Officially support "data sovereignty", aka letting users choose where their content is hosted

(#1113) Feature Under consideration federation privacy

Problem

the premise: I think federation + (obviously optional) E2EE + (optional for power-users) choosing where data is hosted would be the most immaculate solution for most data sovereignty and security/privacy/anonymity issues. for example, if I try to write a message onto fluxer. a hook catches what I was going to send, uploads it to my website (or instance) instead, and posts a link directing to the content of the message. and that link embeds perfectly so that it looks like an ordinary message. and then the same for media, too. a hook catches me trying to upload media to the host instance, and instead uploads it to my website. and then sends a link pointing to the media I am hosting. the instance host only ever saves the link, not the contents. I can choose when I want my data to be deleted or expired. etc. and this would be a win-win for everyone. the host instance saves storage space, power users get unlimited file upload sizes, and have full control over their data. this means, in essence, separating file-hosting from instance-hosting. instances can still host data, but just because a guild is hosted on an instance doesn't necessarily mean that the same instance should also save and host all the content written to the guilds within it. ///

A WIN FOR USERS

if all of your messages are merely links to a server that you host, that you control, that you can delete, then it is your choice whether your original messages stay up. nobody elses. nobody can coerce you. nobody can stop you from taking your content down with a ban. all that personal information you might have revealed, your writing style, your writing patterns, the way you interact, the people you mentioned, all that data. you get to delete it anytime if you no longer feel safe in a community. that right to agency is important, and all users should have this agency. not to mention, there are plenty of "power users" who are more-than-willing to use their own host to get unlimited file uploads, etc. adding an official implementation of this would just be a far more convenient way for these types of users to interact with their file/webserver for posting images, and then sharing the links to the chat they are in.

A WIN FOR FLUXER DEV DONATIONS

The official Fluxer instance receives revenue via their "plutonium" monthly subscription, which is just like Discord Nitro. It provides users added benefits like higher upload sizes, etc. The upcoming rework to support and enable federation among self-hosted instances poses a great problem to the user experience of Plutonium users, who will lose all of their benefits when they start participating in instances outside of the central Fluxer instance. This is where "data sovereignty" or "separating file-hosting from instance-hosting" would improve Plutonium in two ways.
  1. Plutonium users could continue using the official Fluxer instance to host their content, even when participating on self-hosted instances. This makes the Plutonium service incredibly seamless, albeit they may will lose other perks that truly rely on the instance (video quality, etc).
  1. Because Plutonium can work across all instances, this gives Plutonium far more added value and makes it an even more attractive offer. More users will undoubtedly subscribe to the service and donate to the Fluxer Devs if they understand it will work across all instances they participate in.

A WIN FOR BIG SELF HOSTS

If any instance can offer to host your content for you, regardless of what guild you post in, then every single self-host can compete (in the so-called "free market") to offer users their own monetized/upgraded service. Some can offer better pricing, some can offer more privacy/security/less logs/etc. However they want to market it. Fluxer already has plans to allow self-hosts to monetize their server in this way, this would just make the monetization even better and more expansive. Users would be more willing to donate to self-hosters if their benefits carried over to other self-hosted instances, and the central fluxer instance too.

A WIN FOR SMALL HOSTS

And in return, small self-hosts will hopefully see a reduction in the would-be disk usage of their server, as their members use other instances and webservices to host their content/messages on.

A WIN FOR GUILD OWNERS

All your data within a guild shouldn't evaporate overnight just because you or whoever owns the guild choose a bad self-hosted instance, and the owner of it decides to delete your guild or shutdown. A youtube community vanishes because they chose the wrong self-host, etc would be a nightmare for everyone involved.

Proposed solution

ON THE FRONT-END

Images, videos, media, etc already "embed" into a chat when you send the link (assuming it is a valid link, of course) The only addition we would need, is an official way to "embed" links to messages, sort of like webhooks? (im not quite certain). There would also need to be a new section in the settings, where users can customize and configure which instance host they wish to use for hosting their messages and media on.

ON THE BACK-END

And then for self hosts, configurations for if they wish for their users to be able to use their instance as a media/message host outside of the guilds it operates. permission/role levels dictating which users have access to this would've came anyways with the typical planned monetization.

Notes (optional)

I must strongly emphasize that such things already exist. Fluxer can already embed images, videos, etc. Webservers already host content. Users can already link content hosted on a webserver. This suggestion is merely a request to add an official seamless integration into the Fluxer client. on safety/logging: I'm not going to soapbox forever about how much safer this may make users. There are a gazillion ways a bad actor can potentially "get around" the safety benefits this brings. I'm just saying, if you threat model is John Layman and you can wipe all your messages when you desire, then that is likely sufficient safety practice for most people. And FAR EXCEEDS the agency over your own data that other platforms like Discord provide for their users. on moderation: a lot of people in the Fluxer Dev server pointed out that, in an extremely niche case, a bad actor could send a link that embeds as an image for one user IP, and a different image for everyone else. This kind of assumes that every single user is individually resolving the address and generating an embed themselves, which I do not imagine being an elaborate solution (image from random small website gets shared to thousands of people, slows website to a crawl, doesn't sound ideal). I think the instance where conversations are occurring could request the content of the link, and cache the contents in RAM, then serve the content "hot" to the users of the conversation. And when that section of the conversation goes "cold", it can discard the contents of the link from RAM. No writing to disk necessary. further ranting on technical crap: people in the Fluxer Dev server have talked extensively about separating "identity hosting" and "instance hosting". This suggestions is somewhat of an extension of that, to say that "file hosting" and "instance hosting" should be separate things. However, I don't necessarily think it has to "technically" be "separate" things/processes/executables/whatever. You could run an instance, where users cannot 1. create an account under the instance 2. create guilds in the instance 3. use the instance to DM others. Then what you could do, is give users permission to choose the instance as their file host. I prefer the UNIX philosophy of a strong modular system, but if "separating" file-hosting and guild-hosting is "too much" then I believe this could be a valid workaround.

Comments

Sign in with Fluxer to comment and vote.

No comments yet.