7 ms·
Viral.js – Peer-to-peer web app distribution
- wccrawford 10y agoIt was probably fun to make, but there are so many issues (nat, bandwidth costs for users, browsers not processing background pages' tasks well, etc) that I can't see actually using this in any real-life scenario.
- PixelsCommander 10y agoNATs are pain. True. And also I agree that there were a lot of problems to work around and benefits are not that obvious if application size is 3 Mb. However it becomes closer to real life with every additional megabyte of application size. E.g. for video content it definitely worth and it also could work for web games and VR experiences. Other cases? Sure there are some. Let`s consider this as first Viral JavaScript implementation.
- juretriglav 10y agoThis is something that PeerCDN [0] was doing, before it was acquired by Yahoo. What I'm saying is that this definitely has merit, if you can make it easy enough to use for developers. 0. https://www.quora.com/How-is-WebTorrent-different-from-PeerCDN https://www.quora.com/How-is-WebTorrent-different-from-PeerC...
- zer0gravity 10y agoSo many problems. Security : how do you guarantee that a client peer is not tinkering with the code it distributes further? Unreliable: browsing sessions come and go. Before forwarding the app maybe the browser is already closed.. Bandwidth: nobody loves bandwidth thieves And so on...
- 0x6c6f6c 10y agoThis is an idea I've had for websites such as Wikipedia where consumer funding is the main source keeping it alive. This could be great for a small niche of applications, but even for those, these points are still important. Particularly on the consumer end, turning my device into a provider as well as a consumer of data is typically not my intention. It's forced seeding on all clients in a torrent sense, which not everyone wants to be a part of. Or for that matter, can be. In a world of data caps, turning my phone, tablet, or hotspot connected devices into a CDN has moral and fiscal implications that have to be considered.
- PixelsCommander 10y agoExactly. Non profit organizations could benefit most of all here saving on infrastructure.
- huskyr 10y agoFrom what i've heard from people managing the hosting and development of Wikipedia, this (using a P2P hosting solution) is mentioned very often, but very impractical to put in real world use. Hosting Wikipedia is quite cheap: most of the content is text and images, which lends itself very well for caching. Making sure people can edit it at high frequency and the transition to mobile use are far more complex, and not the things that P2P distribution would solve.
- CiPHPerCoder 10y ago> Security : how do you guarantee that a client peer is not tinkering with the code it distributes further? You could make a system involving digital signatures (EdDSA), but then "how do you trust which public key?" type questions mean this doesn't improve much.
- abloodywar 10y agoMaybe Subresource Integrity[1] would be of interest. [1] https://www.w3.org/TR/SRI/ https://www.w3.org/TR/SRI/
- AgentME 10y agoIf I'm understanding this right, you could include the public key in the web page itself, served over HTTPS. There's still a webpage being served from your server. It just delegates most of the resources to be accessed over webrtc.
- klodolph 10y agoSecurity: Sign every chunk served. Clients tampering with the chunks will invalidate the signatures. Not perfect, but not intractable.
- rawnlq 10y agoThe underlying concept behind this isn't much different from https://webtorrent.io/ https://webtorrent.io/ (I am pretty sure this could've been built on top of the webtorrents protocol). I don't believe there are any insurmountable problems. Security, reliability etc have all been solved before. But there's still no way you can make this faster than traditional CDNs (at the minimum you'll need an extra round trip to check for peers). As a matter of fact if my torrenting speed is any indication, it will be abysmally slow. You probably won't be penny pinching over bandwidth cost when every 100ms of page load time costs you 1% in sales. http://blog.gigaspaces.com/amazon-found-every-100ms-of-latency-cost-them-1-in-sales/ http://blog.gigaspaces.com/amazon-found-every-100ms-of-laten...
- jadbox 10y agoFor CDN-style content, IPFS is a much better route. This seems like a proof of concept really.
- brentm 10y agoSecurity and reliability could probably be sorted using the Thin Client. For security could that not be done by validating the checksum of client received against some expected value only available on the real server? In terms of reliability you could say if not received after a very short amount of time, get from real server. Bandwidth I agree with you on for today because you don't know if someone is paying per MB or how it's working on their end. Under some scenarios you could cost someone real money. In a time when bandwidth is next to free for every one everywhere it may no matter but we're not there yet. I don't think anyone is going to use this stuff any time soon in production but I do think the general idea is one that a lot of people have thought about and it's nice to see someone take a wack at it.
- erikpukinskis 10y agoIf they built it as an Ethereum miner that ran in the browser, all of these problems would be solved (at some performance cost).
- rakoo 10y agoThe homepage only talks about enabling viral spreading inside a corporation. In this context Bandwidth is not a problem anymore, and Security is greatly improved (while not full, there is a higher trust into machines inside the company)
- rkeene2 10y agoPossibly related: RAID-CDN, it's come up before on this site: https://github.com/lorriexingfang/webRTC-CDN-raidcdn-sample https://github.com/lorriexingfang/webRTC-CDN-raidcdn-sample
- andrewvijay 10y agoI think this is suitable for less important and publicly available information in sites. If a site has a lot patient users who would wait for this content to load then may be it can be tried. ;)
- rawnlq 10y agoInformation (in the form of text) is tiny and cheap. The main use case for this has to be videos and other medias. All I can think of is high resolution porn which is currently not cost effective to be purely ad driven. Or hosting illegal videos/music that you can't really make enough real money off of to pay for server costs. But definitely not for "distributing web apps" like the author mentioned unless your js is so bloat it is tens of MBs.
- SapphireSun 10y agoHere's an case study from an article I wrote on this topic that I never published: Case Study 1: Google Maps and Offline Mode Alice navigates her iPad to http://maps.google.com http://maps.google.com and looks up the geography of the city she lives in, Boston. Alice knows that she’s going to be traveling later that day and might not have access to WiFi, so she clicks the “Save for Offline” mode button that is either part of the browser or website interface. The interface presents a permissions menu: “Maps will need to use 500MB of space and will add https://maps.google.com” https://maps.google.com” to your offline hosts” Alice agrees and the download begins. Google Maps saves a copy of its client code, the necessary map data, and a light nodejs server implementation into a browser cache. When the browser senses a connection has been lost, and Alice navigates to or is already on maps.google.com, the nodejs server spins up and requests are forwarded to that server. Alice notes that the browser indicates that the connection is offline and sets her expectations accordingly for what she’ll be able to do. When the connection is regained, the server shuts down and the browser forwards requests to maps.google.com’s true IP address. One day Alice leaves the big city to go camping. She has downloaded maps of the campgrounds onto her iPad as is her usual practice. She moves into her cabin with her friends, and they all realize they have no connection and forgot to grab the maps. They have all brought their phones. Alice activates the promiscuous mode of google maps and the nodejs server becomes active on a mesh network and declares itself the secondary access point to the primary maps.google.com. The phones all mesh network with each other and the iPad. When one of her friends goes to maps.google.com, and looks up the camp grounds the phone asks the friend if she’d like to acquire a copy of the maps server from the iPad with a version number and date of acquisition. She agrees, and the phone downloads the copy of maps offline. As all the friends get the copy of maps offline, the servers distribute the requested map tiles using bittorrent. The friends can now go explore the woods without depending on a single device (though they probably should have brought a paper map).
- antoineMoPa 10y agoI tend not to use CDNs as I feel they could hypothetically allow to track anyone on any website and they could be used to provide backdoors in my apps (hypothetical example: Trump gets elected and decides all the jquery.min.js files sent to Canada via US CDNs have to include something that breaks Canadian apps, then my code stops working). I like to have all my libraries on my server. It would be awesome if something existed to use this tool while ensuring users do not modify the files
- chinathrow 10y ago> It would be awesome if something existed to use this tool while ensuring users do not modify the files That should be possible with subresource integrity. https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- Spivak 10y agoI can't tell you how excited I am for this to be commonplace.
- aakilfernandes 10y agoSeems ipfs might give you something like that. Rather than identifying resources by name, you identify them by the hash of their content.
- wybiral 10y agoMy user experience report: 1. Opened website 2. Clicked "Demo" to see what this was all about 3. Read "Please, login via Facebook..." 4. No thanks. Closed tab.
- fizzbatter 10y agoI'm such an "old man" when it comes to Facebook login. I'll happily login to Google/etc (if i want the product of course), but as a non-Facebook'er, i think back to the days of Facebook apps invading the user privacy, posting things, etc, and it built this mental model of worry around linking anything to Facebook. I avoid any type of api interaction with Facebook like the plague. I only use FB maybe twice a year, and apparently it's not frequent enough to rid this old and overly concerned fear i have. Alas, no login via Facebook for this mentally old man, apparently.
- notduncansmith 10y agoDo you feel that your privacy is less at risk when you give your data to Google over Facebook?
- MrZongle2 10y agoI'm not the parent poster, but I feel similarly about Facebook so I'll take a shot at answering. Bottom line is that I already use Gmail and a fair number of other Google services. I don't use Facebook at all. It's not so much about trusting Google over Facebook, but rather an unwillingness to share my personal info with yet another company...and Google beat Facebook to the punch. If Facebook had offered a comparable set of services and had offered them first, the roles would be reversed. That said, I've been looking at ways I can divorce myself from Google because I trust them about as far as I could throw Larry Page.
- wybiral 10y agoFor me, if it doesn't make sense to link something to my accounts then I'm not going to (Google, Facebook, anyone).
- 10y ago
- mxuribe 10y agoTo wybiral's point, signing in via FB login is a turn off. One point i might add to questions of NAT...what if the first types of apps to be distributed this way were games (then later other catgories of apps), and using ipv6? I think that would do 2 things: avoid some (though not all) nat-related issues; and help increase adoption of ipv6 overall. (I suppose my question should not need to be specific to this viral.js.)
- flaviotsf 10y agoI wanted to build something like this - basically a P2P based End-to-End encryption messaging technology (so it doesn't get inspected by peers) for use cases such as messaging (a-la SMS) on a non-networked environment such as cruise ships / National Parks, etc [maybe through bluetooth or something]. Cruise lines should / could easily build a messaging app that works on a closed network (lots of branding potential.. not sure why it hasn't been done yet!). If anyone is interested ping me. :)
- alexandre_m 10y agoDo you mean something like Bittorrent Bleep? Haven't used it, but same premise.
- jondubois 10y agoThat seems interesting this would be good for CDN-like use cases where you want to distribute static, low-security files/assets. Until we have fast, fully homomorphic encryption, I don't see how peer-to-peer apps are going to be useful in the industry.
- fredliu 10y agoThis seems to be built on top of WebRTC, using data channels ? I believe at least Safari doesn't support that, but their github readme does seem to imply support on Safari. Also, since it's based on WebRTC, who's responsible for setting up the STUN/TURN server?
- so898 10y agoThe main problem is that it is not easy to find the nearest person who has the js file. You see, the connecting time is much longer than downloading time when you download small files with P2P software.
- jswny 10y agoCould be cool but I can't find out because I refuse to login to Facebook for a demo of a JavaScript framework.
- AWildDHHAppears 10y agoGood for you!
- heisenbit 10y agoThe edge of the network often has asymmetric bandwidth. ADSL and cable infrastructure are geared towards serving the home and not serving from the home. Niche applications e.g. low bandwidth m2m may emerge where there is a strong use case but in general the limitations of the uplink will constrain server applications for most users in the foreseeable future. It will be interesting to see if anything different emerges from the small set of fiber connected households.
- slowkow 10y agoI'd like to mention related work from 2014 called QMachine. You might also be interested to read the "Security" section of the article. Wilkinson, S. R. & Almeida, J. S. QMachine: commodity supercomputing in web browsers. BMC Bioinformatics 15, 176 (2014). http://bmcbioinformatics.biomedcentral.com/articles/10.1186/1471-2105-15-176 http://bmcbioinformatics.biomedcentral.com/articles/10.1186/... "Modern web browsers can now be used as high-performance workstations" https://github.com/qmachine/qmachine https://github.com/qmachine/qmachine "QM is an open-sourced, publicly available web service that acts as a messaging system for posting tasks and retrieving results over HTTP. The illustrative application described here distributes the analyses of 20 Streptococcus pneumoniae genomes for shared suffixes. Because all analytical and data retrieval tasks are executed by volunteer machines, few server resources are required. Any modern web browser can submit those tasks and/or volunteer to execute them without installing any extra plugins or programs. A client library provides high-level distribution templates including MapReduce. This stark departure from the current reliance on expensive server hardware running “download and install” software has already gathered substantial community interest, as QM received more than 2.2 million API calls from 87 countries in 12 months."
- andai 10y agoI had the idea a few months ago that, since no one wants to see ads, and since most devices greatly under-utilize potential output, ad networks would slowly be replaced by computation networks over the next few years. So for the time you spend (actively) on a website, instead of being shown ads, you "rent" your device's CPU etc in exchange for the content.
- fratlas 10y agoI actually tried to do a proof of concept for exactly this but gave up after assuming you could never truly trust the client to not mess with/read the data.
- jp555 10y agoMaybe a job for quantum computers, if we can figure out a way to run them like we do current computers and not just in a carefully constructed environment (very cold & quiet boxes).
- 235337 10y agoThis seems like its just moving the costs of bandwidth to your users, probably without them knowing. Sooo yea, I guess you can save money by making others spend theirs instead.
- justrossthings 10y agoOP, can you share why social login is necessary?
- brink 10y agoI'm not giving my email address to a random demo through Facebook. At least buy me dinner first.