7 ms·
> Its decentralized nature makes some things a lot more difficult to pull off than its competitors. Help me understand one thing about Mastodon. We choose a Ma
by distcs 4y ago
> Its decentralized nature makes some things a lot more difficult to pull off than its competitors.
Help me understand one thing about Mastodon. We choose a Mastodon server to create account. What is decentralized about it? Doesn't choosing a server make it effectively centralized? I choose mastodon.social. What is there to stop mastodon.social from a change of ownership that makes it fall in the hands of people who take user-hostile decisions?
I know we can create a new account on a new Mastodon server and move all the followers but that's about it. We can only move the followers. We cannot move our post history. So when I choose mastodon.social or any Mastodon server, am I not putting all my eggs in one basket again?
- serverholic 4y agoYes. Also whoever runs the server can read your DMs. This is also true of big social networks however those companies usually have access controls that prevent employees from accessing private data. Some random mastodon server isn’t going to have that.
- bin_bash 4y agoI don't understand why you're being downvoted. I'm not familiar with Mastodon's architecture but I highly doubt DMs have E2E encryption—so the server maintainers must be able to get to DMs. Correct me if @serverholic is wrong here.
- Andrew_nenakhov 4y agoWe maintain a free messaging server for many years and believe me, there are far more important and interesting things to do for a server operator than looking at some random user DMs. It is simply not interesting.
- distcs 4y agoSo the answer is yes, the server operators can look at our random DMs. You may not be interested in looking at them but some other server operator might. So it is a good thing to know this beforehand to know what we are getting into.
- adwn 4y agoNot sure if you're serious, or if this is some attempt at satire? If it's the former: Okay, it's great that you don't feel the temptation to spy on your users, but even the most basic understanding of human nature should tell you that this doesn't generalize to all (or even most) people and organizations that would run a messaging server, free or not.
- Andrew_nenakhov 4y agoI'm serious and I also know many operators of public servers. Unless you are somebody important/person of interest for various three letter agencies, no one cares for your messages. If you are such person, just run your own server and use e2ee. Other than that, enjoy the convenience and easy message syncing and server side search the unencrypted messaging brings.
- bin_bash 4y agoyikes. OK, then I'm definitely never using Mastodon. At least at Twitter and Facebook the employees have a strong incentive to not breach my privacy expectations other than me not being "interesting".
- Andrew_nenakhov 4y agoThat was precisely the same with every single forum or email server since the beginning of time. And you know what, the capability to log in from anywhere and read your messages trumps privacy concernts for 99% of users. For the rest there are ways to exchange information without risk of it being accessed by third party.
- serverholic 4y ago
- Andrew_nenakhov 4y ago> instead of YES WE SHOULD IMPROVE THAT. No, most likely we shouldn't improve on that. If you force an end-to-end encryption on all users, you'll introduce an extreme inconvenience for users so they'll have to do things like identity verification of their messaging partners, do fingerprint matching, and also lose the capability to easily sync messaging history between different devices. Or you could skip on major inconveniences like identity verification, turning your encryption into a security theater [0]. 99,9% of users want convenience and a warm fuzzy feeling of being secure, they don't want to exchange keys and do other nasty stuff that real e2ee requires of the. This was proven in force by Durov, who just promised that his app is the most secure ever, while, in fact, all regular messages in Telegram are unencrypted (except so-called secret chats), and I'm yet to receive a secret chat request in telegram from anyone. [0]: https://en.wikipedia.org/wiki/Security_theater https://en.wikipedia.org/wiki/Security_theater
- 0x20cowboy 4y agoDMs do not have e2e encryption. Don’t use it for non-public things.
- fsflover 4y agoI downvoted the parent, because they are missing the point of a public social network. It was never the goal of Mastodon to provide a place for private communication. Use Matrix for that. Mastodon is for speaking publicly.
- serverholic 4y agoA direct message is implied to have a certain level of privacy. By definition they are not public. Mastodon should at least have some way of indicating that the server owners can read their messages.
- allenbrunson 4y agomy mastodon account is less than 48 hours old, so i am not the best person to answer this. i will say this much, though: anything i write that i feel has value will always go onto a site that i control. currently, that's my blog with my name on it. if i'm forced to move to a new mastodon instance, i won't lose much.
- loudmax 4y agoYou should consider linking to your Mastodon profile in your blog. I didn't see it in that post, or in your "About" page.
- allenbrunson 4y agomy mastodon link is on the front page of my site. i decided not to put it in the article because i want to emphasize the phenomenon rather than my own small place in it. and who knows, maybe i’ll move soon, just to demonstrate for myself that it is possible.
- allenbrunson 4y agoseveral hours later: yep, i did, in fact, just move my account! it wasn’t exactly easy. not something i would expect a novice to be able to do by themselves. but anyone who is reasonably technical can do it.
- loudmax 4y agoYou created your account with mastodon.social. My mastodon account is with techhub.social. So your eggs are in that basket, but my eggs are in a different basket and others' eggs are in yet more baskets. You can argue that all of your own eggs are in one basket, but not everybody's eggs are in that one basket. Some narcissistic infantile billionaire could buy out mastodon.social and burn it to the ground, but the rest of the Mastodon network moves on. You'd have to relocate, which is a pain, but you're not relocating at the same time the rest of the world is relocating. Decentralization is resilient, not bulletproof.
- deleted 4y ago[deleted]
- Andrew_nenakhov 4y ago> Doesn't it make it effectively centralized? The word you are looking for is federated. Different Mastodon servers comprise a so-called federation, so servers belonging to it can exchange data between each other. There are many federated protocols, for example, email and xmpp are federated. Some server owners choose to not be part of federation, or refuse to connect to some specific servers in a federation. That's what happened to Gab a few years ago.
- distcs 4y agoThe word federated makes total sense. Thanks! The word decentralized was written by the author of the OP, not by me and that's why I needed to ask the folks here if Mastodon is really decentralized. Your comment clarifies it for me. So thank you!
- dekken_ 4y agoMastodon is part of the Fediverse. https://en.wikipedia.org/wiki/Fediverse https://en.wikipedia.org/wiki/Fediverse
- taurusnoises 4y agoMaybe a little sticky, but decentralization doesn't discount that there are nodes, or points where things gather. In fact, decentralization, as I've always understood it (coming from anarchism background), is that there is no central node to which all others are beholden. Rather, there are centers (plural). So.... At the level of instances (plural), no one is central. The network is decentralized, containing multiple centers, all (most) of which are connected through federation (the word "affiliation" is not too far off either). And, while yes, any one instance could be considered a "center" and thus maybe considered to be centralized, it really isn't. Decentralization is less about a single specific object or node, and more about how said objects interact and relate. Side note: I think when it comes to convos around decentralized networks, there really needs to be more investment in how they differ from distributed networks. In that difference is a ton of insight about how systems function, etc, imo. Personally, I'm much more interested in distributed networks.
- 4y ago
- zimpenfish 4y ago> We cannot move our post history. At the moment. There's good reasons why not[1] but those can be worked around if people come to consensus[2]. [1] Because it's a push system, you'd have to re-push all those posts from the new account and that's not even necessarily the same set of people they were pushed to in the first place, etc. [2] e.g the re-pushing can be obviated by having servers rewrite their local copies of statuses to the new account ID on receipt of an "A is now B" message. Obviously you'd need to make this unspoofable, etc., but the theory seems sound.