<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub14a7v3r4ppfy007s0tk2h0ujh38h9x4t6jyrndev9qmmazd2vrsvqxg6tv3.rss" />
  <link href="https://nostr.ae/npub14a7v3r4ppfy007s0tk2h0ujh38h9x4t6jyrndev9qmmazd2vrsvqxg6tv3" />
  <id>https://nostr.ae/npub14a7v3r4ppfy007s0tk2h0ujh38h9x4t6jyrndev9qmmazd2vrsvqxg6tv3</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqspqgsag7emyl55twuzh3unk906shhr87xugdg067rvsdzyk53k77szyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpsh8furm</id>
    
      <title type="html">📅 Original date posted:2015-06-10 📝 Original ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspqgsag7emyl55twuzh3unk906shhr87xugdg067rvsdzyk53k77szyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpsh8furm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst0vcevrd052t9sh0js6e2vk8mzj78n2gu6cvh8zt2qzak2skgd6qa5806q&#39;&gt;nevent1q…806q&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-06-10&lt;br/&gt;📝 Original message:&lt;a href=&#34;http://www.howtogeek.com/218764/warning-don%E2%80%99t-download-software-from-sourceforge-if-you-can-help-it/&#34;&gt;http://www.howtogeek.com/218764/warning-don%E2%80%99t-download-software-from-sourceforge-if-you-can-help-it/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;TL;DR:&lt;br/&gt;&lt;br/&gt;&amp;gt; In 2013, GIMP’s developers pulled the GIMP Windows downloads from&lt;br/&gt;&amp;gt; SourceForge. SourceForge was full of misleading advertisements&lt;br/&gt;&amp;gt; masquerading as “Download” buttons — something that’s a problem all over&lt;br/&gt;&amp;gt; the web. &lt;br/&gt;[...]&lt;br/&gt;&amp;gt; In 2015, SourceForge pushed back. Considering the old GIMP account on&lt;br/&gt;&amp;gt; SourceForge “abandoned,” they took control over it, locking out the&lt;br/&gt;&amp;gt; original maintainer. They then put GIMP downloads back up on SourceForge,&lt;br/&gt;&amp;gt; wrapped in SourceForge’s own junkware-filled installer.&lt;br/&gt;-------------- next part --------------&lt;br/&gt;A non-text attachment was scrubbed...&lt;br/&gt;Name: signature.asc&lt;br/&gt;Type: application/pgp-signature&lt;br/&gt;Size: 836 bytes&lt;br/&gt;Desc: This is a digitally signed message part.&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150610/10e90e6d/attachment.sig&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150610/10e90e6d/attachment.sig&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:37:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvhyv63pxhl92rmq79s6acr0dutkv6q86ctmjhg74zrc5e9qs5wfgzyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpsg8sxpa</id>
    
      <title type="html">📅 Original date posted:2015-02-01 📝 Original message:Why is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvhyv63pxhl92rmq79s6acr0dutkv6q86ctmjhg74zrc5e9qs5wfgzyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpsg8sxpa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdvrnscnzvxtmf7k3lfk7nvj4737pcqw3vhujqxkcv862czv993ks8tg7ye&#39;&gt;nevent1q…g7ye&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-01&lt;br/&gt;📝 Original message:Why is that?&lt;br/&gt;&lt;br/&gt;Also, is it correct that there wasn&amp;#39;t a release candidate before the release? &lt;br/&gt;Sounds dangerous to me.&lt;br/&gt;-------------- next part --------------&lt;br/&gt;A non-text attachment was scrubbed...&lt;br/&gt;Name: signature.asc&lt;br/&gt;Type: application/pgp-signature&lt;br/&gt;Size: 836 bytes&lt;br/&gt;Desc: This is a digitally signed message part.&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150201/33933d24/attachment.sig&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150201/33933d24/attachment.sig&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:29:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsztz5dkqusmlh6kuql3dxgvrvltuq8mqvw57q654030p43kwearygzyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpssjrkmv</id>
    
      <title type="html">📅 Original date posted:2014-10-19 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsztz5dkqusmlh6kuql3dxgvrvltuq8mqvw57q654030p43kwearygzyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpssjrkmv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs94laf9n06j8hsjpp86ma9s8ujdzuuqenkp9hsmgeqggcv98vcvfchkupaf&#39;&gt;nevent1q…upaf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-10-19&lt;br/&gt;📝 Original message:On Wednesday, October 15, 2014 10:29:43 AM Wladimir wrote:&lt;br/&gt;&amp;gt; B) I also think it makes sense to move the BIP discussion (both about&lt;br/&gt;&amp;gt; the BIP process and individual BIPs) to a separate mailing list.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; bitcoin-development currently has a dual function: discussion of&lt;br/&gt;&amp;gt; Bitcoin Core implementation concerns, as well as global changes to&lt;br/&gt;&amp;gt; Bitcoin (in the form of BIPs).&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; This makes the list too busy for some people, but it is critical that&lt;br/&gt;&amp;gt; everyone writing a Bitcoin node or client is up-to-date with proposals&lt;br/&gt;&amp;gt; and can comment on them.&lt;br/&gt;&lt;br/&gt;I joined the list when Bitcoin was already in the 10-billions of market &lt;br/&gt;capitalization, and it actually really surprised me how low the traffic is here &lt;br/&gt;given the importance of Bitcoin.&lt;br/&gt;&lt;br/&gt;So as a random stranger to the project, I would vote against that if I was &lt;br/&gt;allowed to. There really should be *more* discussion here, and splitting the &lt;br/&gt;list up won&amp;#39;t help with that.&lt;br/&gt;&lt;br/&gt;Greetings&lt;br/&gt;-------------- next part --------------&lt;br/&gt;A non-text attachment was scrubbed...&lt;br/&gt;Name: signature.asc&lt;br/&gt;Type: application/pgp-signature&lt;br/&gt;Size: 836 bytes&lt;br/&gt;Desc: This is a digitally signed message part.&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20141019/3bafc443/attachment.sig&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20141019/3bafc443/attachment.sig&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:26:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsztrvly4qw506rmvurqs0veutz0500sl7awmu6n39gf690atlgcrqzyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpscqvfnw</id>
    
      <title type="html">📅 Original date posted:2014-08-22 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsztrvly4qw506rmvurqs0veutz0500sl7awmu6n39gf690atlgcrqzyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpscqvfnw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf908y3f2nwdcwsmlatspy22at7nrtc72z5u774ce3vxvew3rk0gcy8whg5&#39;&gt;nevent1q…whg5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-08-22&lt;br/&gt;📝 Original message:On Tuesday, August 19, 2014 08:02:37 AM Jeff Garzik wrote:&lt;br/&gt;&amp;gt; It would be nice if the issues and git repo for Bitcoin Core were not&lt;br/&gt;&amp;gt; on such a centralized service as github, nice and convenient as it is.&lt;br/&gt;&lt;br/&gt;Assuming there is a problem with that usually is caused by using Git the wrong &lt;br/&gt;way or not knowing its capabilities. Nobody can modify / insert a commit &lt;br/&gt;before a GnuPG signed commit / tag without breaking the signature.&lt;br/&gt;More detail at the bottom at [1], I am sparing you this here because I suspect &lt;br/&gt;you already know it and there is something more important I want to stress:&lt;br/&gt;&lt;br/&gt;Bitcoin has currently 4132 forks on Github. This means that you can get &lt;br/&gt;contributions by pull requests from 4132 developers. That is a HUGE amount, &lt;br/&gt;and you shouldn&amp;#39;t ditch that due to not using all features of git :)&lt;br/&gt;To get a grasp of how much that is: When you search projects with more than &lt;br/&gt;4100 forks, there are only 32 of them!&lt;br/&gt;You are one of the top open source projects, and you should be grateful for &lt;br/&gt;that and keep Github up so the other people can send you pull requests with &lt;br/&gt;their improvements :) Volunteer contributions need to be honored and made as &lt;br/&gt;easy as possible, for people are investing their personal time.&lt;br/&gt;&lt;br/&gt;Greetings and thanks for your work,&lt;br/&gt;	xor, one developer of &lt;a href=&#34;https://freenetproject.org&#34;&gt;https://freenetproject.org&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;[1] If you GPG-sign a commit / tag, you sign its hash, including the hash of &lt;br/&gt;the previous commit. So is a chain of hashes and thus of trust from all &lt;br/&gt;commits up to what is signed. It&amp;#39;s pretty similar to the blockchain actually &lt;br/&gt;:) &lt;br/&gt;So Github cannot modify anything. If they did,  the head of the hash-chain &lt;br/&gt;would change, and thus the signature would break. Git would notify people &lt;br/&gt;about that when they pull. &lt;br/&gt;Of course people can still ignore that warning and let Github rewrite their &lt;br/&gt;Git history. But people who aren&amp;#39;t educated about this shouldn&amp;#39;t be release &lt;br/&gt;managers. They should not even have push access to your main repository, they &lt;br/&gt;should only be sending pull requests. Thats is where the decentralization of &lt;br/&gt;Git is: In the pull-requests. The people who deal with them should verify tag &lt;br/&gt;and possibly even commit signatures carefully, and not accept anything which &lt;br/&gt;is not signed. Also, before deploying a binary, the very same commit which is &lt;br/&gt;going to become a binary has to be given a signed tag by the release manager, &lt;br/&gt;and by everyone who reviews the code. The person who deploys the actual binary &lt;br/&gt;needs to verify that signature.&lt;br/&gt;There is an article which elaborates on some of the ways you have to ensure &lt;br/&gt;Github doesn&amp;#39;t insert malicious code - but please read it with care, some of &lt;br/&gt;its recommendations are bad, especially the part where its about rebasing &lt;br/&gt;because that DOES rewrite history which is what you want to prevent:&lt;br/&gt;&lt;a href=&#34;http://mikegerwitz.com/papers/git-horror-story&#34;&gt;http://mikegerwitz.com/papers/git-horror-story&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;-------------- next part --------------&lt;br/&gt;A non-text attachment was scrubbed...&lt;br/&gt;Name: signature.asc&lt;br/&gt;Type: application/pgp-signature&lt;br/&gt;Size: 836 bytes&lt;br/&gt;Desc: This is a digitally signed message part.&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140822/5f63b114/attachment.sig&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140822/5f63b114/attachment.sig&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:25:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdcgrdzdkzm89mv7eyw2z8rdrg33y9jucxhf60yvx0a4lsfkvjspczyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpsn789en</id>
    
      <title type="html">📅 Original date posted:2014-06-03 📝 Original ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdcgrdzdkzm89mv7eyw2z8rdrg33y9jucxhf60yvx0a4lsfkvjspczyzhhejyw5y9y3al6pawe2alj27y7u56402gswdh9s5r005f4fswpsn789en" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvx9u203y32550xq7jz4ts3krzgf5u98xplt3vk6x0ytmuga466kqzfsdfs&#39;&gt;nevent1q…sdfs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-06-03&lt;br/&gt;📝 Original message:-----BEGIN PGP SIGNED MESSAGE-----&lt;br/&gt;Hash: SHA256&lt;br/&gt;&lt;br/&gt;Hi,&lt;br/&gt;&lt;br/&gt;I thought a lot about the worst case scenario of SHA256d being broken in a way &lt;br/&gt;which could be abused to &lt;br/&gt;A) reduce the work of mining a block by some significant amount&lt;br/&gt;B) reduce the work of mining a block to zero, i.e. allow instant mining.&lt;br/&gt;&lt;br/&gt;Bitcoin needs to be prepared for this as any hash function has a limited &lt;br/&gt;lifetime. Usually crypto stuff is not completely broken instantly by new &lt;br/&gt;attacks but gradually. For example first the attack difficulty is reduced from &lt;br/&gt;2^128 to 2^100, then 2^64, etc.&lt;br/&gt;This would make scenario A more likely.&lt;br/&gt;&lt;br/&gt;Now while B sounds more dangerous, I think in fact A is:&lt;br/&gt;Consider how A would happen in real life: Someone publishes a paper of a &lt;br/&gt;theoretical reduction of SHA256d attacks to 2^96 bit. Mathematicians will &lt;br/&gt;consider this as a serious attack and create a lot of riot.&lt;br/&gt;If no plan is made early enough, as in now, the Bitcoin Core team might then &lt;br/&gt;probably want to just do the easiest approach of replacing the hash function &lt;br/&gt;after a certain block number, i.e. a hard fork.&lt;br/&gt;But what about the Bitcoin miners, those who need to actually accept a change &lt;br/&gt;of mining algorithm which renders their hardware which cost MILLIONS &lt;br/&gt;completely worthless?&lt;br/&gt;Over the years they have gotten used to exponential growth of the Bitcoin &lt;br/&gt;networks hashrate, and therefore exponential devaluation of their mining &lt;br/&gt;hardware. Even if the attack on SHA256d causes a significant growth of &lt;br/&gt;difficulty, the miners will not *believe* that it is an actual attack on SHA256d &lt;br/&gt;- - maybe it is just some new large mining operation?  They are used to this &lt;br/&gt;happening! Why should they believe this and switch to a new hash function &lt;br/&gt;which requires completely new hardware and therefore costs them millions?&lt;br/&gt;They will just keep mining SHA256d. Thats why this is more dangerous, because &lt;br/&gt;changing the hash funciton won&amp;#39;t be accepted by the miners even though it is &lt;br/&gt;broken.&lt;br/&gt;Something smarter needs to be thought of.&lt;br/&gt;&lt;br/&gt;Now I must admit that I am not good at cryptography at all, but I had the &lt;br/&gt;following idea: Use the altcoin concept of having multiple hash functions in a &lt;br/&gt;chain. If SHA256d is broken, it is chained with a new hash function.&lt;br/&gt;Thereby, people who want to mine the new replacement hash function still will &lt;br/&gt;need ASICs which can solve the old SHA proof of work. So existing ASIC owners &lt;br/&gt;can amend their code to do SHA256d using the ASIC, and then the second hash &lt;br/&gt;function using a general purpose CPU.&lt;br/&gt;This would also allow a smooth migration of difficulty - I don&amp;#39;t even know how &lt;br/&gt;difficulty would react with the naive approach of just replacing SHA with &lt;br/&gt;something else: It would probably be an unsolvable problem to define new rules &lt;br/&gt;to make it decrease enough so new blocks can actually be mined by the now &lt;br/&gt;several orders of magnitude slower CPU-only mining community but still be high &lt;br/&gt;enough to be able to deal with the fact that millions of people will try their &lt;br/&gt;luck with mining at the release date.&lt;br/&gt;&lt;br/&gt;While this sounds simple in theory, it might be a lot of work to implement, so &lt;br/&gt;you guys might want to take precautions for it soon :)&lt;br/&gt;&lt;br/&gt;Greetings,&lt;br/&gt;	xor - A Freenet project developer&lt;br/&gt;&lt;br/&gt;-----BEGIN PGP SIGNATURE-----&lt;br/&gt;Version: GnuPG v1.4.14 (GNU/Linux)&lt;br/&gt;&lt;br/&gt;iQIcBAEBCAAGBQJTjU9DAAoJEMtmZ&#43;8tjWt5pNEP/2460eHu7ujrUSxinJXY7&#43;wF&lt;br/&gt;E759/NcpNuakqu4NsS3ndi8lSiVIeixiOWZxPwLYkzC0pgPd5JrK5hdrYewsgreL&lt;br/&gt;Ltkh6LKB4YZLYrV3jm62ZPMTzCopYQ1l872xbN3PJQJoXhEp4fKu99&#43;&#43;LDzVg9Gk&lt;br/&gt;n7rvrk6Iy/nSsZ1IMANpKghbU8/Gtn6ppCJv9rxRE//CZdTso1tTyOXXkEEMTHcV&lt;br/&gt;y/iv6CHXtTXPvOgEgciU0oCPq0NOUKdIAOD//ybcKzncOoHSmwr1rZdreCTH6/Ek&lt;br/&gt;9uwq/HaQnseHPrq9qrIkIKrZDlnjKu7Tqw1BlbyBeCrWdJPCeDJg2kyCXgTvIzFD&lt;br/&gt;oXwZ6r16tb2QPR4ByyO1lZy9G2Pp26thk12BnadnPYTf1rMvsY15BjfUrCU9ppt/&lt;br/&gt;YpFAZSFlXUGOuOBKUznUeO8U1bXJylcTTnyER/cudOpcKR8Jt9l5tfm5LTHCB6Q2&lt;br/&gt;Tjmvsmd0BzwafLEhHD5FHoTZFNVdXWvEUO/w4I/2UWTS7CacbE1qk0rVpsF/4L1K&lt;br/&gt;/oFVnZIUKqsm5mMMb6WTQq&#43;MjP2TF/eAAwm2UtFYmj0FVML9HBNwyiAc5UKwnD4Y&lt;br/&gt;Yq3Pl5QfRobwu6pgT3zO7vK&#43;saOl8sePWbU8Skj41OTEDrJM4QIQGAqs1U8xke8&#43;&lt;br/&gt;YnUYiyzreJ8ofHhNBs4/&lt;br/&gt;=dkuk&lt;br/&gt;-----END PGP SIGNATURE-----
    </content>
    <updated>2023-06-07T15:22:13Z</updated>
  </entry>

</feed>