Live data from Hacker News

Trouble with Diaspora

blog.steveklabnik.com

11–20 of 166 posts

Re: Trouble with Diaspora

#11
As other people have already said: this is just an early code drop. It would be good to have it transition into an open source project with many developers, especially because the developers are I assume starting their fall school term.

I enjoyed building and playing with the code, and I hope that there is a much improved version in the future.

Re: Trouble with Diaspora

#12
post #7

They could've really saved themselves some grief is they'd been far more explicit about saying that it's Alpha and months from being production ready. All this 'there's bugs! omfg!' hoo-ha could've been headed off at the pass

I think there's a big difference between "omfg bugs" and "The bottom line is currently there is nothing that you cannot do to someone's Diaspora account, absolutely nothing" from http://www.theregister.co.uk/2010/09/16/diaspora_pre_alpha_l...

Re: Trouble with Diaspora

#13
post #2

It's great that they're getting so much open-source help, but I'm going to ask the obvious question: if a "complete overhaul" is what's needed, as the author seems to imply, and the FOSS community performs said overhaul, then what of the $250k that was given to the Diaspora guys? Is it still even "Diaspora" anymore, as opposed to a FOSS project?

And more importantly, if you're going to rewrite, why help Diaspora, and not a more mature option?

Re: Trouble with Diaspora

#14
post #3

This code was released to developers as an incomplete preview. I'm not sure why people are holding it to the same standards as a finished product that's being released to end users. Seems like a pretext to talk trash.

Indeed. These guys should be lauded for getting something out. It's a very non-trivial accomplishment.

I'm afraid that Diaspora might be in an impossible position. If they release something early, they'll get a lot of bad press from knuckleheads like this one that the quality is no good. If they release late, everyone will be clamoring over the wasted $250k in the interim, demanding: "when will we see something?".

Re: Trouble with Diaspora

#15
They (Diaspora staff) said this as they released it:

"Feel free to try to get it running on your machines and use it, but we give no guarantees. We know there are security holes and bugs..."

Re: Trouble with Diaspora

#16
post #3

This code was released to developers as an incomplete preview. I'm not sure why people are holding it to the same standards as a finished product that's being released to end users. Seems like a pretext to talk trash.

I don't think anybody is "holding it to the same standards as a finished product." I haven't read the code myself, but the OP is claiming "really, really bad security holes", and calls out the encryption code. Security is not something that can be bolted on after the fact; it needs to be baked in from the start, in a product like this. And, remember, security/privacy was Diaspora's raison d'etre. No one expects the f…

Security is not something that can be bolted on after the fact

In fact, this is how it happens in the vast majority of cases, including the case of Facebook.

Re: Trouble with Diaspora

#17
"Release early, release often" (an open source mantra). Here on HN i also find the 'getto launch' being preached -- "if you not embarrest by your product at lauch-time, you should have released earlier".

Judging from the noise their release makes here on HN i think the diaspora guys did well opening up their repo 'early'.

And to steve: i think you hold 'professional programmers' (which i interpret as programmer that get paid) waaay too high..

Re: Trouble with Diaspora

#18

They (Diaspora staff) said this as they released it: "Feel free to try to get it running on your machines and use it, but we give no guarantees. We know there are security holes and bugs..."

The issue is you shouldn't build (or ship) code like this with such major security holes, you build security at the start, it should be an integral part of the application. You can't just dick out some insecure application then add in security, it doesn't work.

Re: Trouble with Diaspora

#19
post #17

"Release early, release often" (an open source mantra). Here on HN i also find the 'getto launch' being preached -- "if you not embarrest by your product at lauch-time, you should have released earlier". Judging from the noise their release makes here on HN i think the diaspora guys did well opening up their repo 'early'. And to steve: i think you hold 'professional programmers' (which i interpret as programmer that…

There are a few reasons why this is worse: first, they are launching to media attention and a rabid community. BCC sucked at launch, but no one saw it, so yay. (And by sucked, I mean looked ugly, not "Anyone can delete all your documents at will.") Diaspora has thousands of end users already. Some seeds have 200+. They are launched. Not prealpha. Launched.

Their entire reason for existing is "Facebook but private". At the moment, they are delivering on that like ROT13Snap delivers on secure backup. And due to a programming bug, ROT13 was applied twice, and indexes are on in Apache. It is a cluster flop.

Re: Trouble with Diaspora

#20

Earlier quoted context omitted.

I don't think anybody is "holding it to the same standards as a finished product." I haven't read the code myself, but the OP is claiming "really, really bad security holes", and calls out the encryption code. Security is not something that can be bolted on after the fact; it needs to be baked in from the start, in a product like this. And, remember, security/privacy was Diaspora's raison d'etre. No one expects the f…

Security is not something that can be bolted on after the fact In fact, this is how it happens in the vast majority of cases, including the case of Facebook.

including the case of Facebook.

...which is Diaspora's claim to existence.

Post reply on HN