The post here is pretty confusing (so no blame to anyone who reads this as "IPFS the project" shutting down instead of just a single maintainer team, it's totally misleading) - but this is actually just a sunset announcement for _Shipyard_ - one of many IPFS implementation maintainers.
*The IPFS Project is not sunsetting or shutting down* - just switching to individual maintainer grants instead of centralized implementation support within Shipyard.
@dang yes, and title is editorialized, the real one is "The end of IPFS at Shipyard" which is more informative
It's still a a real loss, those are widely used products, but the signal that Protocol Labs is sending about IPFS in defunding this might be even worse for the ecosystem. Cloudflare, Brave, and now Protocol Labs have abandoned it.
Sad to see it go having been a maintainer some years ago.
For anyone wondering, there are more sustainable (with a viable, focused business backing the project) options to do p2p, namely Iroh - https://www.iroh.computer/ which was built by ex-IPFS ex-Protocol Labs devs (I have no relation to the team beyond having worked with them back in the day).
Sadly Protocol Labs is doing.. ehh whatever now, except apparently supporting the projects it got its VC/crypto funding from.
Iroh is great! As is ATProto! Both build on DASL (https://dasl.ing/bdasl.html) - which specifies the core content addressing layer of IPFS.
However - important clarification about the Shipyard post that I think a lot of folks are confused by:
While its sad to see the Shipyard team sunset, the IPFS project is decentralized & robust to a single party moving on. IPFS the project/network is not sunsetting or shutting down!
Current focus is lighter-weight stewardship from the IPFS Foundation via grants to individual maintainers, & development of decentralized public infra tools like the Service Worker Gateway.
You are describing Protocol Labs' plans in the first person, as "current focus". If you work there, please say so in the comment. On a thread about Protocol Labs ending the maintainers' funding, that context matters to anyone weighing the reassurance.
DASL specifies CIDs, CAR and deterministic CBOR. It deliberately does not specify UnixFS, and it has no way to chunk a file into blocks. UnixFS is what ipfs add has produced since 2015, and what Kubo, Boxo, Helia and the gateways address today. So DASL is the naming layer, not "the core content addressing layer of IPFS". Writing a new format is easy. The stability people built on came from not rewriting this one, and from someone shipping it in the software they already run.
I run Kubo and Helia in production. "Robust to a single party moving on" would be easier to accept with answers to these:
- Who triages vulnerability reports and ships fixes for Kubo, Boxo and Helia after September? Does the contact in https://github.com/ipfs/community/blob/master/SECURITY.md still reach a person?
- Will anyone cut releases, or should operators pin current versions and plan around that? Should we expect a community fork?
- Who operates ipfs.io, dweb.link and delegated-ipfs.dev day to day after September, and with what experience running public infrastructure at that scale?
- What happens to the Service Worker Gateway at https://inbrowser.link ?
- What happens to Badbits at https://badbits.dwebops.pub ? Does it stop being updated when Shipyard turns the lights off?
A grant to an individual maintainer is not the same as a named owner with commit rights and a release process.
On the Service Worker Gateway as decentralized public infrastructure: the subdomain gateway spec requires a wildcard TLS certificate for the ipfs and ipns subdomains, plus a Public Suffix List entry so each CID gets its own origin. You also need a denylist, or you end up serving phishing. Very few people reading this thread can self-host that, and the ones who try will meet the abuse problem next.
The same questions are open on discuss.ipfs.tech. A direct answer there would help more than reassurance here.
The way I would put is as: Iroh + iroh-blobs == libp2p + UnixFS + Bitswap, and the latter three are some of the critical components that have defined most IPFS implementations.
Iroh got started with IPFS-style content-addressed blob transfers as the primary way to use it, still has that functionality but its now a bit of a second tier citizen. See https://docs.iroh.computer/protocols/blobs
Besides just p2p streams seem to be much more useful, those are plug-and-play into most software, e.g. I wrote https://github.com/magik6k/git-remote-iroh that just plugs the git remote proto into iroh and lets you move repo commits between computers by just copying a string from one place to another on push. Doing that with blobs - not gonna happen, not that easily.
Love DASL (funded by IPFS too)! Iroh also meets the DASL spec (https://dasl.ing/bdasl.html). A great bridging opportunity for agents to build interop between many different content addressed systems!
This. Haven't seen this in the news in years. A few years ago (2022?), they got some $x00 million in investment money. They already had IPFS/IPNS at that point so it was some deep push into Filecoin. But it felt odd at the time. Bitcoin was starting to jump the shark at that point and none of the smarter cryptos had truly found a market fit either.
The way I would put is as: Iroh + iroh-blobs == libp2p + UnixFS + Bitswap, and the latter three are some of the critical components that have defined most IPFS implementations.
IPFS, Freenet, and experiments like that mainly serve as a place for people to store and distribute pirated copyrighted material, child porn, hit lists, terrorism manifestos and plans, and the like.
Scratch a libertarian and, nine times out of ten, you'll find someone who advocates for no or minimal government because they want to do something the government legitimately bars them from doing. Scratch a libertarian decentralized P2P E2EE communication project and you'll find... well, this kind of material nearly every time.
Your local computer hard drive can also be used to store all of the above. Are you also okay to make it scannable by anyone?
Worse you can store child porn as paper pictures in your house and can privately communicate in there with other unknown people and mignt even be do something illegal there. Do you want to install some police security camera in your toilet?
Oh, and in some countries being LGBTQ+ person or political activist or women right activist is illegal and will land you to execution on chop chop square. Should we also let all the governments find these people too?
This is really unfortunate. When cloudflare dropped IPFS you could say this next step was sort of already on the way. I may be biased but I think when IPFS decided to put so much time into "IPNS" in order to support non-static webapps years ago what they came up with did not fit the need. And without webapps on IPFS things were going nowhere.
A year or so ago I wrote IPFS-boot which allows serving webapps on IPFS while providing also an update path and without breaking content hashing:
But now if you want to serve a secure webapp and not use IPFS IMO the only option you have is to tell users to install Tailscale and to host the webapp themselves and then to install Tailscale on all devices.
I agree that IPNS has always seemed a bit naff; but alternatives naming systems can be used too (if your system's name resolver can understand them); e.g. this uses pkarr addresses for IPFS content: http://www.chriswarbo.net/blog/2026-05-08-pkdnslink.html
Regarding an "update path", GNS has support for that built-in; though I've not been able to try it myself, since I can't get GNUNet to bootstrap :-(
I always thought that they should have used ENS instead of whatever coin they ended up making. GNS is cool but IIRC (years ago) it had no incentive mechanism which is I think where a lot of these solutions fall down. Even imaginary "ratio points" that p2p file sharing sites have being using for years work better than "donate your resources out of the goodness of your heart".
Half baked comment but I feel like many of these efforts are too purist. Sure they need to think more carefully about incentives from a systemic angle but also why not accept a hybrid design that doesn't depend on those in the first place? For example plenty of people operate their own nameservers for their own websites to use, or spin up a VPS to support [thing] they make use of. So at a minimum I'm sure webring-style infra where you cover for your friends and they cover for you would work quite well.
For a real world example of a hybrid approach that works see bittorrent where torrents can optionally contain urls that point to alternate download sources in order to speed up the initial seeding phase.
I see this very similar to IPv4 and IPv6, and adoption. Non content addressable URL addressing simply is "good enough" for most use cases, and bittorrent is "good enough" for serving content durably and somewhat in a content addressable manner (file hashes, magnet torrents, immutable torrents). Do we need IPFS URLs? It doesn't appear so, it seems like a solution seeking a problem. IPFS gateways will always be a target for abuse and copyright claims as well.
I think something like IPFS is definitely needed. There is nothing stopping you from distributing a webapp on bittorrent but you'll also need to add a README for instructions on how to run the webapp on localhost so a browser can render it. So thats not something that any non-technical user wants to do.
Arguably that's a browser shortcoming that applies equally to IPFS (as well as all the other "alternative" internet protocols). (But yes I realize IPFS is a much better fit for the purpose when you dig into the details.)
Can you share potential webapp use cases that would rely on IPFS or using IPFS for referencing resources would be an improvement? Perhaps my mental has gaps on this topic, and my thoughts and assertions could be incorrect.
The arguments for "reproducible builds" are strong and so think reproducible builds but for something that can be loaded in the browser. Browser is a big deal because its a sandbox also. For example Signal could be a webapp if we had content addressable hashing and it would be sandboxed.
I don't understand. Billions of non-technical users are loading URLs like `https://cdn.foo/?guid=deadbeefdeadbeefdeadbeef` all the time. Why would they care if those URLs became `ipfs://deadbeefdeadbeefdeadbeef` instead?
My go to example: IPFS is Plan9 to bittorrent's UNIX. Some achingly beautiful design, willingness to completely disregard existing messy conventions(for example: The ipfs unified url format) and, like you said, still not enough better for people to want to change.
Oh and sorry I missed your comment on "Subresource Integrity".
The deal here is Subresource Integrity will only help you if the index.html is considered trusted/authoritative. So you still need a way to get index.html to users and users need a way to say "is this the true index.html"
I think parent is talking strictly about P2P, so you'll need (typically) something to help you tunnel between clients, as there are NATs and all sorts of things between two typical consumer computer at two different homes.
> If you have a favourite memory of working with Shipyard, or an idea you always hoped IPFS would eventually achieve, we’d love to hear it. Google Form
One important thing I'd like to see IPFS or a similar decentralized web technology achieve, is getting rid of the necessity of filling out a Google form in order to tell the Shipyard people what I think about their maintenance of IPFS.
Seriously it bugs me when people who ostensibly care about decentralized or privacy technology use a centralized service hosted by a gigantic tech company to accomplish a task because it's convenient (if you already have an account with them), and don't even try to make a decentralized version available. It would have been better if they simply invited people to send them an email.
I wonder what distinguishes these kinds of communities over others. Some, like 'decentralization' or 'privacy' or 'security', require absolute adherence. If you're building a decentralized tool or a privacy tool or a security tool you must first reinvent the universe. Post on HN? Centralized, privacy nightmare, insecure. Use Gmail as your email provider? Centralized, privacy nightmare, insecure. Fastmail? Centralized. Run your own mail provider? Cool, on a cloud? Centralized, privacy nightmare. On your own infra? Centralized, bus factor 1.
Sort of an interesting market signal. "Don't bother building for me unless you're absolutely pure". Funny stuff.
This is honestly just the nitpickiest complaint of all. Criticizing people who just found out they're losing their jobs for which solution they use to collect fond memories from their users is an outrageous thing to get upset over. Just don't fill out the form.
Imagine if all the energy spent whining on the purity of a system being insufficiently private or decentralized or somehow loyal to a fight against the man, was spent instead on actually improving those systems. They're open source.
It's a problem for the entire ecosystem that the most expedient thing to do, the thing that we should have sympathy for them picking under a time of stress, is the thing that relies on people who want to communicate with them having a Google account and having that communication intermediated through Google with no alternative. And since the entire point of Shipyard as an organization is to be stewards of the decentralized web software ecosystem, the fact that they're not using decentralized web tech is relevant to their mission and values.
I could (sort of) see why you might get this upset if people were required to have a Google account themselves to submit this Google form, but that's not the case. Who are you to tell an underfunded opensource dev company that just lost their biggest project what tools they should use? That email you hypothetically sent will probably get delivered to an account in their Google Workspace, how on earth is that any different?
I've run into a lot of Google forms for projects that do in fact require me to log in with a Google account in order to submit, which I think might be related to Google detecting that I'm using a VPN and treating the submission as higher-risk. I just have this reflexive assumption that if something is presenting me with a Google form, it's not gonna work unless I log into a Google account on my local machine. Which is ultimately the reason I care about this kind of thing.
It's not their job to cater to your nitpicking. Even if this Google form didn't work over a VPN (which it totally does), you're capable of turning the VPN off if you really want to submit feedback. But it doesn't even sound like you have any feedback, so what's your problem?
I think it's a perfectly valid complaint about the ecosystem at large. Not a criticism of the individuals or of this specific case to be clear, but a broader observation that this isn't how things ought to be according to a certain set of ideals and the question then of why we keep seeing it over and over. Clearly there's some sort of systemic shortcoming that applies to the entire ecosystem.
I tried to build a few non crypto decentralized apps. The killer was reliable always deliverability inside the browser. https://inbrowser.link/ was a huge jump in utility but came to late the ipfs.js just never worked consistently. In the end the only way to get good XP for yours users was that you provider the IPFS to http gateway for all content but then whats the point its just decentralization theater.
I remember in 2015 having the IPFS concept blow my mind its such a memorable moment when it really felt like someone designed something significantly different that current mainstream paradigms.
But in the end it seems like it was still a case of a cool technology looking for a use-case not solving a real problem.
> In the end the only way to get good XP for yours users was that you provider the IPFS to http gateway for all content but then whats the point its just decentralization theater.
I gave my static photo album website image files paths that consisted of /ipfs/ as directory name and ipfs hash as file name.
Brave browser was able to figure out that this meant they were available on IPFS, and asked me if i wanted to load the files from IPFS instead of from the web server itself.
So over time if hosting files on IPFS got popular, it could have been used automatically by browsers later to load the files from IPFS instead of the web server of the site. Saving bandwidth for the website operators and distributing storage of content which might also help it remain available for longer time.
That sort of thing would have been one great outcome, for example, where this sort of hosting your own http gateway for your own IPFS files makes sense like I was doing. Mind you, the web server setup for this was completely straightforward and requires no running of the IPFS services on the web server itself. On the web server it really was plain old directories and file names. As long as they are real IPFS hashes. And calculating the IPFS hash itself I did on my laptop when adding photos.
Very sad to hear in this thread that Brave browser has actually removed IPFS support :(
I wonder if (in theory) it wouldn't make more sense to address this sort of thing at the system resolver level rather than in the browser, the way tor does.
Agreed. I was deep in the ecosystem, did the confs, shipped some apps. It’s hard to think of a use case that would be reliable now. Maybe some kinda file sync that is torrent like but http
It kinda feels like the AWS or Azure of file distribution, so much stuff so confusing. Also apparently with Protocol Labs owning several of those things despite not operating those things?
I run a company currently serving ~1.7B requests per day (~20k/s) to ipfs gateways, so presumably still some. Very likely a big chunk of that is bots scraping stuff.
I guess IPFS is an artifact from the crypto craze. It's pretty silly if you think of it. However, I must admit, I got my first ever developer grant from Filecoin while they were flush with ZIRP era money.
btw,I thought it was an Initial Coin Offering, not an actual fundraise.
What's silly about it? Content-addressable decentralized storage -- not tied to a cryptocurrency -- is really valuable for censorship-resistant archiving of politically-sensitive data (such as climate change research).
Except it wasn’t censorship resistant at all, in that your node advertised itself as a node with a-z files on it. Separately you could put it behind a vpn or run a vps you paid for with monero, but fundamentally it’s more of a way just to pin a file to an address that works no matter what domain or IP the file is behind.
In addition to that, this noble goal of being an insurance policy against censorship never played out.
How hard would it be for a country to block the clients and browser extensions you need to use it in the first place? Or to develop a firewall technology that’s capable of blocking the traffic?
Probably not that hard, especially since nobody uses IPFS for anything business critical since it’s not all that great at doing things that you need from file storage systems.
Most reasons you store files somewhere benefit from not being decentralized. You usually want some combination of performance, security, durability, and availability. Decentralization is not generally a demand of file storage.
The only reason it’s decentralized is because blockchain and crypto was hype 10 years ago.
IIRC IPFS was the latest in a long line of Distributed Content-Addressed systems that long predate crypto. AFAICT (obviously I wasn't paying much attention) they went crypto (FileCoin) to fund a base population of storage users to bootstrap its popularity.
What people did or planned to do with IPFS is pretty silly, but the idea of content addressed storage with cryptographic (not in a crypo coin way) names makes a lot of sense. It would make for a great software distribution method e.g. your game downloads get faster the more people want to play the latest version. It's the combination of Git and BitTorrent and has uses far beyond just hosting warez and NFTs.
This. I also always imagined it be able to host some version of an Encarta/encyclopedia that would be so distributed it would probably survive world wide catastrophe.
Wait are you telling me yet another supposedly ground breaking technology turned out to be yet another grift.
I know a lot of people on HN are going to call me overly cynical. But this pattern should be so obvious by now. Any cynicism to any new ground breaking technology which is gonna solve a problem that exists because of capitalism, that this cynicism is more than warranted.
At this point we should all be cynical of any new technology.
Yeah, I now understand why gray beards are seen as grumpy. Mine isn’t gray yet, but after the 2010s and half of 2020s I can only see as very suspicious any new technology pushed hard by the industry
I can not say IPFS was a bad idea. Consider GitHub: it is a massive content-addressed store with a smiley on it. There has been some very hot P2P products, e.g. Tailscale. Protocol Labs had its peak during/after the ICO, but long-term, (1) they did not focus on some particular audience and (2) performance of the network was not great. I personally believe that their bet on DHT was not the right one (I worked in this area long before IPFS btw). OK, in retrospect we are all wise.
I'm currently on sabbatical looking for volunteer work. I always thought IPFS was an interesting project, might be happy to pitch in some of my now-free bandwidth.
I don't think the problem was a lack of effort. The tech was interesting and innovative but the foundation of it had limits that were extremely hard to work past. As a technology it laid a lot of groundwork for better ideas, but I doubt it's worth investing in.
Is anyone aware of where IPFS community discussion is taking place? The forum seems almost dead and the community page has broken discord and matrix links.
What makes/made IPFS special was how it could be seen with relative ease on the standard internet. That feature allowed it to bypass censorship. I cannot say I am surprised that the funding was not re-upped since it seems like the modern web really loves censoring the crap out of things.
Edited: I also liked how it bypassed the traditional domain system.
These are good qualities in general; but it's worth asking why this anti-censorship technology required funding from one organization (Protocol Labs) that could cut off that funding and now has done so. Being economically non-viable without grants is one way that anti-censorship technology is ineffective at its stated goal.
> Protocol Labs is an innovation network driving breakthroughs in computing to push humanity forward. PL connects more than 750 tech startups, funds, accelerators, foundations, open source projects, service providers, and other organizations.
What happened to them? Seems like they drank their own "Web3" Fla-Vor-Aid.
Always found ipfs and the whole "web 3.0" company to be incredibly obtuse to work with especially compared to previous peer to peer networks like bit-torrent.
I could never shake the feeling there is an unnecessary layer of grift embedded in all the protocols.
See I thought if IPFS was picked up by the piracy scene (some bigger private trackers for example) then it probably would have been more successful. Alas I haven't seen it outside of libgen and even there I thought it was a backup option only.
I always thought it could be the evolution of Bittorrent: updatable torrents (with IPNS), peers sharing files from different "bundles" as long as the bits match.
The problem was that there was no good client for it that was better than current torrent clients. When I tested it you had to keep a duplicate of the files in the ipfs cache directory and the client was CLI based which would alienate most users. There's probably no way to have private trackers or to track seed/leech ratios for communities too.
It was also pretty slow (download rate wise), even if the destination and source node had a good link between them. I think the protocol had a lot of back-and-forth chatter, requesting blocks a few a time.
I tried to query a lot of resources (NFT images, many of which are/were hosted on IPFS) from IPFS myself using the official Go server, running on some pretty fast/wide hardware, for a good part of 2021 and 2022. It was a dumpster fire. Here are two specific problems that I remember, though I ran into several more. First, the UDP storm that it created somehow broke my network, where all of my switches gave up and just started sending all of its traffic to all of the nodes on the network. That could have been a "me" thing but it really made it hard to trust. I ended up having to give that server its own VLAN. Second, the caching was brain dead. By default, it would write every resource to the cache even if I was just using it to download them to a local directory, so it wrote everything twice. Even worse, when the cache was full, it would just drop the whole cache, which created huge spikes in IO util. I ended up patching the app to remove caching.
It felt like a really cool demo that never got cleaned up to work as a real production product.
Remember Filecoin? The original concept was that you could buy perpetual storage with a one time payment. It was funded by a crypto asset which was a derivative of mass storage prices, or something like that. Lighthouse supposedly sold such a product.[1] They no longer do.[2]
I wasn't aware of the relationship between Shipyard and Protocol Labs but it looks like Protocol Labs spun out maintenance and development of a lot of core IPFS technology to a new company called Shipyard, with the idea of cordoning off what was a cost center to Protocol Labs, and the hope was that Shipyard would be able to find other sources of revenue beyond the services funding they got from Protocol Labs.
I'm personally quite disappointed because I just built an IPFS based system built on top of Kubo that I was hoping would take off. Now this throws future maintenance of Kubo into question.
IPFS doesn't fetch or store content that the user has not explicitly requested. If your application allows strangers to request arbitrary IPFS objects, this might be a concern. Otherwise, no, simply running a node doesn't expose you to this risk.
The question is why IPFS did not get the traction something like Tor had for decades?
I believe the fundamental problem of those protocols is everyone fear ending up serving child porn just by running a "node" and taking a chance at explaining the future P2P internet to a judge.
IPFS got a CID deny list [0] but it was too little too late
I know you jest, but both the IPFS contributors I knew in college graduated to become web3 degens working on decentralized file storage projects. Specifically Walrus, which grew out of Meta's Libra project.
The asset is more akin to a deed or a claim. Most NFTs are images hosted on S3 or IPFS. The blockchain entry is metadata with a pointer to the hosted asset.
all the NFTs I launched actually were fully onchain SVGs and CSS
tried to be the change I wanted to see
given where the concept actually found staying power (liquidity pools, instead of collectibles) it wholly needs a new name
“NFT” is distracting at this point, they should just called them 721-structs so people don’t get distracted by the fumbled poorly implemented art use case
despite the "non fungible" in the name, tickets in this format ironically adds fungibility that non-blockchain marketplaces decrease
right now outside of the web3 space, all promotion companies release tickets in different ways. the ability to resell them is unknown, the quantity for sale is unknown and opaque, the service fees make no sense for the last 20 years, the ability to transfer them is unknown, and the ability to lose your money on an attempted resale transaction is absurdly high. in comparison, all NFTs in the blockchain space inherit solutions to all of those problems and all marketplaces are just UI's on top of data already there in a uniform way, alongside new problems that are mostly education based and won't be solved with a different user experience (akin to how debit and credit cards introduced new problems with automated teller machines many decades ago, that never were solved but didn't deter the concept)
can a centralized marketplace and issuer that conforms solve all of it? of course, but that hasn't been the rubric for nearly a decade....
developing in the blockchain space isn't to attract non-blockchain users - at least for anything that actually earns revenue - its solving frictions for existing blockchain users because they are there, numerous and its lucrative
it's a parallel economy that you either accept the existence of or you don't, there are a lot of people trying to act like it has merged with other economies or asking you to use a big stake of money on blockchain assets with the hope that it becomes a bigger stake of money if they did merge, but that's really a distraction that has little to do with what's already happened and functioning fine
Looks like at least some of the valuable ones did though. The json payload is on ipfs, then the image url is ipfs://. Example: https://bafybeihpjhkeuiq3k6nqa3fkgeigeri7iebtrsuyuey5y6vy36n... (they stored an ipfs hash only, this link is just a random viewer pointed at it)
Btw it's weirdly annoying to get the json payload for one of these
Finding out NFTs were just links, didn't even embed the asset, was such a moment for me... like either the people pushing this are complete fools or 100% conscious grifters who know it's total bullshit. I suspect it was a mix.
Insane.
I think a lot of the AI skepticism comes from the fact that the last major New Thing (tm) pushed by this industry was crypto. People are very, very burned by that.
That and how badly social media turned out, but that's a whole different discourse.
An NFT doesn't have to be just a link; nothing in principle stops someone creating a NFT that stores the full bytes of some digital asset directly on the blockchain, just as nothing in principle stops someone from creating a NFT that doesn't do this (or equivalently, a NFT whose on-chain content is simply a text hyperlink to something). The Bitcoin Ordinals concept of Inscriptions (https://docs.ordinals.com/inscriptions.html), which is an attempt to build a NFT system for Bitcoin, does culturally encourage placing the bytes of a digital asset into the Bitcoin blockchain, and the tooling around it assumes this model; but again nothing prevents someone from creating an Inscription whose contents are simply a link to something else.
And of course there's no reason why a NFT has to be used to represent ownership of some kind of digital art - there are other uses for NFTs, such as modeling transferable network permissions or resources.
Ultimately NFTs are a just a specific application of blockchain technology, to represent some kind of resource on a blockchain which could in principle be digital art. If people care about ownership of NFTs representing digital art, that's a social fact about what kinds of art there is market demand for; and whether it matters that the bytes of the digital art are on a blockchain or linked from somewhere else (where they could get taken down or bitrot) is also a social fact.
I actually agree that treating NFTs that merely contain a link to some bytes elsewhere that worked at one point in time is a pretty dumb thing to care about, or have a market for (and the use cases for NFTs where the bytes are actually on-chain are, at best, fairly limited, although I wouldn't say completely nonexistent). And certainly the NFT market of 2021 or so, which had a lot of such NFTs, was driven by a weird social mania and people attempting to grift upon that social mania. This has never bothered me though, because I feel the same way about many markets for physical pieces of art; and ultimately it needs to be possible for people to create markets for things I personally think are dumb or at least don't care about.
I don't think they were saying they found out all NFTs must only be links, just they found out the NFTs being peddled usually were. As you say, bytes are bytes regardless what they represent - it's just a lot easier to grift something like a 32 byte hash or a link on a chain because storing all those bytes in the blockchain would have been a damned expensive way to run a grift.
There is a difference between markets for things I don't care about and markets for things I do care a lot about, just not in a positive way. I don't think it's necessary to allow an open market exchange for phone scammers, for example, and it has nothing to do with how uninterested I am in buying people's information. Not all NFT had to fall towards that kind of thing, it's just there was so little practical usage actually being done that 99% of it ended up being that way.
*The IPFS Project is not sunsetting or shutting down* - just switching to individual maintainer grants instead of centralized implementation support within Shipyard.
It's still a a real loss, those are widely used products, but the signal that Protocol Labs is sending about IPFS in defunding this might be even worse for the ecosystem. Cloudflare, Brave, and now Protocol Labs have abandoned it.
Maintainers of IPFS are winding down is much more informative for those not in the space.
For anyone wondering, there are more sustainable (with a viable, focused business backing the project) options to do p2p, namely Iroh - https://www.iroh.computer/ which was built by ex-IPFS ex-Protocol Labs devs (I have no relation to the team beyond having worked with them back in the day).
Sadly Protocol Labs is doing.. ehh whatever now, except apparently supporting the projects it got its VC/crypto funding from.
However - important clarification about the Shipyard post that I think a lot of folks are confused by:
While its sad to see the Shipyard team sunset, the IPFS project is decentralized & robust to a single party moving on. IPFS the project/network is not sunsetting or shutting down!
Current focus is lighter-weight stewardship from the IPFS Foundation via grants to individual maintainers, & development of decentralized public infra tools like the Service Worker Gateway.
DASL specifies CIDs, CAR and deterministic CBOR. It deliberately does not specify UnixFS, and it has no way to chunk a file into blocks. UnixFS is what ipfs add has produced since 2015, and what Kubo, Boxo, Helia and the gateways address today. So DASL is the naming layer, not "the core content addressing layer of IPFS". Writing a new format is easy. The stability people built on came from not rewriting this one, and from someone shipping it in the software they already run.
I run Kubo and Helia in production. "Robust to a single party moving on" would be easier to accept with answers to these:
- Who triages vulnerability reports and ships fixes for Kubo, Boxo and Helia after September? Does the contact in https://github.com/ipfs/community/blob/master/SECURITY.md still reach a person? - Will anyone cut releases, or should operators pin current versions and plan around that? Should we expect a community fork? - Who operates ipfs.io, dweb.link and delegated-ipfs.dev day to day after September, and with what experience running public infrastructure at that scale? - What happens to the Service Worker Gateway at https://inbrowser.link ? - What happens to Badbits at https://badbits.dwebops.pub ? Does it stop being updated when Shipyard turns the lights off?
A grant to an individual maintainer is not the same as a named owner with commit rights and a release process.
On the Service Worker Gateway as decentralized public infrastructure: the subdomain gateway spec requires a wildcard TLS certificate for the ipfs and ipns subdomains, plus a Public Suffix List entry so each CID gets its own origin. You also need a denylist, or you end up serving phishing. Very few people reading this thread can self-host that, and the ones who try will meet the abuse problem next.
The same questions are open on discuss.ipfs.tech. A direct answer there would help more than reassurance here.
The way I would put is as: Iroh + iroh-blobs == libp2p + UnixFS + Bitswap, and the latter three are some of the critical components that have defined most IPFS implementations.
Besides just p2p streams seem to be much more useful, those are plug-and-play into most software, e.g. I wrote https://github.com/magik6k/git-remote-iroh that just plugs the git remote proto into iroh and lets you move repo commits between computers by just copying a string from one place to another on push. Doing that with blobs - not gonna happen, not that easily.
And also working to replace the Radicle's networking stack with Iroh: https://radicle.zulipchat.com/#narrow/channel/369274-General...
inauthentic activity seems to move from one product space to another. in 3 years we'll be hearing about stripe shutting down openrouter for example.
IPFS, Freenet, and experiments like that mainly serve as a place for people to store and distribute pirated copyrighted material, child porn, hit lists, terrorism manifestos and plans, and the like.
Scratch a libertarian and, nine times out of ten, you'll find someone who advocates for no or minimal government because they want to do something the government legitimately bars them from doing. Scratch a libertarian decentralized P2P E2EE communication project and you'll find... well, this kind of material nearly every time.
Worse you can store child porn as paper pictures in your house and can privately communicate in there with other unknown people and mignt even be do something illegal there. Do you want to install some police security camera in your toilet?
Oh, and in some countries being LGBTQ+ person or political activist or women right activist is illegal and will land you to execution on chop chop square. Should we also let all the governments find these people too?
A year or so ago I wrote IPFS-boot which allows serving webapps on IPFS while providing also an update path and without breaking content hashing:
https://github.com/rhodey/IPFS-boot
But now if you want to serve a secure webapp and not use IPFS IMO the only option you have is to tell users to install Tailscale and to host the webapp themselves and then to install Tailscale on all devices.
Regarding an "update path", GNS has support for that built-in; though I've not been able to try it myself, since I can't get GNUNet to bootstrap :-(
For a real world example of a hybrid approach that works see bittorrent where torrents can optionally contain urls that point to alternate download sources in order to speed up the initial seeding phase.
If you want to reference resources securely, https://developer.mozilla.org/en-US/docs/Web/Security/Defens... is available and widely supported.
The deal here is Subresource Integrity will only help you if the index.html is considered trusted/authoritative. So you still need a way to get index.html to users and users need a way to say "is this the true index.html"
Edit: Okay, so a couple of people have downvoted but no-one has answered.
Why would you use tailscale to secure a web app?
One important thing I'd like to see IPFS or a similar decentralized web technology achieve, is getting rid of the necessity of filling out a Google form in order to tell the Shipyard people what I think about their maintenance of IPFS.
Seriously it bugs me when people who ostensibly care about decentralized or privacy technology use a centralized service hosted by a gigantic tech company to accomplish a task because it's convenient (if you already have an account with them), and don't even try to make a decentralized version available. It would have been better if they simply invited people to send them an email.
Sort of an interesting market signal. "Don't bother building for me unless you're absolutely pure". Funny stuff.
Google demands logins if the Form includes any attachments at all.
This is the last gasp of a blockchain hype cycle solution that never found its problem.
I remember in 2015 having the IPFS concept blow my mind its such a memorable moment when it really felt like someone designed something significantly different that current mainstream paradigms. But in the end it seems like it was still a case of a cool technology looking for a use-case not solving a real problem.
I gave my static photo album website image files paths that consisted of /ipfs/ as directory name and ipfs hash as file name.
Brave browser was able to figure out that this meant they were available on IPFS, and asked me if i wanted to load the files from IPFS instead of from the web server itself.
So over time if hosting files on IPFS got popular, it could have been used automatically by browsers later to load the files from IPFS instead of the web server of the site. Saving bandwidth for the website operators and distributing storage of content which might also help it remain available for longer time.
That sort of thing would have been one great outcome, for example, where this sort of hosting your own http gateway for your own IPFS files makes sense like I was doing. Mind you, the web server setup for this was completely straightforward and requires no running of the IPFS services on the web server itself. On the web server it really was plain old directories and file names. As long as they are real IPFS hashes. And calculating the IPFS hash itself I did on my laptop when adding photos.
Very sad to hear in this thread that Brave browser has actually removed IPFS support :(
It kinda feels like the AWS or Azure of file distribution, so much stuff so confusing. Also apparently with Protocol Labs owning several of those things despite not operating those things?
Ironically seems quite a fragile setup.
Regardless, very sad news.
About 800k unique DHT clients are seen weekly.
btw,I thought it was an Initial Coin Offering, not an actual fundraise.
How hard would it be for a country to block the clients and browser extensions you need to use it in the first place? Or to develop a firewall technology that’s capable of blocking the traffic?
Probably not that hard, especially since nobody uses IPFS for anything business critical since it’s not all that great at doing things that you need from file storage systems.
Most reasons you store files somewhere benefit from not being decentralized. You usually want some combination of performance, security, durability, and availability. Decentralization is not generally a demand of file storage.
The only reason it’s decentralized is because blockchain and crypto was hype 10 years ago.
But that didn't pan out.
I guess the user base has proven this out in the end. Torrents are good enough.
I know a lot of people on HN are going to call me overly cynical. But this pattern should be so obvious by now. Any cynicism to any new ground breaking technology which is gonna solve a problem that exists because of capitalism, that this cynicism is more than warranted.
At this point we should all be cynical of any new technology.
- ATProto ecosystem (built on IPFS content addressing, used by Bluesky): https://atproto.com/guides/tutorials
- IPFS contribution guide: https://docs.ipfs.tech/community/contribute/contribution-tut...
- libp2p maintainers call (networking layer of IPFS & other p2p networks): https://libp2p.io/get-involved/
Edited: I also liked how it bypassed the traditional domain system.
We are building systems that live in the same space as projects like IPFS, Secure Scuttlebutt, Automerge, Tailscale, etc.
For folks who are already experts in this space, able to come in and hit the ground running, remote is an option.
For high growth folks, we have in-person in Austin.
For folks w/ a U.S. security clearance - we have in-person in DC.
> Protocol Labs is an innovation network driving breakthroughs in computing to push humanity forward. PL connects more than 750 tech startups, funds, accelerators, foundations, open source projects, service providers, and other organizations.
What happened to them? Seems like they drank their own "Web3" Fla-Vor-Aid.
I could never shake the feeling there is an unnecessary layer of grift embedded in all the protocols.
See: https://pickipedia.xyz/wiki/Cryptograss:Delivery-kid
If IPFS is starting to wane, does anyone else have a suggestion of a replacement about which I might start to educate my fans?
The problem was that there was no good client for it that was better than current torrent clients. When I tested it you had to keep a duplicate of the files in the ipfs cache directory and the client was CLI based which would alienate most users. There's probably no way to have private trackers or to track seed/leech ratios for communities too.
It felt like a really cool demo that never got cleaned up to work as a real production product.
Remember Filecoin? The original concept was that you could buy perpetual storage with a one time payment. It was funded by a crypto asset which was a derivative of mass storage prices, or something like that. Lighthouse supposedly sold such a product.[1] They no longer do.[2]
[1] https://www.lighthouse.storage/blogs/Permanent%20Storage%20P...
[2] https://www.lighthouse.storage/pricing
I'm personally quite disappointed because I just built an IPFS based system built on top of Kubo that I was hoping would take off. Now this throws future maintenance of Kubo into question.
(Couldn't it be that the caching behavior of intermediate nodes still make it a possibility?)
I believe the fundamental problem of those protocols is everyone fear ending up serving child porn just by running a "node" and taking a chance at explaining the future P2P internet to a judge.
IPFS got a CID deny list [0] but it was too little too late
- [0] https://badbits.dwebops.pub/
You are going to see a lot more shutdown posts around decentralized or federated technologies if you do not support those tools.
tried to be the change I wanted to see
given where the concept actually found staying power (liquidity pools, instead of collectibles) it wholly needs a new name
“NFT” is distracting at this point, they should just called them 721-structs so people don’t get distracted by the fumbled poorly implemented art use case
I still think it's pretty obvious that on sufficiently long time-scales that some variant of NFTs will be the winner for event tickets.
right now outside of the web3 space, all promotion companies release tickets in different ways. the ability to resell them is unknown, the quantity for sale is unknown and opaque, the service fees make no sense for the last 20 years, the ability to transfer them is unknown, and the ability to lose your money on an attempted resale transaction is absurdly high. in comparison, all NFTs in the blockchain space inherit solutions to all of those problems and all marketplaces are just UI's on top of data already there in a uniform way, alongside new problems that are mostly education based and won't be solved with a different user experience (akin to how debit and credit cards introduced new problems with automated teller machines many decades ago, that never were solved but didn't deter the concept)
can a centralized marketplace and issuer that conforms solve all of it? of course, but that hasn't been the rubric for nearly a decade....
developing in the blockchain space isn't to attract non-blockchain users - at least for anything that actually earns revenue - its solving frictions for existing blockchain users because they are there, numerous and its lucrative
it's a parallel economy that you either accept the existence of or you don't, there are a lot of people trying to act like it has merged with other economies or asking you to use a big stake of money on blockchain assets with the hope that it becomes a bigger stake of money if they did merge, but that's really a distraction that has little to do with what's already happened and functioning fine
Btw it's weirdly annoying to get the json payload for one of these
Insane.
I think a lot of the AI skepticism comes from the fact that the last major New Thing (tm) pushed by this industry was crypto. People are very, very burned by that.
That and how badly social media turned out, but that's a whole different discourse.
What would I have owned exactly? What would have ownership entitled... All very reasonable question. Mostly entirely ignored or handwaved...
And of course there's no reason why a NFT has to be used to represent ownership of some kind of digital art - there are other uses for NFTs, such as modeling transferable network permissions or resources.
Ultimately NFTs are a just a specific application of blockchain technology, to represent some kind of resource on a blockchain which could in principle be digital art. If people care about ownership of NFTs representing digital art, that's a social fact about what kinds of art there is market demand for; and whether it matters that the bytes of the digital art are on a blockchain or linked from somewhere else (where they could get taken down or bitrot) is also a social fact.
I actually agree that treating NFTs that merely contain a link to some bytes elsewhere that worked at one point in time is a pretty dumb thing to care about, or have a market for (and the use cases for NFTs where the bytes are actually on-chain are, at best, fairly limited, although I wouldn't say completely nonexistent). And certainly the NFT market of 2021 or so, which had a lot of such NFTs, was driven by a weird social mania and people attempting to grift upon that social mania. This has never bothered me though, because I feel the same way about many markets for physical pieces of art; and ultimately it needs to be possible for people to create markets for things I personally think are dumb or at least don't care about.
There is a difference between markets for things I don't care about and markets for things I do care a lot about, just not in a positive way. I don't think it's necessary to allow an open market exchange for phone scammers, for example, and it has nothing to do with how uninterested I am in buying people's information. Not all NFT had to fall towards that kind of thing, it's just there was so little practical usage actually being done that 99% of it ended up being that way.