6 ms·
Thank you! I really appreciate it. > However, no mention of monetization strategy. Thanks for bringing this up. I was hoping to give a brief introduction and
by dmitryminkovsky 5y ago
Thank you! I really appreciate it.
> However, no mention of monetization strategy.
Thanks for bringing this up. I was hoping to give a brief introduction and then to field questions.
I will definitely not be selling personal data, or data otherwise. I do have some monetization ideas, and I'm really excited to try them out. They're all going to fit nicely with the core concept of the platform: periodicity. One of them is advertising, and there are others. If I can find good features to sell with subscriptions, I will. The important thing at this point for me is to demonstrate value, and then to monetize without disappointing or alienating users.
> Also, no E2E
Pony is currently a one-person startup and the focus has been on fleshing out the concept, building solid apps for desktop and mobile, and getting those apps into the hands of users. Privacy is something I take incredibly seriously on a deeply personal, ideological level. While I consider myself a really solid full stack developer and believe that Pony's infrastructure is secure, I do not have the requisite experience with cryptography to honestly represent to people that this is a private platform. I hope that with enough traction and some investment, I'll be able to hire an expert to help add privacy features that I can advertise in good faith.
- pbourke 5y ago> While I consider myself a really solid full stack developer and believe that Pony's infrastructure is secure, I do not have the requisite experience with cryptography to honestly represent to people that this is a private platform. It would be great if this existed as an infrastructure-level service. Something like the Signal “API” that allows apps like yours to be built on top.
- altantiprocrast 5y agoIt could easily be a modified version of Matrix or XMPP (omemo). The protocols, security, and audits are already there. Sending delay should be easy to add on top without hurting security.
- feanaro 5y agoWhat you're describing is exactly what Matrix is aiming to be.
- vorpalhex 5y ago> I do not have the requisite experience with cryptography to honestly represent to people that this is a private platform. Fair. E2E isn't trivial. However, platforms generally need to be built privacy focused from the ground up. It's hard to go back to a platform and add these things back in. I would encourage you to add these features early, with the appropriate warnings until an audit can happen. "Hey, we're trying to keep all your message end-to-end encrypted but we haven't had our implementation audited yet. Thanks for being an early user!"
- neilalexander 5y ago> I hope that with enough traction and some investment, I'll be able to hire an expert to help add privacy features that I can advertise in good faith. Now is a really good time to learn. Seriously. libsodium is an excellent example of a library which provides user-friendly APIs that don't require you to roll your own crypto and is very strongly audited by experts — see https://libsodium.gitbook.io/doc/public-key_cryptography/authenticated_encryption https://libsodium.gitbook.io/doc/public-key_cryptography/aut... for an illustration. There are lots of other similarly good libraries. All you need to do is to implement some public key infrastructure, making sure that private keys stay private and never leave the user's device and that you can look up the published public key of another user.
- ajkjk 5y agoOr they could just not do it because it's not that important to most people... HN comment sections are not representative of the general populace.
- neilalexander 5y agoDo you know this with reasonable certainty or are you assuming this to be the case? Either way, it’s arguably better to design defensively and build in better security than you think you will need up front rather than have worse security and be in the headlines for the wrong reasons later.
- ajkjk 5y agoI'm assuming it, and I'm certain my assumption is right. 99% of people have no idea what encryption is, so there's no way they could care about it. So while I'm not "utterly certain", all anyone would have to do to be as certain as me is go ask, like, five people who aren't engineers about it.
- spacebear 5y agoI don't think this is true anymore. The average user may not know what end-to-end encryption is, but they know they don't trust Facebook. And Apple built a whole marketing campaign around user privacy. I think most people do care about privacy, but they're usually powerless to defend it.
- jonny_eh 5y agoMonetization ideas: Fancy "envelopes", "wax stamps/monograms/watermarks".
- meltedcapacitor 5y agoCharge $1 (per message) as a penalty for express "courier" delivery.