. > Selfhost DNS server (hard to scale in practice). This is act…

Let's Encrypt is not part of our friends here.

DNS is easy for yourself, but if you host it for others (1000+ of people) and it needs to have all domains in the world, then it becomes a struggle.

Re: Interoperability Can Save the Open Web (2023)

#44

I am nobody. I have little impact. I want my programs to be safe from government intrusions, from age checks, from encryption backdoors, from corporate surveillance. How do I win this battle with big tech? I am deeply in self-host. For the self-host to succeed it needs to be better, unregulated, and free. It needs to be easily distributed. The data should be easily distributed. Import and export should be fast and ea…

> I am nobody. I have little impact. I want my programs to be safe from government intrusions, from age checks, from encryption backdoors, from corporate surveillance. How do I win this battle with big tech? If you're only talking specifically about your program that no one else has access to, I don't think there is any battle? Do whatever you want, no one cares nor would even know about it. If you're talking about m…

I am talking about many things. Also about my programs, but also data. Programs are not that important for me. They are just vehicles to get the job done.

All my programs and data are open. It is something that anybody can pick up, and use as they wish

- https://github.com/rumca-js/Internet-Places-Database - domains I found

- https://github.com/rumca-js/Internet-feeds - feeds I found

- https://github.com/rumca-js/RSS-Link-Database-2026 - news from 2026

- https://github.com/rumca-js/RSS-Link-Database-2025 - news from 2025, etc.

Does make any change? I don't know. I run web crawlers. It is interesting for me to see what my crawlers pick up from the Internet. It did change my life, these project changed how I see the Internet. More pro-activly.

I think there are many projects which can be useful for niche groups. I suppose I have 390 stars on one repo. I hope at least my projects were useful for them. That is a hopeful thought.

Re: Interoperability Can Save the Open Web (2023)

#45
post #43
post #42

Earlier quoted context omitted.

> Use HTTP (secure is not the way to decentralize). This doesn't seem like useful advice. If you're going to use HTTP at all there is essentially zero practical advantage in not using Let's Encrypt. The better alternative would be to use new protocols that support alternative methods of key distribution (e.g. QR codes, trust on first use) instead of none. > Selfhost DNS server (hard to scale in practice). This is act…

Let's Encrypt is not part of our friends here. DNS is easy for yourself, but if you host it for others (1000+ of people) and it needs to have all domains in the world, then it becomes a struggle.

Let's Encrypt is a non-profit that defeated the certificate cartel. The main thing you get from using HTTP without it is bad security.

DNS can answer thousands of queries per second on a Raspberry Pi and crazy numbers on a single piece of old server hardware that costs less than $500.

Re: Interoperability Can Save the Open Web (2023)

#46
post #18

Earlier quoted context omitted.

In a world where big tech and governments are requiring user-facing things to do things (like age verification, etc) and be liable for what their users do with it, even the self-host becomes a problem unless you are your only user. There are plenty of people that are still doing it, but they're probably taking on liability they don't realize. For example if I stand up a self-hosted git forge and allow others to use i…

I mean, this is the case for a lot of things? Has always been the case. If you host friends over for dinner at your house a lot, nobody will ever say you are subject to the same rules as a restaurant. You start letting other people host dinners at your house, and things could change. You start letting people solicit your place for paid dinners, similar outcome. Do it once, nobody will probably know or care. Continue…

The problem is obviously that the government shouldn't be regulating private speech. They pass these rules by saying "look how big Facebook is, they need to be regulated" when the actual problem is that they need to be decentralized. But then the rules don't apply only to Facebook, and worse, are designed under the assumption of a centralized service so that they entrench the thing that should be eliminated.

Re: Interoperability Can Save the Open Web (2023)

#47
post #37

Earlier quoted context omitted.

> If you're only talking specifically about your program that no one else has access to, I don't think there is any battle? Do whatever you want, no one cares nor would even know about it. Can I do it on my phone?

No because a phone, despite being made from the same parts as a computer is actually a completely different thing. You can't just run programs on your phone. You have to run apps, which require approved by the government and the company that made the phone, which tacks on additional fees as well. The phone also has constant cellular/GPS/wifi/bt-mesh location tracking, and it can never be completely turned off by the…

> If you don't think this is right, you are literally going to empty the bank account of my dumb ass grandma who can't stop installing malware, and in every way is better served by a flip phone from the early 2000's.

Then why are you demanding that everyone else's mobile computers have to be locked down instead of demanding that somebody make a mobile phone that only makes phone calls?

Re: Interoperability Can Save the Open Web (2023)

#48
post #25

Earlier quoted context omitted.

Yes, again, you run a public service, expect to have to follow regulations for public platforms, not sure why anyone would expect something else. I was talking about creating/running software for yourself, in a self-hosted scenario, not just "I run the software, but it's for others" but really "I run software and it's for myself and/or my family, no one else"./

The point of a social network, or blogging or whatever is that it's for others. Furthermore, I think people have the right to free speech and should have the ability to reasonably address the public square (for example, with a blog, or a forum or something). What I'm saying in the previous comment is that regulations requiring "Age checks, encryption backdoors and other bad/annoying stuff" also apply to small hosts a…

> At what point do you become a "big bad company"?

Revenue exceeds 0.1% of US GDP or market share exceeds 10% of their own market.

Re: Interoperability Can Save the Open Web (2023)

#49
post #45
post #43

Earlier quoted context omitted.

Let's Encrypt is not part of our friends here. DNS is easy for yourself, but if you host it for others (1000+ of people) and it needs to have all domains in the world, then it becomes a struggle.

Let's Encrypt is a non-profit that defeated the certificate cartel. The main thing you get from using HTTP without it is bad security. DNS can answer thousands of queries per second on a Raspberry Pi and crazy numbers on a single piece of old server hardware that costs less than $500.

No root certificate is decentralized.

If your DNS port is closed by your ISP, you can't have people use your DNS server from the outside and then you need Google or Amazon which are not decentralized.

Also to be selfhosted you can't just forward what root DNS servers say, you need to store all domains and their IPs in a huge database.

Re: Interoperability Can Save the Open Web (2023)

#50
post #18

Earlier quoted context omitted.

I mean, this is the case for a lot of things? Has always been the case. If you host friends over for dinner at your house a lot, nobody will ever say you are subject to the same rules as a restaurant. You start letting other people host dinners at your house, and things could change. You start letting people solicit your place for paid dinners, similar outcome. Do it once, nobody will probably know or care. Continue…

The problem is obviously that the government shouldn't be regulating private speech. They pass these rules by saying "look how big Facebook is, they need to be regulated" when the actual problem is that they need to be decentralized. But then the rules don't apply only to Facebook, and worse, are designed under the assumption of a centralized service so that they entrench the thing that should be eliminated.

But there is nothing obvious about this? For one, this is speech that can only be done using otherwise regulated means. You couldn't claim "free speech" and build a radio tower that transmits long distances, as an easy example. For that matter, you can't claim free speech to allow concerts at your house. You similarly could not claim free speech to rent or loan out rooms of your house for storage.

As has been pointed out elsewhere, if you want to take the effort to connect and verify the different parties that are going to communicate with your server, you are almost certainly going to remain free to do so.

Do I think there are probably some concerning ways those burdens can be placed on folks? Certainly. But we already require inspections and other similar activities for things that individuals can do at home without an inspection. See the food industry.

Post reply on HN