5 ms·
The threat model and economics of federated systems devolve to concentrating trust in the hands of a few, while missing out on the scale advantages of purely ce
by mquander 7y ago
The threat model and economics of federated systems devolve to concentrating trust in the hands of a few, while missing out on the scale advantages of purely centralized solutions.
Federation results in the data of users being subject to the whims of the owner of the federated instance.
Administrators can see correspondence and derive social graphs trivially. They are also in a position to selectively censor inter-instance communication.
I am totally happy with picking someone I actually trust to have those powers over me. The thing I don't like is when a random manager I don't know from Adam has those powers over me.
- vanderZwan 7y agoYeah, delegation is inevitable in social networks because it just cannot scale otherwise. Having some power over that delegation is better than almost none
- afiori 7y agoMoreover federated system have a well oiled forking mechanism. Corrupt instances can be left to wither without any major effect on the whole system.
- vanderZwan 7y agoI've seen this happen in reddit too - subreddits that get taken over by crazy powermods are abandoned in favor of one that is true to the original spirit of that sub. That's not a federated system, but it shows the power of communities that can easily fork
- beaconstudios 7y agoIs that inevitable though? A graph of independent but connected nodes could theoretically scale indefinitely in the case where I hold my data and you hold yours. If I want to add someone to my network, I can either get their direct address or navigate through friends-of-friends (graph traversal). The only necessary delegation would be a mailbox provider, but the contents of any messages could be encrypted. Not that any of this is easy to engineer, but in my mind it seems viable.
- rakoo 7y agoIt actually does exist already, in the form of Secure Scuttlebutt (https://en.wikipedia.org/wiki/Secure_Scuttlebutt https://en.wikipedia.org/wiki/Secure_Scuttlebutt). Friends connect directly to each other. When you want to get news about someone, you download from them directly, along with news from friends of friends. If both peers aren't connected at the same time it is possible to use pubs, which are kind of hubs accepting all content and distributing to whomever wants it. Pubs have no special functions apart from being a store-and-forward, so you're not associated to a pub in particular (you can be on multiple, or none at all) and no pub is more "important" than others. Nothing is lost when a pub closes. Cryptography makes sure that only the intended reader can read (unless it's a public message), and that messages can't be forged. The nice things is that it's all just a message passing infrastructure, and applications can and have been built on top of it, like a git repository system or a music sharing application. So, yeah, it is feasible.
- kixiQu 7y agoThe amount of data you have to store for even the network's current larval state does not to me suggest that †he current version is real practical to scale.
- rakoo 7y agoI don't know, people have been on it since the beginning and have only a few Gigs in their db, which is mostly non-text (pics, videos, audio, ...). You'd need to store them in any case. It's true that initial sync is way too slow but they're working on it.
- beaconstudios 7y agoneat, I didn't know Scuttlebutt worked that way!
- pythonaut_16 7y agoMaybe a place for a hybrid identity solution as well? Where you could be "user@mastodon.social" but also have a more numerical/cryptographic id (like a GUID or Pub/Private key pair). One to make it easy to find and connect as users, and the second to make it easier to move between instances.
- smitty1e 7y agoAny system is Checkov's Gun[1]. Even if Adam the Administrator is a boffo chap in Chapter 1, there is no telling what will occur in Chapters 2 or 3. [1]https://en.wikipedia.org/wiki/Chekhov's_gun https://en.wikipedia.org/wiki/Chekhov's_gun
- forgottenpass 7y agoIf you think about a very popular federated system called email, it's pretty easy to see why the local controlling body is not only fine but in some cases a very desirable property. And the "scale" argument for email centralization is obvious bunk for all properties of "scale" that aren't "some people can redefine what email is on a whim", but even without centralization google is still pulling that one off.