Egregoros

Signal feed

Timeline

Post

Remote status

Context

2
SLUFI is published!

https://thegoodwork.substack.com/p/slufi

A Simple, Lightweight, Unopinionated, Federation Interconnect.

The problem: While numerous network transports exist (cjdns, Yggdrasil, I2P, Tor, etc), and numerous name services exist (Namecoin, ENS, Unstoppable Domains, PKT, etc), almost all federation takes place over ICANN+IP because we currently have no way to federate across network boundaries, and ICANN+IP is the only thing that everybody has.

I claim that there is no possible solution SIMPLER than SLUFI, except with central authority or PRECIPITOUS loss of security. Furthermore, I claim there is no possible solution that is more secure than SLUFI, except with something like a blockchain and a PRECIPITOUS loss of simplicity.

So while I do not think this protocol is complete (yet), I do think SLUFI is the only realistic starting point for reaching a solution to this problem.

Tagging some people who might be interested:
@sun
@lain
@p
@mint
@jaff
@silverpill

I probably forgot a bunch of very important people, apologies in advance...
I'm certainly well aware of this...

However, there are certain necessary complexities and trade-offs of every alternative networking solution, for example you need some kind of coins to register a domain on Namecoin, ENS, PKT or Unstoppable.

Furthermore, Tor, I2P, cjdns, and Yggdrasil require installing unique software on your machine, there is configuration and sometimes security considerations, and everybody has their preference.

SLUFI does not attempt to replace any of them, but rather to make ActivityPub able to bridge over ALL of them...

Replies

12

Computers in general are awful at protecting anonymity, this fact is not lost on me. The purpose of SLUFI is not so much to protect anonymity - though some of the networks that would be supported do claim this is their goal. The purpose of SLUFI is eliminate the single-point-of-failure that is ICANN and the PKT certificate authority system.

And some fundamental information theory problems: In any given context you MAY regret deleting, you (generally) never regret not deleting, so the preference is never delete...

BUT, you absolutely may regret it when an entire ecosystem adopts that principle...
@rees @Yoruka @p @lain @silverpill @jaff @cjd @mint @sun It's more of a way to bypass the broken DNS and especially CA system. But still imo if you can configure a few trusted slufi nodes to get DSRs from, you can install two packages, and configure one anyway. The point that you need two external daemons to achieve federation over two clearnet and some overlay network is kinda moot when you already need to configure a list of proxies and check whether they are trustworthy.
The minimum implementation does not require configuring any proxies, or actually ANYTHING other than trusted nodes.

Furthermore, it's designed to be integrated into the ActivityPub server because otherwise nobody's gonna install it anyway.

I think it's acceptable that ActivityPub implementation developers add their own trusted SLUFI nodes as defaults in the configuration, so that it will Just Work out of the box even if the admin touches nothing.

So basically what we're talking about from an administration perspective is you upgrade and maybe you check a box that says you consent to use SLUFI bridging, and then you start seeing posts with names ending in .onion, .i2p, .bit, .pkt, etc