Subject: Re: Introducing RootBadger ? Usenet-style social discussion for the modern web
But free speech does not mean flooding groups, harassing users, doxxing people, impersonating others, posting malicious links, running
fake-account spam, or wrecking every discussion on purpose.
That is where the tools come in: email verification, new-user posting
limits,
rate limits, link scanning, spam scoring, disposable email checks,
duplicate post detection, moderation queues, and admin controls for
banning accounts, email domains, IPs, IP ranges, and spam domains.
So the idea is simple: protect open discussion, but keep out the garbage
that makes open discussion impossible.
I think spam measures like scoring, dup post dect, moderation, banning and rate limits, new user posting limits and the like are good. I would even recommend that dormant accounts get flagged or deactivated after a time.
However, email and IP based identity verification (I know the IPs are more
for threat intel) aren't necessary. This encourages an already centralized ecosystem to be rooted even further, that being email providers. I just
don't see a need where it makes any sense to reinforce their stronghold on
the internet space even further.
Plus, you wouldn't have to worry about running an email connector. Better
to use maybe some kind of authenticated RSS feed for users who want notifications sent to them rather than by email. Especially if it is meant
to not be publicly accessible groups/discussions, it would be an OPSEC
error to assume that gmail isn't reading your private groups through email
and feeding it to one of their AI projects.
Password resets are a threat vector regardless, so to use simple user
account numbers and recovery passwords or keyphrases (which are much
harder to accidentally allow, I would imagine that is) would be better.
Much like GMails Recovery passphrases. Which can be salted and hashed much like passwords without needing to worry about data breaches exposing user emails more than they already are. Also, you wouldn't need to worry about trusting Gmail or Outlook to be an IDp for your users. A keyphrase is something that you can write down, you can't write down a one time
recovery link.
Frankly, if you were to use and endorse any features that contributed to
this ecosystem of these large tech companies (Think oAuth IdPs) and
somehow contribute to or utilize their analytic frameworks I would
absolutely obstain from you product.
Final word:
Sometimes the rules that we put in place and the definitions we place on
"free speech" to encourage civility discussion serve as the framework for
the opression of the free speech we claim to encourage.
Much thought must be put into how one governs their discussion body since
you have the ability, and liability to ensure that freedom of expression
is preserved or to destroy it completely.
Be a form of benevolent dictator for life
--- PyGate Linux v1.5.19
* Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)