Das Böse Büro

Le etichette sono il contrario del pensiero.

Fediverso, 2.0 [English version at the end]

Scrivere Xenomorph da zero, in un linguaggio di programmazione di nicchia come SPARK/Ada, mi ha dato parecchia soddisfazione, ma contemporaneamente mi ha dato una libertà creativa che con gli altri fork semplicemente non avevo. E quindi, a un certo punto, ho dovuto farmi una domanda: ok, puoi cambiare quello che vuoi. Ma cosa? Cosa cambieresti, esattamente, se dovessi progettare una specie di Fediverso 2.0? La cosa interessante è che Mastodon nasce, nel 2016, esplicitamente nel mondo del microblogging come alternativa decentralizzata a Twitter. Eugen Rochko era un utente di Twitter insoddisfatto della direzione presa dalla piattaforma, e descriveva Mastodon proprio come un'alternativa federata a Twitter. Quindi dire che ne imitasse il modello è sostanzialmente corretto, anche se lo scopo era precisamente eliminare il controllo centrale sul sistema. E lo fa bene.

Il problema è che Twitter — e finalmente ve ne siete accorti — è un pozzo di tossicità.

E non soltanto perché è centralizzato, oppure perché a un certo punto è finito nelle mani di questo o quell'altro proprietario. Il problema è più profondo: ci sono MOLTE cose nel design stesso di Twitter, nel modo in cui sono costruite le interazioni, che spingono gli utenti verso la tossicità.

Se quindi prendete Twitter, togliete l'azienda centrale e distribuite il sistema su migliaia di server, avete certamente risolto un problema molto importante.

Ma non avete necessariamente risolto gli altri.

Così, ho deciso che Xenomorph continuerà a federare normalmente con il resto del Fediverso e manterrà, grosso modo, lo stesso insieme di funzioni essenziali di snac, al quale si ispira per filosofia di semplicità e leggerezza.

Ma non sarà semplicemente un altro snac scritto in Ada.

L'idea è precisamente quella di approfittare del fatto che sto scrivendo tutto da zero per modificare alcune delle scelte che, a mio avviso, il Fediverso ha ereditato quasi automaticamente dal modello Twitter.

Perché se il problema è anche nel design delle interazioni, allora non basta cambiare il protocollo di trasporto, decentralizzare i server o distribuire la moderazione.

Bisogna cambiare anche come gli utenti vengono spinti a comportarsi.

Ed è qui che cominciano le modifiche.



Il meccanismo del blocco istanza

È stato pensato, ovviamente, con una delle idee più tossiche del mondo in testa: la cancel culture.

Non intendo dire che storicamente il domain block sia nato dalla cancel culture: tecnicamente nasce da un'esigenza reale di moderazione, cioè poter isolare in blocco un server che produce spam, molestie, contenuti illegali o comunque una quantità di problemi tale da rendere assurdo intervenire utente per utente. Mastodon, infatti, consente agli amministratori di limitare o sospendere interi domini proprio per questo motivo.

Il problema è il modello mentale che ne deriva.

Perché appena mettete nelle mani di qualcuno un grosso pulsante con scritto, metaforicamente, “cancella quella gente dal mio universo”, state anche creando un ruolo che attira tutti gli aspiranti sceriffi del mondo: gente che vuole diventare admin anche per il piacere di poter bloccare Tizio, Caio, Sempronio e magari l'intera città dalla quale provengono, sentendosi nel frattempo investita di un qualche potere morale.

È una feature necessaria in certi casi. Ma è anche una feature potenzialmente tossica.

Xenomorph, invece, prova a togliere il più possibile questa dinamica dalle mani dell'admin.

Ha un proprio meccanismo automatico di rilevamento: se scopre che un'istanza remota lo ha bloccato, reagisce bloccandola a sua volta. Non per ripicca, ma perché continuare a tentare di federare con qualcuno che ha già deciso di non ricevere le vostre attività significa semplicemente sprecare traffico, code, retry e risorse.

La cosa interessante è che il blocco non viene trattato come una sentenza eterna.

Se l'istanza remota ricomincia successivamente a mandare attività valide, Xenomorph interpreta il fatto come un segnale che la federazione è nuovamente possibile e rimuove automaticamente il proprio blocco.

Quindi niente liste nere da amministrare religiosamente, niente vendette che sopravvivono per anni, niente archeologia diplomatica per capire perché nel 2024 qualcuno abbia bloccato qualcun altro.

Soprattutto: niente peso per l'admin.

Va tutto in automatico.

Poi esiste naturalmente il caso eccezionale. Quello nel quale non state semplicemente ricevendo un block remoto, ma avete davvero bisogno di interrompere immediatamente ogni rapporto con un'istanza: per esempio perché sta distribuendo materiale illegale, oppure perché sta causando un problema abbastanza grave da non poter aspettare i normali automatismi.

In quel caso esiste il pulsante Nuke.

Il nome è intenzionale: deve essere perfettamente chiaro che non state facendo ordinaria amministrazione. State usando l'opzione nucleare.

È disponibile soltanto all'admin.

Ma anche dal Nuke si può uscire.

Perché un sistema di moderazione che sa soltanto accumulare blocchi, senza avere anche un meccanismo per dimenticarli quando non servono più, prima o poi non diventa più sicuro.

Diventa semplicemente fossile.




Il blocco degli utenti remoti

Per molti utenti, il blocco finisce per diventare un altro meccanismo tossico: quello che permette di pensare di aver zittito qualcuno.

Solo che non sentire più qualcuno e averlo zittito sono due cose completamente diverse.

Quella persona continua a parlare. Parla con gli altri, scrive, viene letta, continua tranquillamente a esistere. Semplicemente, voi non la sentite più.

Pensare il contrario è un meccanismo abbastanza infantile: è il bambino che si tappa le orecchie e comincia a dire lalalala, non ti sento.

Il problema è che, quando questa cosa viene trasformata in una funzione dell'interfaccia, rischia di nutrire a dismisura proprio quella sensazione: io ho premuto il bottone, quindi tu sei sparito. Una piccola gratificazione di potere che, in realtà, non corrisponde affatto a quello che sta succedendo.

Xenomorph mantiene comunque il blocco degli utenti. ActivityPub prevede infatti l'attività Block, e Mastodon la usa anche tra server: quando un utente locale blocca un account remoto, può inviare al server remoto una Block activity.

Curiosamente, lo stesso standard ActivityPub raccomanda invece che queste attività non vengano normalmente consegnate all'oggetto del blocco nel caso server-to-server; Mastodon ha scelto di farlo ugualmente come estensione del comportamento federato.

Ed è proprio questa informazione che Xenomorph può sfruttare.

Quando qualcuno vi blocca e il server remoto comunica il Block, Xenomorph se ne accorge. Internamente esiste anche una notifica dell'evento, sebbene normalmente non ci sia alcun motivo per sbattervela in faccia: sapere che Tizio vi ha bloccato, nella maggior parte dei casi, non migliora in alcun modo la vostra giornata.

Xenomorph semplicemente blocca di rimando.

Non come vendetta, ma come conseguenza tecnica: se quell'account ha dichiarato di non voler più interagire con voi, non c'è una particolare ragione per continuare a spendere risorse nel tentativo di interagire con lui.

E anche questo blocco non deve necessariamente diventare eterno.

Se successivamente arriva un Undo Block, oppure l'account remoto torna in una condizione nella quale l'interazione è nuovamente valida secondo le regole di Xenomorph, il blocco automatico può essere rimosso. Mastodon stesso prevede esplicitamente Undo anche per annullare un precedente Block.

Il blocco manuale continua quindi a esistere, perché ovviamente ci sono situazioni nelle quali serve davvero. Anche Mastodon distingue il semplice mute, che serve sostanzialmente a non vedere qualcuno, dal block, che modifica anche la relazione tra i due account e impedisce follow e altre interazioni.

Ma in Xenomorph il blocco manuale dovrebbe essere soprattutto uno strumento per le situazioni nelle quali siete voi ad avere bisogno di interrompere un rapporto.

Per tutti quelli che invece decidono di bloccare voi, non c'è bisogno di trasformare la cosa in un piccolo evento diplomatico.

Non dovete controllare chi vi ha bloccato.

Non dovete compilare liste.

Non dovete ricambiare manualmente.

Non dovete nemmeno interessarvene.

Se non volete occuparvi di chi vi blocca, semplicemente non fatelo.

Lasciate fare a Xenomorph.

Niente stress, nemmeno qui.


Il numero di follower

Poi c'è il numero di follower.

È la continuazione digitale del vecchio: sono il ragazzo o la ragazza più popolare del liceo. Un meccanismo competitivo, tossico e abbastanza bullistico, molto da scuola superiore americana: la popolarità trasformata in una quantità numerica, visibile a tutti, e quindi utilizzabile come misura del valore sociale di una persona.

A che serve?

A monetizzare la popolarità? A stabilire quanto vale un influencer? A vendere pubblicità?

Perfetto. Allora nel Fediverso non serve.

Il problema non è nemmeno teorico. Abbiamo avuto esempi quasi caricaturali di questo modo di ragionare.

Nel 2012 Maurizio Gasparri rispose a un utente che lo criticava facendo notare che aveva soltanto 48 follower: prima «Seguito da 48, imbarazzante», poi «Con 48 non arrivi neanche all'angolo», e infine il magnifico «Non sei nessuno». Il

Corriere dell'epoca riassunse la faccenda parlando, molto appropriatamente, di Twitter «tanto al peso».

Per la serie: io so' io, e tu non sei un cazzo.

Gasparri.

Ed è precisamente questo il problema del contatore pubblico. Non misura soltanto una proprietà dell'account: finisce inevitabilmente per diventare una gerarchia. Uno ne ha cento, uno diecimila, uno un milione, e improvvisamente sembra perfettamente naturale pensare che il terzo conti più del primo.

In Xenomorph, quindi, il proprietario dell'account può vedere il proprio numero reale di follower quando è autenticato.

Le istanze federate, invece, vedranno sempre un numero falso e volutamente spropositato.

Non serve a simulare popolarità. Serve esattamente al contrario: a rendere il numero inutilizzabile come segnale di status.

Se ogni account dichiara di avere una quantità assurda di follower, il dato smette di servire per costruire classifiche, confronti, prestigio, ansia da prestazione e gerarchie sociali.

Quando tutti sono star, nessuno è una star.

E abbiamo eliminato un altro piccolo pezzo di liceo americano dal social network.



E con questo voglio dire una cosa.

Passando da un sistema centralizzato a uno federato avete risolto una parte del problema. Una parte importante, certamente: avete eliminato il singolo proprietario, il singolo algoritmo, il singolo centro di potere che può decidere per tutti.

Ma l'altra parte del problema è rimasta lì.

Perché è insita nel design del servizio.

Se conservate gli stessi meccanismi sociali, le stesse metriche di prestigio, gli stessi pulsanti pensati per gratificare il conflitto e la stessa architettura delle interazioni, la decentralizzazione da sola non basta.

Avete cambiato chi controlla il sistema, ma non necessariamente quello che il sistema induce le persone a fare.

E adesso io ho deciso di attaccare proprio quella parte.

Xenomorph si trova qui: https://git.keinpfusch.net/loweel/xenomorph

L'immagine Docker già pronta si trova qui:

https://hub.docker.com/r/loweel/xenomorph

Le istruzioni per l'installazione normale e per Docker/Docker Swarm si trovano direttamente nel repository, nei file INSTALL.md e DOCKER.md.

È già abbastanza stabile per ospitare pochi utenti e per essere usato sul serio. Il README lo definisce attualmente utilizzabile per test reali su piccole istanze e per il normale dogfooding, anche se è ancora in fase di hardening e non viene ancora presentato come scelta conservativa per istanze pubbliche lasciate incustodite.

Il resto verrà provandolo, rompendolo, correggendolo e soprattutto continuando a chiedersi una domanda che, secondo me, nel mondo dei social network viene fatta troppo raramente: questa feature serve davvero agli utenti, oppure serve soltanto a riprodurre un comportamento tossico che ci siamo abituati a considerare normale?



ENGLISH VERSION



Writing Xenomorph from scratch, in a niche programming language like SPARK/Ada, gave me quite a lot of satisfaction, but at the same time it gave me a degree of creative freedom that I simply never had with the other forks.

And so, at some point, I had to ask myself a question: OK, you can change whatever you want. But what?

What would you change, exactly, if you had to design some kind of Fediverse 2.0?

The interesting thing is that Mastodon was born, in 2016, explicitly in the microblogging world as a decentralized alternative to Twitter. Eugen Rochko was a Twitter user dissatisfied with the direction the platform was taking, and he described Mastodon precisely as a federated alternative to Twitter.

So saying that Mastodon imitated Twitter's model is basically correct, even though the purpose was specifically to eliminate centralized control over the system.

And it does that well.

The problem is that Twitter — and finally you noticed — is a cesspool of toxicity.

And not only because it is centralized, or because at some point it ended up in the hands of this or that owner.

The problem goes deeper: there are MANY things in Twitter's design itself, in the way interactions are constructed, that push users toward toxic behavior.

So if you take Twitter, remove the central corporation and distribute the system across thousands of servers, you have certainly solved one very important problem.

But you have not necessarily solved the others.

So I decided that Xenomorph will continue to federate normally with the rest of the Fediverse, and will retain roughly the same essential set of features as snac, which inspired its philosophy of simplicity and lightweight design.

But it will not simply be another snac written in Ada.

The whole point of writing everything from scratch is precisely that I can take advantage of this freedom to modify some of the choices that, in my opinion, the Fediverse inherited almost automatically from the Twitter model.

Because if part of the problem lies in the design of the interactions themselves, then changing the transport protocol, decentralizing the servers, or distributing moderation is not enough.

You also have to change the way users are encouraged to behave.

And this is where the changes begin.


Instance blocking

It was designed, obviously, with one of the most toxic ideas in the world in mind: cancel culture.

I am not saying that domain blocking historically originated from cancel culture. Technically, it exists because of a real moderation requirement: sometimes you need to isolate an entire server that produces spam, harassment, illegal material, or simply so many problems that dealing with its users one by one would be ridiculous.

Mastodon therefore allows administrators to limit or suspend entire domains for exactly this reason.

The problem is the mental model that comes with it.

Because the moment you put a big button into someone's hands which metaphorically says “delete those people from my universe”, you are also creating a role that attracts every aspiring sheriff on the planet: people who want to become admins partly for the pleasure of being able to block Tom, Dick, Harry, and perhaps the entire town they come from, while feeling invested with some kind of moral authority.

It is a necessary feature in some cases.

But it is also a potentially toxic feature.

Xenomorph instead tries to remove as much of this dynamic as possible from the administrator's hands.

It has its own automatic detection mechanism: if it discovers that a remote instance has blocked it, it reacts by blocking that instance in return.

Not out of spite, but because continuing to attempt federation with someone who has already decided not to receive your activities simply means wasting traffic, queues, retries, and resources.

The interesting part is that the block is not treated as an eternal sentence.

If the remote instance later starts sending valid activities again, Xenomorph interprets this as a signal that federation is possible again and automatically removes its own block.

So there are no blacklists to maintain religiously, no grudges surviving for years, no diplomatic archaeology required to discover why somebody blocked somebody else in 2024.

Most importantly: no administrative burden.

It all happens automatically.

Then, of course, there is the exceptional case.

The case where you are not merely receiving a remote block, but genuinely need to cut off all relations with an instance immediately: for example because it is distributing illegal material, or because it is causing a problem serious enough that you cannot wait for the normal automatic mechanisms.

In that case, there is the Nuke button.

The name is intentional: it must be perfectly clear that this is not routine administration.

You are using the nuclear option.

It is available only to the administrator.

But even a Nuke can be reversed.

Because a moderation system that only knows how to accumulate blocks, without also having a mechanism for forgetting them when they are no longer necessary, does not eventually become safer.

It simply becomes fossilized.


Blocking remote users

For many users, blocking eventually becomes another toxic mechanism: the mechanism that makes them think they have silenced someone.

Except that not hearing someone anymore and having silenced them are two completely different things.

That person keeps talking.

They talk to other people, they write, they are read, they continue to exist perfectly well.

You simply do not hear them anymore.

Thinking otherwise is a rather childish mechanism: it is the child putting their hands over their ears and going lalalala, I can't hear you.

The problem is that when this behavior is turned into an interface feature, it risks feeding exactly that feeling to absurd proportions:

I pressed the button, therefore you disappeared.

A tiny gratification of power which, in reality, does not correspond to what is actually happening.

Xenomorph still supports user blocking.

ActivityPub defines the Block activity, and Mastodon also uses it between servers: when a local user blocks a remote account, it can send a Block activity to the remote server.

Interestingly, the ActivityPub standard itself recommends that these activities not normally be delivered to the object of the block in server-to-server communication; Mastodon chose to do so anyway as an extension of federated behavior.

And this is precisely the information Xenomorph can use.

When somebody blocks you and the remote server communicates the Block, Xenomorph notices.

Internally, there is even a notification for the event, although there is normally no reason to shove it into your face: knowing that some random person blocked you will, in most cases, not improve your day in any way.

Xenomorph simply blocks them back.

Not as revenge, but as a technical consequence: if that account has declared that it no longer wants to interact with you, there is little reason to keep spending resources attempting to interact with it.

And this block does not need to become eternal either.

If an Undo Block later arrives, or the remote account returns to a state in which interaction is valid again according to Xenomorph's rules, the automatic block can be removed.

Mastodon itself explicitly supports Undo to reverse a previous Block.

Manual blocking therefore still exists, because obviously there are situations where it is genuinely necessary.

Mastodon itself distinguishes a simple mute, which essentially means that you no longer see somebody, from a block, which also changes the relationship between the two accounts and prevents follows and other interactions.

But in Xenomorph, manual blocking should mainly be a tool for situations in which you need to terminate a relationship.

For everyone who decides to block you instead, there is no reason to turn the event into a miniature diplomatic crisis.

You do not have to check who blocked you.

You do not have to maintain lists.

You do not have to retaliate manually.

You do not even have to care.

If you do not want to deal with people who block you, simply don't.

Let Xenomorph handle it.

No stress here either.


Follower counts

Then there is the follower count.

It is the digital continuation of the old:

I am the most popular boy or girl in high school.

A competitive, toxic, fairly bullying mechanism, very much in the style of an American high school: popularity transformed into a number, visible to everyone, and therefore usable as a measurement of somebody's social value.

What is it for?

Monetizing popularity?

Establishing how much an influencer is worth?

Selling advertising?

Perfect.

Then we do not need it in the Fediverse.

And this problem is not merely theoretical.

We have seen almost caricatural examples of this kind of thinking.

In 2012, Maurizio Gasparri replied to a user who criticized him by pointing out that the user had only 48 followers.

First:

“Followed by 48 people, embarrassing.”

Then:

“With 48 you don't even make it around the corner.”

And finally the magnificent:

“You are nobody.”

The Corriere at the time summarized the affair, quite appropriately, as Twitter being valued “by weight.”

Or, to quote the Roman expression:

io so' io, e tu non sei un cazzo.

Roughly:

I'm somebody, and you're fucking nobody.

Gasparri.

And that is precisely the problem with the public counter.

It does not merely measure a property of the account: inevitably, it becomes a hierarchy.

One person has a hundred followers, another has ten thousand, another has a million, and suddenly it seems perfectly natural to assume that the third person somehow matters more than the first.

So in Xenomorph, the owner of an account can see their real follower count while authenticated.

Federated instances, however, will always see a fake and deliberately ridiculous number.

The purpose is not to simulate popularity.

Quite the opposite: the purpose is to make the number useless as a status signal.

If every account claims to have an absurd number of followers, then the metric stops being useful for rankings, comparisons, prestige, performance anxiety, and social hierarchies.

When everybody is a star, nobody is a star.

And we have removed yet another small piece of American high school from the social network.


And with all this, I want to make one point.

By moving from a centralized system to a federated one, you solved part of the problem.

An important part, certainly: you removed the single owner, the single algorithm, the single center of power capable of deciding for everyone.

But the other part of the problem remained exactly where it was.

Because it is built into the design of the service.

If you preserve the same social mechanisms, the same prestige metrics, the same buttons designed to reward conflict, and the same architecture of interactions, decentralization alone is not enough.

You changed who controls the system.

You did not necessarily change what the system encourages people to do.

And now I have decided to attack precisely that part.

Xenomorph is here:

https://git.keinpfusch.net/loweel/xenomorph

The ready-to-use Docker image is here:

https://hub.docker.com/r/loweel/xenomorph

Instructions for normal installation and for Docker/Docker Swarm are available directly in the repository, in INSTALL.md and DOCKER.md.

It is already stable enough to host a small number of users and to be used for real.

The README currently describes it as suitable for real-world testing on small instances and normal dogfooding, although it is still undergoing hardening and is not yet presented as the conservative choice for unattended public instances.

The rest will come from trying it, breaking it, fixing it, and above all from continuing to ask a question which, in my opinion, is asked far too rarely in the world of social networks:

does this feature actually serve the users, or does it merely reproduce a toxic behavior that we have become accustomed to considering normal?

Uriel Fanelli

--
Written using Blogfrei: https://git.keinpfusch.net/loweel/blogfrei
Fedi: @uriel@bbs.keinpfusch.net
XMPP: uriel@keinpfusch.net
vecchio blog: https://blog.keinpfusch.net
email: blog@keinpfusch.net