Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Facebook Alternative Releases Source Code
 
#9
My Ruby experience is limited (extremely limited); that said, the biggest problem here doesn't seem to be their understanding of their development platform, but rather, of basic security concerns.
What further concerns me is this: even if they do fix each and every security hole that's been exposed, the basic underlying function of this is that each node in the greater Diaspora network is trusted by the other nodes, correct?  And further, nodes can be created and joined to the cloud by anybody.
In principle, this is no different than P2P networks.  But P2P networks don't generally intentionally store private information!
As I used to say back when part of my job was breaking into so-called secure computers: if I have physical access to the machine it's only a matter of time.  And the same is true for encrypted data.  Once it's on a malicious users' machine, it's only a matter of time.*
(* yes I'm aware strong enough encryption makes the 'time' value rather large, but brute force is the last-resort option.  If you have a node running on your box, what's to stop you from sniffing legitimate traffic and ferreting out the key?)

--sofaspud
--"Listening to your kid is the audio equivalent of a Salvador Dali painting, Spud." --OpMegs
Reply


Messages In This Thread
[No subject] - by sweno - 09-17-2010, 05:15 PM
[No subject] - by Bob Schroeck - 09-17-2010, 06:55 PM
[No subject] - by Bob Schroeck - 09-20-2010, 02:50 PM
[No subject] - by sweno - 09-23-2010, 09:08 PM
[No subject] - by Black Aeronaut - 09-24-2010, 05:00 AM
[No subject] - by Bob Schroeck - 09-24-2010, 02:48 PM
[No subject] - by sweno - 09-24-2010, 05:41 PM
[No subject] - by Sofaspud - 09-24-2010, 07:31 PM
[No subject] - by Morganite - 09-24-2010, 07:41 PM
[No subject] - by sweno - 09-24-2010, 08:32 PM
[No subject] - by Morganite - 09-25-2010, 06:35 AM

Forum Jump:


Users browsing this thread: 2 Guest(s)