I think Google could do this entirely with blogger, maybe reader, maybe Picassa, and email, and a bit of code. It would be a huge boon to Android phones.
Google groups is broken for some people, and I'd stay away from using it as a building block. Lots of people have negative opinions about Wave, me included. I don't even know if Buzz would help in any of this, the launch was so botched I never looked at it; people have told me it wouldn't work well for anything like this.
Posterous or Tumblr could do it too. Google doesn't seem to be very motivated in integrating their various acquired apps; maybe this would be that motivation. Or maybe Posterous or Tumblr might find some motivation in this.
It need not, maybe should not, and probably could not compete with Facebook. That's not a reason to not do it. Jones Soda does pretty well, yet I doubt if they think of themselves as a Coca Cola killer.
Whether Google or someone else does it, I'd like:
GENERAL
- Total control. I don't want to be a control freak, I want to be a control super freak. I decide exactly what is private, shared and public. Everything that can be shared in any way should be obvious, and the settings interface for controlling privacy should be very obvious in: a) what setting controls what feature, b) what feature is controlled by what setting. If you have to guess how to change a feature's exposure, or what feature a setting controls, then you don't have control.
- Long-lived settings. New features should never expose tomorrow what was not exposed yesterday. That's just so disrespectful on facebook's part.
- New features should begin with the most restrictive privacy settings.
- No apps or third parties. Make your money through advertising or paid features. If you're Google then you already have great advertising revenue and this just ties into it.
- No friend can expose anything of mine to any greater degree than I have explicitly exposed it.
DISCOVERABILITY
- If I want to be invisible at any level, then I should be invisible as long as the rivers run and the winds blow, until I change it.
Invisibility includes:
- The outside world. I'm either discoverable to anyone outside the system, or I'm invisible, according to my settings.
- People inside the system. I'm either discoverable inside the system, or I'm invisible.
- My groups of friends. I'm either discoverable to my friends' groups, or I'm invisible.
EXPOSURE
- I control what parts of my data are exposed, and how far out. This is both independent of discoverability and cooperative with it. For example, no matter how far out I might expose a photo album, it can't be exposed farther out than my discoverability. On the other hand no object needs to be as exposed as my maximum discoverability.
If I'm invisibile outside the system, then I can't set the exposure of a photo album to outside the system. If I need a photo album or something else to be exposed farther out than my discoverability, then I'd need to create that album outside the system (say, as a picassa album in a different, public account). I might be able to link to such an album from inside (and that link would have the same discoverability and exposure protections as any other object).
FUNCTIONS
- Discoverability. Anyone can discover me, as long as they're within one of my discoverability spheres. If I've set my discoverability to "world" then you can find me through search or browse. You can send a message to me if I've enabled that (with enough hurdles to discourage spam). If you're a member of the system you can request to friend me.
If my discoverability is more restrictive, then you might only be able to discover me if you're already a member. Or you might be able to discover me only if you're a member of one of my friends' other groups.
- Exposure. Objects that you post or share have a settable exposure level. Posting objects to a group gives those objects the exposure that you previously associated with that group.
- Chat.
- Alerts. If a friend logs in while I'm in, I want to know it, unless they've set that data to hidden.
- The usual. Can post comments, pictures, music, books, links, "other stuff" and have conversations about them. Post things about yourself in your profile, with different parts of you profile's exposure individually controllable. Be alerted to comments in conversations related to you or your posts, and changes to posted objects.
- A group of one. I should be my own group, similar to how some Linux distros create a group whose name is your login and whose membership is just you. I may want to keep track of things just for myself. I may want to stage new additions, initially to just me, and then exposed to a gradually wider audience as I see fit. I may want to pull some things in to private that were exposed.
Everyone starts as a member of their own group of one ("self" ?), unexposed and undiscoverable. You have to explicitly make yourself more discoverable, and you have to explicitly expose any objects in your group of one.
- Explicit groups of two or more. I should be able to explicitly band together with other people and form a group. Everyone in the group is aware of everyone else in the group. We can all post, converse and share. The group can be invisible or discoverable. I can expose my membership in the group to any group outsider who can see the group, or I can hide my membership from anyone outside the group. The email analogy to this might be cc:.
- Implicit groups of two or more. I should be able, on my own, to place people and groups inside of implicit groups that only I am aware of. If I post to an implicit group, each individual or group member of an implicit group receives the post or other object, and can carry on a conversation or other activity related to the object, but no individual or group within one of my implicit groups is aware of any other members of the implicit group; they aren't even aware that they themselves are part of one of my implicit groups, although they might guess from my style of writing. The email analogy to this might be bcc:.
The names of the two previous group types, explicit and implicit, may not be the best names. I initially described them as public and private, but those terms had too much confusing overlap with the notions of discoverability and exposure.
- Some groups owned by individuals and some groups owned equally by members. Not sure about this. Worth thinking about.
- Group union and intersection. I'm a little fuzzy on this one. Say you broadcast post an object to two groups. Person A is a member of one group, B is a member of the other group, yet the two people A and B have no relationship to each other within the system. If people A and B's discoverability settings would allow it, then they should see each other's comments related to the posted object and be able to take part in that object's conversations with each other as if they were both members of the same group. If their discoverability settings would not allow either to discover the other, then they should not see the others' comments.
If this function were done poorly, then gaps in conversations related to an object might be disorienting.
- Acknowledgement of the outside world. Under my control and choice, I should be able to make automatic tweets, or posts to my external blog, etc, based on what I post and where inside the system. I should also be able to make incoming posts from the outside, like ping.fm to twitter and facebook.
- Data migration. I should be able to export part or all of my data quickly and easily.
- Data ownership. I should be able to change the exposure of data that I post, and to delete it.
- Existence ownership. If I leave, I should be able to totally delete myself. Or, if I want, I could de-activate myself. But it shouldn't take searching outside the system to find a little known method for deletion. If I delete posts or data that are part of conversations, the system should insert a placeholder, but if it's mine I get to kill it.
IMPLEMENTATION
For this part I'll assume Google is implementing it, because they already have all the parts and we're all familiar with them. Applies equally to Posterous, Tumblr or a player to be named later, acknowledging that they would have more to build.
The fundamental activity in the system is posting objects and having conversations about them. An object might be text, media, a link, etc.
Posting objects could be handled very well by blogger. You can put pictures and links in a post, and there's a comment mechanism. The comments would continue the conversation.
You could also handle posts and reading with gmail, because it has excellent conversation threading. If you use gmail you'll have to be very careful about leakage, in or out.
Slashdot's forum has excellent threading, for inspiration.
Alerts and keeping up to date could be handled by logging in a lot and reading your stream, or via Google Reader, or by email/gmail, or any combination of them. Again, be very careful about leakage in and out.
Be nice to be able to post via email/gmail (hi Posterous!).
Media and albums by Picassa, but not just photos, anything a member has the right to post: books, audio, video.
Implementing some of this might be a challenge. Pick a subset. Iterate.
UI, UX, UXB
If you find anything looking like any part of Facebook, you're probably doing it wrong.
User interface should tend toward minimal. There should be zero or one way to do everything. UI elements should not suddenly disappear, to be found again after a frustrating search. Facebook recently made the logout link hard to find, burying it in the Account menu. Probably because they want to discourage you from logging out. Don't do stuff like that, it's disrespectful, and even if there isn't evil intent it encourages discussions of evil.
You should be able to easily choose where anything will be posted, and not have to worry at all that you might not understand where it's going.
When you view anything, you should get some indication of who else can see it, general by default but able to drill down to groups and individuals if you like.
Name everything well, once, and use only that name, everywhere.
You shouldn't need a help system. But someone will want it, and it should be worth reading. You should also be able to get to help for specific functions, from the context of that function, without having to abandon your context and go into "reading the manual" mode.
As someone who's just removed all my pages, likes, and interests from Facebook -- I just don't think they have my best interests in mind -- a network like this is, of course, a wet dream.
But there is a tradeoff between privacy and network effects. The network relies on its members connecting and conversing; that's how the network derives its value. Facebook's network is valuable because it is the de facto online identity for many millions of people. And to engender and promote network effects, Facebook must necessarily expose information about you to other users. How else would anyone connect with you?
Sure, it'd be nice for you to make yourself invisible at a moment's notice. But it's a terrible user experience for anyone trying to find or converse with you.
As I mentioned, you wouldn't try to compete with Facebook, since they're the de facto standard. This would be for people who want something different (like Jones Soda). It would likely work best by enhancing the attraction to something existing, like Posterous or like Google's other offerings (including Android).
As for discoverability vs invisibility, you're right, discoverable is more valuable to the network. I think most people would opt for more discoverability than invisibility, but invisibility is a logical setting among a level of settings. And it allows a small group of people who are only interested in staying connected with each other to do only that.
I mentioned a few things that bug me in the above reply-to-myself...
Should:
- Be able to export all friend/contact information anytime. CSV is fine.
- Be able to _easily_ block/remove applications & notifications. It's fine people can create "which star trek appliance are you?" quizzes, but let's make it _easy_ for these to be removed from my feed if I don't want to see them.
- Maybe have a more twitter style follow where it does not need to be a mutual follow. Obviously less information is shared if I don't follow back; etc. Just pondering this, it might or might not be better.
I actually don't think there's _that_ many things. There are a few key things that, if done right, would make it a better facebook. I'm just stabbing in the dark though.
Better than removing the deluge of unwanted app notifications individually would be a list, off to the side, of apps your friends have used that you haven't opted in or out of yet. Opt in and they all show up, opt out and it's added to a list of unwanted apps in your profile that you can edit later if desired.
Obviously this would make users happy but not app makers, because the way it currently works is free (obnoxious) advertising for them.
The mixed-access to updates based on bi- or unidirectional association is one of the very nice things about LiveJournal's social scheme. I knew a few people who use FaceBook for one level of communication and retain their LiveJournal accounts for another, because of this.
1: I want ACLs meet Web. I want to publish personal stuff to close friends & family, professional stuff to colleagues, and random miscellany to the world, all via the same tool. I want to be able to customize the layout of my content depending on the audience.
2: I want this without my friends and family having to learn about OpenID or having to sign up for a new account somewhere. (I don't know how to do this, I am just saying what I want. Posterous got this part right.)
3: I want to know that the investment I'm making in generating content will last. This means I need to trust that the host of my content is not going to disappear, or get bought and change its behavior radically. Alternatively, it means that I am given the ability to migrate my content to a well-behaved, API-implementing host elsewhere (including, possibly, on my own server).
Nothing I know of addresses this set of wants elegantly. Maybe because monetizing the social graph requires as much transparency from the participants as possible, at least according to current thinking. But I feel that eventually, what 'sharing on the web' means will inevitably evolve to accommodate this set of wants.
If Facebook decided to be less evil they could do ACLs-meet-web pretty easily, since they already have such a huge installed user base. In fact, they may have already done this a long time ago for all I know; back when I canceled my account, they did not have this capability.
You are describing the Internet. Self-run web sites, blogs, and instant messaging systems:
1. allow you to fine-tune who sees what,
2. do not require extra accounts (save comment systems, etc.),
3. are not tied to any one provider or company and thus will last for a long time.
Even if it did, your assertion is like equating assembly to a high level language. Just because you theoretically can do anything in assembly that you can in a high level language doesn't mean you would want to. I am trying to specify a set of attributes for a non-existent tool that would let me more fluidly publish what I write and create.
----
edit: if anybody reading this would care to explain why I am getting downvoted & the parent is getting upvoted so much, I would appreciate it.
The internet provides something like ACLs using something similar to a password capability model: I post stuff as "tbrownaw" or "Timothy Brownawell" and anyone can know it's me, but I also have logins to various message boards under pseudonyms, which you can only tie back to me if I tell you.
Another interesting question would be: how will it make money?
Websites like Facebook and Myspace are shunning the simple advertisement model. Selling private data will become the new standard. A website similar to scope and feature like Facebook will probably not be able to sustain a positive cash flow or break even without selling people's data. UNLESS...they cut features like photo storage, or make a technological breakthrough.
They are making ~$2/user/year (not including expenses). Since it recently supposedly became cash-flow positive, it would be reasonable to assume that the expenses are also around ~$2/user.
The question then becomes, how much of this $2 is slashed off when you decide to not sell private data? You only have to look at the cost of conventional CPM ads (usually less than $0.01 per impression) and multiply it by how many times a Facebook user opens Facebook each year. My bet is that it is far less than 365/2 since Facebook claims 50% of "active" users login every day.
The prime example that resulted in a lawsuit settlement. I mean really? Opt-in to reveal your purchasing and browsing habits with selected companies and then spam your friends?
These websites are able to scrape your data to provide you a "personal" experience. Another opt-in. I'm not sure if FB is selling this api, but I'm willing to bet its a certainty.
These might not literally be bundling up personal information and selling it outright, but given the track record here, I wouldn't be surprised if they did another "opt-in".
The claim that facebook has changed defaults in order to indirectly make more advertising revenue is very different from the claim that checks were written to facebook in exchange for private user data. You implied the latter, and it's bogus.
None of these programs involved facebook giving user data to advertisers. Even the dreaded Beacon was strictly one-way: it allowed sites elsewhere on the Web to publish to facebook, not vice versa.
Out of curiosity, do you hold Google's AdSense up to similar levels of scrutiny? You're aware that a little pixel is on about 70% of the web by hits, piping your interests, proclivities, and browsing history to Google advertisers can target you? Or is it not evil when Google does it?
Sure I'll admit that it is not literally packaging private info into a file and selling it. But it sure is asymptotically approaching it.
Your argument is analogous to saying Microsoft didn't really have a monopoly because 3% of computers used Linux and OSX. Plus, how does F8 instant personalization work? I doubt it is solely based on a 1 pixel tracking image.
And I do hold up AdSense to the same level of scrutiny. While it also has privacy issues, it is not of the same level. It does not force browsers to become advertisers to their friends, revealing their purchasing and browsing habits. Your friends do not know that you visited a certain website or bought a certain product and can link you by your name, age, friends, and likes/dislikes and organizations you belong to.
That is the sole reason why people think Facebook can beat Google.
You want to make some sort create some sort of moral equivalence between literally selling user data and changing user privacy defaults. Maybe there is some moral equivalent, but I don't think so.
In any case, the way you made your case is by lying.
An anti-US activist might want to claim a moral equivalence between the casualties of the Iraq war and mass executions. But, to say that the US executed 100k Iraqis is lying. That is an analogous to your argument.
You are really stretching it if you are trying to say Facebook isn't trying to exploit private data to the fullest extent possible.
A more apt analogy using your theme would be this: Saddam Hussein didn't kill anyone, his soldiers did. Only a pedant would be worried about the literal meaning without looking at the big picture.
About reasonable privacy, the service shouldn't be able to read content. The provider can tell Alice (user on IP 1) sent something to Bob (user on IP 2) but the message content itself shouldn't be compromised. In particular profile-identifying details should be reasonably safe. This requires client-side encryption, of course.
Plausible deniability isn't that tricky, it mostly requires careful use of protocols at design phase and there is OTR to borrow.
With AJAX or dynamic JS scripts updates should be fast. The intersection of updates of contacts could be done in a single API call with multiple parameters (server-side intersection of data.) Or more scalable but a bit slower by doing multiple calls to separate server clusters (could even be calls to fetch plain files on CDN containing latest updates, aka "the wall".)
I've played a bit with zero-knowledge technologies (similar to Clipperz) and I think it's very doable. The big problem problem lies on images and video. Last year I played with HTML5/canvas with encryption but the CPU and delay is prohibitive since it requires to work on decompressed images pixel-by-pixel.
It would be nice if the major browsers started giving encryption and compression primitives to JS. And even nicer if there was an API to manage images, audio and video.
Chrome NaCl looks also very promising for this kind of disruptive technology.
Of course, the non technical problems of getting traction with users and making it commercially viable are still there just like in any other kind of social network service.
They shouldn't be so successful. They made the same mistake as Goldman. In this case, small, problematic privacy features (people being able to tag you without your permission, etc.) that weren't exhausted + ambitious new platforms and exponential success suddenly caused them to reach a critical mass where people think twice about their service.
It's all about the integrity of the core feature set, and avoiding future, short-term successes that erode into it. Ironically, one only really notices the erosions (which, as with Apple and Goldman, are really not unique within their industry) after a certain amount of success.
Comments
What features should it have? (Or not have?)
I think Google could do this entirely with blogger, maybe reader, maybe Picassa, and email, and a bit of code. It would be a huge boon to Android phones.
Google groups is broken for some people, and I'd stay away from using it as a building block. Lots of people have negative opinions about Wave, me included. I don't even know if Buzz would help in any of this, the launch was so botched I never looked at it; people have told me it wouldn't work well for anything like this.
Posterous or Tumblr could do it too. Google doesn't seem to be very motivated in integrating their various acquired apps; maybe this would be that motivation. Or maybe Posterous or Tumblr might find some motivation in this.
It need not, maybe should not, and probably could not compete with Facebook. That's not a reason to not do it. Jones Soda does pretty well, yet I doubt if they think of themselves as a Coca Cola killer.
Whether Google or someone else does it, I'd like:
GENERAL
- Total control. I don't want to be a control freak, I want to be a control super freak. I decide exactly what is private, shared and public. Everything that can be shared in any way should be obvious, and the settings interface for controlling privacy should be very obvious in: a) what setting controls what feature, b) what feature is controlled by what setting. If you have to guess how to change a feature's exposure, or what feature a setting controls, then you don't have control.
- Long-lived settings. New features should never expose tomorrow what was not exposed yesterday. That's just so disrespectful on facebook's part.
- New features should begin with the most restrictive privacy settings.
- No apps or third parties. Make your money through advertising or paid features. If you're Google then you already have great advertising revenue and this just ties into it.
- No friend can expose anything of mine to any greater degree than I have explicitly exposed it.
DISCOVERABILITY
- If I want to be invisible at any level, then I should be invisible as long as the rivers run and the winds blow, until I change it.
Invisibility includes:
EXPOSURE- I control what parts of my data are exposed, and how far out. This is both independent of discoverability and cooperative with it. For example, no matter how far out I might expose a photo album, it can't be exposed farther out than my discoverability. On the other hand no object needs to be as exposed as my maximum discoverability.
If I'm invisibile outside the system, then I can't set the exposure of a photo album to outside the system. If I need a photo album or something else to be exposed farther out than my discoverability, then I'd need to create that album outside the system (say, as a picassa album in a different, public account). I might be able to link to such an album from inside (and that link would have the same discoverability and exposure protections as any other object).
FUNCTIONS
- Discoverability. Anyone can discover me, as long as they're within one of my discoverability spheres. If I've set my discoverability to "world" then you can find me through search or browse. You can send a message to me if I've enabled that (with enough hurdles to discourage spam). If you're a member of the system you can request to friend me.
If my discoverability is more restrictive, then you might only be able to discover me if you're already a member. Or you might be able to discover me only if you're a member of one of my friends' other groups.
- Exposure. Objects that you post or share have a settable exposure level. Posting objects to a group gives those objects the exposure that you previously associated with that group.
- Chat.
- Alerts. If a friend logs in while I'm in, I want to know it, unless they've set that data to hidden.
- The usual. Can post comments, pictures, music, books, links, "other stuff" and have conversations about them. Post things about yourself in your profile, with different parts of you profile's exposure individually controllable. Be alerted to comments in conversations related to you or your posts, and changes to posted objects.
- A group of one. I should be my own group, similar to how some Linux distros create a group whose name is your login and whose membership is just you. I may want to keep track of things just for myself. I may want to stage new additions, initially to just me, and then exposed to a gradually wider audience as I see fit. I may want to pull some things in to private that were exposed.
Everyone starts as a member of their own group of one ("self" ?), unexposed and undiscoverable. You have to explicitly make yourself more discoverable, and you have to explicitly expose any objects in your group of one.
- Explicit groups of two or more. I should be able to explicitly band together with other people and form a group. Everyone in the group is aware of everyone else in the group. We can all post, converse and share. The group can be invisible or discoverable. I can expose my membership in the group to any group outsider who can see the group, or I can hide my membership from anyone outside the group. The email analogy to this might be cc:.
- Implicit groups of two or more. I should be able, on my own, to place people and groups inside of implicit groups that only I am aware of. If I post to an implicit group, each individual or group member of an implicit group receives the post or other object, and can carry on a conversation or other activity related to the object, but no individual or group within one of my implicit groups is aware of any other members of the implicit group; they aren't even aware that they themselves are part of one of my implicit groups, although they might guess from my style of writing. The email analogy to this might be bcc:.
The names of the two previous group types, explicit and implicit, may not be the best names. I initially described them as public and private, but those terms had too much confusing overlap with the notions of discoverability and exposure.
- Some groups owned by individuals and some groups owned equally by members. Not sure about this. Worth thinking about.
- Group union and intersection. I'm a little fuzzy on this one. Say you broadcast post an object to two groups. Person A is a member of one group, B is a member of the other group, yet the two people A and B have no relationship to each other within the system. If people A and B's discoverability settings would allow it, then they should see each other's comments related to the posted object and be able to take part in that object's conversations with each other as if they were both members of the same group. If their discoverability settings would not allow either to discover the other, then they should not see the others' comments.
If this function were done poorly, then gaps in conversations related to an object might be disorienting.
- Acknowledgement of the outside world. Under my control and choice, I should be able to make automatic tweets, or posts to my external blog, etc, based on what I post and where inside the system. I should also be able to make incoming posts from the outside, like ping.fm to twitter and facebook.
- Data migration. I should be able to export part or all of my data quickly and easily.
- Data ownership. I should be able to change the exposure of data that I post, and to delete it.
- Existence ownership. If I leave, I should be able to totally delete myself. Or, if I want, I could de-activate myself. But it shouldn't take searching outside the system to find a little known method for deletion. If I delete posts or data that are part of conversations, the system should insert a placeholder, but if it's mine I get to kill it.
IMPLEMENTATION
For this part I'll assume Google is implementing it, because they already have all the parts and we're all familiar with them. Applies equally to Posterous, Tumblr or a player to be named later, acknowledging that they would have more to build.
The fundamental activity in the system is posting objects and having conversations about them. An object might be text, media, a link, etc.
Posting objects could be handled very well by blogger. You can put pictures and links in a post, and there's a comment mechanism. The comments would continue the conversation.
You could also handle posts and reading with gmail, because it has excellent conversation threading. If you use gmail you'll have to be very careful about leakage, in or out.
Slashdot's forum has excellent threading, for inspiration.
Alerts and keeping up to date could be handled by logging in a lot and reading your stream, or via Google Reader, or by email/gmail, or any combination of them. Again, be very careful about leakage in and out.
Be nice to be able to post via email/gmail (hi Posterous!).
Media and albums by Picassa, but not just photos, anything a member has the right to post: books, audio, video.
Implementing some of this might be a challenge. Pick a subset. Iterate.
UI, UX, UXB
If you find anything looking like any part of Facebook, you're probably doing it wrong.
User interface should tend toward minimal. There should be zero or one way to do everything. UI elements should not suddenly disappear, to be found again after a frustrating search. Facebook recently made the logout link hard to find, burying it in the Account menu. Probably because they want to discourage you from logging out. Don't do stuff like that, it's disrespectful, and even if there isn't evil intent it encourages discussions of evil.
You should be able to easily choose where anything will be posted, and not have to worry at all that you might not understand where it's going.
When you view anything, you should get some indication of who else can see it, general by default but able to drill down to groups and individuals if you like.
Name everything well, once, and use only that name, everywhere.
You shouldn't need a help system. But someone will want it, and it should be worth reading. You should also be able to get to help for specific functions, from the context of that function, without having to abandon your context and go into "reading the manual" mode.
There's probably more.
As someone who's just removed all my pages, likes, and interests from Facebook -- I just don't think they have my best interests in mind -- a network like this is, of course, a wet dream.
But there is a tradeoff between privacy and network effects. The network relies on its members connecting and conversing; that's how the network derives its value. Facebook's network is valuable because it is the de facto online identity for many millions of people. And to engender and promote network effects, Facebook must necessarily expose information about you to other users. How else would anyone connect with you?
Sure, it'd be nice for you to make yourself invisible at a moment's notice. But it's a terrible user experience for anyone trying to find or converse with you.
As I mentioned, you wouldn't try to compete with Facebook, since they're the de facto standard. This would be for people who want something different (like Jones Soda). It would likely work best by enhancing the attraction to something existing, like Posterous or like Google's other offerings (including Android).
As for discoverability vs invisibility, you're right, discoverable is more valuable to the network. I think most people would opt for more discoverability than invisibility, but invisibility is a logical setting among a level of settings. And it allows a small group of people who are only interested in staying connected with each other to do only that.
I mentioned a few things that bug me in the above reply-to-myself...
Should: - Be able to export all friend/contact information anytime. CSV is fine.
- Be able to _easily_ block/remove applications & notifications. It's fine people can create "which star trek appliance are you?" quizzes, but let's make it _easy_ for these to be removed from my feed if I don't want to see them.
- Maybe have a more twitter style follow where it does not need to be a mutual follow. Obviously less information is shared if I don't follow back; etc. Just pondering this, it might or might not be better.
I actually don't think there's _that_ many things. There are a few key things that, if done right, would make it a better facebook. I'm just stabbing in the dark though.
Can this post be considered a YC application? ;-)
Better than removing the deluge of unwanted app notifications individually would be a list, off to the side, of apps your friends have used that you haven't opted in or out of yet. Opt in and they all show up, opt out and it's added to a list of unwanted apps in your profile that you can edit later if desired.
Obviously this would make users happy but not app makers, because the way it currently works is free (obnoxious) advertising for them.
The mixed-access to updates based on bi- or unidirectional association is one of the very nice things about LiveJournal's social scheme. I knew a few people who use FaceBook for one level of communication and retain their LiveJournal accounts for another, because of this.
1: I want ACLs meet Web. I want to publish personal stuff to close friends & family, professional stuff to colleagues, and random miscellany to the world, all via the same tool. I want to be able to customize the layout of my content depending on the audience.
2: I want this without my friends and family having to learn about OpenID or having to sign up for a new account somewhere. (I don't know how to do this, I am just saying what I want. Posterous got this part right.)
3: I want to know that the investment I'm making in generating content will last. This means I need to trust that the host of my content is not going to disappear, or get bought and change its behavior radically. Alternatively, it means that I am given the ability to migrate my content to a well-behaved, API-implementing host elsewhere (including, possibly, on my own server).
Nothing I know of addresses this set of wants elegantly. Maybe because monetizing the social graph requires as much transparency from the participants as possible, at least according to current thinking. But I feel that eventually, what 'sharing on the web' means will inevitably evolve to accommodate this set of wants.
If Facebook decided to be less evil they could do ACLs-meet-web pretty easily, since they already have such a huge installed user base. In fact, they may have already done this a long time ago for all I know; back when I canceled my account, they did not have this capability.
You are describing the Internet. Self-run web sites, blogs, and instant messaging systems:
1. allow you to fine-tune who sees what, 2. do not require extra accounts (save comment systems, etc.), 3. are not tied to any one provider or company and thus will last for a long time.
How do you see the internet providing built-in ACLs? http://en.wikipedia.org/wiki/Access_control_list
Even if it did, your assertion is like equating assembly to a high level language. Just because you theoretically can do anything in assembly that you can in a high level language doesn't mean you would want to. I am trying to specify a set of attributes for a non-existent tool that would let me more fluidly publish what I write and create.
----
edit: if anybody reading this would care to explain why I am getting downvoted & the parent is getting upvoted so much, I would appreciate it.
The internet provides something like ACLs using something similar to a password capability model: I post stuff as "tbrownaw" or "Timothy Brownawell" and anyone can know it's me, but I also have logins to various message boards under pseudonyms, which you can only tie back to me if I tell you.
Thanks. That is indeed an inverted form of what I was wishing for, and I didn't get the idea from the initial response to my post.
note to self (post is too old to edit): apparently Facebook does have a lists capability: http://news.ycombinator.com/item?id=1341787, http://www.facebook.com/help/?page=768
Another interesting question would be: how will it make money?
Websites like Facebook and Myspace are shunning the simple advertisement model. Selling private data will become the new standard. A website similar to scope and feature like Facebook will probably not be able to sustain a positive cash flow or break even without selling people's data. UNLESS...they cut features like photo storage, or make a technological breakthrough.
They are making ~$2/user/year (not including expenses). Since it recently supposedly became cash-flow positive, it would be reasonable to assume that the expenses are also around ~$2/user.
The question then becomes, how much of this $2 is slashed off when you decide to not sell private data? You only have to look at the cost of conventional CPM ads (usually less than $0.01 per impression) and multiply it by how many times a Facebook user opens Facebook each year. My bet is that it is far less than 365/2 since Facebook claims 50% of "active" users login every day.
Can you provide an example of facebook "selling private data"? I work there, and it would be a great surprise to me if you could.
Sure.
http://en.wikipedia.org/wiki/Facebook#Beacon
The prime example that resulted in a lawsuit settlement. I mean really? Opt-in to reveal your purchasing and browsing habits with selected companies and then spam your friends?
http://gawker.com/5426176/facebooks-great-betrayal
Another opt-in that is equivalent to Facebook buying web coverage at the expense of user privacy.
http://gigaom.com/2010/04/22/facebooks-instant-personalizati...
These websites are able to scrape your data to provide you a "personal" experience. Another opt-in. I'm not sure if FB is selling this api, but I'm willing to bet its a certainty.
These might not literally be bundling up personal information and selling it outright, but given the track record here, I wouldn't be surprised if they did another "opt-in".
The claim that facebook has changed defaults in order to indirectly make more advertising revenue is very different from the claim that checks were written to facebook in exchange for private user data. You implied the latter, and it's bogus.
None of these programs involved facebook giving user data to advertisers. Even the dreaded Beacon was strictly one-way: it allowed sites elsewhere on the Web to publish to facebook, not vice versa.
Out of curiosity, do you hold Google's AdSense up to similar levels of scrutiny? You're aware that a little pixel is on about 70% of the web by hits, piping your interests, proclivities, and browsing history to Google advertisers can target you? Or is it not evil when Google does it?
Sure I'll admit that it is not literally packaging private info into a file and selling it. But it sure is asymptotically approaching it.
Your argument is analogous to saying Microsoft didn't really have a monopoly because 3% of computers used Linux and OSX. Plus, how does F8 instant personalization work? I doubt it is solely based on a 1 pixel tracking image.
And I do hold up AdSense to the same level of scrutiny. While it also has privacy issues, it is not of the same level. It does not force browsers to become advertisers to their friends, revealing their purchasing and browsing habits. Your friends do not know that you visited a certain website or bought a certain product and can link you by your name, age, friends, and likes/dislikes and organizations you belong to.
That is the sole reason why people think Facebook can beat Google.
No it isn't analogous to that at all.
You want to make some sort create some sort of moral equivalence between literally selling user data and changing user privacy defaults. Maybe there is some moral equivalent, but I don't think so.
In any case, the way you made your case is by lying. An anti-US activist might want to claim a moral equivalence between the casualties of the Iraq war and mass executions. But, to say that the US executed 100k Iraqis is lying. That is an analogous to your argument.
You are really stretching it if you are trying to say Facebook isn't trying to exploit private data to the fullest extent possible.
A more apt analogy using your theme would be this: Saddam Hussein didn't kill anyone, his soldiers did. Only a pedant would be worried about the literal meaning without looking at the big picture.
Did I say that?
"Websites like Facebook and Myspace are shunning the simple advertisement model."
? Every one of my facebook pages (feed and profile) always has two or three prominent ads over on the right.
What I mean is they are selling your personal information __in addition__ to regular ads (which are selected by datamining your personal information).
As opposed to just regular ads.
Plausible deniability isn't that tricky, it mostly requires careful use of protocols at design phase and there is OTR to borrow.
With AJAX or dynamic JS scripts updates should be fast. The intersection of updates of contacts could be done in a single API call with multiple parameters (server-side intersection of data.) Or more scalable but a bit slower by doing multiple calls to separate server clusters (could even be calls to fetch plain files on CDN containing latest updates, aka "the wall".)
I've played a bit with zero-knowledge technologies (similar to Clipperz) and I think it's very doable. The big problem problem lies on images and video. Last year I played with HTML5/canvas with encryption but the CPU and delay is prohibitive since it requires to work on decompressed images pixel-by-pixel.
It would be nice if the major browsers started giving encryption and compression primitives to JS. And even nicer if there was an API to manage images, audio and video.
Chrome NaCl looks also very promising for this kind of disruptive technology.
Of course, the non technical problems of getting traction with users and making it commercially viable are still there just like in any other kind of social network service.
Those basic ones allowing communication: essentially directed and non-directed asynchronous sharing.
And those you 1) opt-in for 2) pay for.
There's a long list I have, but that's a startup for another day. (Or for a time a month from now... when school lets out.)
They shouldn't be so successful. They made the same mistake as Goldman. In this case, small, problematic privacy features (people being able to tag you without your permission, etc.) that weren't exhausted + ambitious new platforms and exponential success suddenly caused them to reach a critical mass where people think twice about their service.
It's all about the integrity of the core feature set, and avoiding future, short-term successes that erode into it. Ironically, one only really notices the erosions (which, as with Apple and Goldman, are really not unique within their industry) after a certain amount of success.