Unless I can unplug the WAN connection on my router and connect to your product instead, keep in mind that you haven't invented the next internet. You might be able to decentralize the worldwide web of HTML pages and hyperlinks, or invent another protocol that can be encapsulated in TCP/IP packets and ethernet frames, but the internet (the graph of inter-connected networks that speak common protocols) is still a fundamental requirement for your product, and the metadata associated with those stacks is still very real and trackable.
To that point as well, the internet already "works how real life works." Sick of Company X and the way their business treats employees? Shop elsewhere, remembering that it won't be as convenient with fewer choices. Sick of Google tracking the websites you visit? Use a search engine that doesn't track you, remembering that they probably can't pay as much for great engineers.
It's Conway's Law. We are largely constrained to create systems (including the internet) that mirror the organizational structure we're a part of. Yes, we can evolve and revolutionize occasionally, but it will always mirror "real life" because they will always influence each other.
> Sick of Company X and the way their business treats employees? Shop elsewhere, remembering that it won't be as convenient with fewer choices. Sick of Google tracking the websites you visit? Use a search engine that doesn't track you, remembering that they probably can't pay as much for great engineers.
Hard sell. There's a reason why the government has laws against monopolies. Especially when it comes to the internet, consumers tend to choose the best/fastest product over the most ethical one.
I don't know, the alternatives are getting better. Maybe not consumer grade, but usable, especially for a developer. For the past few years I've made a reasonable effort to use ethical software as long as it doesn't make my job too hard, and here are the results:
- Ubuntu is my daily driver OS, with Windows getting booted once in a blue moon to play some games
- Firefox for 80% of my browsing (the other 20% is Chromium on a Chromebook, which seems to run faster than FF even in an Ubuntu chroot with crouton)
- Thunderbird and a plain ol' IMAP mail server for email
- Maybe half of my messaging has moved to Signal
- Searx.me for web searches, sure I'm using the Google results more often than not, but at least my queries are anonymized, and switching to other providers is easy
I started a business on a very boring, conventional tech stack that gets a lot of hate on HN--PHP and WordPress--but it's a free and ethical stack, and I sleep better at night because of that. I gave our latest hire most of the same desktop software I use, and so far no major problems.
I'll grant you that the UI of some of this software is a little creaky, but I get by, and overall I'd say most of the nasty bugs we have to deal with in our toolkit are in closed source SaaS stuff.
Some notable unethical holdouts include occasional Skype/Hangouts calls, Slack, Google Docs, and Dropbox. Also a bunch of small-time SaaS products. But give me time.
Why do you consider "small-time SaaS products" as "unethical", if I may ask? They may be "potentially unethical" since you don't know exactly what they are doing with your data, but it's not for certain.
This is a deliberate oversimplification, but in order of most to least concerning, these are flags which get raised in my brain most often. If they get raised then I consider the company's ethics questionable and when time permits we evaluate alternatives.
- The company supports or enables injustice or human rights violations - The company collects a lot of personal information and does creepy or obscure stuff with it
- The company does not release the source of its products
Virtually all SaaS gets dinged because of #3, and in a perfect world we'd somehow replace them all with self-hosted, open source alternatives, but that's a tall order.
I'm not a zealot about any of this, I just make sure I set aside a little time aside every quarter to evaluate ethical alternatives. Legitimately "doing no evil" is absolutely a benefit I'll pay money for.
For personal mailboxes we're running exim on a managed VPS with a dedicated IP at a small hosting company. They have very diligent customer support and appear to keep their IP allocation clean, as we've never had problems with our emails being filtered as flagged as spam. They generally handle patching and configuration when we ask them to, or assist us when we want to do it ourselves.
For volume mailing we use ESPs like Mailgun and Sendgrid. Occasional deliverability problems are a fact of life at those.
Yeah, that's a good point. The funny part is that it's the very consumer choice we champion that eventually leads to a total lack of consumer choice. We choose the best, they're rewarded, they dominate, choice disappears, they're free to stagnate without repercussion.
Combatting this, though, seems to be one of the fundamental problems with combatting corruption. If there is a bottleneck in value, then the controllers of that value can demand something of greater aggregate value in exchange for access to it.
Dunno about this. Duckduckgo has become my default search engine at this point for ethical reasons. I just bought a new Linux laptop to replace my surface, and have just about severed all ties with MS/Apple junk at this point.
Outside of programmers, I don't know anyone who takes the time to do this. Be careful of the Malkovich Bias--the assumption that most people who use the internet use it like you do. Most people don't give a second thought to Google and Facebook selling their data... or in insert most countries in the world their government watching and censoring them.
> Unless I can unplug the WAN connection on my router and connect to your product instead, keep in mind that you haven't invented the next internet.
I realize this isn't exactly what you're talking about, but it is indeed possible to unplug your WAN connection and plug something else in instead. Amateur radio operators do this amazing and fun thing with self-discovering, self-linking mesh networks. Great fun to learn and explore!
HSMM-MESH is cool, really really cool, and people should definitely go check it out, but to quote the website you've linked:
it is NOT a replacement for your home internet connection
being an Amateur Radio network, it can only carry traffic that is allowed under FCC Part 97 rules
several types of internet traffic violate these rules
also, it is NOT a replacement for your home internet connection
finally, it is N O T a replacement for your home internet connection
and by the way, it most certainly CANNOT be used in any way with your business network
I understand much of the traffic you'd usually send over the internet is not permissible over broadband hamnet.
Anything of a commercial nature, yes. You can still discuss, talk, etc. about anything else. If you're going to use a mode of communication so drastically different and with completely different content rules, most of your traffic will necessarily fall in those rules. Just don't expect to put up a blog with AdWords about how to run a startup. :-p
Four years ago, Moxie Marlinspike offered a good explanation of why this "vote with your feet" approach doesn't really work, at DEFCON 18. His talk is called "Changing Threats to Privacy" and I highly recommend watching it: https://www.youtube.com/watch?v=DoeNbZlxfUM
This almost assures some quite terrible conclusions in the long-term:
When it becomes technologically possible to interface electronics into our brains, corporations will have almost unprecedented opportunities to do some really terrible things directly when the world becomes socially-pressured to be neurally-connected.
I say "almost" because the manufacturing of consent and desires exist now and it is popularly believed to "apply other people but never me," a direct connection has the potential to make this manipulation cheaper and stimulate the brain in ways a glowing screen looks like banging rocks together.
Muneeb from Blockstack here. We're not reinventing anything at/below TCP/IP. That stack works fairly well and can function in a decentralized way.
We are replacing things above TCP/IP like DNS, Certificate Authorities (CAs), how data is discovered, data silos, and dependence on remote servers for running your apps.
>Sick of Google tracking the websites you visit? Use a search engine that doesn't track you....
I do use alternative search engines; however, look at the traffic on just about any website and you'll see Google ip traffic spewing in all directions. I'm quite confident that tracking still occurs, regardless of how I get from one site to the other. This can be locked down a bit, but not 100% and not without effort and maintenance.
I think your right on about google tracking. you visit a website and they're probably using google analytics or google ads somewhere, or it's a 3rd party feeding data to some form of google ad network.
Baidu is good if you like having Beijing filter your results. I just did a baidu search for "tiananmen square" and the top answers all said "Tiananmen massacre a myth".
>Sick of Google tracking the websites you visit? Use a search engine that doesn't track you...
You have fundamentally misunderstood how Google tracks your visits. If website uses AdSense, they track you, if website uses Google Analytics, they track you, or Google fonts or scripts or what ever, they track you.
This means that the problem is much larger and the solution is not very simple.
I don't think it's that hard, just email the people at http://viewdns.info/reversewhois/?q=dns-admin%40google.com for the full list of Google's domains and add it to a domain blacklist. Then you won't send any data to Google at all. It might break some sites, but sites are broken all the time...
I'm very much aware of all the free tools provided by large companies that just end up reporting back to Google, Facebook, etc.
There are ways to prevent those requests, however. Install a chrome extension to block all adsense & analytics requests, fonts, etc. Black hole their IP addresses or DNS. There are plenty of concerted efforts to improve anonymity despite these issues (e.g. the TOR browser).
There are varying costs to these approaches but it's not impossible, or even that hard if you trust the Tor team more than Google.
I'm not saying there aren't additional avenues worth investigating, but that you nearly always have to decide how much efficiency/cost you're willing to pay for anonymity.
They can tell that a particular IP sent a request to their servers, but they can't correlate different requests to the same underlying entity without cookies. Simply saying "they track you" is misleading.
I guess this was about scripts and fonts (because others are obvious cases).
I did a test, beside IP address also User-Agent, Accept-Language and Referer headers were sent.
Perhaps not good for very precise finger printing but still more that you claimed and can be cross correlated with other requests with more precise information.
Google has claimed that they do not use this cases for tracking. One can believe this statement, or one can prefer to not do.
How can you cross-correlate them? Most people are viewing the internet from behind a NAT, so there isn't a one-to-one mapping between IP address and person.
Pretty much all of those fingerprints require the ability to run javascript on the client side. Getting static content from Google doesn't allow them to do any real fingerprinting. Obviously, if you're executing arbitrary code provided by Google, they will be able to track you pretty much always.
You cross correlate IP address and request header parameters (such as user agent, language etc) with previous requests (or future requests) with the same configuration but with known identity.
It does not give you perfect match but is much more precise than just the IP address and with limited number of users would be probably sufficient to distinguish different users behind single IP address.
I think you're overestimating the entropy of the request header parameters (assuming no cookies). How are they going to distinguish me from all the other English-speaking Windows users using Chrome? True, it is better than nothing, but I'm not sure what you could do with such low quality tracking data. You might be able to do something with that, but I can't think of any possible way to use that to violate my privacy.
To clarify it further, for the case I described, I did not assume a user that actively tries to suppress the signal to Google, but assumed a user that only does not visit Google search (or any other its services).
I then assumed that at certain moment this user can be uniquely identified (by AdSense, Analytics etc).
Then accesses to pages without active tracking but with links to Google fonts or other passive API can be still identified with high confidence given the access happens from the same network.
I do not know if such extra signal is interesting for Google, but it can be acquired. Also mind you that using an ad blocker is also a signal and can be assumed from the access pattern.
The same logic applies also to an user who uses ad blocking but still uses limited Google services.
Again I do not know how much Google finds this kind of signal interesting but it is possible to collect it.
You're overthinking this. Blockstack is just throwing out features that the indigent will purchase shares in during an 'ico' the validity of the claims don't matter. This is what blockchains are for.
> To that point as well, the internet already "works how real life works."
Power corrupts, and absolute power corrupts absolutely? Or did you mean, you can fool some of the people all of the time, and all of the people some of the time, but you can't fool all of the people all of the time ...
I don't follow your argument. You are saying that because we have nearly a tree structure within the workplace, the Internet will approximately have nearly tree structure?
Seems that it's just a matter if the most efficient structure being this way for both cases rather than us mimicking the workplace in the structuring of the Internet.
This actually isn't true; you can invent organizations of the imagination and mirror those. This "imagination driven programming" is actually quite dangerous and tends to devolve into state secrets and so on since you are solving the problems created by people who "don't exist" but may in fact have lives that are SURPRISINGLY SIMILAR to the lives of people who are doing jobs that are better kept secret.
So you can get around the law...but only by risking the integration of something that should be kept secret into the organizational structure...which makes its way into your system. Most people aren't willing to cross that threshold.
So Conway's law is true for most people, just not all.
If you want to think about it from the adversarial point of view, you can say that all programs are designed to transform or destroy organizations; programs mirror organizational structures because people want to determine the "resonant frequency" of an organization and understand its "social vulnerabilities" in much the same way a physical structure has structural vulnerabilities.
One person or AI can do such "imagination driven programming" to mirror any organisation. so i guess organisation of n people can also mirror any organization they want, if that organization is more complex than theirs. Organization can also use some kind of obfuscator to change program structure to not mirror their organization and also mirror less complex organizations.
I don't understand how this is dangerous. can you please give an example? I guess if you mimic more complex organization it may be dangerous.
To that point as well, the internet already "works how real life works." Sick of Company X and the way their business treats employees? Shop elsewhere, remembering that it won't be as convenient with fewer choices. Sick of Google tracking the websites you visit? Use a search engine that doesn't track you, remembering that they probably can't pay as much for great engineers.
It's Conway's Law. We are largely constrained to create systems (including the internet) that mirror the organizational structure we're a part of. Yes, we can evolve and revolutionize occasionally, but it will always mirror "real life" because they will always influence each other.