12 ms·
Fiatjaf/nostr – a censorship-resistant alternative to Twitter
- scsibug 5y agoLots of exciting work going on with this right now. I really like that I can open up websocat, and interact with a relay directly to learn how the protocol works.
- Cameri 5y agoI'm using branle (https://branle.fiatjaf.com/ https://branle.fiatjaf.com/) as my client and you can follow me with my pubkey: 22e804d26ed16b68db5259e78449e96dab5d464c8f470bda3eb1a70467f2c793. You can find my pubring on my bio after following me. There's no ability to discover others at this time! Nostr relay registry hosted here (https://nostr-registry.netlify.app https://nostr-registry.netlify.app) by fiatjaf. Exciting times!
- swalsh 5y agoJust checked it out, my pub key is f0bed2e11260f0f77f781db928f40a34c18713fda1918d3be996f91d0776e985 it's not obvious to me though how you find people to follow.
- wbobeirne 5y agoYou find their pubkey in HN threads, of course.
- kseistrup 5y agoLack of discoverability is often a weak spot of decentralized social networks that don't have a public firehose. Secure Scuttlebutt, Twtxt, Bogbook — and now Nostr — all suffer from this, and new users end up looking at an empty timeline and shouting into the dark.
- webmaven 5y ago> I'm using branle (https://branle.fiatjaf.com/ https://branle.fiatjaf.com/) as my client and you can follow me with my pubkey: 22e804d26ed16b68db5259e78449e96dab5d464c8f470bda3eb1a70467f2c793. It isn't too hard to improve upon the status quo in various ways when you just drop a key usability requirement (in this case, the need for human-memorable 'handles'). It is worth reading 'Why Johnny Can't Encrypt' (1999) [0], 'Why Johnny Still Can't Encrypt' (2011) [1], and 'Why Johnny Still, Still Can't Encrypt' (2015) [2]. [0] https://www.usenix.org/legacy/events/sec99/full_papers/whitten/whitten_html/index.html https://www.usenix.org/legacy/events/sec99/full_papers/whitt... [1] https://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.227.7902&rep=rep1&type=pdf https://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.22... [2] https://arxiv.org/abs/1510.08555 https://arxiv.org/abs/1510.08555
- vidarh 5y agoThat's true, but you can disconnect those requirements on the server side. E.g. a "name/profile to key/value" service would be useful for more than this. If people want mastodon style handles, for example, it's easy enough to create a mapping that can leverage DNS for example to let you query for a matching pubkey in a cacheable and easily scalable way and without the need for that to be built into the messaging protocol.
- webmaven 5y ago> That's true, but you can disconnect those requirements on the server side. > E.g. a "name/profile to key/value" service would be useful for more than this. At which point you've reintroduced a global namespace SPOF that is vulnerable to censorship, etc. You can push the complexity around like food on a plate, but getting rid of it is another matter entirely.
- fiatjaf 5y agoNo, you don't. You can have DNS-based aliases to pubkeys, and then people will follow pubkeys and interact with pubkeys, not with the DNS aliases. So if these users are censored later from the DNS then they still keep their identity, their contacts, their followers etc.
- pseudozach 5y agoYou could even deterministically map pubkeys to handles with something like bip39. it won't be pretty but it will be unique, human-readable and uncensorable.
- webmaven 5y agoThat's kind of like saying that people don't interact with domain names, but with IP addresses. The point of having the mapping of a name to a key is for users to use it in place of the underlying key in their interactions with the system.
- makeworld 5y agoIf ed25519 was used instead of secp256k1, wouldn't pubkeys be shorter? Like SSB.
- swalsh 5y agoOne of the neat things about the way they've done it, is you can use a bitcoin wallet to connect: https://twitter.com/Bumi/status/1476957006653276170 https://twitter.com/Bumi/status/1476957006653276170
- speedgoose 5y agoYou may know it already but "branle" means jerking off in French.
- __MatrixMan__ 5y ago> it does not rely on P2P techniques, therefore it works. followed by > To publish something, you write a post, sign it with your key and send it to multiple relays (servers hosted by someone else, or yourself). To get updates from other people, you ask multiple relays if they know anything about these other people. Anyone can run a relay. Sounds pretty much like P2P techniques to me.
- zapataband1 5y agoAnother nitpick this -> "A relay can block a user from publishing anything there, " sounds like censorship to me We need to realize our problem is not with censoring people, it's with who does the censoring. We don't like it to be the gov, because we don't feel like the gov is 'by and for the people' We don't like it being large corporations because that's doubly the case.
- sa1 5y ago> A relay can block a user from publishing anything there. The point is that it won’t be effective since messages are pushed to/pulled from multiple relays.
- brightstep 5y agoUnless relays come together and agree to block someone or something. As long as there are enough relays this is improbable
- ayende 5y agoAt which point you can setup your own relay, you don't have a block here
- shadowgovt 5y agoUnless nobody is willing to peer with you. These are all questions we've already seen from USENET; in fact, it's not entirely clear to me what the benefit to this protocol is over USENET, except it's new.
- LinuxBender 5y agoI like the intent of these types of projects but a serious question I have is: How do you get the majority of people to switch to something like this? There are many examples but the most recent ones that come to mind are people trying to get their friends to use Murmur/Mumble instead of Discord with basically near-zero success. I've seen this in a few gaming forums. Anyone attempting this is basically laughed off the platform with the responses like "All my friends are on Discord" and "Discord can do x,y,z can your app do that?" So in practical terms how would one make such a platform widely adopted?
- swalsh 5y agoBeing decentralized can't be the only reason (unless you're a part of a group actively being wiped from a centralized platform). You need to do something better that makes people go "oh, this is neat". I had never heard of Murmur/mumble before, so I spent about 5 seconds checking it out. Nothing about the home page appealed to me... so I closed it.
- arsenico 5y agoTakes time, a lot of marketing money, more time, more money. Look at what is happening with Telegram globally. It is used as a serious alternative to WhatsApp in some countries, but far from being a real global competitor still.
- perilouspear 5y agoUI/UX also needs to be buttery smooth and non-technical, especially where setup/onboarding is concerned. The more you stray from that the more difficult it's going to be to bring in a significant population of users.
- _qbjt 5y agoI don’t think the majority of people would be interested in a project like this.
- ldiracdelta 5y agoBe the unreasonable minority https://medium.com/incerto/the-most-intolerant-wins-the-dictatorship-of-the-small-minority-3f1f83ce4e15 https://medium.com/incerto/the-most-intolerant-wins-the-dict...
- r721 5y ago>If spam is a concern for a relay, it can require payment for publication or some other form of authentication, such as an email address or phone, and associate these internally with a pubkey that then gets to publish to that relay — or other anti-spam techniques, like hashcash or captchas. Sounds like these anti-spam measures are not actually implemented yet.
- supertestnet 5y agoCorrect. Spam is not a problem yet because nostr is super new and no one uses it yet. But a few friendly bots have been released for it (since it's very bot-dev friendly) and DMs are open by default (and the branle client has no way to close them) so spam is basically guaranteed to come eventually.
- floober 5y ago> It insists on having a chain of updates from a single user, which feels unnecessary to me and something that adds bloat and rigidity to the thing — each server/user needs to store all the chain of posts to be sure the new one is valid. Why? (Maybe they have a good reason); I assume this is so a relay can't manipulate your messaging by picking and choosing which messages to forward; they'd have to forward messages [0-N]. Edit: > sig: <64-bytes signature of the sha256 hash of the serialized event data, which is the same as the "id" field> Signed hash rather than a mac - might be vulnerable to an extension attack
- sour-taste 5y agoI'm not associated with this project in any way, but your comment got me curious. It seems that since each message is signed with the private key even if you were able to perform an extension attack (which I agree it seems like you would be able to) you wouldn't be able to sign the message so it should be rejected by the relay. The signature is based on the message ID, which itself is the SHA256 of the rest of the message so by doing an extension you necessarily change the SHA256, which should invalidate the signature. But I'm an idiot so who knows.
- gogs 5y agoOpen source Twitter ? We've had that for a decade.... nobody wants to run it's own, it makes no sense, you'll have no audience. If I wanted my twitter, I'd setup a WordPress....
- vlunkr 5y agoFor me the fact that it's censorship-resistant is not the interesting point here, it's that it's decentralized.
- supertestnet 5y agoIt's not decentralized yet but only potentially decentralized if a lot of people run relays. Currently there are only about seven relays powering the whole network: https://nostr-registry.netlify.app/ https://nostr-registry.netlify.app/ Luckily, relays are very lightweight and easy to run so maybe it will eventually get decentralized.
- pseudozach 5y agoAnd remember relays can be incentivized to host content by micropayments via Lightning network if needed.
- uncomputation 5y agoThe protocol is nice and simple, but how does this prevent the issue that Aether has where running a relay just basically destroys your bandwidth and you have to store tons of stuff?
- fiatjaf 5y agoRelays don't have any requirements, you can run very lightweight relays that do very little or very big relays that do a lot of things -- and so on.
- jlelse 5y agoWhy so complicated? Just setup your personal website with RSS feeds.
- antris 5y agoThe people who cry about censorship on big platforms are people who want to access the audience. They aren't crying for the censorship itself (they usually love when people with opposing views get banned), they are just using that word to complain about them losing an audience. Setting up a personal website doesn't meet that goal, and probably a thing like this doesn't either. Most of the nazis etc. are quite miserable in their "censorship-free" platforms, because they can't reach normal people there.
- perilouspear 5y agoIndeed, in many cases the takeaway is that the greater public just isn't interested in what these individuals are saying. If it were, the personal sites and small uncensored platforms you mention would be sought out by it, but with few exceptions that practically never happens. Even with platforms with the potential for limited/no content moderation like Mastodon, the bigger nodes with less polarized demographics tend to be those that moderate their content. It's almost impossible to build a healthy community on a platform where anything goes.
- amadeuspagel 5y agoIt's sad, but not surprising, to see a question about how two protocols compare answered with insinuations about "people who cry about censorship", who supposedly "love when people with opposing views get banned". Any discussion of censorship-resistant technology seems to attract people who just love censorship, and hate anyone who doesn't, and it's not enough for them to express these views in a top-level comment, they even have to spam specific discussions.
- antris 5y agoIf pointing out that having an audience is a central need for people who use social media, makes me "love censorship", then you are delusional.
- endymi0n 5y agoI used to be a huge fan of censorship resistance, freedom and privacy, but I didn‘t appreciate just how much self-selection there was in the kinds of people who went to great lengths to access IRC in the times of dial-up modems. These days, I have the feeling there are only two kinds of platforms left: The clean ones with strong moderation, where any form of edginess and possibly controversial topics including breastfeeding, violence or discussing human rights can be banned globally or in certain countries. And the other ones, where the Nazis, lunatics and scammers hang out. I‘m still not sure what to take from that.
- darthrupert 5y agoI'm like you except I've reached a clarity: the Internet and anonymity destroyed free speech and it's now dead as an ideal.
- warning26 5y agoThe internet has shown that free speech simply doesn't work if literally anyone has the power to broadcast whatever they want to thousands of algorithmically selected users. Comparing "speech" pre and post social media is like comparing "weaponry" between knives and nuclear weapons.
- Ambolia 5y agoI can appreciate censorship if I thought the authorities and experts had any idea what they were doing. I don't think that's the case anywhere at this moment. Seems a good time to create new alternative spaces.
- rpdillon 5y agoThere may be a third category for those with technical know-how, that tend to be like the early internet, since they apply the same selection bias. I'm thinking of things like Gemini and SSB. If SSB could work out the challenges that make it hard to implement in non-JS, I think it could become something like email in its ubiquity.
- hffft 5y ago
- kaba0 5y agoCensorship is not that big of a problem in this age. That exact info will be available on someone’s server God knows where. Hell, moderation is very fundamental so any project not thinking about that is prone to fail due to low-quality/illegal content, driving away intelligent users. Obstructing the truth by misinformation, spamming, etc is the actual problem. It is a much more effective way to target uncomfortable infos. During one of the Russian elections, voter fraud was caught on camera and was uploaded to Twitter, with #villageName. It quickly caught on and censoring was impossible at that point - so Russian bots instead started spamming #villageName posts with no sane content so anyone clicking on the hashtag to learn what happened was left wondering.
- theossuary 5y agoAgreed. What we need is a 21st century web of trust for reliability of information. This way those you trust could help you find others you trust. And if somebody you trust starts to trust people you don't, you can cut them out of your news sources. This might even be a way to validate trust in anonymous sources, without leaking their identity. Just, please, no more keysharing parties.
- deleted 5y ago[deleted]
- olah_1 5y agoYou should follow what Synonym[1] (specifically Slashtags) and Iris[2] are working on. [1]: https://www.synonym.to/products/ https://www.synonym.to/products/ [2]: https://github.com/irislib/iris-messenger https://github.com/irislib/iris-messenger
- krmmalik 5y agoSounds interesting but my main concern is the anti-spam approach. It sounds good for general spam but what about a concerted defamation campaign from someone. How do you deal with that?
- ayende 5y agoThat depend on how you do it. The client selects what you see, you can unsubscribe from accounts with spam, and your client will refuse to show posts from those you don't follow
- al2o3cr 5y agoThis is very simple. Why hasn't anyone done it before? TBH this sounds like UUCP without routing, I'd say people _have_ done it before...
- rfoo 5y ago... congrats on reinventing Usenet?
- dsr_ 5y agoYup. Cryptographically signed Usenet, so spamming requires the overhead of creating a new identity per... something. Unfortunately, creating a new identity is still effectively free, so spamming will exist. Social problems need to be solved by social arrangements and supported by technical tooling.
- JulianMorrison 5y agoBanning people is an upside. Setting boundaries of acceptable behaviour is necessary for having a space where people won't be troll-brigaded and hate-swarmed, and where the worst people on the internet don't drive out everyone else.
- marstall 5y agoexactly. when I see "censorship-resistant," I hear "we don't have a way to control abuse on this platform."
- JulianMorrison 5y agoOr "this platform was explicitly designed to host abusers".
- gaws 5y agoWhen I see "censorship-resistant," I read "I can call someone the n-word and not get banned for it."
- Ambolia 5y agoThat's fine, nobody is taking Facebook and Twitter away if you enjoy those, just opening up new spaces.
- noptd 5y agoSeems like an acceptable position to take until you find yourself outside of the boundaries of acceptable behavior. Personally, I don't mind having to manually filter/ignore non-conformant behavior in order to prevent that possibility for myself and any other minority group online.
- Ambolia 5y agoCustomized chains of trusts can be created too. Where you could choose either directly who you want to read, or who you trust to "whitelist" people, so you can have censorship but you can choose your own censors.
- ss108 5y agoSo a platform whose where any idiot can spout any garbage and they feel expressly empowered to do so? No thanks. Granted, there seems to be no censorship on Hacker News. :thinking:
- MMS21 5y ago> there seems to be no censorship on Hacker News https://jcs.org/2012/06/13/hellbanned_from_hacker_news https://jcs.org/2012/06/13/hellbanned_from_hacker_news
- ss108 5y agoAh, thanks, I wasn't sure there was any moderation on here. That's a good thing in general, though I suppose the example cited is an example of moderation most of us would consider poor or undesirable.
- jmakov 5y agoYou just deacribed Twitter...
- haunter 5y ago>Granted, there seems to be no censorship on Hacker News follow the site through RSS and you can see a huge amount of flagged, dead/removed posts
- didibus 5y agoSo there's no like/dislike? No retweet? And posts are simply chronological? Is there still a text length limit? How does it handle a relay tempering with the content of posts or altering the meta-data? Or a relay who'd be sending out fake posts?
- cuu508 5y ago> How does it handle a relay tempering with the content of posts or altering the meta-data? Or a relay who'd be sending out fake posts? Author signs every post with their key.
- didibus 5y ago> Author signs every post with their key So the client does the verification? Or is it the relay? Also, I didn't mean impersonating a specific author, I meant generating posts that no one truly posted to it. So when your client lists the chronological most recent posts you get a bunch of fake manipulated content that was mass generated by the relay itself for example.
- cuu508 5y ago>So the client does the verification? Or is it the relay? From the README: > A relay is very simple and dumb. It does nothing besides accepting posts from some people and forwarding to others. Relays don't have to be trusted. Signatures are verified on the client side --- > So when your client lists the chronological most recent posts you get a bunch of fake manipulated content that was mass generated by the relay itself for example. From the README: > Each client can decide how to best show posts to users, so there is always the option of just consuming what you want in the manner you want — from using an AI to decide the order of the updates you'll see to just reading them in chronological order.
- Ambolia 5y agoAs far as I can see you subscribe to specific authors, not to a global feed on the relay, an the author is identified by their cryptographic key. Not sure how it allows you to find new people or responses to comments. Seems like it should be a key part.
- Karrot_Kream 5y agoHow is this different than Usenet GPG signed messages? Signing messages on Usenet is in practice right now and can be done with existing stable software.
- rabite 5y agoThis is not censorship resistant. Relays are external points of centralization. For all intents and purposes, they are federated service providers -- central services that can deplatform users by simply choosing not to syndicate their messages. Over time this will result in all relays being compromised by state adversaries. Legitimate "free speech" relays will be removed from the internet via ddos, legal complaints, and just general nuisance complaints that the SPLC and other organizations excel in. Both domain names, ARIN/RIPE/etc IP assignments, and BGP peering relationships are historically subject to revocation via a loud chorus of complainers when the speakers are politically unpersoned. Original nodes will then be replaced with adversarial ones -- sometimes on the same now-reassigned IPs or domain names that were taken from the original operators. This could be reasonably censorship resistant if the first place people checked for the updates of users they follow was a hidden service that is innate to every client. Ricochet Refresh and Bisq are great models of this -- every messenger or trader client launches a local daemon accessible only by a hidden service that corresponds as its identity. Any kind of relay or pub system needs to be an offline-only gossip protocol that is only checked if the publisher's hidden service is inaccessible. Secondly, this just does not scale, at all. The twitter firehouse is petabytes of content a day. If even a single city adopted this and used it like people do Twitter, running relays would be a financially and logistically significant enterprise. This is obviously nonviable. There are great ways for lowering the cost of UGC, namely serving it on some sort of DHT. You could use BitTorrent, or you could use IPFS. You are using neither, which means you haven't done basic napkin math on what being a Twitter alternative would mean. But basically a real useful and actually decentralized and censorship resistant protocol would not be dependent on pubs or relays. If you want to contribute to something in development which actually has a viable model, I recommend Identia: https://github.com/iohzrd/identia https://github.com/iohzrd/identia This proposed service has not confronted a single one of the actual problems of censorship or centralization in the subset of social media. You maybe should actually talk with people who have done significant anti-censorship work and ask them what the actual problems are and what needs to be done to solve them.
- Ambolia 5y ago>This is not censorship resistant I think the good thing about Nostr is that all the network / account / content seems to be stored in the data, not on the servers, so if the relays become a problem at some point it would be trivial to add new channels to distribute the data. >Secondly, this just does not scale, at all I think it does very nicely, in the sense that because the network IS in the data you could have different relays only distributing some of the data for some of the users and by connecting to different relays you could still rebuild the complete conversations in your client. This also solves one of the annoying things of modern internet: when a video or an article gets taken down all of the websites that reference it get a broken link that is very difficult to recover. This is one of the reasons many accounts respond to screenshots of tweets rather that no tweets. With something like Nostr should be easier to recreate all the references in a post as long as at least 1 person has archived them.
- gxt 5y ago
- zft 5y agoIs that possible to have some kind of "global" twitter like feed or search by tags to find some people to follow?
- twodave 5y agoI think we have all seen what happens when a platform has no moderation whatsoever. And a good many of us feel like it goes too far on the platforms that do. Where’s the middle ground? Is there one? Maybe social media is just a bad idea—who does it really benefit anyway?
- betwixthewires 5y agoSounds cool, I might check it out.
- 0xdeadb00f 5y agoMastodon, Pleroma, MissKey, the "Fediverse", all already exist. Set up your own instance - there you have it - censorship resistant Twitter clone.
- Ambolia 5y agoIn this case the content and accounts are independent of the node. In Mastodon as far as I can see both the account and the content are instance dependent and will disappear if the instance disappears.