Decentralized Application Development with Holepunch’s Mathias Buus Madsen
Holepunch CEO Mathias Buus Madsen explains why decentralized approaches to application development will continue to gain traction even as more organizations look to centralize the management of DevOps workflows.
Transcript
This is Textron tv. Hey guys, thanks for the throne. We're here with the CEO of whole punch method boost, and we're talking about well, decentralization as a methodology for building applications at a time when everybody else is focusing on centralizing that process and the age of platform engineering and everything else that's going on.
Mathias, welcome to the show. Hey, thank everyone. Nice to be here.
What is your perspective on this whole conversation that's going on around centralization and we need to, uh, reduce the number of DevOps platforms we have and we're embracing platform engineering, and yet you guys are out saying, Hey, you know what, we can have more cake and eat it too, maybe and still have a decentralized approach? Uh, yeah, well, obviously I'm, I'm very biased towards decentralization, but I think, uh, if you look at the internet the last 10, 20 years, 30 years, that's been a slow movement towards more and more centralization, even though the internet is still started out as a very beautiful, decentralized platform that actually connected people from anywhere else. And we kind of lost that along the way.
Uh, and I think that's really, really problematic. I think one of the, the, the, the most amazing things about the internet and the way modern communication work is that I can sit here in Europe and run a few things on my computers, and you can be somewhere else and one of famous on your computers and we don't need to worry too much about where things are. But yet, somehow we made the future into this place where everything has to go in these big silos and in big data centers, uh, because that's kind of like where the business has driven it.
And I think that's really, really problematic for many, many reasons, uh, as a developer because it's actually surprising the art to bill for, because now all of a sudden we have all these centralized dependencies we have to worry about. We have to protect out our credit card all the time where develop things versus back in the day you can do virtual laptop. Um, and also just from like a personal, um, angle of like, you know, centralizing data and centralizing communications creates, creates all kinds of problems.
Like, uh, big silos become targets for hackers, data leaks, um, monitoring privacy out the window. Uh, everybody knows this. So, so at Hope Bunch we, we, like, we're trying to do things very, very differently where we say centralization, we don't need it.
We can just actually use the hardware we have and then just build a ton of technology that allows you to just make the similar kind of applications, but without servers, without data centers, just with the laptops we have in peer-to-peer networks and, and decentralized technology. Well, I'm sure a lot of folks right now are going well, how does that work exactly. So explain, So basically we've been de the last five years we've been like deep the weeds, uh, through developing a lot of technology.
I come from a long background of, of peer tech. I worked at bit Victorian in the past. Uh, and um, we actually spent a lot of time actually just solving basic problems, um, with computer that you might not realize you have, but actually connecting computers today is really hard.
Like you have to go through firewalls. All that stuff's really, really complicated. Uh, but it's actually all solvable for technology.
So what we did was we spend a lot of time solving all these problems, making, you know, databases that can scale, uh, uh, while not having to be a server partner live everywhere and like, you know, partial queries and things like that, connectivity technology, like I mentioned, that can actually connect people within trend encryption and like punch through firewalls, et cetera, et cetera, with full security still. Um, and like take all that techno babble and like bubble it up and assemble little thing that we call the pair run time. Um, that, that is a little framework you can solve and just make applications on top that are, uh, where you just interface with like non extractions, like, you know, like databases and things like that.
But it's all just decentralized. It's actually really, really simple from a developer's point of view and really, really powerful from, from, uh, users and uh, and uh, also like f four developer's point of view. So That's awesome.
So how do I keep track of what's occurring across what sounds like a peer-to-peer environment per se? But, um, if I have multiple developers and multiple teams, how do I kind of keep some sort of sense of what's occurring? Well, actually the development process is actually very similar to what you normally do with also like centralized technology.
So, so we have a, you know, framework as in JavaScript, um, you just installed that. Um, uh, you can go to our website par com and see how things work. And then just like when you work with like SQL databases or Mongo Tob or whatever your preferred database stack is, we just have a, our own little database, um, called Hybrid db, but it can do similar things, queries and stuff like that.
Um, and then you just have to, uh, make normal applications instead. But instead of like writing to servers, you just write to data structures and you set up rules based on, on like your permission and model there instead. Um, like who can access what data and stuff like that.
But, um, it's actually pretty close. I think if you wanna think like, as a centralized analogy is pretty close to maybe working with something like fire bases, um, where, you know, you just get this code application as you don't think too much about it. And, um, we have a lot of knowledge just makes that really, really simple.
And I think that's really, really fun and, and very powerful. Obviously it takes some getting used to, to some degree 'cause we're so ingrained in our centralized thinking. But, uh, yeah, uh, it's not that hard and, uh, with their on time it's actually really simple and we have a ton of stuff and a ton of modules to work with it.
And what exactly does your company do with that in that regard? And you providing support for it or, um, yeah, I guess the age old question is, is how are you making money in this race? Uh, well, so first of all, one of the beautiful things about peer to PI think, and one of the most incredible things is that we actually made applications with peer-to-peer.
I think things like bit chart and ratios in the past also that can scale incredibly well and um, and make really, really powerful AppSec that has no operational cost. So like we as a company, we don't run anything. We don't have any like big bill scoring error month followed than salary.
Obviously salary, uh, cost money. Uh, but like, we're not paying for any like, for use because our technology just lives on people's computers. Um, and that's, that's a really, really big differentiator in terms of like how we we do business development, how we do run our company in general.
'cause we actually don't have many big expenses in that way. So that completely changes the game. Um, so we are, we're a for, for for-profit company.
Like many other companies, we raised money through Tether, uh, the cryptocurrency and, uh, very backed by the that. But we actually have very a little burn and we actually just developed this Denali for free and uh, it's all source, um, as an app development platform. In addition to that, we make a ton of our own AppSec also on top of peer-to-peer.
'cause we're very, very invested in peer to peer. We have our flag share app, uh, key, which is a peer-to-peer chat app. Uh, that's also, uh, a video chat, kinda like right now we're talking through Zoom, right?
But when we talk through Zoom, uh, all that data goes to like a Zoom server somewhere, a data center, um, that they cost them ton of money and they have a business model around that. Uh, I'm sure you have a subscription of sort, right? Uh, with keys, we don't have any of that because the data just going between peers.
Um, so we actually just to make a lot of these competitor AppSec, um, that are really powerful and I think too much about it, um, while still having tons of ways to, to, you know, you can make tons of business and adapt that is just like more classic, um, supporting businesses and, and these kind of networks. But like, but we're the main developers behind all this stuff and uh, and uh, we have a ton of open source people also contributing, so it's a lot of fun. Are organizations kinda wrapping their heads around this or is this kinda maybe, I don't know, some sort of the ground developer movement that, you know, they're just tracking on the sidelines?
Uh, that's a great question. Uh, well I've been in peer-to-peer for like, uh, like, you know, I've been working very actively in five years, but I've been busy my entire career like 10, 15 years. And what I've seen also with organizations is when I first started out, like I said, that was mostly BitTorrent stuff and things like that.
Organizations didn't care much. And also users care much outside like the use cases for the term, which people probably all, um, can, can think about themselves. Like obviously a lot of video sharing and things like that happen that, uh, but as the world has gotten more and more, for lack of a better word, there's still been in the last many years, like surveillance state has gone up and things like that.
I've seen a lot of, uh, brown shift towards, um, people thinking like, people care a lot about privacy now. Uh, they should, um, organizations care a lot about privacy, regulations care, a lot about piracy. I'm from Europe.
Uh, the regulations here are pretty intense around like, you know, where you can have data and stuff like that. So people are starting to think a lot about these things. And also companies a lot are thinking, trying to think a lot about where their data is, uh, exactly, um, and um, and how much they actually control of it.
And so, uh, we work with a lot of, just like through our communities, obviously, uh, different organizations that are very excited about peer-to-peer and, and obviously also with developers. Uh, and also users are coming to us being like very, very, um, focused around these things. So I think there's a big shift happening and I think it's accelerating quite rapidly the last, uh, two or three years from what I've seen.
And that's also why I'm, you know, we're doing this and, and not very invested in it. Um, and, um, not many people are in this space because it's a space where you're kind of competing, uh, against very, very big, uh, players. And it's like obviously requires some technology, technological edge, and if you want to like raise big money, they always wanted, wanted you to, to build like centralized platforms, uh, outside working with, with our backers that are, uh, because that's where you can squeeze the most money outta your users.
And reason from the get, we don't wanna do that. We just wanna make technology that allows people to, to have freedom of speech and, and like to scale these kind of things. So that's really, really important for us.
Is there also an argument for this approach because it is inherently more resilient, right? I may have some centralized platform somewhere, but um, if it goes down, we all go down. So is there a set, is there an argument to be made about productivity here?
For sure, like, uh, peer-to-peer has many benefits. This also has some complexities, obviously technological wise. Um, that's why we've been working on it for a while, trying to like make up peer, but the peer-to-peer systems when done right is kind of like this whack-a-mole style thing where, you know, you can't really take it down.
Uh, many people have tried to take down bit networks, like I talked about BitTorrent in the past. There's been many, many attempts to take down bit turn in the past, all unsuccessful because it's like these kind of things where you can't just like knock on some server and turn it off. You have to literally go to a majority of the users and get them to turn them off and practice, uh, which is impossible.
Um, and I think the cool thing about thinking about pitch peer in the mainstream is that those kind of properties, obviously us as users is something that's just really, really, uh, incredible to have a normal services, right? Um, even though big services like Facebook, uh, Google exists, they still have downtime. I think it was actually just yesterday or two days ago maybe I had a big uh, um, big downtime thing because of something.
And that's just something that happens in the big systems is gonna continue to happen because it's centralized and the more centralized art, the more things can go wrong. Um, so the resilience aspect is, is amazing both from like a techno technological point of view, but also just from a political and social point of view. Like, um, we may key to our, our messaging app build on PU technology, uh, entering encrypted, uh, we don't even know what's going on in that app because like we don't have servers.
We can inspect our, our encryption keys and stuff like that so people can like, have actually private conversations, um, which I think is, is really, really important. I think that's something that's also essential in in 2025 as we're entering soon. Do you think we're essentially seeing some sort of form of shadow application development where individual developers may prefer to use something like your platform, but yeah, they'll upload it into the centralized system when they're ready as which they're treating as something like a system of record because you know, the company decided that was the way to go, but the developers are doing something different.
Yeah, well I think, uh, you know, big shift takes time and like there's obviously, I I for me, like I'm from a, I'm, I've been educated in a, you know, classic university and stuff like that and I had some computer science classes there and you really notice also how the entire structure is just focused around teaching centralized ways. So it actually takes some on wiring to get out that thinking. Um, that's why we always hack the question about like, listen, decentralized decentralization harder, that's 'cause we're so and so programmed to think about servers and stuff like that.
Um, and obviously that's gonna be, um, a progress there and shift there. Um, but I think once you start developing with peer-to-peer and as obviously like you said, it's gonna come from hackers, it always does. Um, once you start working with peer-to-peer and decentralization, you kind of realize that a lot of this stuff that is really, really hard and uh, creates a lot of hurdles for developers and on the systems just don't exist.
For example, um, when we develop with pair runtime and we make AppSec, um, we don't deploy the AppSec anywhere, which means that each developer can just sit there and iterate, uh, their version up yet and just publish them out on the Pitch P network and other people can just run them. So you don't have like these deployments, you just have, you know, run an app from your computer and other people can access it and run it on their computer. 'cause it just sees through the network.
Um, you don't have database migrations that you have to worry about. You don't have like some stack where you have to have 8,000 access keys. You just have just software on your computer.
So it actually, uh, becomes much more simpler, uh, to some degree I think because that iteration speed is just so much better and it's so much secure and also means you can do it from anywhere. You can do it from home or in the office, it doesn't matter because all this stuff is kind of like taking away. Um, you can still have like access controls always doing stuff, but that's just true encryption versus through like your firewall rules that we have in, in, in normal system.
So I think it's this, it's, it's very much something you can, you can have development flows on that are very much, much better. And I also think there's nothing stopping you from making more like B services on a peer twop network that is more close through, uh, to a central system, but on a centralized, what I mean by that is kind of like you can obviously run services that are just like only affects some people, it's running somewhere, but there's no reason why they should be tied to like AWS or data center or something where like that you can just literally just spin up a, a computer somewhere or just run it on data server. There's period peer-to-peers that it doesn't discriminate.
You can just do whatever you want. Um, it's kind, it's like a include centralization inside to somebody. So I think, uh, once you start thinking about that, um, there's really no second best because what it gives you is like encryption per default of, uh, um, authentication of data for default defense in depth, um, and ability you like distributed in any way on.
So just really, really powerful. And on the security side, there's this argument that says, well, you know, it's an individual machine with a, a developer and something bad can happen and yet if I have a centralized approach, I kind of create as a bigger target for somebody to go after. So what's the right balance there in your mind?
I think to some degree we have to think about this stuff always. I don't think there is like necessary, you know, people tend to think about security a little bit too binary and like something has to be secure. Something does nothing in the world we're live in today with, um, with the targets, uh, and not the hackers.
And by whatever's happening in the world, like the thread models today, you have to really be conscious about security all the time. Uh, if you're sitting and using a computer and you have something running on that computer where the only thing that defends against you losing all your money or all your IP or whatever is some firewall setting on your home network, you're probably gonna have a bad time at some point, uh, is my guess. Um, so you really need to think about this in, in every level.
And I think peer-to-peer actually helps with this because Peter Peer just assumes the networks are meant to be penetrated. Like firewalls are meant to be penetrated. So you put the security in the data layers and then the encryption layers, which, which is where they should be.
Reminds me a lot about the shift. Um, when I was was younger and I did web development, that was a shift from like unencrypted a CP to encrypt to SPS where we had a lot of the same conversation of like, when should we use it? Maybe not this, maybe not in an hour.
Like obviously always, um, because the threat models are just much, much simpler when we just stop thinking about as something we need to do. And so we don't need to do. So we QP like, uh, keep your data secure, keep it locked down.
I think that's what we should do on, on every level. Sure, you can have, you know, machines that do more, uh, advanced things like, um, when you work with cryptocurrency for example, you have machines that have signing keys to something more important than other things. And obviously then there you take a much more serious than other places.
But we need to, we need to raise the base level of security everywhere. Uh, so that just everybody's data is, is, is, is protected. The people who are getting proned today, mostly it's just normal people like our parents, uh, things like that.
That's every time I read a stat about those things, it's going up and up and up and up. Um, so we need AppSec to be more secure in general and I think Peter Peer actually helps with that because it forces you to think about these things upfront and obviously the technology helps you a lot. All right folks, well you heard it here.
Hey, next time somebody's asking you about some need to centralize everything, simple question ask them is maybe why. Hey Batia, thanks for being on the share. Thanks so much for having me.
It was awesome. Alright, and back to you guys in the studio.