3 ms·
Exactly, and: >In day to day development our decentralization increases reliability (leftpad is a sore memory) ...leftpad became a problem when a commonly-use
by SomeCallMeTim 5y ago
Exactly, and:
>In day to day development our decentralization increases reliability (leftpad is a sore memory)
...leftpad became a problem when a commonly-used deep dependency was ripped out of the ecosystem. And because npm is centralized, they can now prohibit anyone from causing that kind of damage again, ever.
Whereas in a decentralized system where people are pointing at random GitHub accounts? Yeah, they could totally delete the GitHub account (or force-push an empty repo) and cause the same exact problem as leftpad.
They are claiming to solve a problem using decentralization that was caused by too much decentralization. And then using Deno as an example install...which has the exact same problem in its ecosystem.
Fail piled on to more fail.
- kyle-rb 5y agoIt seems like he's promoting the wrong aspect of blockchain here; the benefit is immutability. The fact that you can't `npm unpublish` from the blockchain does fit the use case. But you don't need blockchain for immutability, you just need it for trustlessness. And I think in general people don't care about trustlessness enough to deal with the overhead that blockchain requires. Plus the perverse incentives that I imagine will result from having a currency that you need to buy/spend in order to publish your packages.
- verdverm 5y agoYou might find Sigstore and Cosign interesting
- apetresc 5y ago> Whereas in a decentralized system where people are pointing at random GitHub accounts? Yeah, they could totally delete the GitHub account (or force-push an empty repo) and cause the same exact problem as leftpad. To be fair, they explicitly say everything would be backed by a distributed file store like IPFS. Nobody will be able to randomly delete their own Github account and leave anyone in the lurch.
- madisp 5y agowhat if the tea.xyz domain is deleted? or the site serving it is down? even if it's using something like AWS there is some downtime there..
- IanCal 5y agoThat depends on what the site itself is doing. It might be easy to setup mirrors or run your own version locally. The package registry data and hosted content would be available whether the site existed or not.
- SomeCallMeTim 5y agoDidn't see that, but... Now if someone successfully publishes a hack that steals everyone's data and/or creates a botnet everywhere it's installed, there's no way to actually pull it down and override it. Unless there's a centralized authority with the ability to do that, in which case it's not decentralized and we're just changing who controls it.
- kelnos 5y agoRight, but any existing package registry could do the same thing if they wanted to. You don't need a blockchain for this.