10 ms·
The Ecosystem Is Moving [video]
- deleted 7y ago[deleted]
- saurik 7y agoIn this video, Moxie Marlinspike--the developer of Signal, someone who has been consistently extremely negative on not just the idea of federated and decentralized systems but of open protocols and alternative clients for centralized systems (to the point where it shocks me he still does any development as open source, given how hard he pushes on the idea that people who fork his clients are actively doing something that harms the world by leaching resources from his organization for their own client, which I feel like misses the entire point of why people are doing those forks in the first place)--makes the argument that, because decentralization doesn't automatically and inherently solve hard problems merely due to the technology being decentralized, we should not waste time working on decentralized systems and instead work on and support centralized ones (one would imagine, particularly his). While he clearly understands it not only was but still is a very difficult problem to make a centralized service private (as he points out how much work has gone into making some basic aspects of Signal seem usably private), he doesn't want to admit the idea that someone could or should spend commensurate time also working on researching or improving decentralized systems :/. In the process, he ignores attempts to work on what I'd consider the primary problem (something someone thankfully poked him about during the Q&A, though I'd say not hard enough)--transport obfuscation--and thereby goes so far as to claim that decentralized systems are fundamentally less private (using an example involving peer-to-peer video/audio calls on Signal that they decided to instead route through their centralized servers) based on that assumption of non-private transports (as clearly we should all trust Moxie Marlinspike and the handful of people who work at Signal with our metadata over anyone else we might want to be able to choose to trust). As part of this, he spends a lot of time trying to argue that people don't actually have any useful control in a decentralized system anyway, which is, of course, extremely convenient given how he doesn't really acknowledge that the entire point of his thesis is that he and his centralized organization not only should but in fact must maintain all the control so that he can follow the moving ecosystem :/. Meanwhile, he cites federated systems of the past as clear and unmitigated failures, including specifically IP, a layer upon which he somehow manages to build Signal on top of despite being supposedly fundamentally and horribly flawed due to being a decentralized protocol frozen in time and nearly impossible to change (which isn't even true! IPv6 was insane for actively going out of its way to break transition paths, but as many people have pointed out it didn't have to be that way; and even within IPv4 we have seen a lot of manipulation and progress in the form of protocol extensions. many of his other examples are also clearly flawed if you know anything at all about the protocols involved). "Finally"--a word I use here both in terms of it being the most repetitively frustrating things about this talk (and so I list it last) but also as it came up again at the very end (thereby closing the video) due to a question from the audience poking him hard on this point (to great applause)--he continues his apologetic rhetoric for the idea that phone numbers are somehow better as an identifier than any other possible alternative--something that is so wrong on the face of it that we can point at ludicrously popular chat systems, such as Kik, that were largely popular because they did not use phone numbers at all, in addition to the vast majority of popular social networks that merely use phone numbers for account password recovery (and while many of them now require phone numbers to sign up, that is entirely unrelated to the service and how you use it, and was usually not the case when the service first came into existence: it was way more common to require an e-mail address than a phone number)--to the point of seriously claiming multiple times that ceding control of identity to the telecom infrastructure (something we know is horribly insecure even if you trusted all of the players, which I don't think anyone does) is one of the things that makes chat fundamentally better than e-mail (?!?). Really, the best line from the video came from someone in the audience asking a question, leading with: "thanks for the thought provoking talk... you said so many things I disagree with, it is tough to pick a question" :/. For me, that feeling goes well past just this talk and his positions on chat systems: his love for Intel SGX--a technology that has been broken multiple times and whose key feature, Remote Attestation, is just "DRM" by another name--puts him on what I would argue is "the wrong side" of the war over general purpose computing, wanting to rely on user-hostile hardware to protect decentralized cryptocurrencies (such as his MobileCoin) from attack by anyone... other than Intel, obviously, as they can be trusted?... or any governments that can lean on Intel, as maybe we like those governments?... or of course, anyone with a zero-day hardware side channel attack, as we can pretend all of those have been found? :/... essentially, in the end, most of his positions just seem like a way to shill for centralized government control over everything, with metadata being protected only by the security of the memory of his servers (something which was pointed out by yet another question from the audience, and for which he didn't really have a good answer) wherein the best case scenario is that laws like the DMCA end up being what protect us from attackers as opposed to actual math :/.
- rapsey 7y ago> essentially, in the end, most of his positions just seem like a way to shill for centralized government control over everything, No one ever asks who is funding him, Signal development and their running costs.
- x0x0 7y ago> because decentralization doesn't _automatically and inherently_ solve hard problems _merely due to the technology being decentralized_, we should not waste time working on decentralized systems and instead work on and support centralized ones (one would imagine, particularly his) That is an extraordinary mischaracterization of his talk. What he actually says is that decentralization makes many desirable characteristics -- enumerated at some length in this video -- more difficult. The implicit argument, then, is since we're struggling to achieve certain desirable characteristics even in centralized systems, we should focus our efforts there first.
- saurik 7y agoHe definitely states for each of his points that the people working on decentralized systems are misguided because decentralization doesn't automatically solve these hard problems; and while his thesis is what you state--that solving these problems is easier as a centralized system because you are more agile--other than a few awkward straw positions (many of which I addressed, and which aren't even really arguments but just anthropic assertions based on misstatements of history) he doesn't really have much to say on the idea that decentralization makes the problem harder. Hell: I'll admit he could have... I have myself given talks about issues with federated systems (vs. "truly distributed systems", which I think are very different than federated systems) and the pain of trying to deal with things like metadata privacy (something the people behind Matrix actually admit in some of their internal talks), but all of his positions here (with again, exceptions where he just ignores transport privacy or goes down rabbit holes of false tangents about phone numbers) really came down to a repetitive phrasing like "decentralized systems are not inherently encrypted, in fact most decentralized systems are not inherently encrypted by default; there's nothing about decentralization that makes things encrypted, you know?" (exact quote) that are later followed with a couple unrelated points and then a restatement of the (incorrectly argued) thesis that decentralized systems can't change and centralized systems are the only way to get new technology. It is like claiming "decentralized currencies don't automatically cause privacy or anonymity, and in fact the vast majority of cryptocurrencies provide more public records than your existing bank" while just flat out ignoring that things like Zcash not only could exist but in fact already exist.
- thekyle 7y agoSo in the beginning of the presentation Moxie brings up some valid cases where it's good that centralized services can rapidly iterate and improve such as WhatsApp being able to roll out end-to-end encryption with a single update, while email is still not encrypted despite the tools existing to do so for years. Basically centralized services can roll out changes quickly and decentralized ones are more or less set in stone. However, I feel that maybe he isn't considering the downsides of being able to change quickly. Sure WhatsApp was able to add end-to-end encryption with a single update, but they can just as easily remove encryption with another update. Additionally, while I will admit that it sucks that email is not encrypted, knowing how many people and businesses rely on email every day, it should be incredibly difficult to make changes to it. I don't want a single person or company to be able too suddenly decide to change how email works. One area where I am sympathetic towards Moxie and Signal is requiring phone numbers (mentioned at the end in the Q&A). Personally, I don't see it as being all that big of a deal and it does bring several advantages with it: * Users get to store/control their own social network in their phones address book * Users can switch easily between WhatsApp/Signal/etc. Although I agree that requiring phone numbers does reduce the privacy of Signal users, I think it is a worthwhile trade off for making the app usable by the public. Also, it seems like usernames might be supported in the future: https://signal.org/blog/secure-value-recovery/ https://signal.org/blog/secure-value-recovery/
- dijit 7y agoWhy not use something like an email address instead of a phone number though. A phone number can be used to track you in the real world, it’s worse than having someone’s IP in some cases. In fact some countries (Russia, at least) require you to give over Government issued ID when you get a new phone number. So it’s directly tied to your real persona, this is not just one country doing that either. I believe it is also a requirement in the UK now too. (They’re combating “burner” phones)
- BiteCode_dev 7y agoBecause of contact discovery and migration. The success of those apps is directly related to the fact you can instantly see all your contacts with it when it first start. Email wouldn't have the same effect because poeple don't have them saved in the contact list. I think university should have a mandatory course where IT student go and interact with real users and have a budget to manage according to the success of their exhange. It would make those questions much less likely.
- dpc_pw 7y agoGreat talk. It could be an Urbit ad since most if not all of the mentioned problems (and many more) are exact reasons it was designed the way it is. Stagnation of development is caused by fragmentation of platforms. For every app we need to develop the same app over and over and over, and then keep them in sync. That's why we need a precise, unified, and well designed OS/VM layer. Only then we can run and update the same app on many systems with ease. The reason why it takes so many engineers is the byzantine stack of layers we've developed over the years and platform fragmentation. Which compounds with the fact that every decentralized app has to develop the same set of things over and over. If only the OS/VM layer had it ... built in - like in Urbit. Censorship resistance problem described in the talk is not an issue if the ID is decoupled from the infrastructure. Something that I still don't understand why federated protocols don't get (I'm looking at you Mastodon). If you make them scarce and transferable it will additionally help fight the abuse. The list would go on, but it has all been described many times.
- cheschire 7y ago> That's why we need a precise, unified, and well designed OS/VM layer. Only then we can run and update the same app on many systems with ease. Is this not exactly why the web has become a platform for apps? And wouldn’t all of the issues inherent in the web also then apply to this OS you describe?
- dpc_pw 7y agoWeb is built for client-server architecture. And that's what we've got - bunch of big companies, storing all the data, and our thin clients downloading only the part we look at. Urbit is built for p2p architecture.
- Glosster 7y agoWhy is he saying that email is not encrypted? Isn't it actually encrypted when traveling from server to client? Who uses ports without SSL or TSL anymore?
- Ninn 7y agoHe is referencing end to end encryption. Google can see Your to/from/subject/metadata headers even if you bother to use gpg
- Glosster 7y agoThen that's a problem with us using a centralized system (Google) for emails, right? So email is not really decentralized.
- cyphar 7y agoReplace "Google" with "your email provider". Even if there were many diverse email providers with significant adoption, the problem would remain. Unless you're using PGP (and -- critically -- the other people know how to use it as well), then your email is stored as plaintext on your email provider's email server (and the email provider of anyone you send the email to, as well as any forwarding agents that passed the email along).
- ekianjo 7y agoNothing prevents you from not using Gmail.
- cyphar 7y agoIf any of the people you are communicating with are using an email provider that they don't personally host, then the problem is exactly the same. In fact, arguably a better comparison to E2EE is that they have to host an email server on each of their devices (which precisely zero people do).
- 7y ago
- bertman 7y agoThis talk is basically an elaboration of Moxie's blog post from 2016 with the same name [1]. See also a response to this blog post by Daniel Gultsch, developer of the popular Android XMPP app Conversations [2]. [1]https://signal.org/blog/the-ecosystem-is-moving/ https://signal.org/blog/the-ecosystem-is-moving/ [2]https://gultsch.de/objection.html https://gultsch.de/objection.html
- bertman 7y agoBackup link because the OP 404'ed: https://berlin-ak.ftp.media.ccc.de/congress/2019/h264-hd/36c3-11086-eng-The_ecosystem_is_moving.mp4 https://berlin-ak.ftp.media.ccc.de/congress/2019/h264-hd/36c...
- hncensorsnonpc 7y agoThe link gives me an error
- waldfee91 7y agoBackup on PeerTube: https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-674b1cb6b270 https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-...
- geuis 7y agoLink is dead now. 404
- waldfee91 7y agoBackup on PeerTube: https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-674b1cb6b270 https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-...
- mixedCase 7y agoThe irony of having to rely on a federated system to watch this video because the centralized one removed access to it is not lost on me.
- heyflyguy 7y agothe ecosystem is moving!
- seanieb 7y agoDoes anyone know why it was removed? It was removed from Youtube too.
- aorth 7y agoYeah I'm also wondering what happened... I was going to share the CCC page with friends, but the talk is missing from the 363C list (https://media.ccc.de/c/36c3 https://media.ccc.de/c/36c3). Feels weird sending around backup mirrors...
- waldfee91 7y agoBackup on PeerTube: https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-674b1cb6b270 https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-...
- sweden 7y agoEvery time I see Moxie talking about decentralization, I can't help to think that this is all a big disguised agenda used to promote his own business for selling the Signal technology to any messaging vendors (WhatsApp, Facebook, Google, etc.) He keeps bringing data privacy and data encryption as the sole motive for decentralization but that's not really the point. The main point is data ownership and freedom of usage. WhatsApp and Signal are good messaging services indeed but: - We are tied to their official clients. - Which means that we are tied to the platforms they support - We are also required to have Google Play services installed on our Android phones - We are tied to phone numbers - And if (for whatever reason) we trip on their abuse detection services, we might get banned and completely prevented of using their own service (mistakes on their side can happen as we have been seeing with Google) The point of decentralization is to avoid all these annoying constraints. Encryption and privacy are a bonus, not the selling point. Also, all of his points about centralization are completely refuted by the efforts of the Matrix project.
- pa7ch 7y agoThere are trade-offs in user experience between a centrally controlled effort and something like Matrix. If you've listened to him talk many times before, it seems almost disingenuous that you'd believe he hasn't made this choice because mass-adoption and user experience are the first priority of his design constraints. It doesn't mean your criticisms aren't valid wants in a messenger but there is a logical and publicly explained motivation to why Signal is the way it is. One piece of good news is that being tied to phone numbers is a problem Signal appears to be solving in the near future. [1] [1] https://signal.org/blog/secure-value-recovery/ https://signal.org/blog/secure-value-recovery/
- mirimir 7y ago> ... mass-adoption and user experience are the first priority of his design constraints. But then you force users into a risk model where third parties (such as Google or Apple) may know everything, and users must trust them.
- 7y ago
- vanitasvitae 7y agoIts funny how he mentions domain fronting as a technique to counteract censorship, and even uses Google as an example, while in fact Google (and also AWS) banned them from doing domain fronting a long time ago... https://signal.org/blog/looking-back-on-the-front/ https://signal.org/blog/looking-back-on-the-front/
- inputmice 7y agoThe irony of a talk that speaks out against decentralized systems being only available on decentralized backups of the centralized original…