In this episode host Matthias Pfefferle sits down with Will Norris, a seasoned software engineer whose work has paved the way for open standards, federated identity, and open source contributions, particularly in the WordPress ecosystem. From his early days building federated identity systems at universities, to his key involvement in projects like DiSo and OpenID, and onward through formative roles at Google and Twitter, Will Norris has been at the heart of the open web movement.
Together, they explore the roots of distributed social networking, the evolution of collaboration on the Internet, and the stories behind influential protocols like ActivityStreams and WebFinger, many of which form the bedrock of today’s Fediverse and IndieWeb. Whether you’re a developer, open web advocate, or just curious about the foundations of online identity, this conversation is a fascinating look at two decades of open source innovation and the future of a user-owned social web.
Our sponsors keep the lights on.
Take a moment to check them out.

Since 2005, Automattic has built tools for the open web including WordPress.com, WooCommerce, and Jetpack that are used by millions of people to create, sell, and publish online. They believe in ownership, flexibility, and open source and we’re grateful for their support. Learn more at automattic.com.

InMotion Hosting brings over 25 years of experience, NVMe-powered speed, and 99.99% uptime to every plan they offer. When you need help, you get a real human, not a bot, and they’ll migrate your site for free. We’re happy to have them in our corner supporting the conversations we have here at Open Channels FM. Find your plan at inmotionhosting.com

Omnisend just dropped SMS pricing to $0.007, and their migration team moves your automations, templates and contacts in five days, free. That means you could be saving up to 35% in less than a week. We’re glad to have them supporting the show and the community we’re building around it. Use the code OpenChannels and get 30% off your first 3 months of any paid plan.
Takeaways
Long History in Open Standards and Identity: Will Norris has spent nearly 20 years working on open standards, particularly around identity, federation, and open source technologies, with a focus on protocols like OpenID and standards like Shibboleth, both in academic and corporate settings (01:38).
Contributions to WordPress and OpenID: Will Norris played a key role in developing early OpenID integration for WordPress, including plugin maintenance and enhancements that made identity more seamless and unobtrusive for users, and contributed core changes to better support diverse authentication methods (06:49, 09:23).
DiSo as a Predecessor to the Fediverse: The DiSo (Distributed Social) project, which Will Norris co-founded along with others like Chris Messina, aimed to create open, distributed social networking years before the Fediverse and ActivityPub, paving the way for modern decentralized platforms (15:56, 19:37).
Activity Streams and ActivityPub Origins: The Activity Streams spec, to which Will Norris contributed, started as an extension for Atom/RSS and became the foundation for ActivityPub, enabling federated social web activity—its early design focused on backwards-compatible, unobtrusive enrichment of existing feeds (20:01, 22:23).
Shifts in Big Tech’s Approach to Openness: Will Norris described a period when major companies like Google, Facebook, and Yahoo were interested in open standards and portability (eg, embracing OpenID and OAuth), but later shifted priorities, often resulting in walled gardens and lost momentum for open social protocols (35:02, 40:22).
Transition from Buzz to Google+: While Google Buzz embraced federated social networking and standards-based interop (such as activity federation with Identica), its successor Google+ shifted to a closed, partner-only API and mirrored other proprietary social networks, disappointing many advocates of the open web (39:02).
Lessons from DeSo to IndieWeb: Will Norris sees IndieWeb as an evolution of DiSo’s philosophies, putting greater emphasis on principles of data ownership and broadly adopted protocols rather than specific platform implementations, enabling broader, ecosystem-wide adoption (44:45).
Identity Layer Limitations in Mastodon: Will Norris believes Mastodon and ActivityPub missed an opportunity by not supporting proper delegated identity as OpenID did, which would have vastly improved portable identities and interoperability in the Fediverse (47:32).
Open Source Career and Go Contributions: After managing open source offices at Google and Twitter, Will Norris returned to hands-on engineering, making significant contributions to the Go ecosystem, such as the popular go-github library, and currently works at Tailscale focusing on identity tech (43:02, 54:04).
Ongoing Value of Open Standards and Community: Despite stepping back from direct involvement in standards bodies, Will Norris affirms the enduring impact of early open web initiatives and highlights the importance of contributing to, maintaining, and evolving open protocols and plugins even as the technology and participants change (23:18, 01:00:00).
Important Links and Resources
- WordPress.tv (Plugin Development Talk by Will Norris) – Will Norris’s “How Not to Build a WordPress Plugin” talk at WordCamp Portland 2009. 🔗 https://wordpress.tv/2009/09/20/will-norris-building-plugins-portland09/
- Will Norris (Personal Website & Blog) – Personal site of Speaker A, including reflections on leaving Google and other web identity topics. 🔗 https://willnorris.com/ and 🔗 https://willnorris.com/2020/leaving-google/
- IndieWeb (Open Web Principles & Protocols) – A continuation of distributed social philosophies, emphasizing ownership and interoperability. 🔗 https://indieweb.org/
- ActivityPub (Federated Social Networking Protocol) – The protocol that evolved from early efforts like Activity Streams and Diesel, shaping today’s Fediverse. 🔗 https://www.w3.org/TR/activitypub/
- Activity Streams (Distributed Social Meta-Data Framework) – Early standard for unified activity aggregation; foundation for ActivityPub. 🔗 https://activitystrea.ms/ and 🔗 https://activitystrea.ms/specs/atom/1.0/
- DiSo Project GitHub (Distributed Social Networking Plugins) – GitHub repository for Diesel-related projects, including Activity Streams and OpenID implementations. 🔗 https://github.com/diso/
- DiSo Project Main Site (Distributed Social Networking Philosophy) – Central resource for the Diesel Project’s standards, specs, and community. 🔗 https://diso-project.org/
- WebFinger (Federated Identity Mapping Specification) – Modern standard for mapping email-like identifiers to web resources. 🔗 https://webfinger.net/
- OASIS XRD Namespace Documentation (Extensible Resource Descriptor) – Documentation for the OASIS specification underpinning resource discovery. 🔗 https://docs.oasis-open.org/xri/xrd/v1.0/os/namespace.html
- OASIS XRI Syntax Specification (Extensible Resource Identifier Syntax) – Detailed technical documentation of the XRI naming system discussed in the episode. 🔗 https://docs.oasis-open.org/xri/2.0/specs/xri-syntax-V2.0.html
- Email to ID (Service for Email-to-URL Transformation, Archived) – Early experimental service for mapping email addresses to OpenID URLs. 🔗 https://web.archive.org/web/20080912104748/http://emailtoid.net/
- Shibboleth WordPress Plugin (Federated Identity Integration) – Official WordPress plugin for integrating university Shibboleth authentication. 🔗 https://wordpress.org/plugins/shibboleth/
- WordPress Core Ticket #19714 (Authentication Filters Discussion) – Ticket documenting changes and discussions for authentication filter improvements in WordPress core. 🔗 https://core.trac.wordpress.org/ticket/19714
- Hugo (Static Site Generator) – Used by Speaker A for generating a static website and adopting indie web protocols. 🔗 https://gohugo.io/
- Tailscale (Private & Trusted Networking) – A platform championed by Speaker A for building small trusted networks and enabling privacy. 🔗 https://tailscale.com/
- Learning from Our Mistakes (OpenID & AtomPub Web Failure Analysis) – Blog article reflecting on broader web protocol adoption failures, cited in discussion of standards. 🔗 http://www.25hoursaday.com/weblog/2011/01/30/LearningFromOurMistakesTheFailureOfOpenIDAtomPubAndXMLOnTheWeb.aspx
Timestamped Overview
- 00:00 Early identity protocol experiment
- 06:47 Developing an OpenID WordPress plugin
- 14:53 Learning WordPress and deployment challenges
- 18:07 Early efforts to unify activity
- 22:23 Switch from XML to JSON
- 30:27 Early XML and JSON protocols
- 37:11 Google Buzz and open standards
- 40:30 Leaving Google over ethical concerns
- 44:45 Comparing DESO and Indie Web
- 52:14 Joining Twitter to lead open source
- 57:04 Privacy and control online
- 01:01:12 WordPress API and OAuth issues
Episode Transcript
Matthias Pfefferle:
Hello, you are listening to the Open Web and Fediverse series, part of the Open Web Conversations channel an Open Channels event production. And today’s guest is someone I’ve been following for almost 20 years and we never met in person or talked in person, so this is the first time. I’m a big fan of his work around open standards and I’ve personally learned a lot from the way he builds WordPress plugins. He was part of Diesel, one of the first, if not the first, distributed social networking project built on top of WordPress. He helped push the WordPress OpenID integration, or OpenID in general. He paved the path for what later becomes Web Finger. So it’s a real pleasure for me to have you here. Welcome to the podcast world, Norris.
Will Norris:
Thanks. I’m super happy to be here and yeah, it’s great to finally actually be talking. We’ve corresponded online for years and this is, this is a lot of fun.
Matthias Pfefferle:
Yeah. And especially it’s 20 years ago when you worked on that stuff. Yeah, you stopped. Not 20 years ago, but yeah, it was.
Will Norris:
It’s been a long time for sure.
Matthias Pfefferle:
Yeah. But before we dive in, maybe you want to say some words about yourself.
Will Norris:
Sure, yeah. I. Living in Southern California, I’m a software engineer. Most of my career has revolved around identity and open source in various capacities. Started out my, my very first introduction to open source was a project called Shibboleth, which is a. A SAML implementation. So I was doing, I’ve been doing identity related and adjacent things most of my career and yeah, so it’s just been identity in general and privacy and stuff. It’s just been always been something that I’ve been really passionate about and have found a way to kind of weave that into my work and have really enjoyed that. The social networking aspect of all of this is kind of interesting because like I’m not, I don’t spend a ton of time on social media and stuff and like I have a love hate relationship with it and so my interest has always been more on the identity side. But yeah, we can definitely get into
Matthias Pfefferle:
some of that and it was quite open source in general related with your work at Google and later Twitter when it. When they still were the good ones.
Will Norris:
Yeah, so I started out, my career has been. So I was at. We’ll probably talk about this. Chris Masina and I were Both at an OpenID startup called the Dupe while we were working on DiSo, they actually basically hired us to continue the work that we had been doing.
Matthias Pfefferle:
So yeah, let’s start from the beginning
Will Norris:
and then go from there.
Matthias Pfefferle:
Let’s start from the beginning. So how did you stumble upon the identity stuff 20 years ago? Why Shibboleth? Why WordPress?
Will Norris:
So with Shibboleth, I was, I was working at the University of Memphis as a. I’d gone to school and at Georgia Tech and then came back to Memphis and was, was finishing my degree there. Never, still never finished it, but was working there. And it’s funny, I built a, a little website at the university for. So like you buy your books at the bookstore and they charge you ridiculous amounts and when you sell them back to the bookstore, your used textbooks, they’ll. They pay you like minimal prices, like half of the face value or something. And so I built a little site to facilitate selling. It was a used book market for university Memphis students and I had them logging in by. I had a username password form and, and I would hit the university LDAP directory to authenticate, to authenticate the users. So they were able to log in with their university credentials, but it meant that I was handling their password now I wasn’t doing anything with it, I was just using it to hit the LDAP directory. But as soon as the university found out, I got contacted by some people in their IT department, like, wait a minute, what are you doing here? This is not cool. I wasn’t technically doing anything wrong, but they were very uncomfortable with it. And so I went off and designed my own very, very bad federated identity protocol. I think I called it like, um, Passport. It was, the name was modeled after Microsoft Passport, which was like one of their things way, way, way back when. And, and I presented it to them, to the team and, and they, you know, they were very gracious and like, okay, yeah dude, whatever. They’re like, why don’t you come work with us? Because we’re working on this thing, Shibboleth, where it actually does proper federated identity and all this stuff. We never. I ended up shutting the site down and all that. So then I went and worked with them and started. I didn’t really know anything about that stuff and so I just learned a ton by working on the Shibboleth project and doing that at U of M. I then went, moved out to California and did similar stuff at USC University of Southern California. And so I worked in there. I Managed the Shibboleth environment at USC for a while. And part of my time at USC was funded by Internet2, which is the organization that does shibboleth. So I was doing that, I think around that time I guess I had switched my blog to WordPress. I started off with Blosxum. I don’t know if you remember that one. It was Pearl Bases from Rael dormfest was the one who wrote it. It was actually really cool. I was actually just communicating with Anil Dash the other day about it that the original markdown implementation from Jon Gruber was written in Perl. And so but the way it was written it was a drop in plugin for Blosxum. You basically set this pipeline of plugins and it was kind of like the UNIX philosophy, right of just standard in, standard out. So you would just pipe things through all of your plugins and. And Markdown was one of those plugins. You just drop it in and it would take markdown input and it would emit HTML output and that was it. So anyway, switched over to WordPress. And I don’t even remember how I learned about OpenID. I don’t know. That was around the time it was coming out. Brad Fitzpatrick had developed OpenID originally for like LiveJournal maybe LiveJournal was owned by Six of Art at that point, I don’t remember. And Yeah, I found OpenID was very related to the identity work I’d been doing. Wanted to run it on my own website. And there was actually an existing plugin for OpenID on WordPress written by Ellie Is her name had written this up. And I was really, I think my first, I was looking at it before our chat. My first contribution to that plugin was it was influenced by a blog post from Sam Ruby who he had this idea of, I think he coined the term of unobtrusive OpenID. And the idea was so on your WordPress blog, right everybody you’ve got your comment section and the standard for WordPress and probably most sites is like you put in your name, I think WordPress you put in your email, although that stays private. And then you put in your URL, your website because it’s WordPress and everybody has a website, right? But then the way the OpenID plugin worked is that added a fourth input which is enter your OpenID URL. And Sam Ruby had this idea of like, well if you’re already inputting your URL, why don’t you just detect. Use that OpenID capable. And so that was my first contribution was to Kind of merge those together and it’s like, okay, well when you input a URL, if you’re. If we detect that you have OpenID set up, we prompt you to log in and then you have an authenticated comment. And so your identity kind of goes with you when you comment on someone else’s blog. And then if it’s not OpenID capable, then it just nothing happens. And so I did that first and then I ended up forking the plugin or it kind of took over maintenance of the plugin and that led to other things.
Matthias Pfefferle:
When was that? Is. Was that already 20 years ago?
Will Norris:
That was 2000 here I can actually look. My first blog post when I Talked about unobtrusive WP OpenID was February of 2007. So almost 19 years ago.
Matthias Pfefferle:
Yeah, impressive. And that was not the only thing I might remember that you started when with your work on the OpenID plugin, you had a look into WordPress itself to kind of improve the login filter thing.
Will Norris:
I totally forgot about that. Yeah, there’s like a WP authenticate filter or something. I forget exactly. Yeah. I’m trying to remember how did. What led to that. I ended up doing a number of different things in WordPress. Specifically one, it was like. Yeah, I think I have a blog post about it where I talked about some of the changes I needed. I don’t even remember the details, but yeah, it required just sort of changing the way there were some assumptions in WordPress that authentication, I think it was like it was assuming that it was always going to be username password based. And so now granted, the password I think could come from other systems. You could like hook it up to maybe LDAP or something, I don’t know. Or at least there were plugins to allow you. Or there were. Let me state this right. There were either hooks or filters to allow you to hook into other places, but there was no real affordance for non password based authentication. And so yeah, I ended up having to add in some filters somewhere to let you overhaul or replace the entire authentication stack which I originally wrote for WordPress. I then later used it for OAuth as well.
Matthias Pfefferle:
Yeah, I think that was also kind of the idea behind all of that, that you could have several different authentication or login mechanisms in the same or looping them behind like you said, with the standard in standard out from. How was the block system called?
Will Norris:
Blosxum. Blosxum, yeah. Blosxom. Oh, does it now ring a bell?
Matthias Pfefferle:
Yeah, because I wouldn’t have spelled that Blosxum, so.
Will Norris:
Or you would have Pronounced it. That’s how I pronounce it. Maybe it is something else. I don’t know. I don’t know that I’ve heard many people say it out loud. So as with many things online, so
Matthias Pfefferle:
it was not only. So that was kind of the time when you had your first contribution directly to WordPress core, was it?
Will Norris:
Probably. I can’t remember. There might have been other ones, but yeah, that was probably the first big one for sure.
Matthias Pfefferle:
And I think later on it was. You started with all the PHP stuff, but later on you.
Will Norris:
I did some Android stuff as well.
Matthias Pfefferle:
Yeah. The Android app.
Will Norris:
Yep.
Matthias Pfefferle:
Were you the maintainer of that?
Will Norris:
No, no, no, no, I never the maintainer.
Matthias Pfefferle:
I’m not even.
Will Norris:
I can’t even remember exactly how I got into that. It feels like it was around the time that I was trying to get OAuth working in WordPress and I feel like they might have been related because I wanted to use OAuth to authenticate the Android app to my personal WordPress instance. Right. And so it required setting up OAuth both on the server side, but then also doing it client side. And so I did a bunch of UI work on the Android app of like, kind of restructuring some of the views and whatnot. I didn’t stick around with it for like super long, maybe six months or a year. I pitched in a little bit on the Android app and kind of moved on to other things. But yeah, I mean, I’ve been. And then like you kind of said at the top. I’ve done a lot of plugins over the years, just random stuff, as a lot of people do. When you spend enough time in WordPress and you find that like there’s just some little thing that you need and so you start developing random plugins to scratch your own itch. Definitely did a lot of that. Yeah.
Matthias Pfefferle:
I looked up one of the talks you had. Let me see.
Will Norris:
Oh, just the WordPress pet peeves thing.
Matthias Pfefferle:
Yeah. How not to build a WordPress plugin. Because that was one of the talks that impressed me a lot because I think you can summarize it, something like there is a way how you would normally code stuff and there’s a WordPress way and that might differ.
Will Norris:
Yeah.
Matthias Pfefferle:
So WordPress is kind of works differently, but it’s okay. You simply have to rethink how to implement things. And yeah, it was quite inspiring.
Will Norris:
I. I think a lot. It’s funny, like, I think I gave that talk at like a WordCamp Portland or something.
Matthias Pfefferle:
It was around 2009.
Will Norris:
Yeah, 2008, 2009. Okay, yeah, that sounds about right. And I think it. I also did like a series of blog posts about it where I like talked about some of these things and then I turned it into a talk. Or maybe it was the other way around, I don’t remember. But it was mostly out of frustration because I did. I forget exactly what it was that I did. I think like my WP content directory was not inside the WordPress folder. I kept it outside. And like, I laid things out a little bit differently. That made it easier for me to manage. And a lot of plugins didn’t work that way because they assumed where the WP content directory was and where some of this other stuff was. And. And I just got so frustrated and I was like, stop doing this. I gave it like a whole talk just because I was frustrated with how people were building plugins. It’s like there are global variables for this, there are hooks, there are like, just use the things that WordPress and it’s like. And I mean, I’m joking about how frustrated I was, but like, it’s a lot of people just don’t know, right? There’s a lot inside of WordPress, there’s a lot to figure out and it definitely. There’s a learning curve to learning how to do things so that they feel within WordPress and how that. And that is hooking into the right places so that they’re flexible for different types of environments. I remember when we were doing some diesel stuff, we were working with Andy Peeling maybe at the time, doing BuddyPress and WordPress Muse stuff. And so like we were trying to figure out how do we. And that actually taught me a lot of like thinking about a completely different deployment environment for. For WordPress where it’s laid out a lot of the assumptions that I had thinking about a single WordPress install didn’t work. And so I had to kind of learn a lot and find the right places to hook in and do things kind of the right way.
Matthias Pfefferle:
So now that you dropped DiSo, how came that all together? And what is DiSo? What was DiSo?
Will Norris:
Yeah, DSO was more. Was kind of an idea, kind of an umbrella project. It was started by Chris Messina and I think Steve Ivy. The two of them, I don’t even know that the origin story of the two of them, it stands for Distributed Social. And the idea was, I mean nowadays when you start talking about this, people understand it a lot better because we have Mastodon, we have all of these things that projects have kind of taken root. But back in 2006, 2007, this, I mean this was early days of Facebook. A lot of the kind of early, early social web. MySpace was still pretty active at that point. It’s, I think the site still exists, but it’s a totally different thing now. You know, we had friend feed. There was like, there was a whole slew of different kinds of sites that most of a lot of them at least don’t exist anymore. But we wanted a way to, to more own our presence online. Right, right. Of say no, I want this stuff on my personal website or how do we actually. Let me rephrase that. Actually the original impetus was more about how do we get these things talking to each other, how do we have a distributed social web instead of having all of these walled gardens. And so our initial implementation, I think Steve was using Movable type as his primary platform. Chris and I were both ended up joining very soon after the kind of the initial kickoff, within the first few weeks. Because I had been, you know, I knew Chris online and through, you know, OpenID and other kind of related stuff. And so we started working on this and we were kind of picking off little bits and pieces of what we thought about kind of makes this social experience. It’s like, okay, it’s identity or we’ve got OpenID. Great. You know, we’re doing profiles of like so that you can build out which like a lot of people had about pages on their website but they weren’t always, you know, they weren’t marked up with micro formats that you could easily consume or whatever. We were thinking about like blog roles and contact lists using like XFN style things. And then the really big one was Activities. So we’re all using all these sites we’re checking in on. I don’t know, it was Bright Kite at the time or Gowalla or whatever it was. And we’re like, we’re still, we have all this activity across the web but I, at least I want to like, I want a unified view of all of that. And so the original model that we had with Activity Stream with, well, with what became Activity Streams was to pull all of this data in and combine it and render it on some page on my site so that I can say, okay, here’s all of my check ins, here’s all of the photos that I’m posting over there. This was pre Instagram, I don’t know, wherever Flickr I think is probably where we were posting on those days. And so it was, it was a very kind of loose effort, very grassroots of just a bunch of individuals, like, hey, we really care about this. But we also, and Chris especially had a lot of contacts at the companies that were building these. We had. So we brought in people from MySpace, we brought in people from Facebook, we brought in people from Yahoo and. And a lot of the companies. And it was just. It was individuals that just really cared about this stuff. And like, hey, yeah, I can. I can add support for that in our product. And so we did. And we did it for a number of years. It was just around that this was the same basic community that ended up doing, like, OAuth and a lot of that stuff. Although some of those were. Those efforts were a little bit disjoint, but kind of the same group.
Matthias Pfefferle:
Yeah, and it’s quite impressive because you mentioned the Activity streams, because it was that era, I would say, I think it was around. It was around 2009 when you start building the Activity Stream Spec. And it started as an. As a namespace for Atom and rss and it is basically the foundation of what is now Activity Pub. So the. This all evolved into Activity Pub. So you can kind of see Diesel as the one of the first Activity Pub predecessor thingy that paved the path to what’s now called the Fediverse. I would say.
Will Norris:
Yeah, yeah, in a lot of ways. I mean, in that, like, what we had originally, like you said, we did it as a namespace for Atom and rss and it was interesting. Like, that was very intentional because we were trying to figure out. We very much took inspiration from microformats, where with microformats, right, it’s like, okay, you’ve already got your markup. What is the minimal amount of additional information we can. We can add to give semantic meaning to the things that you are already putting in markup? And so we took inspiration from that. Okay, you’re already publishing an RSS feed. And at the time, like, you know, Brightkite and Flickr and all of these sites were publishing RSS feeds of whatever their content was. And so, okay, what is the minimum amount of additional data we can put in here to allow us to have a common vocabulary across all of these different sites so that we can kind of have common understanding and meaning of what these actions are? Because the reality was, like, there was very. There was a lot of commonality already of kind of the basic structure of the kinds of things that you were doing on these sites? And so I always like to say in the early days that every Atom feed was an Activity Streams feed. It just might not be a Very good one.
Matthias Pfefferle:
Yeah. Because you mentioned the unobtrusiveness of OpenID and in a way that is the same with the namespace for Activity Pub, because you always have the RSS feed and if it’s enriched with the Activity Streams format, perfect. And if not, you can fall back to the at least the basic key values you have with classic RSS and Atom.
Will Norris:
Yeah, that was very much an intentional design decision. Interestingly, the XML version of that did not last terribly long. We pretty quickly converted it to JSON because it became more of a using it for APIs and things like that, not just like a RSS style consumption feed. But yeah, back to what you were talking about earlier, it did go on and got taken to the W3C and some of the original authors stayed with it then, and then it got handed off to other folks and there’s like been a tremendous amount of work that has been done on top of that to turn it into Activity Pod. Like, yeah, we did a lot of early stuff, but I’ve just been amazed of looking now and seeing how much more was done with it and like super impressed and proud of having been a small part of the early parts of that.
Matthias Pfefferle:
You were part of that history.
Will Norris:
Yeah, yeah. It’s funny like, and I think about it, it’s like, man, if I’d have stuck around, like I could have like continue to be a part of stuff now. But I, I moved on and ended up doing other things. That’s actually been like been me. Been the case with a lot of different things where I was involved in very early stuff but never really stuck around. So I kind of missed out on being part of the thing that finally took off.
Matthias Pfefferle:
But it’s, it’s not too late.
Will Norris:
It is not too late. It is never too late to get involved in open source and open standards. Yeah. Except now I’ve got kids and I’ve got like a. Like my life is so different now than it was back then, so.
Matthias Pfefferle:
But that’s not an excuse.
Will Norris:
Yeah, yeah,
Matthias Pfefferle:
yeah, maybe it is, but so. But it was not only working on that stuff. Yeah, you kind of were involved in also defining the specs around that. So it was. It, I think mostly started as proof of concepts, but most of them turned out or ended up in either an ietf spec, a W3C, there was a foundation around, or there is a foundation around OpenID these days.
Will Norris:
The.
Matthias Pfefferle:
Oh, XRD.
Will Norris:
XRD. Yeah.
Matthias Pfefferle:
Yeah.
Will Norris:
So XRDU is extensible resource Descriptor and it’s an OASIS spec. And this I’M trying to remember how did I even get involved in that? Well, so SAML is no way suspect.
Matthias Pfefferle:
Yeah, I know how you get involved into that because you were one of the first ones who tried to map emails to.
Will Norris:
Oh, that’s right.
Matthias Pfefferle:
IDs. And you built one of the. You built that because there was a huge discussion around no one cares about URL.
Will Norris:
No one understands URLs. Yeah, they don’t identify with URLs.
Matthias Pfefferle:
Yeah. And then there was a discussion around how can we map emails to IDs. And you built. Or you were. At least I think you built it.
Will Norris:
Yeah, I think I probably. I built some of it. Yeah. It was email to ID. Oh, so we had two things. It was. Ut was the way I pronounced it eAut, which was email address to URL transformation. And so that was the spec that defined. What’s that?
Matthias Pfefferle:
Catchy.
Will Norris:
Catchy. Yeah, right, exactly. That was the spec to convert an email address into a URL that could be used for like OpenID. And then I think we had built this was when we were at V and V, built a service like a service called Email to id, which I always pronounced email toyed. I don’t think anyone else pronounced it that way, but I did, which I think was like a hosted service to do some of this translation for you or whatever. But yeah, it was very, very early ideas around how do you use that email address as an identity. My involvement with XRD, interestingly, was not related to that. It was something else. But. But like Web Finger ended up sort of was. Was a cleaner implementation of the ideas that we had done.
Matthias Pfefferle:
I remember. Yeah, same with me. It was because of. How was it called? Simple.
Will Norris:
There was simple XRDs.
Matthias Pfefferle:
Yeah.
Will Norris:
Okay, so the original. There was originally Yottas, which was yet another distributed identity system that was the original name for OpenID.
Matthias Pfefferle:
Yeah.
Will Norris:
Before it was called OpenID, it was called Yottis. And then I think somehow like Yacht became like the discovery mechanism for like once you have an open ID when someone types in their URL. So let’s go back to the WordPress comment form. Right. Someone puts in their URL. I need to find out, does this URL have an open ID connected to it? Right. And so there you do a certain amount of discovery. I mean we were still doing like link tags or whatever in the markup is one way of doing it. And so.
Matthias Pfefferle:
Or.
Will Norris:
And then sometimes we want to get like more information about like what are the capabilities of this server, what version of OpenID is it running? You know, all of this stuff. And one of the interesting things with. Well, okay, so. So there was that. And there were XRDs came out of parallel efforts happening at Oasis, which was there was a system called XRI as Extensible Resource Identifier. And so there were these names that like started with an equal sign. It was like equal Will Norris or something was my XRI. And I think ats were supposed to be. Did they have. I think they might have had at. I think they were supposed to be.
Matthias Pfefferle:
I think there were two different identifier types. One was more a personal thing.
Will Norris:
Yeah, I think equals was personal and AT was companies or something.
Matthias Pfefferle:
Yeah.
Will Norris:
And. And this kind of came out of more of the Semantic Web kind of space. And there was like a. I never fully wrapped my head around it because there was this.
Matthias Pfefferle:
Really, totally forgot about that.
Will Norris:
Yeah, there was this very. It was a lot of indirection and there was a lot of mechanics. There was XRI and XDI and Drummond Reed is still around. He was heavily involved in some of those things and he is still doing identity stuff to this day. I keep meaning to reach back out to him. But XRDs came out of that space. And it’s the idea of if you have. There’s a couple ways to talk about this. Um, one of the key things about the web and sort of. This goes back to sort of the rest dissertation from. From Roy Fielding. But it’s the idea of being able to link between resources. Right. And being able to resolve resources. So you have an identifier and you can, you know, get some representation of that resource and then that can link to other things. Right. And this is all very basic obvious stuff when we think about the Web. You have a URL. I can put that into my browser and I can get back an HTML web page and I can view that and that can link to other pages. But if you have something that you can’t simply plug into a web browser, say like an XRI, which is what they were dealing with, or an email address. What can you do with an email address? Well, I can email it like it’s bound to the SMTP protocol, but if I want to do anything else, there just isn’t an affordance for that. Like, so there’s no way to get more information about that email address. Right. And so that’s very much. That’s where webfinger fits in. Right. It’s given. Well, webfinger is technically an account uri, but it’s an email like identifier. How do you get more metadata about this? And that’s the same problem that XRD was solving. They were solving it for Inames or for XRIS or whatever originally, but it was all kind of in the same space. So anyway, Aaron Hammer, Lahav and I were the editors on the XRD spec. Aaron went on and was the one of the Chief editors on OAuth2 and other things. So he and I worked on that together within the it was called the XRITC, the technical committee or whatever within Oasis. And then that again we wrote it as XML originally. Kind of like the original activity streams was all XML based because this was. That was that era. And then that eventually got rewritten. He ended up going off and doing a bunch of IETF specs for things like Host Meta and well Dot well known now that’s pretty common. Like that came out of that, that work that we were doing and then then a JSON version of XRD, which is 1 thing or at least that’s what, sorry, it’s XRD, which is what Web Finger uses as its representation. And so that’s the JSON flavor of XRD, which was a thing that we did for other things.
Matthias Pfefferle:
At least in the final flavor there were some flavors in between where you could choose between XML and JSON. Yeah, there might have been based on different stuff.
Will Norris:
Yeah, it was confusing, it was a messy process but like we ended up pretty in a good spot. I think.
Matthias Pfefferle:
How did you end up working on that specifications finally? Was that something you forced or was that something because you worked on that, that someone came to you asking would you like to define that finally on
Will Norris:
XRD?
Matthias Pfefferle:
All of your work?
Will Norris:
Yeah. Oh man, I can’t even remember. I know it predated my Time at Google I was already working on it, so it must have been when I was working with Internet 2. And I guess I had been involved in the space long enough that I kind of knew a lot of the people and as the. I’d always kind of been interested in standards work, but I’d never actually tried editing a specification myself. And so it just kind of seemed like a good opportunity to give it a try of actually doing the editing directly. But I do remember I then was working at Google and was working on originally Google Buzz and then Google. And I remember trying to explain to Vic Gandotra who is the. He was the senior vice president of social at Google because I had to have his sign off on the final XRD spec or something or no, sorry or for like because Google owned my work at that they had to sign whatever the paperwork was. I just remember spending a day in his office trying to explain XRD to him and why this was important and that no, Google’s not actually using this and will probably never use this, but we should be doing this where it’s part of the open web. It was a really awkward conversation because that was a time at Google where they were very much trying to just fast follow Facebook and it was not a period of being interested in interop. Right. So this is a fascinating story. A lot of people don’t know Google Buzz was. Do you remember Google Buzz? Very little. Maybe like. Yeah.
Matthias Pfefferle:
Okay, so maybe one thing before because that was kind of. That was the high time of the open Internet. So it was around that. DiSo was around. Then there was the Data portability. Org, the famous Hammer stack. And it was kind of very open, decentralized, interoperable. And a lot of big companies were very interested in that. So there was Facebook implementing OpenID and OAuth. There was Google around, there was Yahoo, as you said, MySpace. There were. The big players were around and had at least a subset of the stack implemented. And there was a huge discussion and then I tried to look that up, but I couldn’t find it. There was an article in I don’t know, maybe TechCrunch maybe what was the other big one?
Will Norris:
Read Write Web, Read Web.
Matthias Pfefferle:
Yeah, and it was something like the. The cool kids were now hired by the big companies because it was you And Chris Messina joined Google. Then David Recorden went to Facebook and
Will Norris:
some others, Joseph Smar and yeah, of the.
Matthias Pfefferle:
Yeah, let’s say cool kids that defined all of that and that worked on the open stuff were hired by the big companies. And then there Was a bit of a shift. It started in a good way, like with what you said, I think Chris. And you worked on Google, what later became Google, but it shifted a bit and now back to you.
Will Norris:
Yeah, that’s actually really good context. Right. So I wasn’t involved in actual developing Google Buzz. It was interesting. Like I started at Google on. It was like February 1st or 2nd and Google Buzz launched my second week of work. Like it was, it was built and ready to go and I was like, it’s my first day. Everybody was like super excited, like, hey, have you tried out Buzz yet? And because we were dogfooding it internally and stuff. And Buzz was basically a social product built into Gmail at the simplest idea. Just think of it as like Twitter, a Twitter style thing where you can post short form messages and comment and whatever, but it was actually integrated directly inside of Gmail and you had like a little tab there and all of that. But the more interesting thing about Buzz was that it was built on, or it wasn’t necessarily built directly on all of these open standards, but they had supported them. And so at the time it was Identica, which later became StatusNet. And this was Aaron Padramo. This was his thing that he was working on. Evan, sorry. So they had actually both implemented, they implemented both sides of this so that you could post on Google Buzz, you can see it on Identica and then you could reply on Identica and the reply would go back to Buzz and you. So they’d actually built an end to end working like federated identity or federated social networking or distributed social networking. And it was all kind of proof of concept. But it was there, it was in production, it was like in. And it was just from Google they were like fully embracing this idea. And it was, it was. I just, I still love the protocol for, for sending a comment from one stream, for from one system to the next was called Salmon because the idea of the salmon swimming upstream there was like all kinds. There was, there was, there was a. Magic signatures was something involved in this and there was something that. I don’t think it ever officially got called this, but it was called a Salmon slap. And I don’t even remember what that was, but we were coming up with all kinds of weird crazy names and there was like, I mean there was to credit where it’s due. Like there was a bunch of really smart people at Google that had built all of this. Jon Panzer and a whole bunch of folks. Anyway, so. And then Buzz ran into issues, privacy, decrees, and various things that ended up kind of killing the product, which was really sad because the tech was so cool. And then that did eventually morph into Google. But the philosophy of Google was wildly different than Google Buzz. It was very much. We took a lot of the same technology that had been built for Buzz and ported that over, but the approach was basically another walled garden. I was working on the API side of Google Buzz or sorry of plus. And there was an API from day one, but we never actually onboarded people. We only gave access to very select partners and stuff. And so it was not an open ecosystem in any meaningful way, which was just really disappointing for someone who came in having spent so much time seeing Google Buzz and how much the Buzz product had embraced that. And I don’t know if that was because it was more engineer led that the individuals working on it were like, we’re just going to do it this way and no one’s telling us no. And Google was much more kind of top down driven. So it was, the motivations were very different, which was, it was sad. But yeah, that’s how things go.
Matthias Pfefferle:
Yeah, even more because of your background, because all your work in the open. So was that also part of the decision to move on inside of Google, to change to the.
Will Norris:
Yeah, for sure, for sure. I had had some conversations with folks inside Google and it was just kind of talking mostly about like just kind of concern over the fact that we are just building another Facebook, we’re just doing another walled garden. And I remember this, this person said to me, he’s like, just my, my view on this is that Larry and Sergey, you know, from the early days of Google definitely felt that they had, there was definitely a, a kind of philanthropic view of like, we have gotten so much from the web and we want to give back and kind of an altruistic sort of thing of like we really do legitimately want to give back. And what this person told me was like, I think somewhere along the way they kind of decided they’d given back enough and they’ve repaid the debt and like, no, we’re good now. And I don’t know if that’s true or not, but, but it made just. And I thought about like, I can kind of see that like, like there is this shift now where like Google had changed. This was, you know, what, whatever year this was, 2011, 2012, something like that. And so yeah, I ended up moving on. I was beginning to look around at other places within Google, different teams I wanted to join. And then that was where I got involved in the open source Office there. It was a funny story there too. Google had their own code hosting platform at the time. Google code, yeah. And Google’s policy was that Google open source projects are hosted on Google Code. Like totally makes sense, whatever. But this was the time when GitHub was getting really, really popular. I think GitHub started in 2007, 2008. And I was a really early adopter of GitHub and had been involved in that from, from really early. And I was working in developer relations at Google and I was like, look, the, the developers we’re trying to reach are not looking on Google code. That’s not where they’re expecting to find their projects. Like at least for developer relations kind of projects where we’re really trying to reach this developer audience. We need to go where the developers are and so they’re on GitHub. And so I started as a 20% project managing Google’s presence on GitHub. Like I set up the Google. Org and we published a few projects there and whatever. And it became very, became very apparent very quickly that this was not like a 20% project. This is something that needed full time work. And so I moved over to the open Source office to do that.
Matthias Pfefferle:
And you even started on a go library for GitHub?
Will Norris:
Yeah, it’s funny. So we were building a lot of tooling for interacting with GitHub. GitHub is a very rich API. This was pretty early days of Go. I think it was still pre 1.0 release, or maybe 1.0 had been released at this point. And we were building this tooling to manage Google’s presence on GitHub. And I was like, well, we’re going to do it in Go. We kind of made that decision. And I made the decision very early on that’s like, well, let’s extract the GitHub API piece of it as a standalone library. This was my first Go code I had ever written. I did not know what I was doing at all. So I was learning GO as I was writing that library. But fortunately being at Google I had access to the Go team and to people. So it was very easy to get good code review and make sure that I was doing things that were idiomatic. But yeah, that library has now taken off and it is the pretty standard way of Talking to the GitHub API in Go. I’m not involved with it directly anymore, but it was a lot of fun building that. And now I just have fallen in love with Go. And that’s what we use at tailscale now. And that’s all I use.
Matthias Pfefferle:
Now, looking back at what you started with all your Open Web work and with Diesel and WordPress, why have that failed? So have you thought, okay, now I have the opportunity to go to Google and build that into the product, or was it simply that the DZO itself failed even before?
Will Norris:
I think one of the things I think maybe a good comparison here, if I can pivot in a different direction, is comparing DiSo to the current Open Web or, sorry, indie Web work. And I think that you can think of Indie Web as sort of a continuation of a lot of the philosophies and things that we were doing with DiSo. But the emphasis is very different where with Indie Web it is much more focused on principles, on the idea of ownership of data, and a lot more on protocols, of doing webmention, of doing some of these things. Whereas with DiSo, yeah, standards came out of it, but we were also very focused on a very specific implementation of the stuff inside of WordPress. And so because the focus was just on the implementation, it doesn’t work well when people are running other software. Whereas I think the great thing about the Indie Web community is that there is this ethos of a lot of people are kind of building their own tools that they’re using. There’s a lot of collaboration and sharing, but there is such broad support of these protocols and of these kind of philosophies on so many different platforms. Like my site is, I run a static website now generated by Hugo, and I have a bunch of little Go Sidecars that do that, implement some of those protocols and that works great with WordPress being, you know, running plugins that you’re maintaining. So I think that emphasis on principles and protocols Indie Web, I think has allowed it to be much more successful. And also I think it allows it to kind of survive the shifting tides of interest of people because the principles don’t change even if the actual implementation does.
Matthias Pfefferle:
So you would see it more like it was the predecessor of the Indie Web. So it’s not directly dead, but it was, I think, I think it’s fair.
Will Norris:
I think the Indie Web folks would agree to some degree. Yeah, I mean that it’s because like Tantec Chelik was very involved with DiSo. He was very much in that community now and he went on and helped to found Indie Web and all that.
Matthias Pfefferle:
So I think he even called it DSO 2.0.
Will Norris:
He might have. I think he did at some point. Yeah.
Matthias Pfefferle:
Okay. So, yeah, it’s not that. But it changed.
Will Norris:
Just change names.
Matthias Pfefferle:
Yeah. Okay. That is a nice way to see it. Yeah.
Will Norris:
Yeah.
Matthias Pfefferle:
Okay.
Will Norris:
The one thing I was just thinking about this before and I was going to say one thing that I do. So it was thinking about Mastodon specifically because we were talking about activity streams and that involving into Activity Pub and Webfinger. One of the things that I think Mastodon got wrong and I really, really wish they had gotten right. And I kind of kicked myself for not pushing me more previously.
Matthias Pfefferle:
No, I’m serious.
Will Norris:
Yeah. The way that they use one finger specifically, there is an assumption in Mastodon and this might be old data. I mean, like, I haven’t messed with it a lot recently, but there’s this idea that, okay, you have an account on a specific server. Right. And so you are, you know, I’m Will at whatever that server is. And one of the things that was so great with OpenID from the very beginning, like OpenID 1.0, I think 1.0 had. This is the idea of delegation, which is on my website. I point to a web server, to an OpenID server and I can even say, here’s my account name on that server. But the consumer knows that. No, no, no. I’m actually willnorris.com even though I’m logging in with some server over there. And so my identity is. Is distinct from the server that’s actually implementing the protocol. And that was something that Mastodon does not do today. Like, I can’t delegate and say I am, you know, Will at Mastodon Social. Like, so I have to run mastodon.willnorris.net because I care about that identity. And so now I’m paying to run my own Mastodon server, which is silly. Like, I shouldn’t need to do that.
Matthias Pfefferle:
I think it’s even worse without blaming them, it’s. You can delegate, but not the. What you would call the single source of truth will be used as your id. It delegates to the other ID and the other ID will be.
Will Norris:
Becomes the true identity. Right. And so then that’s not actually meaningful delegation.
Matthias Pfefferle:
Yeah, yeah. But you can use that to delegate to the other id, but not the delegating ID will be used.
Will Norris:
Yeah, you can do it for initial discovery.
Matthias Pfefferle:
Yeah.
Will Norris:
Yeah.
Matthias Pfefferle:
So maybe we.
Will Norris:
But then it will only use the thing over there.
Matthias Pfefferle:
Yeah, And I totally agree because that would solve all the current issues we have with portable identity because that would even be a thing. You could buy a $1 domain at certain host and a. A static hosting thing. What only hosts. Just a basic lucky blob yeah. That’s all you need and that’s it. And you could direct that to any server you want. We wouldn’t even have to discuss stuff like did what from my perspective is the same level as what was it inames? No, no.
Will Norris:
What was the names?
Matthias Pfefferle:
Yeah, it’s insane. Yeah, that’s.
Will Norris:
That is super. And I know there is an issue or there was on the Macedon GitHub, whatever. It wasn’t exactly this issue but it was like close enough that it’s like. Yeah, that basically is the issue. And I don’t remember why it either got closed or there’s. It’s just the. The unfortunate thing is that we are like so far into Macedon, the Fediverse in general, that it is probably going to be very difficult to change that. I don’t know. Maybe. But yeah, that is one thing I wish.
Matthias Pfefferle:
And because we now shifted a bit into the did Blue sky thingy. Yeah. You switched jobs from being the open source guy at Google to being the open source guy at Twitter.
Will Norris:
Yeah.
Matthias Pfefferle:
Back then when Twitter was the goal.
Will Norris:
When it was still Twitter. Yeah.
Matthias Pfefferle:
Were you involved at least a bit in the Blue sky discussion thingy?
Will Norris:
I was involved in discussions, yeah. Like, I mean I had, I had had maybe one call with Jay who leads that and it kind of. This was when they had, I think the. It had been announced like the fact that there was going to be some funding that it was kind of a separate organization from Twitter. But there was no. They hadn’t hired any engineers yet or any of that. And so I was involved in like some internal conversations around that. It wasn’t, it was kept pretty, pretty separate from Twitter. I was running Twitter’s just main open source office. And so it was most of my day was internal stuff at Twitter.
Matthias Pfefferle:
So that was not really an option.
Will Norris:
I guess it would have been an option, but it wasn’t the reason I had gone to Twitter. So when I left Google I was managing all of the engineering within their open source office. So the open source office was basically a bunch of engineers and a bunch of program managers that ran programs like Summer of Code and lots and lots of those things. And I was running the engineering and I knew, I figured my boss, Chris de Bono was like, he’s not going anywhere. He’s a lifer at Google. So if I ever want the, the opportunity to run an open source office myself, I’m going to have to go somewhere. And Twitter was looking for someone and so that was why I went over there to run their open source office. And so it was. I think there was probably a possibility of being more involved in Bluesky, but it would have been a different job. I would have had to actually rescope it a bit. And so that wasn’t really. And I think I was maybe less interested in doing social stuff at that point, which is funny. Going to go to Twitter and I’m like, not super interested. But I went there to do open source. So that was really, my focus was on running an open source office.
Matthias Pfefferle:
So I think we have the same kind of history on all of that. It’s not mainly building social stuff, but keeping your identity and your interactions not private, but in your own hands. So yes, it’s kind of social, but not in a way like big social networks are these days.
Will Norris:
So yeah, very much, very much so.
Matthias Pfefferle:
And now you ended up at tailscale. How. How was that?
Will Norris:
It’s been good. So when I left Twitter I discovered that when I, when I did move over to Twitter that I was. Turns out I don’t like running an open source office. Or at least I mean the job, exactly the job that it was. I found that I was a little bit too removed from the hands on engineering.
Matthias Pfefferle:
Okay.
Will Norris:
And, and so, and I found that I just didn’t enjoy that as much that I really, at the end of the day, at heart I’m an engineer and I really like building. And so I was, I knew I wanted to find something where I could get back closer to the engineering and more of a hands on kind of role. And so I was already looking when Elon, you know, got involved with Twitter. And I was looking at it and I was like, okay, I don’t know how this is going to end because when I left it was before the acquisition had closed. It was when he had like made the announcement and, and then was trying to back out of it. And I was like, okay, I don’t know if he’s going to be able to successfully get out of this or not, but either any scenario that I could imagine was not going to end well. And I was like, okay, I’m going to find something else. And so I knew a lot of the tailscale folks. We crossed paths at Google and in other places.
Matthias Pfefferle:
Yeah, mainly Brad.
Will Norris:
Fits perfectly. Yeah, I mean, yeah, known Brad for almost 20 years through OpenID and all of this stuff. And so he was one of the very early engineers, but also like David Crawshaw and Avery and others, the co founders came from Google and so they were, they had been involved in open source related stuff at Google and so being in the open source office we had crossed paths before. So yeah, I came here just to be an engineer again and just wanted to write some code and it’s been a ton of fun and I, I definitely look back and say okay, that was definitely the right move of moving back to a hands on engineering role. Like I’ve done a lot of people management and that kind of thing and I have a ton of respect for good managers and I think I was probably okay at it, but it’s not my passion, like it’s not what I really enjoy and so I’ve really enjoyed doing this. And then funny enough like about a year, so I’ve been at tailscale coming up on four years. About a year and a half ago I moved over to our Identity team. Previously I was not doing anything identity related. I was doing a bunch of other stuff, APIs and so I guess I was doing OAuth. So I was still doing kind of working in similar protocols but now I tech lead our identity team and doing. So I’m kind of back at identity again which has been a lot of fun of kind of dusting off those skills that I haven’t used in a little while.
Matthias Pfefferle:
So we have to give you around 10 more years and then you’re back into the.
Will Norris:
Then I’ll be back into social again. Wait for the pendulum to swing back the other way and yeah, maybe, who knows? I mean when the kids think about the house. What’s that?
Matthias Pfefferle:
When the kids.
Will Norris:
Exactly, yeah, once the kids are out of the house then yeah, about 10 years it sounds about right. The funny thing is there is a lot of potential overlap and like part of the idea with, with Indieweb, with DiSo, with all of these things is just having more control over your content, over your presence online, over, you know, not being, you know, subjected is not the word I’m looking for. But reliant on the big social platforms and especially in the modern day where like, I mean a lot of these companies I just don’t want to be, I don’t want them holding my data, I don’t trust them, I don’t, you know, whatever it is. And tailscale at the end of the day is about making small trusted private networks. And so like you can imagine having a private network using tailscale that then you put social stuff on top of that and that allows you to have that same kind of interaction but in a closed environment where it is just you and your friends. And so like that wasn’t the reason I Came to Tailscale. But things like that, that idea of being able to have privacy, of being able to, like, not everything I do needs to be on the public Internet. Not everything I say necessarily needs to be on Facebook. Whatever I have the choice. If you want to put it out there, great. But I want to be able to keep some of those things private and do it in a more. More private environment. And so I think it sounds like a.
Matthias Pfefferle:
That sounded like a project pitch.
Will Norris:
Yeah.
Matthias Pfefferle:
Social network based on Tailscale.
Will Norris:
Yeah, I mean, there have been a bunch of. There’s definitely some chat stuff that people have built. There’s a bunch of different things that. Yeah. That people have built. So, I mean, at the end of the day, the core part of Tailscale is basically like a layer three network. And so you could put anything on there. There are other things you could do as well. But.
Matthias Pfefferle:
Yeah, I wait for that.
Will Norris:
Yeah, it would be great.
Matthias Pfefferle:
I’ll wait for the big announcement.
Will Norris:
Yeah, we’ll see. And funny enough, I think Brad has actually had some interest in that too. I mean, keep in mind, like, he built LiveJournal before MySpace, before Facebook, before all of these. And it was about like being able to interact with your friends. I think he said he built it for like his. His high school friends or whatever, wanting to be able to publish online and interact or something. And so it was. I mean, livejournal predates a lot of these modern social networks and it is really one of the earliest implementations of it. So that’s still very much, I think, in his. In his heart, that kind of interaction.
Matthias Pfefferle:
Get famous by accident.
Will Norris:
Yeah, much.
Matthias Pfefferle:
Yeah. So it was me a pleasure to chat with you about the good old days. And I feel honored because you shifted away from WordPress. I have the honor to maintain some of the little famous plugins I learned a lot from.
Will Norris:
Yeah, I think I might have like handed you a few of my old WordPress plugins too. So thank you for helping maintain those.
Matthias Pfefferle:
That was what I wanted to say.
Will Norris:
Yeah.
Matthias Pfefferle:
I have the great honor to maintain some of your old plugins and I even. Shame on you. I was the one shutting down your big famous OpenID plugin.
Will Norris:
Oh, is that one closed now, is it?
Matthias Pfefferle:
Yeah, but to my credit, because it
Will Norris:
wasn’t really being maintained.
Matthias Pfefferle:
Yeah, yeah, to my credit, you would close it even before.
Will Norris:
That’s true. Yes.
Matthias Pfefferle:
I kept it going for life for some more month, I would say.
Will Norris:
Does WordPress have native open or. Sorry, OAuth support now?
Matthias Pfefferle:
Oh, I forgot to say that I wanted to blame that for you. I wanted to blame you for that because you left too early on and the WordPress API still lacks OAuth support.
Will Norris:
It still doesn’t support OAuth. It’s a bummer. Yeah, I had an OAuth plugin
Matthias Pfefferle:
for DiSo.
Will Norris:
Well, no, there was a. I thought. I thought I had a standalone WP OAuth plugin or something.
Matthias Pfefferle:
Yeah, everything you.
Will Norris:
It was part of DiSo. Yeah, yeah, yeah.
Matthias Pfefferle:
But yeah, I think there were two follow up plugins especially made for the WordPress API rework but they are still not really maintained lying around in some GitHub sub in a sub organization. It’s. It’s still. And it’s a shame because every modern API endpoint needs OAuth so every plugin that extends the API brings its own OAuth authentication endpoint with it. And I speak for myself because I just recently implemented the client to server stuff for Activity Pub bringing in my own.
Will Norris:
I was just looking this up. It was WordCamp San Francisco 2013 that I gave a talk when you pitched was about generally contributing to WordPress and I think some of the WordPress the Android app and stuff. But I thought I also talked about OAuth at that one. So not. Shame on me, man. Shame on the rest of the people that stuck around. Why haven’t y’ all built it?
Matthias Pfefferle:
Yeah, okay, I take that with me.
Will Norris:
But anyway, yeah, we’ll get there. It’s. It’s ever evolving.
Matthias Pfefferle:
Yeah, good things take time, so.
Will Norris:
They do. Yeah. Well, yeah. I thank you for having me on. I know it took us a while to finally get this set up, but I’m really glad that we did.
Matthias Pfefferle:
It’s almost 20 years when we at least chatted in some weird Google code project thingy.
Will Norris:
Let’s node another 20 years before we talk about this again.
Matthias Pfefferle:
Yeah, but the next in 20 years will be about your tailscale saving the world project thingy.
Will Norris:
Something.
Matthias Pfefferle:
Thanks a lot and yeah, let’s wait not for so long for the next episode.
Will Norris:
That’s great.






