https://groups.google.com/g/upspin/c/Whma_O-iexM/m/lSConHZ5DwAJ [logo_group]Groups Conversations All groups and messages [Search conversations][ ] Send feedback to Google Help Training # Sign in Groups Upspin Conversations About Privacy * Terms Groups keyboard shortcuts have been updated Dismiss See shortcuts Turning down Upspin infrastructure 1,681 views Skip to first unread message Eric Grosse's profile photo Eric Grosse unread, Feb 11, 2025, 12:02:07 PM (4 days ago) Feb 11 Reply to author Sign in to reply to author Forward Sign in to forward Delete You do not have permission to delete messages in this group Copy link Report message Show original message Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message to Upspin Upspin, like Unix and Plan 9, was intended to foster communities of sharing, but has been less successful at that than we hoped. As a consequence, with regret, we have decided to turn down the central infrastructure such as the keyserver over the coming months On March 4, we will turn off keyserver for a week. This warns even people not following this list that something is happening. Then on May 6, we will turn it off permanently. If this will cause more pain than we're aware, please email gro...@gmail.com and let's discuss options. There is much about Upspin that still seems attractive compared to alternatives. The combination of strong end-to-end encryption with the convenience of upspinfs letting you run existing apps effortlessly has been great. Bringing the idea of automatic nightly snapshots from Plan 9 to modern systems also feels great in use. Contributors have proposed valuable improvements, and a backlog has developed on reviewing and installing these, which is part of what prompted this decision. Some examples are: switching from a central keyserver to ssh-like authorized_keys files in clients and dirservers, revised API for Block unpacking enabling parallel reads, a clearer model for permissions on Access and Group files, and post-quantum-cryptographic packing that can defend against future rogue governments. The question is whether the size of the community justifies the effort. We thank all who tried out Upspin! Andrew, Dave, Eric, and Rob Aram Havarneanu's profile photo Aram Havarneanu unread, Feb 11, 2025, 4:47:42 PM (4 days ago) Feb 11 Reply to author Sign in to reply to author Forward Sign in to forward Delete You do not have permission to delete messages in this group Copy link Report message Show original message Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message to Eric Grosse, Upspin A vary sad day, but also another cautionary tale about the danger posed by centralized infrastructure. -- Aram Havarneanu Filip Filmar's profile photo Filip Filmar unread, Feb 11, 2025, 9:21:53 PM (4 days ago) Feb 11 Reply to author Sign in to reply to author Forward Sign in to forward Delete You do not have permission to delete messages in this group Copy link Report message Show original message Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message to Aram Havarneanu, Eric Grosse, Upspin "A distributed system is one in which the failure of a computer you didn't even know existed can render your own computer unusable" :) On a more serious note, how impossible would be self-hosting a keyserver, say based on the public keyserver data available today? I use upspin as it can use Google Drive as a backend, and is fast enough at doing so. But I have no friends, so I have no use for others' key data. :) Ideally I'd "just" take the public key server data, self-host and be done with it. Thank you all for your service so far! F -- You received this message because you are subscribed to the Google Groups "Upspin" group. To unsubscribe from this group and stop receiving emails from it, send an email to upspin+un...@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/ upspin/ CAEAzY38a6KY5vt1XLzmr7BvGxAyzXW4qZgN3JahD9PQ7XQKMPg%40mail.gmail.com . Eric Grosse's profile photo Eric Grosse unread, Feb 11, 2025, 10:12:52 PM (4 days ago) Feb 11 Reply to author Sign in to reply to author Forward Sign in to forward Delete You do not have permission to delete messages in this group Copy link Report message Show original message Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message to Upspin, Filip Filmar, Aram Havarneanu With regard to alternatives to a centralized keyserver, there was a relevant discussion at https://github.com/upspin/upspin/issues/614 a year ago. In short, the proposal is to keep sets of known_keys at each client and also sets of known_keys at dirservers, with some automation to warn users of changes and maintain consistency. This would require more manual work by users than the central keyserver, and in particular adds some friction for new users. But in hindsight it might have been a better way to go. I remain open to modest-sized pull requests that fix bugs in the Upspin repository. The known_keys proposal is probably at the upper size limit of what would be considered, and would have to be completed before any others make sense. If such a change is making good progress, I'd of course be willing to keep keyserver running in the meantime to support a transition. Leaving aside keyserver, there continues to be uncertainty about how far away a cryptographically-relevant quantum computer might be, but I've heard from a credible source that it is now likely less than ten years off. Maybe not, but I'm uncomfortable leaving Upspin users at risk with the status quo; this is a more difficult risk assessment than we can responsibly be imposing on ordinary users. So the other critical Upspin proposal is to switch from the existing elliptic-curve packings to ML-KEM in some form. This would require help from people with the right PQC expertise, at minimum to review my changes if I'm the one doing the design and implementation. It was nice when our team was at Google and had such expert reviewers available. For sharing files among very small groups there are simpler solutions available, admittedly with less convenience. Given the effort needed to implement the two critical steps above compared to the size of the community, it seemed time for Upspin to join its Authors in retirement. Ozgur Kesim's profile photo Ozgur Kesim unread, Feb 12, 2025, 5:14:14 AM (4 days ago) Feb 12 Reply to author Sign in to reply to author Forward Sign in to forward Delete You do not have permission to delete messages in this group Copy link Report message Show original message Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message to Eric Grosse, Upspin Hi Eric, Andrew, Dave and Rob, thank you for upspin. This news is sad, but expected, I guess. I agree with both of your observations that a) upspin has still something valuable to offer and b) that it needs refurbishing with substantial effort. On the upside: the code is available to us and some of the ideas for improvements do precisely include decentralization, such that this news might just be the right push to turn it into an oppurtunity. (Last sentence in the uplifting voice of self-motiviation) Thanks again! Cheers, Ozgur Thus spake Eric Grosse (gro...@gmail.com): > -- > You received this message because you are subscribed to the Google Groups "Upspin" group. > To unsubscribe from this group and stop receiving emails from it, send an email to upspin+un...@googlegroups.com. > To view this discussion visit https://groups.google.com/d/msgid/ upspin/ CAHfGVNdPnbuFDb74ZvkvcSk8%2BZvwcDQm5xGcp9OouGcLV_ceNg%40mail.gmail.com . Reply all Reply to author Forward 0 new messages Search Clear search Close search Google apps Main menu