51 ms·
Ask HN: You have one shot to redesign the Internet – what do you change?
This was just an idle conversation we were having at work. Imagine that one day you wake up and you've been sent back in time, where you are now a researcher at DARPA in the early 1960s. You've got the influence to effect fundamental changes in the next sixty years of the Internet's history, and can make your changes any time in the next sixty years - but you know that as soon as you change one thing in history, you'll be sent back to 2021, to continue living in the world you have wrought.
How are you going to make the Internet better?
- DLA 5y ago3 things: Security, Security and Security. BGP security, DNSSEC, TLS by default, etc.
- abecedarius 5y agoThe most basic problems seem to be: 1. Everything being 'free' by default drives us to ad-supported centralized services. Economics aren't a separable concern. 2. Too few IP addresses. (At least one of the pioneers, I forget which, said he pushed for longer addresses but was overruled. So the technical constraints probably did not force this.) I'm not sure how to fix #1, but here's an approach from the 90s: https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.16.9665 https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.16....
- aspyct 5y agoIPv4 adresses fit in a standard 4byte integer, that might be a reason. Quite frankly, if they didn't allocate full /24 to single entities (including localhost...), we might still have enough addresses left.
- jhgorrell 5y agoIsnt it "127.0.0.1/8" which is allocated, not "127.0.0.1/24"?
- deckard1 5y agoyes, according to wikipedia[1] IPv4 is just inefficiently allocated in general. Why does the world need 10.0.0.0/8 in addition to 192.168.0.0/16? Isn't 65k addresses enough? Is there a private organization in need of 16 million addresses? Not to mention AMPRNet (amateur radio) owned the entire 44.0.0.0/8 up until 2019 (a portion was sold off to Amazon). That may have seemed reasonable in 1980 but now it's just plain crazy. [1] https://en.wikipedia.org/wiki/Reserved_IP_addresses https://en.wikipedia.org/wiki/Reserved_IP_addresses
- profmonocle 5y ago> Is there a private organization in need of 16 million addresses? Plenty of mobile phone networks have well over 16 million subscribers, and they typically don't have enough public IPv4 addresses for everyone. This has led to really hacky stuff, like using DOD IP ranges as psuedo-private space, or re-using private IP addresses in different regions (which can't be fun to maintain.) Some networks have fixed the problem by using NAT64 - forgoing IPv4 altogether internally, and translating to public v4 at the edge. (Works surprisingly well, T-Mobile US has been doing it for the better part of a decade.)
- asymptosis 5y agoIt's not about number of addresses available, it's about reflection of organization hierarchy in the octets. The 10.0.0.0/8 range is useful for breaking a distributed company's network up so each major office gets a 10.x.0.0/16, and each department a 10.x.y.0/24. This is why 192.168.0.0/16 is often used for services like libvirtd, kubernetes and docker. And the use of the range by those services makes it even more unwieldy to try and put some other LAN in there. You can work around these considerations if you want, but many people won't. When you're the network engineer responsible for designing a company's networks, you'll be wanting to keep things simple and robust. When you're called in at 3am on a Sunday because the network is down, you better hope your ability to recover doesn't require making a bunch of subnet calculations because you decided to try and use the pool of available IP addresses efficiently.
- nonameiguess 5y agoI think this is a problem with the World Wide Web, not the Internet. At the network level, per-user cost accounting and quality of service is implemented quite well, to the point of being able to pay per byte if you really want to. And access to any network beyond your own LAN is not free. The problem of how to fund actual web application development is not much different from the problem of how to fund media development in general. Newspapers, television, and magazines alike long ago settled on some mix of premium-tier subscription services augmenting a more open, ad-funded free tier. This is so much more of an issue today than 30 years ago not because of anything specifically about ads to fund media, but because ad profitably has been driven sky-high by individual consumer profiling that relies upon privacy invasion and surveillance of your customers. Ads back in the day would improve via voluntary focus groups and that was fine. Today, they improve by tracking every digital action a person ever takes in order to more accurately correlate interacting with an ad with making a future purchase. Volunteers for focus groups are pretty much okay with giving their opinions in return for cash. Every person on the planet is not nearly as okay with having every digital action they ever take recorded and analyzed.
- abecedarius 5y agoIn the alternate history I'm imagining, with network-layer accounting and payments from the beginning, flooding and spam were never much of a problem -- they were at most a "nice problem to have". Endpoint security became a priority from the beginning, because failures that cost money (even if not much per computer) get treated that way. Participating in the network as a full peer, e.g. running the equivalent of a webserver on your home PC, was considerably more practical and normalized. (The bigger address space of course went into this too.) And this history made other peer-to-peer software easier to develop and more practical and economically sustainable, in a virtuous cycle. This doesn't mean it'd kill advertising. It wouldn't even kill all of the forces encouraging me to put my 'content' on centralized services even though I'm nothing like a media corp. But I suspect the right changes could've helped a lot towards a healthier computational ecosystem now. This early architectural decision that costs are out of band didn't fundamentally make anything impossible. But when you see a lower-level problem addressed by higher-level workarounds, and you're getting to redesign the system, isn't that exactly what constitutes an opportunity?
- ryeguy_24 5y agoI might have read somewhere that the original design of HTTP allowed for transactions to occur. This free point is a big one. Once Apple set the price of 0.99 for an app it really dropped the market price for software. It's funny that there is so little different between enterprise software and consumer apps except for a monstrous difference in price point. Funny thing is, consumer apps are sometimes better.
- mprovost 5y agoThe 402 HTTP status code is "Payment Required". At one time people envisioned micropayments etc but it never went anywhere.
- mjevans 5y agoTransaction fees are what kill this. That and moral police / "fraud" charge-backs caused by insufficient user authentication. I also don't want to be nickle and dimed to death, given the transaction fees there's a huge push to subscriptions and other models. Where if I could instead just pay exactly what a generic ad I'd _never_ click on anyway pays to get placed (like 0.00001 dollars for all the ads on a webpage stuffed with them) I might actually pay instead of using adblock for all of the security, usability, and bandwidth saving reasons.
- dublin 5y agoThere have been many micropayments schemes over the years. IIRC, there was a decent one slightly cleverly called "Millicent" developed by DEC and pushed in the early Internet days... (Then there were the various pre-bitcoin internet banks/e-cash outfits - First Virtual, eGold, etc....)
- vb6sp6 5y ago> 1. Everything being 'free' by default drives us to ad-supported centralized services. Economics aren't a separable concern. I hate this argument. I've been online for a long time and the internet existed just fine without, for example, facebook. We don't have to accept ads but we do have to be willing to not use certain things out there.
- effie 5y agoIndeed, on the surface the argument is sound, but when you look back into past, it's clear it is not how things have to work. Web can exist even without pervasive surveillance. It would be different, no huge ad companies growing like cancer, but that would probably be good for information quality/communication freedom on the web.
- nocturnal_pt 5y agoBlockchains right now mostly are trying to do exactly this - bring economics into computation and network space. This is of course a higher level solution, but the one that is quite achievable now. Protocols like NEAR and Internet Computer can be good examples of this. I know this is a holywar topic and many would disagree simply by seeing `blockchain` word used here. But to my mind this exactly the place where this technology is beneficial. We need automated algorithm controlled currency to have this type of smart internet subscription.
- abecedarius 5y agoYes, I only left this out because it was over the horizon at the time. I did find these papers inspiring in the 90s, and as with the Digital Silk Road paper I linked above, the ideas could have been thought of earlier (e.g. capability security goes back to the 60s): http://www.erights.org/talks/agoric/index.html http://www.erights.org/talks/agoric/index.html
- ArtWomb 5y agoThis is a really great question! I can't help but think that for some small multiple of the cost of the International Space Station or Large Hadron Collider or any other large government science experiment, the nations of the earth could have gotten together early on and funded a free satellite internet project. It would have been limited bandwidth, high latency and error-ridden but it would have been ubiquitous in coverage, much like the GPS system. And would have accelerated adoption of many of the digital cash and e-banking innovations we are seeing today. As well as gotten a jump start on the physical layer of space based internet ;)
- mikewarot 5y agoI think it's too soon, but security security security. I'm push as many examples of capability based security into the academic world as I possibly could, in the 1970s. Alternatively, push a version of Pascal with a standard library, and drown the insane practice of ending strings with a null instead of knowing their lengths.
- lurker137 5y agoI don’t know how it would be implemented but I always thought it would have been better if there was more meaningful separation of domains, and that you need a different browser to connect to a different domain. That way the net could be divided. There could be a domain for only verified information. A domain for public use. A domain for only educational content, etc. I have no idea how it would be moderated though
- jeroenhd 5y agoSuch a categorisation already existsed in the form of the original top-level domain names, but it was never enforced. .gov for government, .mil for military, .com for commercial, .edu for educational facilities, etc. For good reason, though. Who says what information is "verified", the government, the news media, the publishers? And what governments, media, and publishers get a say? Perhaps it'd be nice for browsers to show a little indicator to confirm that a website is hosted by a government (although .gov and .mil are only valid for American governments, government could use a given domain as their government basis). There's a big difference between what's right ("climate change is real") and what the government is saying ("who knows, maybe drinking bleach is a good idea?"). Dividing the net goes straight against the idea of the internet. I don't think using a special browser for special domains is very tempting. We'd probably end up with the alt-net version of onion.to to proxy all different kinds of sites to a single application.
- deleted 5y ago[deleted]
- bruce343434 5y agoYou're conflating authenticity with authority. It would be nice to quickly and reliably tell whether something is a government source, or a educational institution, or what have you. Whether the information is then correct, that's another matter.
- renewiltord 5y agoOh, something minor. I’d make both domains and paths go from least significant to most significant, so com.google.mail/u/0/html
- dijit 5y agoI didn’t realise how much I wanted this until now.
- nickt 5y agoJANET in the UK did this until it adopted the internet standards in the 1990’s. Always seemed more logical to me too. https://en.m.wikipedia.org/wiki/JANET_NRS https://en.m.wikipedia.org/wiki/JANET_NRS
- TheSpiciestDev 5y agoOne of my only two attempts of an Ask HN was this specifically [0] and I've wondered this still. With subdomains, top level domains being at the top and being able to drill down into subdomains and then folders feels a lot more intuitive. Could a browser add-on be made to experiment this? [0] https://news.ycombinator.com/item?id=24438978 https://news.ycombinator.com/item?id=24438978
- aliasEli 5y agoSecurity should have been been a top priority right from the start. It is very strange that ARPA, a DOD agency that sponsored most of the Internet technology, cared so little about security.
- eqvinox 5y agoA gun doesn't have built-in security either. But there's generally people with guns standing in front of the armory. I'd say they probably expected people with guns standing in front of the computers too.
- philipswood 5y agoRequire emails to be signed by the sender cryptographically.
- dijit 5y agoWe have DKIM and you can safely drop non-DKIM mail. This tells you the MTA is actually sending the mail. The problem is that these MTAs get hacked or people just hijack domains. Heck, the barrier to buying a domain is so low that this is a legit way of spamming too.
- dane-pgp 5y ago> the barrier to buying a domain is so low This suggests that one way of making spam unprofitable would be to require any domain which sends email to put up a bond of $100 which is forfeited if any of the big four email providers decide that the domain is sending spam. To make this acceptable to public opinion, the forfeited bonds would to go directly to popular charities, and all existing domains would be automatically grandfathered in, so there would be no extra cost for any current business or user.
- pteraspidomorph 5y ago> safely drop non-DKIM mail Yes, but the customer will blame you when e-mail from a misconfigured MTA doesn't arrive (from my experience running one). If only we'd had DKIM from the start, preventing thousands of broken servers from being set up in the last twenty five years...
- jart 5y agoIt's the 1960's. There's no RSA or AES or even DES.
- wantsanagent 5y agoSure but it's a small community that hung out in person a lot. Tokens, pass phrases or one-time-pads could have been physically swapped. There's really just a difference in thinking, "private by default for email" vs "public by default." Or "untrusted network" vs "trusted network." However you want to think about it.
- geocrasher 5y agoI'd advocate to build DARPANET for an untrusted environment with the expectation that DARPANET would be unleashed on the masses at some later point.
- polygotdomain 5y agoThis. I think there are so many changes that I'd like to make, but a lot of them stem from switching from everything being public and out there to being private and with restricted access. I would only hope that assuming things would be untrusted from the beginning would lead to a more securely designed web from day one. I'm sure that's wishful thinking, but still.
- giantg2 5y agoBetter child protections. Not sure what the implementation would be though.
- noobquestion81 5y agoIt's not entirely fair, because in the 60s basically all modern crypto primitives were missing. If I had those: 1. Encrypted onion routing on layers that betray source/dest IP. 2. eSNI on all TLS connections. 3. Privacy-focused DNS.
- an_opabinia 5y agoThe most toxic part of the Internet today is identity. Some of the IP address space should have worked like mobile phone numbers - paid for by subscribers and representing single identities. Even better, after the invention of RSA, the government should have backed ISPs or states issuing signing identities for a protocol level identity standard - sort of like SIM cards that would “represent” you on a single, authoritative device without the possibility of delegation.
- NewNetNow 5y agoMy guess is that most people who use the internet by 2050 will be strongly authenticated, whereas the current anonymous internet will remain as a relic of barbaric times for most, but still in use.
- handrous 5y agoI expect we'll have one or more protocols enforcing end-to-end route verification at the packet level on most Internet routers by 2050, so I'm not sure how anonymous any Internet served over that infrastructure will be. I expect bans will be much more effective, international traffic will have much more advanced filtering and blocking, and that proxying will basically be illegal without some kind of business arrangement and being subject to surveillance & ban-supporting laws (and anyway, proxying weird traffic will get you banninated by the entire "legitimate" Internet, much faster than it does now).
- dane-pgp 5y agoI'd go so far to say that by 2030, at least one OECD country will have a law requiring ISPs to enforce remote-attestation of the Secure Boot of every device accessing the internet. Such a government could then require app stores to remove "dangerous" technologies like Tor and messaging apps that support end-to-end encryption. Perhaps ISPs would be allowed to support "legacy" devices and OSes, but with a special "Evil Bit" set on packets, so that websites could (and in some cases would be required to) refuse access.
- 5y ago
- YossarianFrPrez 5y agoWhat a great question. One of two things: A) Establish the expectation that websites "close" in the middle of the night for ~5-6 hours, local time / for each timezone. I don't know if would best be done via cultural influence -- giving talks, writing essays, personal communication, testifying / making inroads with politicians -- or via creating some sort of protocol. The idea is to prevent the unhealthier aspects of internet binging and screen addiction. B) Establish the expectation that internet comments are transcriptions of voice recordings. I.e. to leave a comment, you have to call a phone number and leave a message which then gets transcribed as "the comment." In order to respond or reply to a post or a thread, you have to listen to the message and tone of voice of the person you are replying to. I don't think this would solve every internet dialogue, but it'd promote healthier interactions and less division. In my book, the largest problems with the internet are techno-cultural, not technological.
- dentemple 5y agoRegarding A, for which timezones? Any attempt to narrow browsing time would ultimately fail as soon as the web goes global.
- YossarianFrPrez 5y agoGood question. Ideally, each user's timezone would be required information. The server would check to see if the requesting user's local time meant that the website should be "open" for them.
- bruce343434 5y agoA minute of silence for those with unusual circadian rythms.
- bmcooley 5y agoHonestly this would probably just make VPN services more widely used to workaround shutdowns.
- deleted 5y ago[deleted]
- thrower123 5y agoBrendan Eich gets to actually use Scheme for Netscape. It never takes off, because everyone hates Lisps, instead VBScript becomes standardized through IE, which is then phased out in favor of a C#-based script in the early 2000s, and we have a massively better web development enviroment.
- petermcneeley 5y agoAdam Curtis provides some historical context on what went wrong with the internet https://thoughtmaybe.com/all-watched-over-by-machines-of-loving-grace/ https://thoughtmaybe.com/all-watched-over-by-machines-of-lov...
- jedberg 5y agoTL;DR: Constants shouldn't be hard coded in the software, they should always be in a separate config The problem is that it's the 60s. My first thought was "security", but unless you an also teach them about elliptic curves, they're going to use the security of the 1960s, which as we now know isn't very secure. Maybe at least having security baked in would help make it easier to switch to better security later, like how ssh can use different protocols as old ones are broken. But you'd have to make sure that you were very clever about how it was implemented so that it could be switched without major changes. Another thought is "more IP addresses", but again you are in the 60s. The computers don't have enough memory to deal with IPv6 length addresses. So again the best you can do is try to set them up with easy upgrades. Which makes me think the best suggestion would be to teach them about Moore's Law, which of course would have a different name, and try to push for every protocol being extensible as technology grows -- make sure that more octets can be added to IP addresses without them breaking, that security is baked into everything but everything has a way of negating a protocol so that they can be upgraded, that there are no hard upper limits that are assumed and can always be changed. Basically, teach them what we now know are software best practices -- constants shouldn't be hard coded in the software, they should always be in a separate config.
- bruce343434 5y agoI really don't understand what stopped ipv4 from being extended like this: w.x.y.z == 0.0.0.0.w.x.y.z In fact, you can even ping any 32 bit unsigned integer and it will turn it into an ipv4. Try it: `ping 134744072` will ping `8.8.8.8` So why not 64 bit? 32 bits fit in 64. Instead we now have 2 concurrent protocols. ps. 8*256^3 + 8*256^2 + 8*256 + 8 = 134744072
- jedberg 5y agoBecause all the existing routers would break on all the new addresses. A new protocol was created specifically so that legacy equipment would never get the request. For example, if an old router got a packet for 1.2.3.4.5.6.7.8, where would it send it, if it didn't crash just trying to read that address?
- _huayra_ 5y agoHonestly most of it is pretty great. Folks who want to give it better, more reliable performance end up reinventing circuit switching, and anything involving security is difficult to solve at the IP layer. The last big things to secure are DNS (can be done with DNSSEC), and possibly somehow mandate TLS for connections (although you definitely don't want that all the time). One big glaring problem is BGP, which we don't really have an answer for. Whereas "just use DNSSEC" pretty much solve the last big security hole above, BGP is still difficult because you have to basically have a system to attest the path for each BGP node. AS1 can't say "I have a path of length 5 through AS2 AS3 AS4 AS5 AS6 to AS6" unless that message can be attested to by each node, but then this comes into a bootstrapping problem (e.g. how do you reach those ASes to get some sort of key without going through AS2 first?) or trusting some authority as we do for ssl certs. God knows the first thing I do on any fresh install is uninstall those root certs from any sketchy government I don't trust. Having worked on SDN in its heyday for some of the big players in the space, there are definitely good ideas in the space, but getting to adoption is damn difficult, bordering on impossible. I don't know what it will take to oust BGP, so we're kinda stuck with it for the foreseeable future.
- iptrans 5y agoThere are only about 100k ASNs. It would be fairly easy to solve the bootstrapping problem by just preloading all the keys.
- _huayra_ 5y agoYes that isn't too many, but right now any device can just hop on a network and start communicating (after DHCP). Not only that, but they can start communicating with any public IP address. If people decided to take this away by adding some security directly into the IP layer (i.e. such that communicating without it is impossible, such as mandatory IPsec), I don't think the tradeoff would be worth it. Now you would have to manage all the normal stuff that comes with keys (e.g. expiration and renewal), and you may find your device gets wedged if you don't do the delicate key expiry dance correctly (i.e. you can't even connect to the site to get updated keys). It's very easy to say "those DARPA morons not designing security was a big mistake!", but I am not convinced that the tradeoffs of solving it at the internet level (i.e. L4 and down) are worth the bootstrapping / flexibility hits.
- uncomputation 5y agoPush for content-addressing over URLs. To be honest, I don’t know if this would hamper the development of the internet or be a good thing at all, but I would love to see what people would come up with and how it would change the web.
- rektide 5y agoThe Web Packaging specifications[1] are surprisingly close to turning URLs into a content-addressed system. Content-addressed networking is all about names for content, after all, which philosophically is a close match for what a URL is, it just so happens that HTTP uses urls to resolve servers that serve the content. But with Web Package, content is signed by the origin, and can be distributed via other means. One of the primary uses cases for Web Package is to let two users exchange content while offline, perhaps via a usb stick or what not. This isn't part of the specification, but we could begin to imagine sites that have a list of the web packages they have available for download. And we could imagine aggregating those content indexes, and preferring to download from these mirrors over downloads from the origin's servers. I'm hoping eventually we get a fairly content-addressed network, via urls. [1] https://github.com/WICG/webpackage https://github.com/WICG/webpackage
- seltzered_ 5y agobacklinks. (see http://www.youtube.com/watch?v=bpdDtK5bVKk&feature=youtu.be&t=15m45s http://www.youtube.com/watch?v=bpdDtK5bVKk&feature=youtu.be&... by Jaron Lanier, also see Ted Nelson)
- seltzered_ 5y agoGoing a bit more philosophical, I found myself thinking about the lack of backlinks and people like René Descartes (via https://en.wikipedia.org/wiki/René_Descartes https://en.wikipedia.org/wiki/René_Descartes) : " Refusing to accept the authority of previous philosophers, Descartes frequently set his views apart from the philosophers who preceded him. In the opening section of the Passions of the Soul, an early modern treatise on emotions, Descartes goes so far as to assert that he will write on this topic "as if no one had written on these matters before." "
- awill 5y agoreplace https:// https:// with https: (I believe that was TBL's biggest regret too) :).
- grillvogel 5y agoCancel the project, Terminator 2 style
- dbingham 5y agoFind a way to better decentralize it, so that it doesn't rely on single hosts(and later sites) as the source of truth for any particular function. The original idea was that protocols would allow any one to participate by simply making their own webpage. But dynamic IP addresses, the DNS system, and even just HTML design were out of reach for most people so that got lost and monsterous websites under centralized control became the mediators for most people. So if we could find a way to bake that decentralization into the protocols even more strongly while making them accessible to non-technical people, that's the change I would make. The aim is to create a world where central platforms are not dominant, but any user can easily participate in the communication protocols with out there being a central point to collect all the data or force changes from. ...of course, I have no idea how one would go about doing that, and there in lies the rub.
- Jtsummers 5y agoYou seem to be talking about WWW and not the Internet. The Internet itself was designed to be decentralized, in fact that was a major motivator (distributed command & control in the case of a major war cutting off large chunks of the C&C groups from each other or eliminating them entirely). Now, it could've been done in a better fashion, more deliberately, or more broadly, but there are at least two notable early protocols with decentralization/distribution in mind: email (consisting of several protocols) and nntp. Now an individual may still access a, to them, centralized authority for sending/receiving content, but the protocols themselves were meant to support a distributed architecture.
- dbingham 5y agoWhile yes, "the internet" and "www" are different systems, the latter built on top of the former, in practice "the internet" and "www" are one in the same. When we're talking - culturally - about problems with the internet, we mean the problems with "www".
- Jtsummers 5y agoIn practice they are not the same thing. And the original prompt poses sending you back to the 1960s, about 30 years before the WWW came into existence.
- diminish 5y agoi would remove javascript.
- pteraspidomorph 5y agoI think there would always be something invented to take its place. It addresses a real need that lots of people have. If you want to remove it, you have to replace it with something else...
- thrill 5y agoEliminate comments.
- nasalgoat 5y agoZero trust as a factor of the protocol itself.
- sa1 5y agoDecouple IP addresses from locations, to make it harder to balkanize the internet.
- joemaller1 5y agoThe internet actually works really well. Its problems are human.
- pteraspidomorph 5y agoI mean, kind of. It does work, but under the hood there's a big fossilized mess of a technology stack that could have been better had it not been the result of many years of accumulated unrelated solutions to different, smaller problems...
- shutdownhn 5y agoEasy, I'd shut down this website.
- uniqueuid 5y agoThere is only one protocol, for file transfer. Consequences: * There is no live user tracking. * Access control can be user/password or ssh keys * You always have an archive of what you read * You always have an archive of chats * Everything is in principle decentralized (whether it is in practice depends on whether people keep files. * Clients are in control.
- underseacables 5y agoI remove most centralized control so that private companies have no power to censure, but governments could if they chose. I think private companies have vastly too much power over the internet, something that is unlikely to change.
- rouanza 5y agoI want to be able to run a lan cable from the street and basicly join the worlds largest LAN. Free open access
- K33P4D 5y agoSearch for URL, should be hardcoded into a new standard| Every PERSONAL IDENTITY/WEB URL should exist as its own resource cluster on the hosting server, either as a microservice on a distributed kuberenetes and provide API's to query information | NEWS and ELECTIONS should be blockchain | Blood donation/organs should be on global blockchain | A new Data standard for open health analytics | Pollution, toxic levels of chemicals from known pollution control boards of every country, based on location should be on blockchain.
- alfanick 5y agoSymmetric connections for everyone, everywhere by default (assymetric only when it's not feasible, i.e. mobile devices). This I always thought would open door for more peer-to-peer or onion or some superdecentralized architectures.
- mikewarot 5y agoIt was pretty much always symmetric connections at the beginning. It's only the economics of ISPs that changed it.
- swiley 5y agoWe already have IPv6. The only things broken on the internet are smartphones and closed IoT firmware.
- bob1029 5y ago>We already have IPv6 I feel like starting with IPv6 would make a dramatic difference in adoption rates today... I.e. IPv4 never gets created. Imagine a world without a single NAT device or port translation algorithm.
- HWR_14 5y agoWhy am I the only one who likes all my devices in my house having one IP address. It's no one's business if I have 10 computers in here or 1.
- breck 5y ago2-D syntax everywhere. It's a 2-dimensional binary. Suddenly the intermediate layers between binary and the higher level langs we work with day in and day out have the same form. For example, 2d langs for HTML, CSS, JSON, others: https://jtree.treenotation.org/designer/ https://jtree.treenotation.org/designer/ A 2D lang that replaces Markdown: http://scroll.pub/ http://scroll.pub/ You can have 2D langs for TCP/IP, DNS, HTTP, et cetera. A grid is all you need. I figured the math out 8 years ago, https://medium.com/space-net https://medium.com/space-net, and slowly getting there. Still in early days, but good annual growth rate. I'd be surprised if it doesn't happen. The math makes too much sense.
- dmos62 5y agoI don't follow. Can you elaborate? What is 2-D syntax?
- breck 5y ago1D syntax assumes a linear pass from beginning to end across the bytes of a program to build the AST. You have concepts like brackets and parens and quotation marks and colons. 2D languages have none of those. They imagine all programs as laid out on a grid. Think of a spreadsheet. For trees, you use indentation. There is not a single computer language in all the world that cannot have it's semantics represented with just that 2D syntax. This realization has long fascinated me. It knocks me off my feet, the same way I feel about binary notation. Here is a talk I gave in 2017 about 1D vs higher D languages: https://www.youtube.com/watch?v=ldVtDlbOUMA https://www.youtube.com/watch?v=ldVtDlbOUMA Here is a video that makes the connection between programming languages and spreadsheets clearer: https://www.youtube.com/watch?v=0l2QWH-iV3k https://www.youtube.com/watch?v=0l2QWH-iV3k
- neolog 5y agoAre you related to https://www.tree-annotation.org/ https://www.tree-annotation.org/ ?
- 5y ago
- PostThisTooFast 5y agoGet rid of limited TLDs, making any combination of something.somethingelse a registerable domain.
- seph-reed 5y agoSeparate data and views. Basically: servers focus on serving their data, and then it's up to the user to figure out which "renderer" they want to use to display it. Ofc defaults would be provided. But, say, you wanted to view tweets in a table form: no problem. Or maybe, you want to have a really wacky "whip the llamas ass" UI for podcasts: go for it. ----- The big benefit of this is that it would allow for artistry in websites, rather than the boring old blue, black, white, grey material design.
- peter_d_sherman 5y ago>"This was just an idle conversation we were having at work. Imagine that one day you wake up and you've been sent back in time, where you are now a researcher at DARPA in the early 1960s. You've got the influence to effect fundamental changes in the next sixty years of the Internet's history, and can make your changes any time in the next sixty years - but you know that as soon as you change one thing in history, you'll be sent back to 2021, to continue living in the world you have wrought. How are you going to make the Internet better?" You leave it the hell alone! <g> You leave it the hell alone -- because if you don't, upon returning to 2021, you'll discover that in addition to your wanted change -- there will be all kinds of unwanted "butterfly effects" in the world, resulting from that change, and not limited to the Internet, either! <g> Like, propagating in and through actual reality -- not just constrained to a computer screen or virtual world! Unwanted/unforseen/unexpected (but mostly unwanted!) "butterfly effects" (imagine just how scary these could be if you were unprepared for them -- the scariest Stephen King novel wouldn't do them justice!) resulting from Chaos Theory (which programmers know to be actual fact -- make a small change early on in a program -- get vastly differing results later on, as the program moves through TIME...) So if it one day happens that you magically appear (through time travel, or other plot element) at DARPA in the 1960's -- then you take a quick look, like Clark Griswold in "National Lampoon's Vacation", when he takes a brief look at the Grand Canyon (all of a few seconds!), and you appreciate all that DARPA and all of the other earlier Internet researchers did -- and you leave all of it the hell alone! <g> Yup, sorry, nothing to see here, nothing to change here, no changes for me! Just passing by, not going to touch a single thing! <g> You also appreciate the fact that while today's reality is a mess in many ways (and it is!) -- it could also (with Time Travel/Butterfly Effects/Chaos Theory) -- have been a much, much bigger mess(!) -- with Butterfly Effect horrors beyond your wildest understandings! <g> https://en.wikipedia.org/wiki/The_Butterfly_Effect https://en.wikipedia.org/wiki/The_Butterfly_Effect https://en.wikipedia.org/wiki/Butterfly_effect https://en.wikipedia.org/wiki/Butterfly_effect Disclaimer: The above was written for thought-provoking and possibly (depending on the reader's viewpoint!) comedy purposes only! <g> (Though it also works if read from a serious viewpoint...)
- onion2k 5y agoI'd make payments a prominent, application-native, easy to use feature from Day 1, right down in the network protocol level. 100% of the transaction would be transferred from the user to the service owner without a middle-man service taking a cut (payment gateway fees not withstanding). That way there wouldn't be any need to rely on advertising, app stores, or external subscriptions to run something on the internet.
- tpmx 5y agoObservation: That's how https://en.wikipedia.org/wiki/Minitel https://en.wikipedia.org/wiki/Minitel flourished and then stagnated and ultimately died when facing competition from the more "free" Internet. (Still upvoted you.)
- onion2k 5y agoToday I learned. That sounds like a good system. It's a shame it didn't lead to a more payments-oriented internet.
- asciimov 5y agoThat would have just made the internet in accessible to the poor. I remember my dad scraping enough money to buy us a computer in '97 with unlimited internet (aol was still selling the internet by the minute back then). As a kid who hardly ever had enough money to buy a comic let alone magazine, and who's local library was lacking, it was life changing being able to just lookup and read about anything for free.
- onion2k 5y agoThe price of giving free access to everyone has been very high though. We continue to pay with our eroded privacy, personal information that's frequently breached, the cost of advertising that's passed on through product pricing, the cost of giving up so much control of the internet to three or four giant companies, the sheer cost of fighting against advertising in our browsers and so on. We're practically held hostage by advertising - a downturn in ad spending leads to content and publishing companies closing down. The cost of free is strangely expensive. Maybe it would be better to fund more useful things, like sites that give children access to knowledge through direct contributions. Like how Wikipedia is funded.
- phkahler 5y agoVerifiable identity. We need to be able to verify the source of all data on the network, even if that's just proving the source IP address, or better yet the physical location it came from. People often argue that anonymity by default is a good thing, but I argue that trust of origin by default is better. You can still strip identification for things like posting in public forums, but for everything else knowing where shit came from is critical. From spam email to well everything. It baffles me that spoofing callerID is not only possible but that some people think its important. Along these lines I have a pet idea that a subset of IPv6 be geo-located, meaning your latitude, longitude, and possibly altitude are encoded in the IP address. This allows routing without the huge tables in the routers. Combined with the ability to verify that a packet came from its advertised location this is very powerful for security. One way to verify the origin of data (email for example) is not to send it, but to send something akin to a URL (preferably better than that) so we have to at least be able to request the data from somewhere rather than have it sent to us anonymously. Unfortunately being able to verify the source of data also enables end-to-end encryption fairly easily and nobody in power wants the public to anything like that...
- fragmede 5y agoFacebook verifies identities, yet it's still a cesspool of hate in some corners, so it might help, but it's no panacea.
- president 5y agoIt could help cut down on bots and spam. Think of a Twitter free from bots and propaganda from marketing agencies and governments.
- rpmisms 5y agoNot necessarily as an enforced standard, but normalizing sharing your identity online earlier on might have changed some of the formational culture of the Internet. The Internet was also a dangerous place, and still is, so perhaps this is not the best idea
- president 5y ago
- muxxa 5y agoDecentralisation in that you'd preferentially download 'web' content via your friends. Every house has an always-on server and networking hardware to enable selected local connections (long range WiFi?) across town with no reliance on an ISP. Think Wikipedia content living in tens of millions of locations around the world, with updates being pushed out with versioning and flagging if your extended network lacks consensus on a change.
- d--b 5y agoHonestly I think it couldn’t have gone a lot better... The worst that happened to the internet is Google becoming evil. The internet circa 2000 was mind blowing.
- paulcole 5y agoJust curious, how old were you circa 2000?
- harel 5y agoIt was mind blowing indeed. It was such an adventure building stuff on the web back then. We didn't have the choice we have today. I don't think Google became "evil". It just realised (or remembered) it's a business.
- ant6n 5y ago> It just realised (or remembered) it's a business. Exactly, it became evil!
- tunesmith 5y agoDoes this include laws about the internet? Because I think if the Computer Fraud and Abuse Act were altered somehow sufficiently that aaronsw hadn't been arrested, I'd prefer that future.
- mhh__ 5y agoI can't immediately see a law in which he wouldn't have been arrested, that seems more like a matter of interpretation and zeal given that what he was doing does seem like it has to be illegal just not subject to such outrageous punishment.
- notamy 5y agoJavascript. Not to remove it, but to make it better from the start. Current JS feels painful to me because it feels like piling hacks on top of a poorly-designed language to make it palatable. Doing it better from the start sounds amazing.
- D13Fd 5y agoI'd give it a better name, which does not involve the word "java."
- creativeembassy 5y agoAnd ECMAscript still sounds like a disease.
- kzrdude 5y agolet's just pick a letter and it's fine. escript cscript mscript ascript
- pteraspidomorph 5y agoLet's face it, it would end up as "JScript". What we now know as "JScript" would probably become "MScript" or something.
- deleted 5y ago[deleted]
- FranchuFranchu 5y agoEcma balls
- ryall 5y agoBut it's such a great litmus test to instantly identify the people that don't know what the hell they're talking about ;)
- masswerk 5y ago
- Animats 5y agoChanges I would have made in the early days: - 48-bit static IP addresses. 70 trillion should be enough. 128 bits was overkill. - Nodes, not interfaces, have IP addresses, so you can use multiple paths. - IPSEC available but initially optional. - Explicit congestion notification, so packet loss and congestion loss can be distinguished. - Everything on the wire is little-endian, byte oriented, and twos complement. - You can validate a source IP address by pinging it with a random number. If you don't get a valid reply, the IP address is fake. Routers do this the first time they hear from a new address, as a form of egress filtering. This contains DDOS attacks. - Routers will accept a "shut up" request. If A wants to block B, it sends to a router on the path, the router pings A to validate the source, and then blocks traffic from B to A for a few minutes. This also contains DDOS attacks. Routers can forward "shut up" requests to the next router in the path, for further containment. - Fair queuing at choke points where bandwidth out is much less than bandwidth in. - Explicit quality of service. At a higher quality of service, your packets get through faster, but you can't send as many per unit time. - No delayed ACKs in TCP. - Fast connection reuse in TCP. - Mail is not forwarded. Mail is done with an end to end connection. Mail to offline nodes may be resent later, but the sender handles that. Mail, instant messaging, and notifications are the same thing. Spam is still possible but hard to anonymize. If you want your mail buffered, use an IMAP server at the receive end. - One to many messaging uses a combination of RSS and notifications. - Something like Gopher should be available early. The Web would not have fit in early machines. but Gopher would.
- pteraspidomorph 5y ago> Nodes, not interfaces, have IP addresses, so you can use multiple paths. Isn't this difference academic/software? What is the crucial point here that can no longer be implemented as an abstraction? (Not a networking specialist so this might just be my ignorance speaking.) > You can validate a source IP address by pinging it with a random number. Good idea, but I suspect this is the type of feature that might quickly fall prey to implementation laziness/incompetence, or in other words, enough implementers would both ignore it and not use it until it became unreliable. > Routers will accept a "shut up" request I like this idea but couldn't this system be abused by a malicious man in the middle to much more easily hinder connectivity to a targeted system? The man in the middle can fake the validation too... > Mail is not forwarded I don't think this is a good idea. People would quickly invent a forwarding protocol if one didn't exist. I mean, I see what you're trying to do here, but I don't think you would succeed on this one.
- ayansq 5y agos-expressions instead of docbook or xml. (html (head ...) (body ...))
- efficax 5y agoWidespread adoption of trusted keystores and encryption keys, completely eliminating the need for passwords.
- gmueckl 5y agoOme change is enough to transform the mature of the net: no JavaScript or other way for pushing esecutable code or dynamic state chamges to the client, instead, extend HTTP to contain a Turing complete query language to be executed on fhe server. Pondering the implications is left as an exercise for the reader.
- michaelbrave 5y agoReplace HTML with something closer to hypercard - it would give simple interactions, database management and user interface that you need. Failing that, Flash should have become open source and part of the W3 web standards, but opened up such that we could observe the code that's running.
- masswerk 5y agoActually, this became a thing very early on, compare Viola Net.
- quickthrower2 5y agoI rather liked Adobe flex programming and through Adobe air was very cool (the ElectronJS of the 2000s)
- holidaystarship 5y agoThe internet itself is pretty solid: other than a few technical tweaks, I think the infrastructure evolved as well as it could. One thing I'd like to see changed is a re-thought internet protocol that's more privacy focused: an IP address is an absurdly specific identifier, fingerprinting a user down to a single household in most cases. An ephemeral addressing scheme for clients that changes with every new connection would be really quite helpful, perhaps along with some safeguards that allow law enforcement to still track that ephemeral identifier to an internet connection in the case of abuse. The web is a different story, especially social media. I'd like to make social media, and the web in general, more forgetful. "Digital natives" (second-flight millenials and Gen Z) are going to get screwed with the persistence and easy archiving of social media data. This is partially a result of the natural shift in cultural expectations that occurs over time, as well as a consequence of having their awkward-for-any-generation blunder years recorded forever. This is definitely more a legal change than a technical one, but I would mandate (1) a time span (such as 5 years) where public social media posts must revert to author-only private unless consent is otherwise obtained and (2) a prohibition against public mass archiving of social media posts from people who aren't public figures. This type of mass archiving for the use of closed-off academic research libraries is acceptable, but merely going and hoovering up every public tweet or Youtube comment or Reddit post and and putting it up with a public search engine shouldn't be permitted. Treat it like many countries treat the census, and only allow publicly opening up these archives far into the future (for example, the raw underlying questionnaires used for the Canadian census are not released to the general public until 92 years after collection). Different story for public figures such as politicians, but we shouldn't archive everything that everyone has said in perpetuity.
- cpr 5y agoI think you mean the late 60's and early 70's.
- JohnBooty 5y agoI pick the year 1995, right as the web starts to hit the mainstream. I'd add some kind of built-in, frictionless, privacy-respecting, user-friendly, transparent payment/micropayment system. Built on open standards so we could have multiple competing UX's and the best one(s) would win. Basically, think about how Patreon and Kickstarter (which are not without their flaws) have allowed people to support creators more or less directly. Now, imagine if we'd somehow baked something like that in to the internet itself. The web is 99.9999% garbage and one of the biggest reasons is because we spent nearly two decades training people that everything on the interwebs was free which meant that it had to be ad-supported which means that nearly everything has been forced to pander to the absolute lowest common mass-market denominator. Even with some kind of "good" micropayment system, sure, most stuff would still be free/ad-supported lowest common denominator crap. I have no illusions. Just look at every other form of media that has ever existed. However, just imagine how books or movies or whatever would look they were de facto forced to be free for the earliest part of their existence.
- selfsimilar 5y agoWider IP address space at the beginning could have led to static IP deployment to the home, allowing for self-hosted websites and email service that would have obviated the need for ad-supported websites and web services. We still would have had the issue of asymmetrical home connections but that’s a separate issue.
- seized 5y agoYou don't need a static IP though. You just need dynamic DNS and to use the name. And depending on the ISP you might be "static" until a long enough power outage anyway.
- asciimov 5y agoI would fix the order of URLs instead of http://news.ycombinator.com/item http://news.ycombinator.com/item it would be https:com/ycombninator/news/item
- dane-pgp 5y agoI actually really like this idea (and once created a browser extension to at least make URLs look like that in the address bar), but I still think there is a benefit to having domain names distinguishable from paths, so it would be: https://com.ycombinator.news/item https://com.ycombinator.news/item Having just checked, I see that ycombinator.news has already been registered, so maybe the lesson is that everyone should register "palindromic" domains, like com.ycombinator.com for example.
- Y_Y 5y agoCan we just do this now anyway? Also I like that ycombinator becomes "ycombninator".
- musicale 5y agoThe hierarchical order and flat namespace is logical, but for privacy reasons you may not wish to make a DNS query on the full path. So we might want to leave it split: com.ycombinator.news/item On the other hand, you could do an incremental query perhaps and cache the path length. But I wonder about having the protocol name in there. Couldn't DNS return the ports for the supported services and then you could pick whichever one you want?
- jjav 5y agoHonestly, just one thing, and I only need to go back to the early 90s. Just before the Internet was opened to commercial use in the mid 90s, would've made a perpetual prohibition of advertising over the Internet. Ads are what have ruined everything. Take just about anything unpleasant about the Internet today and it is either directly a consequence of ads, or an indirect consequence of someone trying hard to make you see ads.
- asciimov 5y agoAd's got us here to begin with. Without ads the internet would have been only for the rich. There would also have been no google, no amazon, no android, no kindles. I'd still be ordering everything from the Sears Catalogue, waiting 6-8 weeks for it to arrive.
- philwelch 5y agoNo Amazon, really? Amazon ships physical goods to your house in exchange for money--they aren't dependent on advertising. Even Google landed on advertising as a monetization technique but existed before it and easily could have been a sustainable business without it (though not the behemoth it has become).
- jedberg 5y agoGoogle existed before ads but had no revenue. Ads are the only thing that kept it alive other than investor money.
- philwelch 5y agoI might have overstated a bit. Ads were obviously a sufficient revenue source, but provide far more revenue that is necessary for the core search engine. It’s possible some other revenue source might have been sufficient to support the search engine, even if not as lucrative.
- asciimov 5y ago
- cmason 5y agoI'd make it so you can only set the evil bit to 0.
- janci 5y ago1. Prevent protocols to cross layer boundaries. FTP, SIP, etc. are application protocols, yet they use ports and IP addresses for identification of endpoints. They break if the transport layer does something they did not anticipate (e.g. NAT). NAT is not evil, nor broken. Protocols not respecting layer boundaries are broken. 2. Make use of DNS SRV records for all services. Why HTTP must be on port 80? Why not consult DNS to resolve the port too? Pretty much related to my first point.
- therealplato 5y agoClient certificates are required with every http/s request. Back in 2021 we've never logged in with user/pass
- _joel 5y agoThat sounds horrendous imho, how would it be administered and what privacy concerns would there be.
- munro 5y agoFiber internet. Having 1000 mbps up/down was so nice when I lived in a city where I had access to fiber.
- dxbydt 5y agoi had to answer this question on my computer networks exam ages ago. i forget my exact answer, but it was along the lines of “ATM is the greatest tech since sliced bread. IP is bad because connectionless blah blah… therefore http over tcp over atm better than http over tcp over ip” i passed the course.
- rawgabbit 5y agoEncourage the App store paradigm and discourage the browser paradigm. Users download apps that they trust instead of using a browser to directly go to a URL that (a) could be fake e.g. "whitehouse.com" (b) installs malware on the client computer. The theory here is that app developers know how to wade the shark infested waters of the internet better than grandpa or grandma and can code basic protections in the app. e.g. just because a website says click here, you don't really have to click there. Especially if a dialog pops up asking do want to give elevated permissions to XYZ? Encourage the development of browsers for kids. Parents can configure their kids' computer to only run "KidFox" browser which has all the security features turned on. Only allows white listed sites that has been vetted by various agencies, denies escalated privileges, turns off all webcams, prevents remote hackers taking over their kids computer etc. Lastly, it is more of mindset. Developers should take the attitude that every client computer, server, and database has been compromised to some degree. That is we should have defense in depth and not rely solely on one mechanism to protect us from the bad guys.
- woodruffw 5y agoDNS is a bit later, but: the domain-name specificity notation. As a coworker of mine pointed out, it's a little bit ridiculous that URLs on the web look like this: `more.and.more.general/more/and/more/specific`. They should really be `more.and.more/specific`, just like bang paths[1] were. [1]: https://en.wikipedia.org/wiki/UUCP#Bang_path https://en.wikipedia.org/wiki/UUCP#Bang_path
- reactspa 5y agoEmails cost money to send. The money goes towards some good cause (maybe even towards internet infrastructure).
- deleted 5y ago[deleted]
- karaterobot 5y agoNot sure how to accomplish it, but advertisements should be captured in a semantically distinct way in markup. I hate ads, but I'm not saying you can't have them if you want, you just have to wrap them in the equivalent <advertisement>../</advertisement> tags, so that there is no question about what content contains an advertisement and what doesn't. That way, it's trivial for me to block them. The flip side of the coin is that my browser will tell you if I'm blocking ads, and you can decide if you want me as a viewer or not.
- teraflop 5y agoEven if you could come up with an "objective" definition of what counts as an advertisement, what incentive do site owners have to be honest about it? Likewise, why would I want my browser to tell the site that I'm blocking ads? This idea reminds me of the Evil Bit: https://datatracker.ietf.org/doc/html/rfc3514 https://datatracker.ietf.org/doc/html/rfc3514
- karaterobot 5y ago> Not sure how to accomplish it I am hoping that the same technology that transported me back in time and made me director of DARPA would help me solve those issues.
- FreeAssange 5y agoNothing bad could ever be permanently fixed, because these changes were inevitable. The problem is how laws destroy fair competition by favoring those with the most $$. Fix that, and you fix everthing else (not gonna happen).
- ilrwbwrkhv 5y agoSmart documents instead of web apps. And no JavaScript of course.
- PicassoCTs 5y agoAdd a fallback protocol, that allows for onion-protected mesh-net-routing. All that is ever revealed for routing a package, is the next human-supra-organism you want that package to be handed over. Imagine you write a reply: "This is not a good idea" and hit send, but some benevolent leader decides this message is not a good idea. So it fails on the centralized infrastructure. Now you wrap the adress of me: Individual > Household> Street > City> Airport into encrypted shells, that only reveal the next destination upon arrival within the data-organism. These of course are valid only, if a public ledger certifies their longterm existence. Your reply will take time, it will travel on land, air, water and, by all means possible. But it will reach me, i promise you that. To add plausible deniability, all you need is hostile apps, who participate within the meshnet, without the users consent. To add motivation to participate, just allow the transfer of crypto-currency - a currency backed up by the promise of data-transfer, no matter were, no matter what.
- nickdothutton 5y agoThere is no need to put IP stacks on non-server endpoints unless you know what you are doing and the implications. Each non-server device could establish a context with the network as and when needed to send and receive traffic, as you did in the dial-up age. Removes a huge raft of security problems, IP address shortages, DDoS, privacy/tracking.
- pmontra 5y ago> How are you going to make the Internet better? Anything that allows me to send files to a device of a person I know on a direct connection without a service in between and regardless of our locations in the world. Still an unsolved problem AFAIK.
- FranchuFranchu 5y agoIf you're both connected to the Internet and NAT didn't exist, you could run a small server and he could get your files
- closeparen 5y agoI would probably have most nodes on some kind of overlay network contained within a jurisdiction/extradition area, with fewer and more structured interconnections across hostile national borders. I don’t think it’s reasonable to make every small business with an email or web server for its local customers and partners, have to defend against large and well funded criminals operating in broad daylight from Russia.
- nickdothutton 5y ago…also I’d like to add… It’s a pity @dakami isn’t around to give his response, I’d have liked to hear it.
- brundolf 5y agoIPv6 from the beginning. I have a theory that NAT killed the open web. There was this idea at the beginning that everyone could host their own website, email, etc. But when you're behind a router, you suddenly have to be quite technical in order to set all that up on the computer in your room. So only (bored) technical people bother. It's possible this is the reason platforms came to dominate.
- btgeekboy 5y agoI'm not sure I'd subscribe to that theory. The port forwarding issue is a few clicks; actually getting a site to host is another issue entirely. Even if it was some application you ran on your desktop 24/7 that holds your hand through the process, NAT + DHCP aren't insurmountable.
- brundolf 5y agoPort forwarding + static IP. And don't be so sure that it's trivial; despite having taken a course on the network stack I'd have to do some research to figure out port-forwarding and get it set up correctly. Normal people's response would be, "What's a port? Like the holes on the back of the computer?" In an IPv6 world you could have a free program you download that gives you an interface like Squarespace except you can host it for free on the very computer you're using to make your site. Could be totally accessible to nontechnical people. Same goes (much more powerfully) for distributed protocols like Matrix. You could have encrypted messaging platforms like Signal that don't even need a handshake server; devices talk exclusively to each other. Etc. It would be a radically different internet.
- generalizations 5y agoIs there any way to get there from where we are now? Seems like even with ipv6 we still have to use routers.
- brundolf 5y agoMy understanding is it would be hard/impossible to get everyone to IPv6 at this point because there will always be a long tail of devices that aren't there yet, and we can't just jettison those from the internet But yeah, I think even if everything magically changed to v6 overnight, we'd still be stuck with NAT to a large extent because so much is tangled up in it at this point. For one, it probably makes it easier for ISPs to bill their customers. Especially the dynamic-IP side of things.
- pkb 5y agoAdd requirement for every user to have to solve mathematical equation before being allowed to post anything. Make it hard requirement and enforce at all times.
- PeterWhittaker 5y agoStretch goal: No password authentication whatsoever. Target goal: No cleartext password authentication. (No telnet as it was, no ftp as it was, no smtp as it was, etc., yada, and so on....) Fallback goal: Get HTTPS right far sooner, with cryptographers working on SSL 1.0 from the beginning, with funding, and eliminate HTTP as soon as possible.
- 8bitsrule 5y agoAt least one domain where NO commercial activity is allowed. No buying, selling, advertising, trading. Companies who are convicted of mens rea transgression (along with whichever employees are guilty) lose ALL access to the internet in perpetuity.
- deleted 5y ago[deleted]
- vb6sp6 5y ago> advertising This one would be hard to enforce. Still a good idea.
- warmfuzzykitten 5y agoThis seems unworkable. Gaining attention is intrinsically commercial activity. Attention has value; you can't stop it bleeding into the rest of the world. Some examples and questions: - An "influencer" gets her photo on a Wheaties box. After that, the influencer doesn't have to do overt advertising to promote the cereal, their fortunes are bound together. - In politics, as the former US president so amply demonstrated, attention is a currency. - What about the exchange of ideas? Can one talk about the contents of a book without selling (or discouraging the sales of) the book? - Is any mention of brand names to be prohibited? If you can mention a brand, unless all the brand's marketing has been completely ineffective, you are selling the brand. Don't like it? Pass the Kleenex.
- dublin 5y agoUntil the late 90's the entire Internet was this way - even .com domains were subject to the Internet AUPs (Acceptable Use Policies) that strictly banned "commercial" use of the Internet. AUPs lasted only a very short time after O'Reilly showed their Global Network Navigator site at Interop showcasing the capabilites of a new graphical web browser from NCSA called Mosaic that could - gasp! - display inline images along with the HTML hypertext! (Probably hard for the younger crowd here to believe, but early browsers had to open images in a separate window, sometimes with a separate image viewer helper program. Yeah, really. Mosaic was a game-changer, that made the vision of the modern web obvious to at least 1% of the people who saw it.)
- deeblering4 5y agoLaws to prevent and penalize monopolies from forming on the internet. E.g. prevent google, facebook, amazon, etc from becoming all-consuming evil entities. That and probably mandatory native layer 3 encryption
- anotherevan 5y agoCivility.
- cesarb 5y agoI would make packets over the MTU truncate (with a flag indicating the truncation), adjusting the IP checksum (the same way it's currently adjusted for changes in other fields like the TTL) to match, instead of fragmenting or dropping. That would avoid all the issues with PMTU blackholes or non-initial fragments.
- strictfp 5y agoPut AJAX back in the bottle.
- __turbobrew__ 5y agoI assassinate Osama Bin Laden and therefore prevent the patriot act and the erosion of personal freedoms in the pursuit of “national security”.
- kderbyma 5y agoI would have built in a protocol which could be used for decentralized ad networks in a federated fashion unlike the craziness that we see today with TOS designed to fight all competition and to selectively control the markets.
- musicale 5y agoHere are a few things off the top of my head (and trying not to duplicate too many things): - Get rid of ARP - just append the LAN address to the network address like other networks. By default LAN addresses are random. (Note IPv6 enables this basically.) - Support encrypted DNS and authenticated BGP. - Let DNS return other metadata including the port as well as the IP address. - Let DNS caching work. Don't misuse short DNS timeouts for load balancing. - Ingress traffic filtering - reject source IP addresses from outside the current prefix. - Not IP per se, but let multipath work in the LAN (and give Ethernet a TTL so that packets don't loop forever if things go bad.) - Eliminate (or minimize) broadcasts. Use unicast/multicast for DHCP, service lookup, etc.. - Support relocation/forwarding of TCP connections so they don't break when your IP address changes. - Fix TCP congestion control so that the data rate doesn't decrease as latency increases. - Second adding congestion notification to TCP to differentiate between packet loss and congestion. - Encrypt the host name in SSL/TLS.
- dublin 5y agoBiggest thing I'd change: Build in the ability to do long-duration keepalives from the git-go to avoid three-way handshakes when you want to send data later after establishing the connection. A whole bunch of other changes to reduce latency in general - no one really quite realized how important latency was back when this stuff was designed, but in all fairness, it's almost, "how could they?" Lastly, extend DNS to provide not only encryption and non-repudiation, bu most importantly, more info, or just absorb Project Athena's Kerberos and Hesiod into DNS at first opportunity. This also allows AFS or other global distributed filesystem support, which in turn could have changed database architecture and semantics for the better. Imagine how different the net would be with a scalable global federated name and directory service that could do everything that Yellow Pages did in the 90s. (N.B.: When I was at Chevron, we built our own version of YP that was hierarchical and multi-domain. It worked really well ("really well", as in damn near flawlessly from the Monday morning we turned it on after a coffee-fuelled weekend hacking session by one of the three true geniuses I've ever met!), seamlessly syncing the info that was in Hesiod/Athena, YP, and DNS to make as much of it as made sense available to clients of each. I've never seen anyone else ever do anything like that, even in all my consulting exposure to other big companies' network services architectures.)
- TheOtherHobbes 5y agoSurprised there are comments about essentially trivial network-layer implementation details, and not so much about culture and UX. As an alternative: - Private and federated. Everyone has a personal server application which spans multiple personal computing, storage, and peripheral devices and supports federated access at varying levels of security. - The server stores and manages a user's private data and anything else they feel like storing or sharing. (This requires unobtanium level security, but since we're imagining let's pretend this is a solved problem and see where it takes us.) - Sharing of all kinds is user controlled and is opt-in across multiple competing federated networks. This includes social networks - with the difference that anyone can start their own network, for any purpose. - Networks are decentralised and peer-to-peer, and do not store personal data, track, or profile users. This is a user=centric network where users own and control their data. Not an industrial data silo network. - Users can share different interest profiles and personal details across different networks with varying levels of security and implied credibility. - Ads are opt=in not opt-out, and defined by voluntary and informed profile and interest sharing, not involuntary and uninformed data harvesting. - Anonymous microtransactions are a thing. Anyone can sell at scale with as little friction as possible. - There are no cryptocurrencies and no blockchain tech, because generating random numbers with the equivalent of your own electrical substation is fucking stupid. There is a low-energy secure equivalent. (See unobtanium. Or is it?) - A common kit of essential server apps is open sourced and community-maintained. - Commercial and/or professional apps are available by hire or subscription. Servers have a multi-profile multi-layer security model which controls which layer of personal and/or server data outsider apps have access to. - All paid-for apps supply full details of the schemas and file formats they use, to guarantee that users can freely transfer data to a competing app provider so apps and services hold personal data hostage and have to compete on service quality, not on retention gaming. - Hacking, malware, virus creation, phishing, and so on, are punished by deletion of personal server data and reduction to the most basic server hardware and software. For serious and repeat offenders, this is for life. - IoT devices are treated as personal server peripherals with no external data sharing (except by opt-in.) - Government and military networks use an expanded version of the same system. Municipal, military, and internal gov services run on separate private subnetworks which can only be accessed through authorised devices with extra ID verification, not through general public logins. Basically it's a combination of device security, private ID (probably biometric), sacrosanct personal data protection, high user-controlled privacy, super low cost of entry for entrepreneurial service provision, squashing of local, national and international scales, and strong forcing of anti-monopolistic competition - the opposite of the current model, which seems to be about herding users into virtual pens owned by monopolists, applying various psychological patterns to control and trigger behaviour, monitoring behaviour and sentiment through minimal privacy, and having to deal with very leaky and insecure devices and systems.
- eointierney 5y agoI've so many ideas for this question. So so many protocols (history), but how few could we get away with, and what would they look like?* Why don't we have constructive computational contracts for computational work? How do we make the Internet easier to understand? How do we manage the agency problem? We yield far too much agency as a matter of daily life, our data is not our own, our decisions are shared with barely knowable third parties. How do we design human computer interfaces with health, especially mental health, as primary constraint? How rapidly can the EU coalesce around a combination of a RISC-V general purpose CPU (with suitable trimmings) and a SEL4-influenced-kernel, perhaps in Rust (https://gitlab.com/robigalia https://gitlab.com/robigalia)? How do we standardise on constraints of discourse such as those pertaining to offensive language or hate speech? How do we make it easier for people to communicate with kindness? Autohinting everywhere? Like a shellcheck for human bashfulness? VR and AR are coming very soon and without care they will be shatteringly destructive of human life. Humans addicted to computationally modeled utility functions mediated by multi-sensory computer games? How do we embed the lore in the experience? How do we make available all the references as delightful marginalia? What areas of Mathematics and Physics do we need to study to get ahead of our problems? Category theory is beyond trendy, what's trending? How about rigorous dimensional analysis to match the type theory, or sumthin? How do we invite the world's smartest financiers to apply and share their thought more generously? Can we settle on a basic curriculum? What functional minimum of linguistic, mathematical, physical, visual, and other skills do we need? Is lisp or a variant the first language we should learn, and if so how should we be able to learn it? If not lisp then what? APL? Fortran? Compiler forbid, Haskell? How do we ensure that code and documentation are always in sync? How much time will this require? How do we guarantee a standard of professional attainment and delivery of ICT expert that is globally effective? How do we standardise how we do, not just what we do? How best can we help each other make our Internet an even better place? (much spelling, apologies) *4
- tabtab 5y agoA better DOM. I know this topic is mostly about data transfer, but I'm going to complain about web UI standards. For many uses, a state-ful coordinate-based UI standard is needed. It's why PDF's proliferate: DOM can't faithfully reproduce documents in a WYSIWYG way. It's not practical for every document/content author to become a "semantic auto-flow" layout expert: the learning curve to do semantic right is too damned long. We could have things like interactive flow-charts and ERD diagrams with our favorite GUI widgets in them if we had a decent state-ful coordinate standard (and maybe the "missing" GUI idioms like combo boxes, tabs, editable grids, MDI, drop-down menus, etc. Reinventing them in JavaScript has proven a mess.)
- ipspam 5y agoNothin free. Pay. Small amounts here and there.
- naveen99 5y agoBitcoin !
- HerbsMan 5y agoQUIC full way.
- HerbsMan 5y agoQUIC full way. TCP is currently the biggest bottleneck.
- specialist 5y agore banning ads. I expected Xanadu. Centralized, omniscient namespace, two-way links, micropayments, etc. We got The Web. Which eschewed all of that. Much as I hate The Web (repeating myself), I grudgingly accept that it probably succeeded because it wasn't Xanadu. Even if Xanadu launched, like a better AOL or Prodigy, I suspect most people wouldn't have grokked it. Another triumph of Worse Is Better. Like PHP and JavaScript and so many others. Then hot patch it towards something less offensive.
- jgerrish 5y agoI wouldn't change anything. Centralized control will be abused. The people I see harassing others online a lot of times are US citizens, on US domains, in US jurisdictions. Sorry.
- lmilcin 5y agoVery easy choice. All services paid explicitly. Having thing given for free to be then exploited for various purposes is reason why these services are shit - because you are not the client, the guy who pays for your data or advertising space is.
- kevdevwebsaid 5y agoA law that requires apps and websites to ask their new members what they want from that company And then the most repeated comment/idea/design should be applied.
- x0n 5y agoYou clearly have something in mind. Speak up.
- x0n 5y agoAll porn on .xxx top level domain only.
- mtnGoat 5y agoSimple answer. No third party cookies. And no JS. ;) /jk
- deleted 5y ago[deleted]
- jrnichols 5y agoIt would be marketing & advertising free. As in, if you need ad revenue & marketing to support your website, you simply don't exist. You can have a website, but no advertisements or "user engagement" nonsense. You're either free or you're offline.
- emptyparadise 5y agoDevelop stronger cultural and technological safeguards to let people remain anonymous and unmasked, preventing the eventual erosion of privacy.
- reph2097 5y agoUse IPv6 from the beginning and banish NAT.
- randomperson_24 5y agoEncrypted SNI and No Paywalls
- ecesena 5y agoRemove the cookie consent popups. Or, if we're talking about the ground work, specs the cookies such that browsers must implement the cookie consent and therefore sites can't build it in js.
- drpixie 5y agoOne general change and one specific: - A general idea: Arrange so that sending packets costs way more than receiving, just like snail-mail. (At the moment, a large website or spammer pays very close to $0 per message, individuals pay much more per byte to receive junk.) This would encourage decentralisation, nicely small web pages, and discourage spam. - And "disappear" XML. It might be "ok" (just) as document markup, but it's a terrible for structured data and config, and for transfers.
- no_time 5y agoBan all commercial activity. Make that law loosely defined so it can strike down any company trying to work around it. A centralized internet will inevitably do more harm than good.
- me_me_me 5y agoMake everything small endian, its a small ask and would make so many lives easier.
- deleted 5y ago[deleted]
- rubenfonseca 5y agoNo JavaScript
- jeegsy 5y agoA server in every home
- thatthatis 5y agoEmail. Cold email costs $0.01 per message per address to send. How we distinguish warm va cold, idk
- threesmegiste 5y agoCall Ted Nelson
- jokestir 5y agoThe internet is fine. I would change the web. I would remove JS and design browsers to natively run python instead.
- denton-scratch 5y agoDNS. Others here seem to be redesigning the entire intarwebs. I'll just pick one thing I might have been able to digest. DNS is brilliant - but insecure, and centralised. The dependence on registrars was a huge mistake. The competition for names is an unintended consequence; the DNS created artificial scarcity, which resulted in commercial businesses that produce nothing of value. So something like GNS, I guess. https://tools.ietf.org/id/draft-schanzen-gns-01.html https://tools.ietf.org/id/draft-schanzen-gns-01.html
- streamofdigits 5y agoIts a darn difficult question. The "internet" is the first time humanity got a technology for information exchange that can scale arbitrarily. It creates a complete graph that can enable data exchange between any two individuals (and of course an arbitrary additional number of devices). How this increadible technical potential got translated into social reality says more about society than the technology[0]. If the stack of applications that has been built on top of it has become dystopic it is because society had dystopia in its dna. The technology simply allowed it to be expressed, so to speak. By the same token, any technical tweak that maintained or improved this scalability would simply have led to an alternate dystopia. It may be counterintuitive but maybe the only internet that would actually be "better" would have been a more local / less scaling version. A more gradual transition might have given society time to adapt, develop some defense mechanisms and not be dominated by the lowest common denominator [0] Keep in mind that all communication technologies of the 20th century (phone, radio, TV) quickly degenerated and never delivered the utopia initially projected
- swman 5y agoJust have the internet be a bunch of data streams that people can start/pause/stop any time. It would be "real time" from the beginning, and then you can just build whatever around these streams. It'd be like my brain broadcast just multi subscription stream, bunch of inputs and reacting to those events.
- softwaredoug 5y agoAccepting but regulating centralization of the Web I think we failed to appreciate how much the average user would need centralized services (Search & Social) to use the Web. Both of these services are around discoverability of content. Humans want a water cooler to visit and chit-chat, or an organized library to look for information. Additionally, because accessing the Web was seen at first as "free" (outside your ISP), people would gravitate towards "free" centralized services like Facebook and Google. This created a recipe for what we see today with the incredible power of these companies over so many aspects of our lives. So what would I think should be different? I would have been more thoughtful about regulating these centralized services in the way the FCC regulates the airwaves & media companies. Which is even more proactive than antitrust law. It's OK that they're profitable. That's good! But we ought to avoid single companies owning the entire search / social space.
- atmosx 5y agoNot my idea and it's not too late to change it IMHO. We use the word "free" for services that extrapolate and sell data. These services are not "free", this small thing IMHO drives the data broker industry to a big extend.
- j10c 5y agoI will propose decentralized Domain Registration system which can overcome all monopoly, sensors and bureaucracy related to ICANN.