giovedì 22 gennaio 2015

Why I do not support ind.ie anymore

Some time ago, I started sharing and "liking" links from ind.ie. This is because I totally agree with the motivations and the goals of the project, relating to provably private social networking, file sharing, and communication. Now I have to do an unpleasant thing: RETRACT my recommendation.

The reason is, they decided to start by focusing on a single platform, and a proprietary one, which is only supported on proprietary hardware. This decision is not just questionable, or debateable, in the context. It's wrong.

Software aimed at being a private communication platform must first of all be open source, and that's what they are doing, but second, it must be portable. This is because if you find out, or believe, that your hardware or operating system is bugged (on purpose or not) and leaks your private conversations, you must be able to go to a different vendor, chose a product that you consider better, and recompile the product in order to access your data and contacts again. That's not ideology; that's what you technically need, to decentralise power and be on the safe side of things. If their software is not portable, I don't see why I should even consider using it in the future.

Giving money or effort to an open source project is an investment of the whole society, and I think we all should do it more often, but what do I do with the source, if I can't even compile it, since it's written for a proprietary hardware/software combination? I can imagine parts of the software will be portable, so we all could hack alternative interfaces for a product. But why should I accept to be on the wrong side of the technological gap, that is, be unsupported from the maker, when I am supporting the product as an user? In other words, why should I invest in a maker which is not investing in me as an user?

Since ind.ie recently referenced the Paris deaths and freedom of speech, which I found untasteful from the start, I'll add that if we all want to be Carlie Hebdo -- and I'm not claiming I do -- we must start from having the courage to say unpleasant things to people, and to put our face, name and reputation on it. I am doing this now, with my 29/37 coding/life ratio (TM ;-) ) and my 18 years (half of my life) of formal computer science education and academic research activity, which I think gives me some authority on what is correct and what is not correct in designing a secure, private, decentralised software.

So: my not-so-politically-correct statement is "what ind.ie is proposing to do with the money of their donors is totally wrong".

For the time being, I advice my friends to keep using dropbox, google, facebook, whatever centralised product you use, it's just safer. It's one player less in the game, more mature products, less potential bugs. If you really want to have something like what ind.ie promised, you can fork their code, or fork somebody else's code, or start over from scratch, or support someone else in doing that. I'll be glad to support and even contribute work to any future project along the same lines, who also shares with me the values and reasons I explained above.

Let me conclude by saying that: 1) I am writing this only because I am sorry for the false advertising I unwantedly did when sharing links to ind.ie, but 2) that I want to leave a positive note too, because the effort, dedition, and communication abilities of the ind.ie team have been really great; it's unfortunate that I can't agree with the direction they took, but at least I can say they worked very hard, and maybe in the end they will change their mind. I'll be glad to change my mind in turn in that case.

Vincenzo

Nessun commento:

Posta un commento