This is the answer I was hoping for. I know of at least one solution for your ISP concerns. I think it will work very nicely.
ISP's can obviously block anything they want to block. But with bigger bandwidth and things like VOIP services on the rise I would think that means letting some regular customer UDP traffic pass in/out. In your opinion, would you think that most ISP's would not allow customers to keep some long-term UDP "connections" open on any port? I have not had any trouble with this in the places I've tried, but it's hard to know what most ISP's do. Honestly I just can't see any reason they would block a low number of low traffic UDP peer-to-peer connections per customer (the customer's social network), when you consider they are allowing things like Bittorrent which are huge network hogs by comparison and are being blatently used for the sole purpose of downloading bootlegged entertainment media from random strangers.
The interesting thing is that if we can achieve this sort of peer-to-peer social networking, concerns about email servers being online, at least with respect to mail that you send to people on your social network, may turn out to be less of an issue. Why do I say this? Because the reason you want your email servers to always be up is so you can receive mail as timely as possible. Ideally you would like to have near "real-time" mail. Otherwise, if time is not an issue, then storing messages for pickup later on, e.g. in the cloud, should be fine. But if you and I are both on a private peer-to-peer social network, all that's required to send "real-time" email (or whatever format of bits you choose) is that we are both logged in. We might leave low power machines on in order to stay logged in over long periods. I would guess this might be a much more popular form of "email" between friends and family.1 Remember the UNIX programs talk and finger?
1. Obviously there is no spam. The only people who can send and recieve mail to members of the peer-to-peer private social network are those who are logged in. Spammers can't log in. Nor can they be bothered to try to crack their way into myriad disparate small p2p social networks.
As someone else said, why are there passwords in the logs? If these were submitted via POST (multipart), they would not be visible, right?
Then there's the issue of permissions. That's how these logs were visible. Why can't we scrap this idea of permissions? Plan 9 did it. The shared computing era ended long, long ago. If permissions are too error-prone for even the admin at IEEE to get right, how can users ever be expected to master permissions? They're not even being used for their original purpose - use on systems that were intended to be shared. Instead they're being used on systems that are not supposed to be shared with anyone. Think about this. Why do you need to have permissions on a system that is _not meant to be shared_? Who would introduce that into the design? It is a (poorly) repurposed relic.
As for plain text passwords, unless I read this wrong, the passwords were gleaned from server logs not a password database. It seems that people want to discuss "storing plaintext passwords" even though that had nothing to do with this incident.
Yeah, but who said anything about writing drivers? Very few people can do that. How about just really basic stuff, like how to not have ads for Amazon popping up when there is no need?
The driver issue is, in my opinion, the single biggest problem with not using Windows or Mac. If you just jump right into that issue i.e. that the latest driver for your peripehral is not going to be available for some time and ignore all the other benefits of Linux and other UNIX-like systems, then you could pretty easily conclude these systems are worthless. Hardware manufacturers don't care about them.
They only care about Windows and Mac.
But we all know these other systems like Linux are far from worthless.
Clearly, there is some middle ground.
You can still do a heck of a lot without the source code for the 2012 driver for Whiz Bang Hardware Component.
If Canonical and Ubuntu decided not to accept any binary blobs I wonder if the "strides" would seem as huge.
Do you think the possibility of "always on" computers at home (e.g., running low power ARM CPU's) is a real one?
Would this change the way we think about "reliability"? (Of course the canonical example of the need to be "always on" is email. We've come to expect that the server handling our mail is always up.)
This makes it easier for me to understand your comments on P2P. Thanks for filling me in.
I might have guessed (incorrectly) that the reason you would suggest the cloud over home is security. Is it easier for me to secure my laptop behind my home ISP connection (by just disconnecting it; or relying on the ISP's DMZ, NAT and the lack of any programs listening for connections) than it is to secure a cloud server that is always on, always connected and always listening for connections?
Random thought: Does anyone ever use Wake-On-Lan anymore? Could it be useful in some present day context?
Yes, I'll admit I did jump from HTTPS to P2P. Although, I'm assuming that Tent is capitalizing on the term "decentralized" as in P2P.
I do believe in the idea of using the cloud and having your own server. I hear you. I cut the knot myself. I'm just not sure that such use of cloud servers has to include storing lots of (sensitive) data on them. We all know that's been the marketing push. But I'm not convinced it's the wisest thing to do.
Think of it this way. That cloud server you pay for gives you a reachable IP, something maybe your ISP does not give you. What can you do with a reachable IP? You can use it to traverse NAT. And once you can do that, then many possibilities open up to you. The internet becomes vastly more functional.
From perusing the website in your profile some years ago I know that you were once interested in P2P. Have you "given up" on it?
If you and I have a peer-to-peer connection and I queue up some content for you and possibly others who are on our private network, and you choose to retrieve it, is that "hosting"?
Are these rules about what belongs in the cloud and what does not published somewhere? Who drafted them? Marketers? Do they apply to both home and business consumers?
C'mon.
(Now there may be some interesting uses for the cloud, for sure. But to suggest I have to upload everything I want to send you to someone else's server in "the cloud" before you can access it makes little sense, unless of course you are working for a cloud provider.)
How do users behind NAT run their own tent servers? If they can manage to run their own HTTPS servers from behind NAT, if they have those skills (not to mention a reachable IP), then why do they need tent? Couldn't they just host all their content on their own server? I can see tent as providing some sort of coordination of user data hosted on different servers, but I'm not seeing how tent enables users to host their own content and have full control over it. Maybe that's not the goal?
Correct me if I'm wrong but what this tent idea seems to lead to is a proliferation of tent service providers, not independent users running tent servers behind consumer ISP accounts. If that's true, then how can we be sure these service providers will not adopt the same sort of annoying monetization strategies of providers like Facebook and Twitter?
By no means am I suggesting tent could not be useful. I just want some clarification of what problem they are trying to solve. (There is no shortage of problems to choose from. :)
Is there really even a "right" or wrong" in this process? Isn't it more of a matter of being able to support your choice of design trade-offs with cogent arguments? And being able to persuade others?
There is no doubt some amount of "Why" questions that a developer can ignore. The ones that come from people who have not done their homework and thus have failed to locate the (obvious) answers. But any developer who thinks he can ignore each and every "Why" question, even if he's highly competent, is not someone I would trust with really important stuff. Is it that he is afraid of being "wrong"? That he does not have a good argument to make? Is he hesistant to say, "Honestly, I don't know. That is just the solution I chose." I don't see anything "wrong" with that. No single developer is going to be able to think of everything, of every possible solution or scenario. I thought that is an important reason behind something like code review.
The thing with LFS is that it would cause Linux users to learn. Not necessarily a bad thing. And I would predict it could lower their tolerance for the lots of the garbage that many ditributions force on them. (Like this brilliant move by Ubuntu!) Who knows, it could lead to a more DIY capable userbase.
They would not have to ask anyone how to remove things or plead with decision-makers to implement their desired changes, they'd just do it themselves.
But yeah, from what I know the Arch Linux distribution imposes a very minimal amount of "pre-configuration".
I've always found it easier to add stuff to a bare bones OS configuration than to remove it from a pre-configured one (you have to thoroughly understand what you're removing first; it's easy to break someone else's delicate Rube Goldberg contraption). But maybe that's just me.
It's great to see Nature, itself a high-priced journal, running this story.
arXiv.org really makes downloading papers a breeze. If only it were so easy in other discliplines. It's a lot easier than downloading articles from, say, ScienceDirect. The latter is, despite its name, a lot less "direct" than former. Just count the HTTP redirects and the number of domain names looked up. And many journals seem to have their own idiosyncracies vis-a-vis downloading. arXiv is by comparison beautifully simple and reliable. It has a nice consistency about it.
If you wanted your personally identifiable data protected from public access (being cached by search engines), then presumably you would not submit it to a web site that is open to the public (not password protected).
If Craigslist changes its name or sells its SF apartment listings to some site with a name you do not like, what can you do? Answer: Nothing, because you gave them an exclusive nonrevocable license to your data. If you really wanted control over your personally identifiable data then it would probably be wise not to submit it to a site that gets scraped and cached by Google (from which anyone can make fair use) and certainly not under a license that gave you no control over the data after it's submitted. You would want a site that has some sort of protections like passwords, that allows some degree of pseudo anonymity so your name is not embedded in an evergreen search engine cache; and you would want the right to tell the site to remove/delete the data at your direction, if that became necessary (e.g. in your example scenario).
In short, Craigslist really isn't in the business of protecting your data for you. Its terms are what they are because it's seeking to protect its own business, which relies on your data.
I would expect that many users would feel this way.
I can guess why. But could you tell us specifically?
Assume for the sake of the question that whereever the data may appear on the web, it would always have a "Source: " line to indicate its original source, i.e. the site to which you submitted it. Assume that the integrity of the data could also be verified, e.g., through a digital signature.
I fail to see a qualitative difference between "mobile", "laptop", "desktop" or "stovetop". Those are just form factors. They are all computers. We can put a computer inside almost anything nowadays. What matters to me besides what's on the motherboard are peripherals, drivers and access to networks.
Things got smaller. We all knew they would. But they should not become less functional. (Hello Apple.)
"most of the complexity burden of the web is purely gratuitous"
To think that some people are actualy getting paid to make submitting and retrieving data using web overly complicated and annoying is one of those things I try not to think about. The standards idea clearly is not working if it is being interpreted as a mandate for needless complexity to keep web developers entertained. Instead we hear web developers complain that standards are being ignored because some browser will not support their desired gratuitious complexity. I would say they've lost the plot but I'm not sure there ever was a sane plot to begin with.
If Craigslist can assert copyright protection over classified ads and can make people grant exclusive licenses to the ads they submit, then why didn't newspapers do this before the web? Shouldn't there be a nice line of precedent for Craigslist to cite in its Complaint?
I think those web developers who actually think they "own" UGC may be in for a rude awakening if something like this ever goes to trial. As a UGC site they are providing access, and that's all. There may soon come a day when users will not need third party websites in order to provide access to data they want to make public. Web developers should consider themselves lucky if they are running a UGC site and managing to make people believe they, not the users, own the content. Cease and desist letters alleging copyright infringement claims that have no legal basis (where is the case law that says anyone can copyright classified ads?) will only work for so long.
ISP's can obviously block anything they want to block. But with bigger bandwidth and things like VOIP services on the rise I would think that means letting some regular customer UDP traffic pass in/out. In your opinion, would you think that most ISP's would not allow customers to keep some long-term UDP "connections" open on any port? I have not had any trouble with this in the places I've tried, but it's hard to know what most ISP's do. Honestly I just can't see any reason they would block a low number of low traffic UDP peer-to-peer connections per customer (the customer's social network), when you consider they are allowing things like Bittorrent which are huge network hogs by comparison and are being blatently used for the sole purpose of downloading bootlegged entertainment media from random strangers.
The interesting thing is that if we can achieve this sort of peer-to-peer social networking, concerns about email servers being online, at least with respect to mail that you send to people on your social network, may turn out to be less of an issue. Why do I say this? Because the reason you want your email servers to always be up is so you can receive mail as timely as possible. Ideally you would like to have near "real-time" mail. Otherwise, if time is not an issue, then storing messages for pickup later on, e.g. in the cloud, should be fine. But if you and I are both on a private peer-to-peer social network, all that's required to send "real-time" email (or whatever format of bits you choose) is that we are both logged in. We might leave low power machines on in order to stay logged in over long periods. I would guess this might be a much more popular form of "email" between friends and family.1 Remember the UNIX programs talk and finger?
1. Obviously there is no spam. The only people who can send and recieve mail to members of the peer-to-peer private social network are those who are logged in. Spammers can't log in. Nor can they be bothered to try to crack their way into myriad disparate small p2p social networks.