3 ms·
My issue with ActivityPub is that it is yet another overengineered specification by w3c that somehow despite being a bloated mess manages to miss important feat
by dependenttypes 6y ago
My issue with ActivityPub is that it is yet another overengineered specification by w3c that somehow despite being a bloated mess manages to miss important features (such as end-to-end encryption for DMs or end-to-end authentication, now you can have admins forging posts in the names of their users and/or reading their DMs, which is not that big of a threat for the average person when you are in a big semi-serious platform like twitter but it is when your admin is some random dude online). In addition it depends on stuff that are universally despised, such as JSON-LD, and it forces federation down your throat (you can't use it in a distributed way like bittorrent for example, your user is binded to the domain name of your instance).
- rapnie 6y agoI think you are off the mark and reposted an article explaining how the spec should be interpreted [0]. If the spec had added auth, authz, e2ee and such, then it had been overengineered. They were left out intentionally because of the complexity involved in decentralized environments. Something a bunch of other specs-in-the-making are struggling with for years. And things that may be adopted in vNext versions of AP. There is nothing as far as I know that precludes AP from being used in pure p2p applications, other than that p2p software in general knows more challenges than federated ones. And the spec is written such that any dev can treat the message format as plain JSON. They only need to add a fixed @context property, so it can be processed as JSON-LD by those who want to use the additional power that offers. [0] https://news.ycombinator.com/item?id=23857644 https://news.ycombinator.com/item?id=23857644