Live data from Hacker News

Trouble with Diaspora

blog.steveklabnik.com

21–30 of 166 posts

Re: Trouble with Diaspora

#21

The trouble is that they were so ambitious but lacked any experience from which to chart those ambitions. They're just a bunch of young twenty-somethings just getting out of school. They haven't built any large-scale real-world security-hardened software yet. More than the fact that the code isn't production ready (by a long shot it seems), I'm just surprised the released anything at all. Perhaps spending all that mo…

What were these kids thinking, starting some ambitious software project from scratch without much of a clue how to do it? This is unheard of on the internet!

Re: Trouble with Diaspora

#22

They (Diaspora staff) said this as they released it: "Feel free to try to get it running on your machines and use it, but we give no guarantees. We know there are security holes and bugs..."

The issue is you shouldn't build (or ship) code like this with such major security holes, you build security at the start, it should be an integral part of the application. You can't just dick out some insecure application then add in security, it doesn't work.

Microsoft didn't "build security in at the start", nor did Apple, nor did Twitter, nor (I suspect) did Facebook or YouTube. It's a pre-alpha of an open source project. Of course there will be problems.

Re: Trouble with Diaspora

#23

They (Diaspora staff) said this as they released it: "Feel free to try to get it running on your machines and use it, but we give no guarantees. We know there are security holes and bugs..."

The issue is you shouldn't build (or ship) code like this with such major security holes, you build security at the start, it should be an integral part of the application. You can't just dick out some insecure application then add in security, it doesn't work.

Good point. We'll wait for the security experts to build this.

.............................

................................................

Still waiting.........................

Re: Trouble with Diaspora

#24

Earlier quoted context omitted.

I don't think anybody is "holding it to the same standards as a finished product." I haven't read the code myself, but the OP is claiming "really, really bad security holes", and calls out the encryption code. Security is not something that can be bolted on after the fact; it needs to be baked in from the start, in a product like this. And, remember, security/privacy was Diaspora's raison d'etre. No one expects the f…

Security is not something that can be bolted on after the fact In fact, this is how it happens in the vast majority of cases, including the case of Facebook.

Not sure Facebook was an exemplary choice.

Re: Trouble with Diaspora

#25
post #3

This code was released to developers as an incomplete preview. I'm not sure why people are holding it to the same standards as a finished product that's being released to end users. Seems like a pretext to talk trash.

Their product is released to end users, because the first thing every early adopter is doing with their shiny new host-you-own federated social network is sending out invites.

Re: Trouble with Diaspora

#26
As far as I can consider, there are two possible alternatives to this (that is, releasing their flawed code). They could have either released flawless code, or they could have released no code at all. I understand OPs concern, but considering the alternatives I don't really get the tone of the article.

Re: Trouble with Diaspora

#27

As other people have already said: this is just an early code drop. It would be good to have it transition into an open source project with many developers, especially because the developers are I assume starting their fall school term. I enjoyed building and playing with the code, and I hope that there is a much improved version in the future.

"the developers are I assume starting their fall school term." Two of the Diaspora team graduated in May, and the other two have taken a leave of absence from NYU to continue to focus on the project. See: http://www.joindiaspora.com/2010/08/26/overdue-update.html

Re: Trouble with Diaspora

#28

The trouble is that they were so ambitious but lacked any experience from which to chart those ambitions. They're just a bunch of young twenty-somethings just getting out of school. They haven't built any large-scale real-world security-hardened software yet. More than the fact that the code isn't production ready (by a long shot it seems), I'm just surprised the released anything at all. Perhaps spending all that mo…

The trouble is that they were so ambitious but lacked any experience from which to chart those ambitions. They're just a bunch of young twenty-somethings just getting out of school. They haven't built any large-scale real-world security-hardened software yet.

Thank God that our industry isn't lousy with ambitious but inexperienced twenty-somethings. If we let them run amok, we'd get crapware like MS-DOS and computers like the Apple II.

Re: Trouble with Diaspora

#29
post #12
post #7

They could've really saved themselves some grief is they'd been far more explicit about saying that it's Alpha and months from being production ready. All this 'there's bugs! omfg!' hoo-ha could've been headed off at the pass

I think there's a big difference between "omfg bugs" and "The bottom line is currently there is nothing that you cannot do to someone's Diaspora account, absolutely nothing" from http://www.theregister.co.uk/2010/09/16/diaspora_pre_alpha_l...

Not really, in fact that article was exactly what I was thinking of, reading it it'd be easy to get the impression they were talking about production software after the first sentence. Bugs are fixable and I haven't found any serious design or protocol mistakes, nor seen anyone else point any out. Given that, I'd say they're doing pretty damn well.

Re: Trouble with Diaspora

#30
post #2

It's great that they're getting so much open-source help, but I'm going to ask the obvious question: if a "complete overhaul" is what's needed, as the author seems to imply, and the FOSS community performs said overhaul, then what of the $250k that was given to the Diaspora guys? Is it still even "Diaspora" anymore, as opposed to a FOSS project?

And more importantly, if you're going to rewrite, why help Diaspora, and not a more mature option?

What more more mature option were you thinking of?
Post reply on HN