5 ms·
There isn't much left of the free Internet anyway. Search engines no longer work, all discussion forums are ranked/censored by interest groups, mail delivery is
by asjgGa6 4mo ago
There isn't much left of the free Internet anyway. Search engines no longer work, all discussion forums are ranked/censored by interest groups, mail delivery is between large entities.
Maybe we need an alternative set of root servers for a free Internet.
- dredmorbius 4mo agoAnd content is increasingly produced for, and by, machines. Human initiative and/or access is increasingly incidental. It's easy to create an alternative. The problem isn't that, it's keeping that alternative clanker-free. (As well as free of all the other enemies / plauges on the useful, generative, Internet.)
- 2001zhaozhao 4mo ago> keeping that alternative clanker-free which brings you right back to verification...
- dredmorbius 4mo agoPerhaps, but in both cases, I think that the principle problem is attempted control at the wrong portal. Rather than individuals or devices, residential / mobile / business service providers should be able to vouch for personal traffic and be in a position to validate patterns of use without undue profiling of specific activity. That is, just looking at the encrypted traffic patterns (rather than MITMing SSL/TLS or other secured comms) should show usage that's typical vs. atypical / malicious. Traditionally, service providers of all stripes (email, ISPs, Web, etc.) seem to have focused far more on ingress security than egress security, or potentially malicious traffic from within their own networks. That's got to change, it's ultimately a hygiene question. For residential and mobile Internet, accounts are managed at either the household or individual level, and it should be possible to provide attestation and reputation management (as well as, perhaps, broad-based subscription access to compensated content) at those levels. For commercial access things get more complicated, particularly where a location might provide public Internet access (e.g., public WiFi), or have a mix of human and system-generated traffic at an office, commercial, or industrial site. Still, there should be both well-established patterns of use and indications of anomolous or malicious traffic possible here. Another option for smaller human-scale networks (e.g., Fediverse / Mastodon / PeerTube / Pixelfed / Lemmy / WriteAs networks and the like) is a mix of harder authentication (Yubikey or NFC-based wearable authenticators, perhaps) as well as a more manageable human-scale moderation (1:1,000 or 1:10,000 scales far better than 1:1 million or 1:1 billion services), allowing for both oversight and keeping the opportunities / benefits of malicious use limited. The comment I'd originally responded to had me thinking of under-delivering federated systems such as Gemini (the lightweight Web protocol, not Google's AI) or Diaspora* or countless web boards and wikis which ended up overrun by spam and abuse. Simply saying that you're going to re-invent things at small scale in no way means you'll succeed. The ecosystem's changed, the pathogens are far more numerous and capable. Modern systems and networks (social or otherwise) must face those facts head on, and not ignore them or pretend they don't exist. I think we're going to end up with some form of cost-based (though not necessarily financialised) reputation management systems. I'd very much like to see those not being terribly invasive of privacy, or putting extreme barriers to those with limited means or technical knowledge. It's a tough problem all the same.
- cobertos 4mo agoWould be nice to see something referral based. If you don't like X, block them. If X invited Y and Z and their invites behave poorly, you can block the whole tree. Kinda like lobste.rs referrals but for wider internet I guess the correlary would be like how you can block an entire ASN if you find a lot of abuse from it, but at the human-network level.
- AuthAuth 4mo agoJust peeping Fediverse for a few years i can only imagine how toxic that would get. It would be a constant ideological war.
- dredmorbius 4mo agoThere are several problems with this. Aside from social dynamics, a chief issue is that if you're relying on this as a mechanism for content filtering, personal relations have low predictive value. E.g., I may really like a person's content, but not their curation or referrals to other accounts. Conversely, I might not care for a person, but their recommendations may be excellent. More common might be the case that a given account produces little or no content of their own, but makes reliably predictable (either good or bad) recommendations, which would be useful for further filtering. Or the highly verbose individual who emits a constant stream of near-drek, but an occasional diamond. Content production, content curation, and talent spotting are all distinct skills. Success or lack in any one says little about the others. This is where Bayesian indicators (including relationships and referrer / invite relations) would probably be more robust. That said, tainting an entire invite tree is likely useful, with a caveat that if a particular invitee has an independent, untainted, relation, they might be worth following. In practice what I've found most useful is to have a pretty tight primary list of follows, ~50 or fewer, and a slightly broader secondary list. Allow recommendations be default (that is, re-shares / boosts), but curtail those too if problematic. Be quite liberal in blocking / muting anything in the least bit annoying or problematic. Or participate in a selective group with excellent moderation. HN isn't quite there, but it approaches this ideal more closely than any other major forum I'm aware of presently.
- EarlKing 4mo agoVerification tells you that a human being is behind it, not that a human being made it.
- dredmorbius 4mo agoIf you can at least attest who is responsible, other tests for AI-generation might be applied, with reputation following from that. Sadly, that's bullshit most of us didn't ask for, and it's turning up all over the place, e.g., among book and short-story publishers, journalism, academic publishing, as well as blogs and social media.
- EarlKing 4mo agoAttesting who is responsible is more of that "bullshit most of us didn't ask for". I'm not interested in identifying myself so some cretin can know whether I am, or am not, an AI... particularly when the vast majority of posters on any platform act like NPCs anyway.
- beej71 4mo agoThe trick is to stay small. If your network only has a few millions of people, nobody targets it.
- tumult 4mo agoNot true at all. Even small, insular, just-a-few-hundred users PHPBB-style forums have to run Cloudflare or Anubis to try to stem DDoS-style scraping, and have a constant patrol of moderators to stop AI spam posts.
- pocksuppet 4mo agoNot true. You can also make your code fast enough so your server doesn't get overloaded by three requests per second. Then you can just handle the requests.
- tumult 4mo agoI agree with you that the PHP forum software is not fast at all. But, try hundreds of requests per second, including requests that require text searches. Also, uh, how does speeding it up that help with the AI spam? (Sorry, I should have emphasized that part of my most more, since that's mostly the topic of this sub-thread I was replying to.)
- dredmorbius 4mo agoThere are multiple facets to the problem. Technical site performance is a very small part of those. The disruption, manipulation, and most of all erosion of trust which bad-faith actors create (AI or otherwise) are the most serious issues in my experience. The concept of "evaporative cooling", in which a platform starting to go bad sees an accelerated departure of well-intentioned, high-value participants. See the original article from 2010: <https://web.archive.org/web/20101012105003/https://blog.bumblebeelabs.com/social-software-sundays-2-the-evaporative-cooling-effect/ https://web.archive.org/web/20101012105003/https://blog.bumb...> (HN discussion: <https://news.ycombinator.com/item?id=1777665 https://news.ycombinator.com/item?id=1777665>). And an interesting follow-up, 2015: <https://blogs.cornell.edu/info2040/2015/10/14/the-evaporative-cooling-effect-in-social-network/ https://blogs.cornell.edu/info2040/2015/10/14/the-evaporativ...> (HN discussion, from 2025: <https://news.ycombinator.com/item?id=42597962 https://news.ycombinator.com/item?id=42597962>).
- 1970-01-01 4mo agoAlready exists: Opennic.org
- smitty1e 4mo agoThe future is balkanized. Occasional communities may survive in a walled garden fashion. Sorry, Tim Berners-Berners-Lee.
- gorgoiler 4mo agoOutbound mail gets harder every year as opaque reputation systems flag mailer daemons as false spam positives. Inbound mail on the other hand — notably, the OG form of Internet identification — is very achievable for a stick in the mud to set up. Losing one’s Gmail account would likely have very little impact on one’s ability to send mail, but no longer being able to receive mail at a given address can be devastating. Set up your own domain!
- NoMoreNicksLeft 4mo ago>Maybe we need an alternative set of root servers for a free Internet. Can't even do that. We'd need (ultra?) stable IP addresses, and the entities in charge of those don't hand them out anymore. We've sort of been cut out of the basic infrastructure to let us build stuff a second time.
- pocksuppet 4mo agoYou can still get a block on the grey market for (I believe) currently a 4-digit payment, which is not free, but it's quite accessible if you have any serious usage at all. (It will be officially transferred to your name - there's nothing grey about the blocks themselves - the greyness is that RIRs officially forbid selling them, but they can't really do anything to stop it and they don't forbid buying.) IPv6 blocks are still available from RIRs and you don't really have to care about anyone stuck in the 1980s if you don't want to. Also each of the root servers is itself run by a different organization. If you had some clout, you could ask them to also host your alternate root server on the next IP address. Half of them are anycast blocks which means they likely have 253 addresses free as anycast blocks aren't really shareable.
- Bender 4mo agoI would suggest that we should not conflate the internet with these corportate platforms. The internet still works fine for now. I can still stand up my own DoH resolvers, forums, chat servers, email servers, DNS servers, vpn servers, etc... Many social circles are bound to have a tech-nerd one or two layers removed. That used to be a pejorative. The hardest part is the psychology. People think they have to be on the big platforms as that is where their friends and favorite streamers are. Willpower can bring back the old platforms onto the current fast internet. Critical and free thinking people can choose to ignore the big platforms if they wish. People can go to local stores to buy most things. There are arguments for and against all these points but I am choosing the aforementioned options and accepting the psychological challenges. People can use old style self hosted platforms as a "fallback" and once people realize it is more private and they can speak freely amongst their friends it can get comfy real fast. Glowies are seething. Some friends and I have private forums and chat servers. We talk shite all the time about Reddit threads yet none of us have Reddit accounts. We talk about HN threads, brain rot on Twitster and many other platforms free of censorship, free of voting brigades, people trying to force narratives, etc... Oh and most important, free of "AI".
- HerbManic 4mo agoIn a way it is the bad players that are ruining it. Yeah I can setup all manner of servers for this stuff, but the instant I miss a patch or a patch is late to be developed and you can be compromised in no time. And unfortunately it just becomes a game of endurance between you and the army of folks trying to crack systems open. I have said it for decades, if there weren't bad players then we wouldn't need any of this security. That is a very utopian idea. I have thought that a way to put people off is to have such an anaemic server that they wouldn't bother. Like a tiny RiscV board running Haiku that delivers basic HTML and email. There is little incentive to raid that thing. I haven't thought this idea through much however.
- Bender 4mo agoFor what it's worth I have been running my own things since the 90's and not yet compromised. I disable the CPU mitigations and have a minimal firewall configuration. I do keep things patched and keep an eye on news regarding the public services I run but only enough that I can still call it a hobby. I try to only expose daemons that have been battle hardened on the internet for decades. In the early 2000s I ran phpBB and that was a little risky and did require hardening php.ini There really isn't anything utopian however, it's just a hobby and a way to let friends communicate without big brother putting their peanut butter in our chocolate. If you don't feel comfortable tinkering then of course don't. Never feel pressured. One can always start off sharing their services with a few friends and not advertise it globally. Find a hacker friend that can help pen-test your stuff. Perhaps even restrict access to your friends IP addresses or the CIDR blocks of their ISP's to limit access. Or use wireguard to restrict access to a VPN. If it's a web daemon just adding simple authentication with obscure usernames and good passwords in front of it will get nullify most of the bots until one is comfortable sharing it with the world. Probably one of the riskiest things I have set up was just this week exposing Unbound DoH to the internet. Unbound has had a handful of security issues in the past. The HN crawling bots are getting confused by this weird thing listening on port 443 but they just can't figure out how to connect to it. If it gets popped I will just nuke that VM and revoke the cert. There's nothing sensitive on it.