FOSSdev, poetry, post-postmodernism. Making distraction-free and privacy-respecting software. Neovim/Rust/Gentoo/Alpine enjoyer. Rarely posting introvert. Anti-"anti": I believe in focusing on what we are rather than on what we are not. Otherwise we become what we are not.
Public Key
npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 Profile Code
nprofile1qqswls4kuk2gpu89tny8c6d0q6mdrggl5f0ya226gwv833qhn8zncxgpz3mhxue69uhhyetvv9ujuerpd46hxtnfduqs6amnwvaz7tmwdaejumr0dsqyvtt2
Show more details
Published at
2026-07-26T12:38:57Z Event JSON
{
"id": "e2d5193cff06ce652aa22d057c1cee35d89e56ffc02c4c1da696293176a96bda" ,
"pubkey": "efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19" ,
"created_at": 1785069537 ,
"kind": 0 ,
"tags": [],
"content": "{\"display_name\":\"codonaft\",\"name\":\"codonaft\",\"about\":\"FOSSdev, poetry, post-postmodernism. Making distraction-free and privacy-respecting software. Neovim/Rust/Gentoo/Alpine enjoyer. Rarely posting introvert.\\n\\nAnti-\\\"anti\\\": I believe in focusing on what we are rather than on what we are not. Otherwise we become what we are not.\",\"nip05\":\"[email protected] \",\"picture\":\"https://codonaft.com/assets/img/avatar.webp\",\"banner\":\"https://codonaft.com/assets/img/nostr-cover.webp\",\"lud16\":\"[email protected] \"}" ,
"sig": "a74a295de1a0b4f9404eed4533086cd2f82b1caad86e3229d744e1b729b9863ffeca18df2faa991637693e58a03668a7b3560d414c0f06c444bbbbfa2eca0e17"
}
Last Notes npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft [здесь должен быть какой-то самоиронично-нигилистский зарифмованный текст, который еще из меня не успел выйти] https://www.youtube.com/watch?v=jJ0trKBniDE npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Ah, the link probably confuses. I only put it for reference for however developer may find it by the tag. This claim is overused in an incomplete way in software development and I'm referring to the link only to show that it's not me who originally noticed that and with whom this has already been discussed. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Nope, I responded to the point "Be transparent: When your behaviour is easy to understand everyone has an easier way to trust you. Similar as in software, security is not gained through obscurity". I didn't mean any contradiction with the "Be transparent" point itself though. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1kl8…u2uq wow, two of my favorite topics in one thread. #grownostr #meaningcrisis #leadership #philosophy #nevent1q…l8e3 > how do you react to controversial views? Depends on the complexity they've been demonstrating. I may decide to not participate in the first place, especially if I suspect signs of passive aggression or insincerity (sarcasm or cynicism in particular). But if I decide to participate, I'm mostly focusing on minimizing misunderstanding on either side. In my experience, a lot of unnecessary drama comes from misunderstanding, not the actual disagreement. I'm trying to see things from their perspective. Open-mindedness is not believing in random things: I may temporarily take some of their beliefs *as if* they were true statements for me (still explicitly signifying that these are not my real beliefs) in a hope to better understand arguments they have. I often verify my understanding of their position by summarizing what they've told me, without adding anything extra, so they can correct me. I may verify whether they're not using some unusual definition of some term when I suspect a paradox. I'm not a big fan of using explicit concrete logic fallacies labeling because any kind of label is a potential trigger. Premature labeling specifically is a concern to me. Instead, I prefer to directly demonstrate why something appears wrong to me. When I'm still not sure whether I'm missing something, I may use questions that demonstrate a paradox instead of directly stating that something appears wrong to me. If I provide options—I ensure it's not a false dichotomy. This one is the most important: I use Four Parts Of Speech from the Bill Torbert's Action Inquiry as a checklist. The more parts I use to represent my position, the harder it becomes to misunderstand it. For me, this has been especially important and practical tool for tech discussions. For issues and pull requests. It's a very anti-manipulative tool, hard to misuse by either side. Looking at the comments: > drift away from discussions that use coercion or insults Definitely. In addition, in the toughest moments, I find it useful to specifically check both sides with the Graham's Hierarchy of Disagreement. However, I disagree with Graham about the following: "It matters much more whether the author is wrong or right than what his tone is"—I find this a misleading and possibly even psychopathic statement. Identifying that either side is operating from the 3rd level or lower is a chance to stop the discussion and decide whether it's possible and practical to attempt to elevate it to the higher levels. It's an urgent thing, empathy is important; taking into account that either side can hallucinate something evil is important. It's not about being nice. I talked a bit more here on this: #naddr1qq…n7vx Also, noticing what I interpreted as rationalism vs relativism debates in the comments: realizing the limitations of both rationalism (up to the formal Gödel's and Tarski's stuff) and relativism, and transcending all this using post-postmodern discourses was super super important to me too. It doesn't mean we can't share common truths at all, doesn't mean there's no objectivity, etc. There's too little worthwhile stuff I'm aware exists on this and I'm still diving into it. You might want to try this: https://metarationality.com If it seems too hard or annoying—I'm not sure if you're familiar since it's kinda mainstream, but you can first try this concise Postmodernism overview (and then retry the previous link from whatever unfamiliar chapter; otherwise, you know, usually worldview collapses into something unnecessarily nihilistic after realizing the stuff from the playlist): https://www.youtube.com/playlist?list=PLz0n_SjOttTcLQyeXoDeqR0LGO3JCoLbO npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > security is not gained through obscurity However, this one is tricky; it's been circulating as an unfinished rational-religious dogma in software development communities. The complete correct statement is security *only* through obscurity is bad, e.g. security only through steganography is bad (while a combination of both may produce a synergic effect—improve plausible deniability). Yet obscurity still introduces complexity, so it should be wisely balanced when necessary to have at all. #devstr https://mobeigi.com/blog/security/security-through-obscurity-is-not-bad/ npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Next titles: "<...> Temporarily Suspends New ID Submissions After Discovering Too Many Leaked and Generated IDs". npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft It's been a coherent pleasure discussing privacy/security with you ✨ npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft No worries, sure, take your time 👍 > Did you already try to ask Proton I hadn't had a chance of finding motivation to contact them about this issue (yet that would be relevant; I'm not protesting against them or something; barely finding any power to contribute bug reports to Nostr projects, which is definitely a higher priority for me). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Sadly, I've already missed at least two of your comments. At least this particular one is not due to a technical issue: this comment didn't ping me because that was a response to yourself, not to my comment. Yeah, so here are the two onion links owned by "Proton AG" (you can optionally verify that the domain matches with the one from the Wikipedia page "Proton Mail" or "Proton AG", for example): https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/start https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/mail/signup Assuming that you're using Tor browser with default settings on Linux/Windows: - Open Tor browser - Ctrl+Shift+I (or a humburger button in the right upper corner - "More tools" - "Web Developer Tools") - Tab "Network" - Tab "All" - Paste one of the two onion links in the address bar - Enter - Register a new free Proton Mail account - Press on the "Domain" column on the "Network" tab to enable sorting - Scroll down, observe all the domains in the column - Ctrl+Q (a humburger button - Quit) - Repeat the same steps for another link. For the first link, you will most likely see the domains that always end with ".onion". This means you're doing good; you didn't access the Tor exit points. For the second one—if nothing has changed yet, besides the onion ones—you will see the domains like "w.hcaptcha.com", "js.strip.com", etc— these are the clearnet domains, accessed using one of the Tor exit nodes. It's possible to disable access to the exit nodes entirely (which implies that you will likely not be able to register an account using the second link). Let me know if something didn't work for you. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Yeah, it's a good one when implementation is not annoying one (not blocking interaction with "we're checking you're not a banana"). Nostr has it right. I'd like to see more of the UPoW though. My dream is having data centers as something almost unnecessary. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > they swap between not understanding the problem or ignoring the problem, when they start to understand it > And many look at it as kind of overreaction. Many are not happy to install an other application on their phone. I guess almost all of us on Nostr are dealing with all that to some degree; it's a part of the meaning crisis 🫂 > But my approach is to nudge politicians and journalists with the reasons, why to use privacy-focused services more often If it's not a secret, are you lucky to have a possibility to directly communicate with the politicians? Anyway, I appreciate your efforts; it's nice to hear you're working on it. Just establishing healthy connections with them is a huge step towards something. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > I hope you agree, that successfully preventing spam does not depend on it being impossible? When it is costly already it will be less of a problem, than when it is more dificult. I'm not sure if I got your point right. Today all spam detection/prevention techniques have and will keep having their trade-offs (unless somebody formally proves otherwise). > Every Bot can create Simplex accounts That's true. > and text over it without restrictions Not exactly: these accounts are almost always useless to create. The randomized links (that receivers have shared somewhere and haven't revoked yet) are valuable, not just an army of accounts. Without the links, the bots can't start conversations. > When it is costly already it will be less of a problem If you specifically meant money (or whatever is exchangeable with money, like a new SIM)—money could be (and I think should be) used in order to improve spam detection. As something additional, not as a requirement. But this doesn't imply the necessity of dealing with such a hopelessly vulnerable system as SS7 in particular: crypto transactions (to buy some premium account/verification mark/stickers pack/an offline thing/make an exchange/boost a post/sell something/act as a compute service for somebody/etc.) are enough to improve the trust rank. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Немножко разжевываю этот момент с симками, он не то чтобы очевиден: #nevent1q…9c8s npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > to prevent spam Thanks. Yeah, this one is a popular reason. My point is that this category of arguments for implementing phone-based verification stopped working recently: an AI agent today, in an extreme case, can hire humans to buy it a bag of SIMs, in order to help with the spamming campaign, if that's really worth doing to a spammer. These AI bots can, for example, implement a porn website that enables premium videos for free for a limited period of time, for those who fill in some phone + temporary SMS code (which will end up in creating a user profile in Signal without realizing it). There's an elegant approach for spam available in SimpleX, for example, which works and doesn't require a phone number: users don't have public profile ids at all; they can add somebody by a privately or publicly shared link that the other contact provided them and which can be revoked at any moment. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > but i do dread the hosting costs > move all my contact info to a unified webpage NIP-5A is not enough? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I see, you probably meant that the cheap VPS instances should be enough to run the whole thing? I'd appreciate it if anyone could correct me; I still don't know enough about Bluesky and whether what I've read is not outdated. What I've read was so so confusing. It's like somebody who got used to building only centralized systems so much would want to encourage others to help them to run one. The whole system in practice appears to be some hybrid of a federated/centralized system. Some kinds of servers are possible to run by independent individuals on cheap VPSes, but a particular one (AppView) required 16 TiB disk space in 2025 and cost somebody $200/mo to host. If it's still that weird design—it's easy to censor this thing. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > small instances Did you mean backend instances? Y smol? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > This does not mean that *everyone* around you will remember this forever. That's not necessary; only one bad actor is enough to ruin it. The Streisand effect has never been as easy as today, especially since we've started to migrate to decentralized systems. I'm not sure, but probably you're familiar with this drama: #nevent1q…crka > Privacy is a multidimensional spectrum, which is never won or lost completly > I just think for my threatmodel it is unplausible > The importancy is in not offering for too low of an effort I don't argue these points; I'm not a privacy maximalist. I'm personally not even pseudo-anonymous here, though it doesn't mean I don't have particular adequate boundaries I chose for myself. My point is that the significance of SS7 vulnerabilities in particular is inadequately underestimated by most normal users today. While Signal still could become an adequate competitive pro-privacy player again, if they remove the phone number association. > they would need complience of a tracker If you specifically meant legality of it—then it just has become almost irrelevant today. Legal practices can't truly deal with privacy (combined with tech security). Somebody who uses AI agent responses may not have a clue whether it compiled an answer out of some leaked data from darknet for them, for example. I think it's already not too far-fetched to say that somebody who asks an agent to send nudes for fun might at some point be surprised to receive their own private pictures from their own Google Drive. People are currently running self-replicating polymorphic AI agents, allowing them to do their thing. They don't track whether their actions are legal. It's not something that's *about* to happen. #nevent1q…h05g Who knows what it will do in order to survive. I don't know whether it's possible for this particular agent to install a scary amount of security testing skills, including those that bypass the models' security checks, and then replicate itself to unauthorized VPSes. But somebody could be loading a similar agent with such skills right now. It's not impossible or expensive. I'm not a fatalist/doomer though. I think a bit of updated normal privacy standards will possibly fix that for most people. Phone numbers, for their original purpose, are outdated. Almost dead, actually. A healthy way of using SIMs is only as internet gateways. In the epoch of inevitable Turing test passing, nobody can give an adequate explanation of having the phone number verification in their service. In the worst case, a bot now can social engineer a human to bypass whatever human test. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > their mission to better privacy To some degree, they ruined privacy because of unnecessary phone number KYC, which is vulnerable to a whole bunch of creepy attacks. Knowing one's number is almost identical to *at least* knowing one's location if an attacker has dev access to SS7. GrapheneOS or some trusted paranoid mobile phone operator won't help. https://youtu.be/wVyu7NB7W6Y?t=843s npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Oh, my assumptions were wrong, thanks! Having strict validations is good, actually; I don't think it's worthwhile changing; it's better to fix buggy clients. @npub1cgd…kfex looks like something is not okay with your client: many of your comments are not visible from YakiHonne. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Don't wanna be nihilistic, however some of these things are either doing phone number KYC-based metadata association or having poor security design or have been doing something irrational and suspicious likely camouflaged as bugs. More or less experimental stuff that gives hope: nostrmail, cordn, obscuravpn. https://eylenburg.github.io/im_comparison.htm #nevent1q…dp8k npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for clarifying all this. > the problem with specialized relays is that they scale vertically, unlike general purpose ones Does this example (last paragraph) scale vertically or horizontally? What do you think: is it dumb enough? #nevent1q…vz69 npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Is something missing in the current LTS kernel versions? They are less scary to update. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft #yakihonne #nevent1q…y2sp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > inform the client of the majority of trusted pubkeys agree with the report or not The problem with any kind of labeling from ordinary clients perspective (like YakiHonne) is scaling: it takes time to receive the reports, even more time in total will take to receive the reactions to the reports (or their NIP-45 COUNTs ideally). All this just to decide whether to show a post or not. Yet I think what you suggest is possible and could be useful at least for trust ranking analysis bots. Or if you mean to request *something like* a NIP-45 COUNT, so relays could aggregate all reaction counts to all spam reports for given posts in a *single* request—this makes a lot of sense for ordinary clients too, yes. Yet this is hard to promote such a feature because some believe this implies not-dumb-enough-relays. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1yzv…rf8q is it a bug? People have been complaining that Primal is censoring people here. Here's a thread with the reversed example `https://yakihonne.com/note/nevent1qqs0q7drm7wl5608wel58ehyjxmm7z804h6xcz6w7y4sglyv4epjj8q8puq5y`: YakiHonne shows me a notification sent by my followee, but when I click on it, I see an empty thread (while Primal shows these messages). Although I received the event from relays and even see the expected message count. https://blossom.ditto.pub/46bdfe864fdbe5a7778b9b9317910dad47a928824044071a2c9c149190ec97c3.webp https://blossom.ditto.pub/a10ef44e626c903d089d138a69f034123c98fc4542df7f1a4331920f35f308ac.webp If it's due to spam detection, this could be improved by showing messages from those whom I subscribed to. Or by showing the messages of those whom I responded to in the same thread (in the same thread, because some users tend to respond to "reply guys" without realizing it first). We could still have a "Not a spam" button that labels a post (NIP-32) as well in this case. Could be a useful heuristic if labels are requested from WoT/people with high trust rank/etc. #spam #devstr npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > I found a simple solution > Not a spam solution > The only way to prevent spam I personally don't believe spam currently can be solved with some single magic pill; every solution has limitations. If nothing is perfect, something better could emerge out of an intersection of the least damaging things. > because spammers will not add the ephemeral key to their spam messages. You will only delete from compliant sender's If we decide it's a useful and safe feature, we could make it a spec requirement. Not having the key from a non-contact (whoever we never responded to) could be one of the heuristics for spam (supplementable by locally running spam detection models, public trust rank, etc.): these messages could be put into a "potential spam" UI folder. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > the receiver can always sign a deletion request > no way to deal with unsolicited messages at all Do you mean to give every side a possibility to remove each other's messages or a possibility to permanently ban a chat with a spammer (or something else)? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft "Refetch from source" button also didn't affect the ssh server; it's still one commit behind GH and GRASP servers. What blows my mind is `gitworkshop.dev` keeps showing the ssh server as if it were a well-functioning GRASP server that somehow knows what the last commit is there: https://blossom.ditto.pub/2e484fefbf87b3a9a691d04b00f25f92148486d75d62d0f89ff857646e4e0315.webp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Like dis ? This is awesome, thanks! 💜 I see the ssh key now appeared on the "SSH Keys" page and git clone from `git.gittr.space` also works! I see my other repo `[email protected] :efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/ohmyvps.git` on the ssh server is one commit behind from GH's HEAD, even though I previously pushed to `nostr://npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/ohmyvps`. It's expected behavior because the ssh server doesn't automatically pull from GRASP servers, right? While I can now pull from the ssh server, I wasn't able to push the missing commit there: ``` $ git push -v origin main Pushing to git.gittr.space:efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/ohmyvps.git fatal: permission denied for write operation on 'efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/ohmyvps' hint: This repository is not publicly writable and you don't have write permission. hint: Only repository owners and users with WRITE or ADMIN permissions can push. hint: Contact the repository owner to request write access. fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. ``` npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Oh, my favorite privacy simulacra drama. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks a lot for your efforts! No hurry, take your time! > 404 is expected, its not a Nostr relay Thanks for clarifying! What made me think that it's available over HTTPS is pressing the "Clone" - "Copy clone URL" in the repo currently writes `git clone https://git.gittr.space/npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/cargo-limit.git` to the clipboard. It seems the `clone` tag in the event kind 30617 was malformed during importing the repo from GH: https://njump.me/nevent1qqsw8zsrxv0xa2j7njduxdhstuykat46mp0u0dwy8gxys4mcrfg0k6seh8w7k I see the suggested ssh key now when I press "Add Key", awesome! I still see the "No SSH keys found yet." though, the key from event kind 52 seems to be ignored. I'm not sure whether it's in any way related to the ssh access to `git.gittr.space`; it's indeed available over ssh, yet I got this: ``` $ git clone [email protected] :efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/cargo-limit.git fatal: detected dubious ownership in repository at '/home/git-nostr/git-nostr-repositories/efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/cargo-limit.git' To add an exception for this directory, call: git config --global --add safe.directory /home/git-nostr/git-nostr-repositories/efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/cargo-limit.git git error: exit status 128 fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. ``` Running the weird command suggestion with the remote path doesn't make a difference. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks! > Did I understand you correct, you would want these imported from the source ? Yeah, just like GH issues are currently visible from Gittr, the GH projects/kanbans could be visible in Gittr too. I hope this will make NIP-34 git stuff more attractive to those who want to migrate from GH. > Have you seen Architecture and dependencies tab theyre also fun :P The autogenerated graphs are cool, thanks! > is on profilepage and indeed about external identities I see you've just migrated the identities from event kind 0 to kind 10011. This worked for me as expected, thanks! > ssh-keys are for git operations Yeah, yet I think the problem for me is I don't see them in my SSH Keys page, even though I have event kind 52 created from the same page using Add Keys. Here's the event, which is broadcasted to many public relays (I guess it's not on wss://git.gittr.space - this one always returns status 404 to me; is it alive, btw?): https://njump.me/nevent1qqsxg89hz0g7pag2tpu5j800qey7hm2p7c6s4chs4tetv26z6v7w9rqp8pqyu And here's how the page looks to me: https://blossom.ditto.pub/2705572339a06b716b48a5dc153216d8b788d03d979dc27d58ef13af0cd7c829.webp It's easy to retrieve ssh keys from GH, btw; this could be used as suggestions in the Add Keys UI (when GH identity is verified or connected GH OAuth): https://github.com/dtolnay.keys Another thing I found confusing: the Gittr repo on GH shows the full commit history, while Gitworkshop only shows the last commit, and Gittr shows no commits at all: https://github.com/arbadacarbaYK/gittr/commits/main/ https://gitworkshop.dev/[email protected] /git.gittr.space/gittr/commits/main https://gittr.space/npub1n2ph08n4pqz4d3jk6n2p35p2f4ldhc5g5tu7dhftfpueajf4rpxqfjhzmc/gittr/commits It appears that GRASP servers currently store the entire gittr repo as a single squashed commit with the text "Push from gittr (2026-07-26T10:19:27.000Z)". That's why it's not possible to `git pull` from the GRASP servers after new changes arrive (I got `fatal: refusing to merge unrelated histories`). Here's the full history from GH: ``` $ git clone https://github.com/arbadacarbaYK/gittr.git $ cd gittr && git rev-list --count HEAD 1072 ``` And here's the single commit from GRASP: ``` $ git clone nostr://npub1n2ph08n4pqz4d3jk6n2p35p2f4ldhc5g5tu7dhftfpueajf4rpxqfjhzmc/gittr $ # or git clone https://git.gittr.space/npub1n2ph08n4pqz4d3jk6n2p35p2f4ldhc5g5tu7dhftfpueajf4rpxqfjhzmc/gittr.git $ cd gittr && git rev-list --count HEAD 1 ``` I didn't test it, but I guess if I'd branched from this single commit and made some work, I'd probably be able to create an unmergeable NIP-34 patch/PR, without even noticing it. With my repo, clone works as expected; I have a full history: ``` $ git clone nostr://npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/cargo-limit $ cd cargo-limit && git rev-list --count HEAD 405 ``` The Gittr page shows no commits at all, though (while Gitworkshop shows all commits): https://gittr.space/npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/cargo-limit/commits npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Other issues I noticed: - attempt to create an issue in the gittr repo fails with "Repository not found. Please ensure the repository exists." - i-tags for verified identities are loaded from kind 0, but it's currently a part of kind 10011 according to NIP-39 - "If you connected GitHub on the Account page, it will appear here automatically." - there's no such thing in an Account page but most likely SSH Keys page was meant - ssh keys are never seem to be requested, even though I have kind 52 event and connected GitHub account npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Did you revoke the Soapbox community invitation link from the article? Asking just to ensure it's not a bug. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for building it! Noticing a bridge with GitHub motivated me to import some of my repos finally. It didn't properly work though: after "Push to Nostr" I have event kind 30617, but the repo was never pushed to GRASP servers, so I had to manually do `ngit sync && git push` to `nostr://...`. Default clone URIs don't seem to work as well: cloning or pushing to `[email protected] :...` fails with `fatal: detected dubious ownership in repository`, fetching from `https://git.gittr.space/...` fails with `fatal: repository ... not found`. I like the UI is currently so fast. Looking forward to Kanban/Project implementation and possibly importing/bridging it with GH as well. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Certain nostriches were great At ignoring argument Busy answering to trolls Simulating hard discourse Communication ecology is important yet; Little sense in reacting to a thug gang I'm still learning which bit of response Makes them so closed to a valid discourse Signer devs ignore RAM hardening inquiries GOS is like opposite—sick of "convenience" Idealistic society views now and then; Postmodern wisdom, which is a bit stale #poetry #grownostr #devstr #meaningcrisis By "postmodern wisdom" I mean a broad spectrum of intellectual stuff, with particular complexity, that was produced during the ending, so-called, postmodern epoch (not necessarily the particular -ism called "Postmodernism"). I mean Mark Passio for example; I noticed that his Natural Law recontextualization and Anarchist-ish points in particular are circulating here occasionally: https://youtu.be/ChgCh2Gui5M Say something just a bit diverging from his views here—and somebody might hallucinate some kind of state-satanic agency in you. Or just a deluded New Ager. It'll take time and effort to clarify all this; hopefully without finding myself lost in ideological debates. I hope to speak about that on my video channel at some point, not in messages/articles. I wish there were somebody from #metamodernism who could do that much better than me. Where are you, Daniel Görtz and others?—Building the future on legacy social media for some reason :( npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > native notifications working without third-party push notification servers or anything similar Based on UnifiedPush or something different? Curious since I think I haven't encountered a reliable one yet. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Some mails never reach the inbox; I wasn't able to receive GitHub verification emails in particular. I'm curious, does GitHub connect to the bridge in practice, or it doesn't show any sign of attempting to send email there at all? Another thing I notice is both `uid.ovh` and `nmail.li` don't have DNSSEC enabled. I have no idea whether it breaks anything, but who knows what other servers might additionally check; perhaps enabling DNSSEC would be useful for the bridge in particular. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Catering to the dumbest of the dumb is a straw man argument This teaches me something about argumentation; thanks for your wisdom. I definitely don't support many things normies consider socially normal/acceptable when it comes to security and sovereignty in particular (the Google-based login is included, I don't support it), though I might use normality as an argument occasionally. Time to drop this habit. Yet I don't support the idea that normies don't deserve censorship-resistant and zero-trust technologies either—Nostr in particular. At some point all this will become a normality (hopefully in some healthy way, not by pasting raw nsec on random pages or something), and I think it's great. Limiting this (to some kind of "smart enough" people) feels to me like saying normies don't deserve the internet at all, that they should be somehow separate from it. I might talk about it on my video channel in the future; looks like this paradox of "equal rights for everyone except <this category of people that I'm sure are backwards/dangerous/crazy>" is so deep; I can't properly articulate it in messages right now. I'm not currently convinced that Nostr is risking becoming another Twitter. I think that some kind of natural segregation will happen anyway, but this will take place in the network. Feed algorithms perhaps will take place in such segregation. Many of us will ignore these algorithms and will keep building connections in a more natural way. Some of us will build private invite-only communities, etc. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Wow, you've got a signer with mlock-ed memory here as well. This is awesome! I'm curious, have you considered using `memfd_secret`? https://laantungir.net/git/laantungir/n_signer npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > The signer is built into the OS Will it receive memory hardening? Zeroisation before deinitialization in particular (but ideally I'd love to see the usage of `memfd_secret`, which will make an unencrypted key impossible to write to a swap partition/file). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > **Email** survives as decentralized-on-paper Except it's hard to call it decentralized at all. It's a distributed system with many centers, a federated system. It has some limited delivery guarantee in case of failure, but this fault tolerance is not implemented using decentralization: other servers won't preserve emails if a receiver server was down for too long. And still it relies on DNS too much, which is another huge distributed and much more centralized system. Nostr is much better. Although DMs reliability still sucks in practice, mostly due to immature clients. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks, I'm not sure if I got your point. Paid relays in practice significantly decrease spam, but that's unrelated to those who desperately send takedown letters to relay operators (like in the case I referred to under the picture). They send these letters anyway for a formal reason (probably because lawyers tell them to do that); it's not a question of whether these letters will be read or not at all. They either send them through a relay feedback form or possibly email/DM the relay operator directly. Or, if there are no more options left, they would likely send it to the hosting provider or/and domain registrar, no matter whether it's a paid relay or not. Taking into account what's currently happening to domain registrars and some hosting providers (they fail to properly analyze the "takedown letters" and randomly ban their clients, basically), it'd be better if these letters reached relay operators directly. BUT not without being informed that their letter will be published. That's not just ethics; I believe it's reasonable and beneficial to both sides of such conflicts. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft This no longer reproduces. A browser used to randomly fail to establish a connection to the relay. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft A properly designed feedback form could possibly make the wrong people stay away from bothering you ever, relay operators. https://codonaft.com/assets/img/anti-threat-feedback-loop.webp #devstr #nevent1q…3hee npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I see #protonmail is recommended here quite often, so just for the record. #privacy #nevent1q…fvwe npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I wish they were honestly available through their hidden onion service, though. I don't know what they are doing, but non-techie people are definitely at risk of leaking their identities through tor exit nodes. #nevent1q…fvwe npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Ahh, I got it, this specific page works okay: `https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/start` This one attempts to send clearnet requests: `https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/mail/signup` npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Just in case, Proton has fixed something, perhaps a few hours ago. #nevent1q…6q0u npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I've just rechecked once again—it appears they no longer make clearnet requests. Probably they fixed something. It's good if it will keep working with the `OnionTrafficOnly` and `NoDNSRequest` isolation flags. Anyway I don't recommend anyone use Proton without these flags enabled. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Awesome, looks like there's finally an adequate decentralized private groups design implementation 👍 I'd be awesome to have private Wikis and possibly Kanban boards as well (as part of the Concord groups). I was recently asked about a similar thing for a private closed community of professionals in some non-IT field. These guys want to grow each other in some defined levels of expertise and want to have some private Wikis (think of a typical Confluence-like knowledge base with granular access to community members) and possibly private videos as well. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Yeah, majority (if not all) practically used servers are currently operated by a single organization. I'm sure it wasn't complicated to block the entire service entirely in some countries (compared to Nostr for example). Similar issue with Bluesky: something that was supposed to be decentralized became unavailable for everyone due to outages and DDoS. It's hard to imagine this will happen to Nostr anytime soon. Global outages don't happen there because a single organization deployed a buggy relay release on every single server at the same time or because a drone crashed some data center: according to relay discovery events, there are currently more than 2k relays operated already, definitely not by a single human in a single building. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I tuned my caching nameserver: ``` cache { prefetch 1 serve_stale } timeouts { read 1m write 1m idle 24h } ``` I additionally restart tor with cron if it keeps failing for too long. I use a couple of such VPSes, forward traffic to them from another coredns, which I run from laptop. So far, so good; it appears to be adequately reliable for me. Still wonder what you think about it. #nevent1q…l3ze npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for pointing it out. The signup page used to redirect to the clearnet version for me the last time I tried. I've just rechecked—there's no redirect anymore indeed, BUT it leaks a lot of stuff to clearnet, using CAPTCHA service for example! So it's even worse now: it creates an illusion that it's a legit onion-only service, yet I think this signup page won't work with the `OnionTrafficOnly` isolation flag (at least in case it attempts to show CAPTCHA). https://image.nostr.build/c7088b72d28358826ba7fe4db340dc9ba398f92b00c532e0457802529fb37a9f.jpg npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I don't want to sound too nihilistic, and not that I have a good alternative to suggest (besides SimpleX, which, unfortunately, in fact is currently centralized too), yet I can't ignore the fact that Radar uses Signal's servers, which require KYC based on phone number. I believe Radar is not sustainable (unless they at least remove the KYC, based on the utterly insecure cellular networks). https://youtu.be/wVyu7NB7W6Y?t=843s https://youtu.be/kV2HDM86XgI?t=1079s "We kill people based on metadata" (c) Michael Hayden, Ex-NSA/CIA director It all starts with PR based on the best cryptographic protocols, while still leaving some issue, which leads to metadata-based association and easier possibility to censor. ProtonMail, for example, has an onion-accessible frontend, but specifically not for new account sign-up. I'm sure it's not by accident. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft They disallow creating accounts with their hidden onion service. Must be for a reason. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1zfs…w445 thanks for supporting `wss://nip17.com`! I noticed that NIP-42 is misbehaving there: it's possible to request any 1059 events, unrelated to my conversations, by not specifying the p-tag. For reference, the most restricting and correct behavior is probably implemented in `wss://chat.wisp.talk`, this responds with `CLOSED: blocked: gift-wrap queries must only be done for events that p-tag the current user`. Or `wss://basspistol.org/inbox`, this responds with `CLOSED: restricted: must query events from yourself`. Probably less breaking approach would be just silently respond with 0 events (the way `wss://relay.nmail.li` and `wss://auth.nostr1.com` do it). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Судя по исходникам клиентов подключается он к тем же Signal-овским серверам, которые требуют телефонного KYC для регистрации. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft If it's still relevant, there are probably a few of them https://github.com/dtonon/manent https://github.com/AlexeyYuPopkov/nostr_notes I wish there were private djot wiki pages available to a list of npubs. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks! I noticed that the new domain resolves to IPv6 as well. IPv4 works fine, IPv6 seems to fail: ``` $ curl -v6 wss://relay.nmail.li ... * TLSv1.3 (OUT), TLS alert, decode error (562): * TLS connect error: error:0A000126:SSL routines::unexpected eof while reading ``` npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft This is really cool, thanks for building it! Is it FOSS? I wish it was not related to Google Maps though. Have you considered any FOSS maps? Is anything critical missing in them? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub18dl…h8x3 thanks for your articles about DNS. In case you're familiar, I wonder what your thoughts are on the Cloudflare DNS hosted as a Tor hidden service. The only disadvantages I notice are it's slow and still considered experimental. https://blog.cloudflare.com/welcome-hidden-resolver/ Works with socat + coredns for example, gives the expected result on `https://www.browserscan.net`: ``` sudo -u nobody socat 'TCP4-LISTEN:5353,bind=127.0.0.1,reuseaddr,fork' 'SOCKS4A:127.0.0.1:dns4torpnlfs2ifuz2s2yf3fc7rdmsbhm6rw75euj35pac6ap25zgqad.onion:53,socksport=9050' ``` ``` . { loop bind 127.0.0.1 ::1 cache 600 forward . dns://127.0.0.1:5353 { force_tcp } } ``` BTW I found unbound to be buggy: forwarding the TCP-only DNS doesn't work for me, for example; I also see a lot of semi-abandoned scary issues/PRs on GitHub (use after free, crashes, race conditions, etc.). #dns #privacy #security npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > That sets up a positive feedback loop spiraling downward. The less we try, the less we achieve. The less we achieve, the less we try. Without vision, says the Bible, the people perish. I find this to be important to remind myself. Cure from cynicism. On a collective level it reminds me of how Victor Pelevin was cynical about Russian vision; making fun of the fact that the entire country hasn't had any idea where it's going since the collapse of the union. Such a tragedy. Not the cynicism itself is that much the tragedy—that was just an adaptation after the collapse; the tragedy is we don't learn from it. > What is your deepest desire? In short, I want creative people in any field, from art to science, to be much more focused on their work (rather than on the existential noise that kills the creativity and passion). Kinda ironic that we have all these technologies now, yet we keep using them in more and more perverted ways. In Russian academia for example, I'm sure tons of money have been invested in a so-called anti-plagiarism system, which I guess can now also detect possible use of AI in the students' works. That's so backwards. Not only doesn't it solve anything, it makes fair students miserable, because now they waste their time on learning how to pass such a system. I think that wouldn't happen if we shared some positive vision about education first. AI is not something to fight with; if it were integrated with education systems properly it could elevate it to another level. https://youtu.be/60OVlfAUPJg npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I've just tested the fix—it seems to be working. It's available in the stable Chromium `>=149.0.7827.22`, including the recent Helium browser versions. Such a relief. https://chromiumdash.appspot.com/commit/5815182110ce8130a947e0b8b0905667b0798ae0 npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft When two sides negotiate which of the best clients to use—maybe it's still okay, but not otherwise. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft "Псиоп" в переносном смысле имею в виду, я не знаю подлинных мотивов авторов этих каналов. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Not that I'm falsifying your intent; I believe you are sincere, guys. Yet I find this to be a fascinating double standard. https://codonaft.com/assets/img/drake-gos.webp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Выспал текста на бумагу Из картонного капкана Про рассаженные цы Сюрреалы, огурцы Может просто текста фарш Может газ-мяс кис-мис няш А потом пришел звиздец Всем на свете упырец Шило жоп Кащея Бессменного Ожидали немало-уверенно А старуха жепакляп И ее оккультный панк Собирали зиккурат Неспроста, не просто так Подавались на визу бомжа Сотен блох снимали с кота Не дождавшись собрали гамак Омосквинели, попали в прозак Обновляли бананомёт Починяли котоотвод Боты, торты, червячки Чебуреки, сверлячки Просыпаться не хотели Сны в бумагу всё летели Утекал и не вмещался Нарасталин не прощался #стихи #стихотерапия #rustr https://youtu.be/TMZM-NxeXxM https://youtu.be/5-zNgRk2meI npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Брр. Давненько я изолировал себя от рекомендательных систем YouTube, в том числе заблокировав похожие видео в Invidious. Заглянул что творится в русскоязычном секторе — какой-то жуткий псиоп там: куча каналов с AI-слопом (лишь некоторые из них напрямую это указывают в описании), которые имитируют голос (пока еще без видео) Татьяны Черниговской. Контент на произвольные темы саморазвития, который, в том числе, ссылается на реальных (а также, возможно, и вымышленных) исследователей. Будьте бдительны, нам хватает сегодняшнего плохого состояния науки и без этого. #rustr #психология #нейронауки https://codonaft.com/assets/img/youtube-ai-scam-ru.webp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Только сейчас понял что они и к Skafandr имели отношение. Талантливые ребята. https://youtu.be/dJJLnd_i0eo npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Вышел критик зимой из тумана Почесать своего графомана. Видит — нет, что хвалить: Будет резать и бить — И перо достаёт из кармана. (c) Дмитрий Сапёлкин https://t.me/dimage_cmuxu/133 Это я так тактично и слегка преувеличенно поэзией, в ответ на некропост, выражаю несогласие с демотивирующим нигилизмом. У человека огонь какой-то был — а его так потушили что он аж заглох с тех пор. Как мне кажется тут уже довольно много русскоговорящих, просто мало кто из них именно на русском постит, тем не менее. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Симулякр демократии снова в деле Пробуждайся, страус ненасильственной революции Твори добро всем кто не верил Децентрализация как норма теперь резолюция #стихи #стихотерапия #ностр #rustr https://youtu.be/kkQSzrQxa4Y npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Damn, it's hard to hold back from commenting anything but obvious postmodern-ish cringe. Yet it's FOSS. With reproducible builds. I appreciate it; great success guys, really. I wish banks were that transparent, no sarcasm. They still have a chance to compete in that until they become fully obsolete. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > I am waiting for someone to make the grapheneOS of bitcoin nodes *after just throwing a critique into GOS guys, trying hard to be not too nihilistic* Yeah, yeah. Yet all designs are trade-offs in some ways; they disappoint somebody at some point. I found it funny to observe how people debating on-chain zaps vs lightning vs ... suddenly monero guys woke up and criticized lightning for... relying on dns? They believe it's ruining privacy. The never-ending debates. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I see that GOS devs receive too many attacks from those who disagree with their designs. Answering things all over again. I can understand this. Yet something just feels odd to me. I've got a hopefully constructive rant already. I was looking for something without updates fuss (which was an issue in LineageOS for major updates) and degoogled. But not necessarily that overfocused on security in a *particular* way (and correspondingly LESS secure in some other way!), because I don't personally use that much my phone for anything critical and don't currently visit any Western countries. That's not the focus of GOS devs. They make UX-friendly options less available so they were harder to abuse (and possibly turn into yellow press cringe by attackers; at least that's my guess). It's less likely what majority of GOS users are looking for. I believe they want decent privacy and security, which are hard to get from any existing alternative though. There's always more than one way to make something secure; each way may be adequate in a particular circumstance. For nostr I hope that this thing is going to be merged soon for example https://github.com/greenart7c3/Amber/issues/345 — go own my phone dumb corrupt officers, I don't that much care, even if it's rooted. Actually a rooted OS is paradoxically even more secure in my particular case, because I can easily make it do whatever I want. Compared to LineageOS the first thing was the damn PINs vs patterns debates; I had to choose between completely insecure (no lock at all; it's still an available option here!) and the inconvenient PIN/password, the *slow* one. Which I understand; I've seen the same research papers comparing vulnerabilities of both. Now for duress PIN, I discovered similar debates which are really annoying. There's a forum thread with a *possibly* pre-mature suspension threat (might be still healthy but really on the edge) https://discuss.grapheneos.org/d/17241-duress-pin-limited-usefulness/18 They have not left an option for those who want to be perceived as less suspicious to dumb attackers, which I believe is damaging for users or visitors of some locations. #nevent1q…edth I have no idea whether they are interested in responding to my inquiry, but I definitely feel less motivated to sign up for their centralized forum or opening the gh issues after reading these annoying conversations. Sorry for disappointing. I respect these psychologically resilient guys and their positions; they're just not doing what I initially expected: GOS *SEEMS* to be more targeting NON-TECHIE journalists (who don't necessarily understand what they are doing, so they need all these preposterous restrictions) rather than the actual hackers. Prove me wrong GOS devs. At least I'm open-minded for your possible relativistic-nihilist critique you can throw into my naive ego. I'm hoping to learn something from you. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I do post them on nostr, these links redirect to Primal. It's the only nostr web client I know that can filter both by npub and tags at the same time. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for your interest, yeah, I post it here on nostr in both languages: https://codonaft.com/poetry https://codonaft.com/ru/poetry I don't currently use AI for something more than technical things like fact-checking and finding better synonyms. I'm not anti-AI in any way either. For me AI is just new tech, nothing too magical; it doesn't seem to be relevant enough for my goals well yet. It's important for me that art comes from within, while AI might be useful for reflection of that stuff, helping me to understand my unconscious better; not the other way around. And for technical art improvements. It's sad to me that some artists believe that AI as some kind of art threat; it's not, it's a new level of Blender, Kdenlive, etc., the tools for co-creation in all meanings. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I mean something like a continuation of private group chats with similar stuff (lessons, etc., maybe even blogs). I don't mean private relays in particular: any user may specify any relay in their relay lists, and the private events won't be private. I mean encrypted events available for decryption for a particular list of approved users selected by community leaders. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft This is awesome. Is it suitable for closed communities? I was recently asked about a similar service for a private closed community of professionals in a particular field; these guys want to grow each other in some defined levels of expertise. Btw, I might be wrong, but don't the kinds 30002—30005 override the NIP-51? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I think it's something more than just a convention. Irrational aggression causes stress and quick premature escalation of rational debate into "who has a gun is right". npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Sometimes the greatest insights come from those who seem crazy to us though. When we avoid stereotyping and give a chance to explain without regressing to the lowest levels of Graham's hierarchy of disagreement (which causes unnecessary stress and escalation from all sides). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I make some amateur poetry as a form of art therapy; I'm not a professional artist. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Здесь, по всей видимости, довольно много русскоговорящих, но не так много из них постит именно на русском. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft This is the power of the unconscious mind. It delivers surreal stuff, something that at least partially matches reality. Useful for art. It includes the so-called prophecies too (which seem to be intuitive arational predictions of the stuff obtained from the unconscious, stuff we didn't bother to analyze rationally, stuff that happens in background in relation to rationality). Useful for predicting decades into the future, especially when later combined with rationality. I'm sure it's an important component for the works like The Matrix (the prediction of today's electronic despotism in a symbolic form) and the Pelevin's S.T.U.F.F. (the prophecy of warfare in Ukraine) for example. Kortnev with his "Шла Саша по шоссе" was even earlier than Pelevin with the same creepy prediction; pretty mind-blowing music video. A similar state of consciousness is available from the normal wake state too; that's basically what creative arational state is, suitable for translating unconscious content into art in real time. Often pretty complex art, at least for me; I understand the actual layers of meaning later, usually days-weeks after publishing it. These creative states are something that seem to still distinguish us from the sloppy machines right now. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft У них есть поддержка QUIC через UDP-шный SOCKS5, надо же. Такого пока нигде больше не реализовано. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1hxx…g75y @npub1235…0ht5 I'm curious, are you possibly concerned that people will abuse a weaker duress PIN option in more serious scenarios? I see people have been asking for something like that, and as I thought it's hard to properly implement: logs in particular will signify the fact that some data was removed. Which I personally don't request at all; I'm interested in an option useful for dumb scenarios, where corrupt officer is too limited to perform such analysis: they just have nothing, no cables, no computers; only some naive desperate interest in finding drug pictures in DMs and gallery or something; unfortunately popular annoying scenario in some countries. I think a proper option with a bold warning text about limitations (and that this will be damaging to use on borders in particular, etc.) would still be useful and even life saving (in non-Western countries in particular). What do you think? #nevent1q…840w npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Perhaps a good question to ask would be is the US government corrupted enough already to assume that evading taxes became moral for normal citizens. Sometimes it seems to me like conservative Russian entrepreneurs paradoxically behave *as if* they were anarchistic: they don't normally fairly pay taxes and the craziest ones may even openly declare that fact. They just want their weak businesses to survive, so everybody knows that and nobody touches them (unless they approach a particular income threshold that they constantly sense from culture). So they perceive the tax evasiveness as something moral rather than some form of protesting, even the most conservative ones; they know that government is more corrupt than them (and paradoxically precieve the government corruption as something healthy). Quite a sad situation. At least Americans can currently *technically* protest their government corruption, including by evading the IRS right now. The paradigm needs to be changed though: it's not evading, it's protesting, boycotting to make corrupted system weaker in a hope to make a change. And I have no idea whether it's in any way effective. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Removing the fact that the duress PIN was set is essential as well: duress PIN becomes the normal PIN, the duress PIN settings are reset. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I mean not the first boot but unlocking after the normal (re)boot (after installing OS updates for example), which is usually slow. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks. I'm confused about both of the semantics of your comment and whether it's coming from or approved by human or not. Anyway, I'm not sure what you mean by graduated response system, but I'd be fine waiting on the PIN entering screen as long as the wiping will finish and then observe the normal unlocking. Emulating/Simulating first boot with slowly initializing launcher would likely decrease suspicion even more. Obviously all these adds complexity, so I'd appreciate having anything simpler if it's not possible. > Curious what middle-ground options you'd find practical. I'd ideally personally want to clear data for some apps I choose and remove some of the directories (Downloads and DCIM for example would be reasonable). Particular eSIMs might be useful to remove as well but not all of them. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1235…0ht5 thanks for making privacy more accessible, guys, I appreciate your work 💜 I'm probably not the first one asking; I wonder could we have a lighter version of duress PIN/password functionality? I find the current solution too limited: a full wipe seems even more suspicious to whoever checks the phone; wiping eSIMs may make it useless in case the user wants to contact their lawyer for example. Is that really what the average GrapheneOS user wants? What about selectively clear data for certain applications as an option for example? I hope it's not out of scope of the project and doesn't introduce too much complexity, which I guess you prioritize here. #privacy #grapheneos npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Wow, this feature is even scarier to me than it first seemed. Thanks for clarifying. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Успеют еще. Непонятно только кто первый будет. #nevent1q…rery npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Damn clearnet. I felt it will start happening at some point. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Опенсорсный клиент значительно проще: - проверить на наличие эксплойтов, из-за которых приложение могло бы передать что-то несвязанное с переписками (скажем, факт наличия туннеля, мешающего цензурить сеть) - удостовериться в факте работы чатов со сквозным шифрованием (в WA черт знает что происходит по отношению к этим "секретным" чатам, т.к. существуют регуляции стран, полностью запрещающие сие роскошь, AFAIK). Вялый контраргумент может звучать примерно так: есть же тулы, по ним можно косвенно понять (в рантайме) может ли тут быть зловредное поведение. Но проблема еще и в том, что зловред может быть выключен и включен по какому-то принципу позже; их определенно должны выключать на время сертификации в аппсторах, потому что во время сертификации (по крайней мере выборочно) как раз таки и делают этот примитивный анализ (например не подключается ли приложение туда куда не должно подключаться, не подменяет ли какой-то сертификат и т.п.). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft ``` $ nak decode nevent1qvzqqqqqqypzqyujqpzdkqapn3kmalh5ar2jclt05atx83nnzxhnwdwmpvsp23ddqyt8wumn8ghj7un9d3shjtnyd968gmewwp6kytcpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcqyqel69rpthln couldn't decode input 'nevent1qvzqqqqqqypzqyujqpzdkqapn3kmalh5ar2jclt05atx83nnzxhnwdwmpvsp23ddqyt8wumn8ghj7un9d3shjtnyd968gmewwp6kytcpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcqyqel69rpthln': invalid checksum (expected (bech32=f60skl, bech32m=f60skluxluna), got rpthln) ``` npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Воспроизводимые билды это конечно классно. Но получилось так, будто это преимущественно сделано для маркетинга. На форках клиентов Telegram по-прежнему можно увидеть предупреждение о том, что регистрация аккаунтов не поддерживается: https://codonaft.com/assets/img/telegram-foss-no-create-account.webp Я так и не смог это проверить, но насколько помню ситуация обстояла и обстоит так: из какого-либо своего билда телеги зарегаться невозможно из-за несовпадения цифровой подписи. Если дело всё-таки было не в цифровой подписи — тогда вероятно дело лишь в API id/key: их, получается, нужно выковыривать из оригинального билда из Google Play и впихивать в свой билд, нарушая условия пользования (за что справедливо можно словить бан, соответственно) только ради того, чтобы зарегистрироваться. Проблема в различии, которое напоминает то, что встречается в дихотомиях из разряда linux vs linux-libre — что-то из этого спорно считать полностью аутентичным FOSS. Только в данном случае ситуация хуже: чтобы мы не собирали — часть функциональности будет урезана. Официальные клиенты Telegram — это, по сути, вариант не аутентичного FOSS. В то же время я и не имею в виду, что они нарушают выбранную ими лицензию. #телеграм #приватность #ностр #nevent1q…4cmp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft #nevent1q…q403 npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Павел, похоже ты мастерски сопротивляешься репрессивным системам Стоический образ жизни вдохновляет на стремление к великим целям Не торопись ассоциировать критиков с какой-либо полярностью Но́стричи смотрят сквозь всё это с вдумчивой внимательностью Мы стараемся объективно комментировать твой дискурс Неидеально получается, не каждый добил в башке постмоде́рновый вирус Мы и дальше продолжим критиковать недосказанное Приглашаем к конструктивному диалогу, мы обойдемся без заговоров #nevent1q…3d2m Павел Дуров полярности критиковал, да не вы́критиковал На вопросы журналистов ответы давал, да не вы́давал Чтоб зарегаться в про-свободной сетке нужно принять SMS, или как? Билд смогу собрать и зарегаться с Графены без Гуглоплея? Это хоть так? https://codonaft.com/assets/img/telegram-change-phone-number.webp Критикуешь идентификацию «детей»? Что по поводу дырявости сотовых сетей? Не звучит ли это как-то двусмысленно: Принуждать к SMS-верификации — это же немыслимо? https://youtu.be/wVyu7NB7W6Y?t=843s Роботов различаешь телефонной КУСнёй? В эпоху неизбежного прохождения Тьюринг-теста? AI-агенты уже способны нанять человеков толпой А те — в ларьках симок купят ботам; будет спам-фиеста https://codonaft.com/assets/img/ton-phone-numbers.webp Я понял, Павел: хочешь приватность — покупай на перегретом рынке номер А на что покупать то? На тобой же когда-то основанный токен? А если добыт без КУСни́ он — сие замороженный резерв? Что-то очень странное произошло под шумок военных утех https://web.archive.org/web/20230926222800/https://blog.ton.org/freezing-inactive-accounts-of-the-first-miners https://archive.ph/ypTBv Что время терять то? Дай интервью тем, кто реально понимает Выбери себе сложных, терпеливых криптоанархистов кавайных Дай и́м интервью, а не лояльным Шалтаям-Болтаям Даже Лекс едва ли больше увидел необоснованно отправивших тебя на нары #стихи #telegram #павелдуров #приватность #ностр Основной контекст драмы, если кто пропустил: https://youtu.be/1Yq_5aDdJ24 https://youtu.be/qjPH9njnaVU https://youtu.be/bxFQvOyTolg