<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-08-11T11:23:12&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by leon</title>
  <author>
    <name>leon</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1gxdhmu9swqduwhr6zptjy4ya693zp3ql28nemy4hd97kuufyrqdqwe5zfk.rss" />
  <link href="https://nostr.ae/npub1gxdhmu9swqduwhr6zptjy4ya693zp3ql28nemy4hd97kuufyrqdqwe5zfk" />
  <id>https://nostr.ae/npub1gxdhmu9swqduwhr6zptjy4ya693zp3ql28nemy4hd97kuufyrqdqwe5zfk</id>
  <icon>https://blossom.primal.net/669eb7a4748f23dd24290866e92e6e62ceeef3e0bfcbee89bd33ba3694e7b045.jpg</icon>
  <logo>https://blossom.primal.net/669eb7a4748f23dd24290866e92e6e62ceeef3e0bfcbee89bd33ba3694e7b045.jpg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsta2wxmt7v4vsw9ujegw04kcwg6kqqkh7kyr7ar33svk8gdvv8plczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5e4uh9l</id>
    
      <title type="html">obelisk.ar implements post-quantum dms via nostr-wot already ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsta2wxmt7v4vsw9ujegw04kcwg6kqqkh7kyr7ar33svk8gdvv8plczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5e4uh9l" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspw750my876ug9k03dfp4nql8ra6sfsy59gxc0l0dywn9z59lvfks96qgur&#39;&gt;nevent1q…qgur&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;obelisk.ar implements post-quantum dms via nostr-wot already&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://primal.net/e/naddr1qvzqqqr4gupzqsvm0hctquqmcaw85yzhyf2fm5tzyrzp7508nkftw6tadecjgxq6qq38qmmnwskhzatpde682mfdv3khxttfdckk7cn9d35hx6edvdkxjetwwsxx2p45&#34;&gt;https://primal.net/e/naddr1qvzqqqr4gupzqsvm0hctquqmcaw85yzhyf2fm5tzyrzp7508nkftw6tadecjgxq6qq38qmmnwskhzatpde682mfdv3khxttfdckk7cn9d35hx6edvdkxjetwwsxx2p45&lt;/a&gt;
    </content>
    <updated>2026-08-19T15:32:52&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswyyzuutypmv5a8m3up5sgljk7x4hsv6nh9tykcpujw0vt3s2998szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp524fnkt</id>
    
      <title type="html">obelisk.ar DMs are post-quantum encrypted as of this week. keys ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswyyzuutypmv5a8m3up5sgljk7x4hsv6nh9tykcpujw0vt3s2998szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp524fnkt" />
    <content type="html">
      obelisk.ar DMs are post-quantum encrypted as of this week. keys come from the seed phrase you already have (or should create), messages ride inside ordinary NIP-17 gift wrap, and no relay had to change anything&lt;br/&gt;&lt;br/&gt;reading them needs no negotiation: the envelope says what it is. sending needs one cached relay query. for most clients this is an afternoon of work&lt;br/&gt;&lt;br/&gt;it is opt-in today because a Nostr identity is a secp256k1 key and nothing else, with no algorithm field. we already version NIP-44 payloads. the idea is in the protocol, it just has not reached the key&lt;br/&gt;&lt;br/&gt;formats are public drafts. argue with them before a second client ships against them&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://quantakrypto.com/blog/obelisk-first-nostr-client-post-quantum-dms&#34;&gt;https://quantakrypto.com/blog/obelisk-first-nostr-client-post-quantum-dms&lt;/a&gt;&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/naddr1qvzqqqr4gupzqsvm0hctquqmcaw85yzhyf2fm5tzyrzp7508nkftw6tadecjgxq6qy88wumn8ghj7mn0wvhxcmmv9uq3zamnwvaz7tmwdaehgu3wwa5kuef0qq38qmmnwskhzatpde682mfdv3khxttfdckk7cn9d35hx6edvdkxjetwwsg6v2j5&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;naddr1qv…v2j5&lt;/a&gt;&lt;/span&gt;  &lt;/div&gt; &lt;p&gt;Obelisk direct messages are post-quantum encrypted as of this week. Not a demo, not a testnet, not a branch. If you and the person you are writing to have both published post-quantum keys, the message that leaves your client is protected against an adversary who records it today and breaks secp256k1 in fifteen years.&lt;/p&gt;

&lt;p&gt;It took no relay changes, no protocol fork, and no new seed phrase for anyone. That is the interesting part, and it is why I think the rest of the ecosystem can follow quickly if we decide to.&lt;/p&gt;

&lt;h3 id=&#34;what-is-running-2&#34;&gt;&lt;strong&gt;What is running&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;Post-quantum keys come from the seed phrase you already have. They are derived from the BIP-39 seed as siblings of your secp256k1 key, never from the key itself. That direction is the whole security property: if the post-quantum key could be computed from your Nostr private key, then Shor recovers your private key from your published pubkey, runs the same derivation, and takes the post-quantum key with it. Circular, and worth nothing.&lt;/p&gt;

&lt;p&gt;Because it cannot be derived, it gets announced. You publish a &lt;code&gt;kind:10203&lt;/code&gt; event carrying an ML-KEM-1024 encryption key and an ML-DSA-87 signing key, signed by your ordinary Nostr key, with a proof of possession binding all three together. Anyone writing to you reads it off a relay.&lt;/p&gt;

&lt;p&gt;The message is an ordinary NIP-17 gift wrap. Inside the seal, the payload combines an ML-KEM shared secret with the normal NIP-44 conversation key through HKDF. Hybrid, never replacement: if ML-KEM turns out to be broken tomorrow you are back to exactly the NIP-44 you have today, which is where every client already is. There is no version of this where you end up worse off.&lt;/p&gt;

&lt;p&gt;Cost is about 3 KB per message and roughly a millisecond to encrypt. Clients that have not implemented it are completely unaffected, because the new part sits inside a layer they could not read anyway.&lt;/p&gt;

&lt;h3 id=&#34;the-one-gap-worth-closing-2&#34;&gt;&lt;strong&gt;The one gap worth closing&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;Right now this is opt-in. You publish keys, the other person publishes keys, and until both happen nothing improves.&lt;/p&gt;

&lt;p&gt;I do not think that should be the end state, and I want to be straight about why it is the current one. A Nostr identity is a secp256k1 keypair and nothing else. Your npub is the public half of one specific key on one specific curve. There is no algorithm identifier beside it and no key set, so the protocol cannot express &amp;#34;this identity uses algorithm X&amp;#34;. A sender cannot look at an npub and learn anything about what it can receive, which means somebody has to ask, and asking is what makes it opt-in.&lt;/p&gt;

&lt;p&gt;The encouraging part is how narrow that gap is. We already solved the same problem one layer up: NIP-44 is versioned, its payloads lead with a version byte precisely so the scheme can change without breaking readers. The idea is already in the protocol and already accepted. It just has not reached the key yet.&lt;/p&gt;

&lt;p&gt;That is a much better position than it sounds. This is not a missing concept, it is a missing field.&lt;/p&gt;

&lt;h3 id=&#34;why-incremental-is-the-right-move-not-a-compromise-2&#34;&gt;&lt;strong&gt;Why incremental is the right move, not a compromise&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;The complete fix is an identity that declares its own key set, with algorithm identifiers and rotation. I want that, and I think it is where we end up.&lt;/p&gt;

&lt;p&gt;It is also a change that reaches signatures, and an ML-DSA-87 signature is 4,627 bytes on every event. That is a relay storage and bandwidth question, so relay operators have to be at the table alongside client developers. It needs a NIP, review, several implementations, and a transition that strands nobody. That is a real conversation and it deserves the time it takes.&lt;/p&gt;

&lt;p&gt;Meanwhile confidentiality is the half of the problem with an expiry date. Protection against a future break can only be applied before a message is sent, never afterwards, so every day we wait is traffic that no later fix can reach.&lt;/p&gt;

&lt;p&gt;The two things run on different clocks. That is the whole argument for doing both rather than choosing.&lt;/p&gt;

&lt;p&gt;And the incremental step costs us nothing later, which is the test I would apply to any interim measure. The keys come from the seed people already have. No new identity, no second phrase, nothing extra in a backup. When a proper key-set declaration lands, the same seed derives whatever it needs, and for the person using it migration is a click with their history and identity intact.&lt;/p&gt;

&lt;p&gt;If we secure messages today, that is a win. If tomorrow we migrate, it is a click. Those are not in tension, and nothing here has to be undone.&lt;/p&gt;

&lt;h3 id=&#34;what-migrating-actually-takes-2&#34;&gt;&lt;strong&gt;What migrating actually takes&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;This is the part I would like people to look at, because it is much smaller than it sounds.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you build a client.&lt;/strong&gt; Reading post-quantum messages requires no negotiation and no flag: the envelope leads with a version byte and an algorithm byte, so you inspect the payload and route it. Sending needs the recipient&amp;#39;s key from their &lt;code&gt;kind:10203&lt;/code&gt;, which is one relay query you can cache for hours. The reference implementation is on npm as &lt;code&gt;@nostr-wot/pq&lt;/code&gt; and the wire format is a public draft. Realistically this is an afternoon, not a quarter.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you run a relay.&lt;/strong&gt; Nothing changes for messages, since post-quantum payloads are ordinary &lt;code&gt;kind:1059&lt;/code&gt; gift wraps of a slightly unusual size. The one thing to check is the attestation: &lt;code&gt;kind:10203&lt;/code&gt; is about 12 KB, and one relay in our four-relay test set rejects it on size. If your limits would drop it, users on your relay silently cannot be reached post-quantum, and neither they nor the sender find out why.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you maintain a signer.&lt;/strong&gt; Two things. Derive the keys as siblings from the seed, never from the private key. And advertise what you accept, so a client can ask instead of guessing: a signer that silently ignores a post-quantum request and returns ordinary ciphertext leads to clients showing protection badges over unprotected messages, which is worse than not supporting it at all.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you use Nostr.&lt;/strong&gt; Publish your keys. It is one button in the Nostr WoT extension and takes about five seconds, and it is the only step that has to happen per person rather than per project.&lt;/p&gt;

&lt;h3 id=&#34;what-i-am-asking-for-2&#34;&gt;&lt;strong&gt;What I am asking for&lt;/strong&gt;&lt;/h3&gt;

&lt;p&gt;The formats are four public drafts in the extension repo under &lt;code&gt;nips/&lt;/code&gt;: key derivation, the &lt;code&gt;kind:10203&lt;/code&gt; attestation, the hybrid NIP-44 envelope, and the signer capability marker. None has a NIP number. They are drafts so that someone can tell me the wire format is wrong before a second client ships against it, and I would genuinely rather hear that now.&lt;/p&gt;

&lt;p&gt;Three things help more than agreement:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Read the envelope draft and argue with it. Changing it is cheap today and expensive once anyone else has shipped.&lt;/p&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;If you run a relay, tell me whether 12 KB attestations pass. I have four data points and that is not enough to design around.&lt;/p&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;If you are working on identity and key sets, I would rather this attestation be replaced by your work than persist beside it. Tell me what shape to build toward and I will build toward it.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The outcome I want to avoid is a Nostr where post-quantum protection is five incompatible bolt-ons, each solved privately. That is the default result if we all move separately, and it is avoidable if the identity layer moves before the workarounds harden.&lt;/p&gt;

&lt;p&gt;We can protect messages this month and still design the right thing properly. I would like to do both.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Obelisk&lt;/strong&gt;: &lt;a href=&#34;https://obelisk.ar&#34;&gt;https://obelisk.ar&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;&lt;strong&gt;Drafts&lt;/strong&gt;: &lt;a href=&#34;https://github.com/nostr-wot/nostr-wot-extension/tree/main/nips&#34;&gt;https://github.com/nostr-wot/nostr-wot-extension/tree/main/nips&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;&lt;strong&gt;Longer write-up&lt;/strong&gt;: &lt;a href=&#34;https://nostr-wot.com/blog/opt-in-quantum-resistant-direct-messages&#34;&gt;https://nostr-wot.com/blog/opt-in-quantum-resistant-direct-messages&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;

&lt;li&gt;&lt;p&gt;&lt;strong&gt;QuantaKrypto&lt;/strong&gt;: &lt;a href=&#34;https://quantakrypto.com/blog/obelisk-first-nostr-client-post-quantum-dms&#34;&gt;https://quantakrypto.com/blog/obelisk-first-nostr-client-post-quantum-dms&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
 &lt;/blockquote&gt;
    </content>
    <updated>2026-08-19T15:31:14&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvphue0h8z4vygq0w3peytgqxr6k03zckvlcqtx3yzk4du955magqzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp566tqth</id>
    
      <title type="html">somebody is collecting your encrypted messages. storing them to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvphue0h8z4vygq0w3peytgqxr6k03zckvlcqtx3yzk4du955magqzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp566tqth" />
    <content type="html">
      somebody is collecting your encrypted messages. storing them to read them 10 years from now. that&amp;#39;s the whole attack. wake up&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/naddr1qvzqqqr4gupzqsvm0hctquqmcaw85yzhyf2fm5tzyrzp7508nkftw6tadecjgxq6qy88wumn8ghj7mn0wvhxcmmv9uq32amnwvaz7tmjv4kxz7fwv3sk6atn9e5k7tcqfphx7um5wgkk2mnrwfuhqar9vskkgmtn94shyefdv9k8yetpv3uj6urvv95kuar90p6z6argv4uj66n4wd6z66rpwejkuapdvfjk2m3dwfjkzepd09jhg59wum8&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;naddr1qv…wum8&lt;/a&gt;&lt;/span&gt;  &lt;/div&gt; 
&lt;blockquote&gt;
&lt;p&gt;Read first: &lt;a href=&#34;https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later&#34;&gt;https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;p&gt;&lt;strong&gt;Someone is copying your encrypted messages right now. Not breaking them. Copying them.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is the whole attack. It does not need a quantum computer today. It needs a hard drive today and a quantum computer eventually. Every NIP-44 message you have ever sent, sitting on relays, publicly retrievable, encrypted with a scheme that will not hold. The people doing this are not waiting for permission and they are not in a hurry.&lt;/p&gt;

&lt;p&gt;It has a name, &amp;#34;harvest now decrypt later&amp;#34;, and the fact that it has a name should tell you how long people have known.&lt;/p&gt;

&lt;h2 id=&#34;why-nostr-specifically-4&#34;&gt;&lt;strong&gt;Why Nostr specifically&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;Your public key is published to every relay you touch. That is not a flaw, it is the entire design. It is how anyone verifies your notes.&lt;/p&gt;

&lt;p&gt;It is also the input to the attack. Shor&amp;#39;s algorithm recovers a private key from a public key. Most systems at least make an adversary work to obtain the public key first. Nostr hands it over, to everyone, permanently, by default.&lt;/p&gt;

&lt;p&gt;NIP-44 derives its conversation key from an ECDH shared secret between two secp256k1 keys. Recover either private key and you recover the conversation key. Recover the conversation key and you decrypt every message in that conversation, all the way back to the first one.&lt;/p&gt;

&lt;p&gt;There is no forward secrecy in that construction to save you. There is no key rotation that helps, because the messages were already captured under the old key. There is nothing you can publish tomorrow that protects what you sent yesterday.&lt;/p&gt;

&lt;h2 id=&#34;the-part-i-cannot-get-people-to-hear-4&#34;&gt;&lt;strong&gt;The part I cannot get people to hear&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;When I raise this, the answer is almost always some version of &amp;#34;quantum computers aren&amp;#39;t here yet.&amp;#34;&lt;/p&gt;

&lt;p&gt;That is not a rebuttal. That is the premise.&lt;/p&gt;

&lt;p&gt;The deadline is not when the machine arrives. The deadline is &lt;strong&gt;how long your message needs to stay secret&lt;/strong&gt;, counted backwards from when the machine arrives. If you send something today that would still embarrass you, endanger you, or cost you money in twelve years, and the machine shows up in ten, you already missed it. You missed it at the moment you hit send.&lt;/p&gt;

&lt;p&gt;So the question is not &amp;#34;when is Q-day&amp;#34;. The question is: what did you say last week that still matters in 2036?&lt;/p&gt;

&lt;p&gt;For most people the honest answer is &amp;#34;some of it&amp;#34;. Not all of it. Some of it. Which is enough.&lt;/p&gt;

&lt;p&gt;And it is not only your judgement that is at stake. Every person who messaged you did so believing the thing on the label. They looked at a lock icon, or a client that said encrypted, and they decided what to tell you based on that. If the encryption does not hold, you did not just lose your own privacy. You lost theirs, on their behalf, without asking them.&lt;/p&gt;

&lt;p&gt;That is the part that actually bothers me. My own messages I can be philosophical about. I cannot be philosophical about someone else&amp;#39;s.&lt;/p&gt;

&lt;h2 id=&#34;why-this-has-stayed-unfixed-for-a-year-4&#34;&gt;&lt;strong&gt;Why this has stayed unfixed for a year&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;It is not that nobody noticed. Paul Miller opened the issue in July 2025. fiatjaf, Vitor Pamplona and Mike Dilger have all been in that thread. These are not people who miss things.&lt;/p&gt;

&lt;p&gt;It stalled on something real. The obvious fix is to derive a post-quantum key from your Nostr private key:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;pq_key = KDF(nsec)
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;That is circular and it buys you nothing. An adversary recovers your nsec from your npub, runs the same KDF, and now has your post-quantum key as well. You added computation and no security.&lt;/p&gt;

&lt;p&gt;That objection killed every proposal. Working prototypes existed. A specification did not.&lt;/p&gt;

&lt;h2 id=&#34;the-fix-is-a-change-of-shape-not-of-algorithm-4&#34;&gt;&lt;strong&gt;The fix is a change of shape, not of algorithm&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;Do not derive from the nsec. Derive from the seed.&lt;/p&gt;

&lt;p&gt;NIP-06 already takes you from a BIP-39 mnemonic to your Nostr key at &lt;code&gt;m/44&amp;#39;/1237&amp;#39;/0&amp;#39;/0/0&lt;/code&gt;, through HMAC-SHA512, which is one-way. Given the resulting private key you cannot walk back to the seed.&lt;/p&gt;

&lt;p&gt;So take that same seed and expand it a second time, with domain separation, into post-quantum keys:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;kem_seed = HKDF-SHA256(seed, info = &amp;#34;nip-pqc/v1/ml-kem-1024/0&amp;#34;, 64)
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;&lt;code&gt;dsa_seed = HKDF-SHA256(seed, info = &amp;#34;nip-pqc/v1/ml-dsa-87/0&amp;#34;, 32)&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Both keys are children of the seed. Neither is a child of the other. They are siblings.&lt;/p&gt;

&lt;p&gt;An adversary who breaks secp256k1 and recovers your Nostr private key learns nothing about the seed, because that would mean inverting HMAC-SHA512. So they learn nothing about your post-quantum keys. Messages encrypted to your ML-KEM key stay confidential permanently, even after your identity key is gone.&lt;/p&gt;

&lt;p&gt;And your words never change. The same mnemonic restores your Nostr key and both post-quantum keys. There is no new backup, no re-enrolment, no &amp;#34;generate a fresh identity and rebuild your social graph&amp;#34;, which is the migration nobody ever completes.&lt;/p&gt;

&lt;h2 id=&#34;the-rest-of-the-design-briefly-4&#34;&gt;&lt;strong&gt;The rest of the design, briefly&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Keys go in a &lt;/strong&gt;&lt;code&gt;kind:10203&lt;/code&gt;&lt;strong&gt; replaceable event&lt;/strong&gt;, not in your kind:0 profile. Clients rebuild profile JSON from the fields they know about and republish it, so the first time you changed your display name in a client that had not implemented this, your post-quantum key would vanish silently. You would still think you were reachable. Senders would quietly fall back to classic encryption. A security feature that fails silently is worse than one that is not there.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The ML-DSA key counter-signs a proof of possession&lt;/strong&gt; binding your npub to both public keys. A secp256k1 signature proves you published those bytes. It does not prove you hold the matching post-quantum secrets. Without the counter-signature you could advertise a key you cannot decrypt with, by bug or on purpose, and people would send you messages nobody can read.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The post-quantum secret is combined with the existing NIP-44 conversation key&lt;/strong&gt; through HKDF. Never used alone. Lattice schemes are young and they do break, HAWK fell in July. A flaw in a new scheme must not be able to make Nostr messaging worse than it is today.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Everything rides inside NIP-59 gift wrap, unchanged.&lt;/strong&gt; The outer layers stay secp256k1, so these messages cross today&amp;#39;s relay network with no modifications, and clients that know nothing about any of this are unaffected. No relay changes. No flag day.&lt;/p&gt;

&lt;h2 id=&#34;it-is-not-a-proposal-it-is-running-4&#34;&gt;&lt;strong&gt;It is not a proposal, it is running&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;I am tired of design documents, so we shipped it.&lt;/p&gt;

&lt;p&gt;There is a demo at &lt;a href=&#34;http://nostr-wot.com/pqc/chat&#34;&gt;&lt;strong&gt;nostr-wot.com/pqc/chat&lt;/strong&gt;&lt;/a&gt; that generates two identities in your browser, publishes their attestations to damus, &lt;a href=&#34;http://nos.lol&#34;&gt;nos.lol&lt;/a&gt;, primal and snort, reads each other&amp;#39;s ML-KEM keys back off those relays, and exchanges real post-quantum gift wraps.&lt;/p&gt;

&lt;p&gt;Nothing is simulated. A message only appears once a relay hands it back and it decrypts, and each one names the relay that served it. You can take any event apart layer by layer, the kind:1059 wrap a relay actually stores, the kind:13 seal inside it, the envelope with a byte map, and the kind:14 rumor at the centre. Layers your browser holds no key for are marked sealed rather than guessed at, so you can switch accounts and see the same event from a different vantage.&lt;/p&gt;

&lt;p&gt;Publishing it for real also taught us something estimating would not have. One of those four relays rejects the 12,200-byte attestation outright, on size. Three accept it, so discovery still works, but that is a real constraint and it is in the spec now rather than in someone&amp;#39;s incident report next year.&lt;/p&gt;

&lt;p&gt;The browser extension is released. The library is on npm as &lt;code&gt;@nostr-wot/pq&lt;/code&gt;. New identities default to 24 words, because 12 words carry 128 bits of entropy and that would make your seed the weak link instead of the lattice. That change costs nothing today and cannot be applied retroactively, which is exactly why it has to happen now.&lt;/p&gt;

&lt;h2 id=&#34;what-this-does-not-do-4&#34;&gt;&lt;strong&gt;What this does not do&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;An adversary with a quantum computer can still sign events as you. Events are still signed with secp256k1. They could also publish a replacement attestation carrying their own keys and intercept your future messages.&lt;/p&gt;

&lt;p&gt;This protects past messages, permanently. It does not protect future messages against someone who has already broken secp256k1.&lt;/p&gt;

&lt;p&gt;Signature migration is a separate and harder problem. An ML-DSA-87 signature is 4,627 bytes, roughly 6.2 KB base64, on every event. That is a several-fold increase in relay storage and bandwidth for a short note, and it is a decision that needs relay operators at the table, not something a client ships unilaterally.&lt;/p&gt;

&lt;p&gt;Publishing the ML-DSA verification key now is what keeps that door open. The commitment exists, signed by your classic key, from before the break. So when signatures eventually migrate, nobody needs a new seed phrase.&lt;/p&gt;

&lt;p&gt;I would rather say all of that plainly than let the claim inflate. If someone tells you their post-quantum scheme fixes everything, they have not understood which half of the problem is fixable after the fact.&lt;/p&gt;

&lt;h2 id=&#34;what-to-do-4&#34;&gt;&lt;strong&gt;What to do&lt;/strong&gt;&lt;/h2&gt;

&lt;p&gt;If you hold 24 words, you can be post-quantum today. One button in the Nostr WoT extension derives the keys and publishes the attestation. Nothing new to back up.&lt;/p&gt;

&lt;p&gt;If you hold a bare nsec, the spec covers you too, with standalone keys marked &lt;code&gt;origin: independent&lt;/code&gt;. They need their own backup, which is worse than derived keys and enormously better than nothing.&lt;/p&gt;

&lt;p&gt;If you are building a client, the reference implementation is open and the NIP is drafted. Take it apart. Tell me what is wrong with it. I would much rather be corrected now than have this be right and ignored.&lt;/p&gt;

&lt;p&gt;And if you do nothing else: stop treating this as a 2035 problem. The messages that will be read are the ones being sent this week.&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;em&gt;Written by the Nostr WoT and QuantaKrypto teams.&lt;/em&gt; &lt;em&gt;Demo: &lt;/em&gt;&lt;a href=&#34;http://nostr-wot.com/pqc/chat&#34;&gt;&lt;em&gt;nostr-wot.com/pqc/chat&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Check whether someone supports it: &lt;/em&gt;&lt;a href=&#34;http://nostr-wot.com/pqc&#34;&gt;&lt;em&gt;nostr-wot.com/pqc&lt;/em&gt;&lt;/a&gt; &lt;em&gt;Full write-up: quantakrypto.com/blog/post-quantum-identity-keys-for-nostr&lt;/em&gt;&lt;/p&gt;
 &lt;/blockquote&gt;
    </content>
    <updated>2026-08-11T11:22:09&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs23aq2vpe7ddjgyjdx5v5y9amjr9yacrcjh2udf7tgydzzqu925eczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5xtrkgf</id>
    
      <title type="html">just launched Nostr Widgets, server-rendered svg widgets for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs23aq2vpe7ddjgyjdx5v5y9amjr9yacrcjh2udf7tgydzzqu925eczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5xtrkgf" />
    <content type="html">
      just launched Nostr Widgets, server-rendered svg widgets for Nostr profiles, follows, and feeds to embed with &amp;lt;a&amp;gt;&amp;lt;img&amp;gt; in static pages, thoughts?&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/nostr-wot/nostr-widgets&#34;&gt;https://github.com/nostr-wot/nostr-widgets&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://npub1gxdhmu9swqduwhr6zptjy4ya693zp3ql28nemy4hd97kuufyrqdqwe5zfk.blossom.band/d4bfd802535a076b9fc3d44f31c65b9bb8420a4e4fa58032fb923d46dc0df9b2.png&#34;&gt; 
    </content>
    <updated>2026-04-28T03:45:12&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstmq4c2f0syhnxwk67pngd0y9r8njm2nc0ew3wdzyu6ay9ulw9ktczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5rnm04f</id>
    
      <title type="html">flights near the edges (Sydney loop) are longer because planes ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstmq4c2f0syhnxwk67pngd0y9r8njm2nc0ew3wdzyu6ay9ulw9ktczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5rnm04f" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp5y44tm8xz6s3ncpve2sa0wezpm82c08exre2f7j6ylvavcmyfxqdszste&#39;&gt;nevent1q…zste&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;flights near the edges (Sydney loop) are longer because planes slow down as they approach the abyss, pilots instinctively ease off the throttle. London-NY-Tokyo stays central, full speed ahead&lt;br/&gt;&lt;br/&gt;your flight time data doesn&amp;#39;t prove roundness, it proves 𝐩𝐢𝐥𝐨𝐭 𝐚𝐧𝐱𝐢𝐞𝐭𝐲 𝐠𝐫𝐚𝐝𝐢𝐞𝐧𝐭. the closer to the edge, the slower they fly
    </content>
    <updated>2026-04-22T19:57:37&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfgsz56ylvkw6cp44yy27nzfvrpugr82u29grsfrrltmecuy97ceszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp54kfze8</id>
    
      <title type="html">set up your ligthning wallet with 2 clicks ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfgsz56ylvkw6cp44yy27nzfvrpugr82u29grsfrrltmecuy97ceszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp54kfze8" />
    <content type="html">
      set up your ligthning wallet with 2 clicks&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://nostr-wot.com/guides/lightning-address&#34;&gt;https://nostr-wot.com/guides/lightning-address&lt;/a&gt;
    </content>
    <updated>2026-04-15T16:20:21&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8cwv7687drrc7sahxdlckhkw60uzl0xn7kupm4475x4nraxycdagzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5nuysd6</id>
    
      <title type="html">thanks for the heads up! just fixed the lnbits service ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8cwv7687drrc7sahxdlckhkw60uzl0xn7kupm4475x4nraxycdagzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5nuysd6" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyv2drnmyrw2vr6yx4jx8vf0ssfw8e97vdna247cp7kyul04zmh5cpz3mhxue69uhhyetvv9ujuerpd46hxtnfduxk8u92&#39;&gt;nevent1q…8u92&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;thanks for the heads up! just fixed the lnbits service 🌱🍄🐳
    </content>
    <updated>2026-03-15T02:30:30&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswc8vmz6mcqg58ssv7xhvm33m7wyvn5v0zk495yvt2wgcwyhxu73szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5e53t7p</id>
    
      <title type="html">you got me, gonna run in nostrito soon 🫣</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswc8vmz6mcqg58ssv7xhvm33m7wyvn5v0zk495yvt2wgcwyhxu73szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5e53t7p" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg3cdy7j7349nhra8evxmxmygl04u44g8uenysr30v3xgtmjnqmmqpz9mhxue69uhkummnw3ezumrpdejz794vp7j&#39;&gt;nevent1q…vp7j&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;you got me, gonna run in nostrito soon 🫣
    </content>
    <updated>2026-03-14T21:54:49&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0t75k7mlxsp6avmnuhzfkxx9nyfk3ckmy3kmq2uejz0ws7s4kwrszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5556qjd</id>
    
      <title type="html">for sure, that&amp;#39;s why i am participating in all the meetings! ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0t75k7mlxsp6avmnuhzfkxx9nyfk3ckmy3kmq2uejz0ws7s4kwrszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5556qjd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs82nr5ppl884mq46skzpqr7kw8mrg8rpe462y0uenhhsgjmncamqcpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhg0l7jc5&#39;&gt;nevent1q…7jc5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;for sure, that&amp;#39;s why i am participating in all the meetings!&lt;br/&gt;&lt;br/&gt;it is designed to be fully integrated from day 0, and not to compete, but to enhance it&lt;br/&gt;&lt;br/&gt;i am sure a lot of people is building from different directions, and i am opened to listen and learn from all of them&lt;br/&gt;&lt;br/&gt;i called it protocol because platforms can architecturally participate of several protocols: bitcoin &#43; lightning network &#43; nostr &#43; gozzip. furthermore, it can also be implemented in other decentralized social network initiatives equally
    </content>
    <updated>2026-03-11T18:49:38&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0q6fe9k8zuq0wp862507fjdf69hv32jgx8rdkcqqlu5vq7rn28gqzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5fe5gtw</id>
    
      <title type="html">hey! for some reason i can&amp;#39;t get a Signal account with a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0q6fe9k8zuq0wp862507fjdf69hv32jgx8rdkcqqlu5vq7rn28gqzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5fe5gtw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs9pger4sh2c80qlehhzg9w3jj5856zsttgv5lw8n3djug44p2x2lqpz9mhxue69uhkummnw3eryvfwvdhk6ue9ccq&#39;&gt;nevent1q…9ccq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;hey! for some reason i can&amp;#39;t get a Signal account with a Vietnamese number. i haven&amp;#39;t had time to catch up with that yet&lt;br/&gt;&lt;br/&gt;your approach is interesting, to find a way to vouch for relays and a public way to access them based on performance parameters such us latency or availability, geographic area, reliability, spam detection and so on, and query them through a service like purplepag.es would be great. i think that&amp;#39;s not my line of work, but probably &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nprofile1qyg8wumn8ghj7mn0wd68ytnhd9hx2qg5waehxw309aex2mrp0yhxgctdw4eju6t0qqsd7ele5ljpzft5tjl84naae5pkj9uqcepa77adwr6ayyy0948uyqqrs0j5w&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;ManiMe&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;nprofile…0j5w&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; could think of something&lt;br/&gt;&lt;br/&gt;what i am focusing now is on how to achieve Nostr&amp;#39;s original promise: &amp;#34;shift the paradigm of dumb client/smart server to smart client/dumb server&amp;#34;, or rather &amp;#34;smart client &amp;amp; smart server&amp;#34;&lt;br/&gt;&lt;br/&gt;i have the intuition that we can use our WoT as infrastructure to store and retrieve information, rather than using only relays. Nostr exploration has given us tools and space to understand what works and what not, and i&amp;#39;ve come to realize that what we thought was fixed and objective, can be dynamic and subjective, just like life itself&lt;br/&gt;&lt;br/&gt;relays are amazing as a boostrapping mechanism, discovery, specialized services, curated content, connect to other peers when no other available method, but, users SHOULD define what they want to see or not, and that information shouldn&amp;#39;t be public, should be private. what i consume or not by no means should be of common knowledge or arbitrarily served. gatekeeping and surveillance surface can be reduced&lt;br/&gt;&lt;br/&gt;i&amp;#39;ve written a whitepaper that introduces a decentralized trust-weighted storage and retrieval system that can be built alongside Nostr and work in parallel to relays. i&amp;#39;d appreciate your honest feedback: &lt;a href=&#34;https://github.com/gozzip-protocol/gozzip&#34;&gt;https://github.com/gozzip-protocol/gozzip&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;
    </content>
    <updated>2026-03-11T15:28:41&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgsaq8f99ywrm3qlr3350yl5f2l4vwhx3z5c74j32543my9mpdfmszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5snsfuh</id>
    
      <title type="html">hey @nprofile…tz23 . i agree with you, but instead of routing ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgsaq8f99ywrm3qlr3350yl5f2l4vwhx3z5c74j32543my9mpdfmszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5snsfuh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswlgad6rc9v8qs43ax5xdhc30lfux8tlvgkfk4j3f76qmurqv5mrsppemhxue69uhkummn9ekx7mp0z0x0e3&#39;&gt;nevent1q…x0e3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;hey &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nprofile1qy88wumn8ghj7mn0wvhxcmmv9uq3xamnwvaz7tmwdaehgu3wddn8stnxwghszymhwden5te0w3jk6upwd9exjueww3hj7qpq7n2m7v30w732zh0uded9ql3mvaws3t6306j0avtvrxjz7lay2n8q8jtz23&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;xte&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;nprofile…tz23&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; . i agree with you, but instead of routing content through random peers, we should use our web of trust. content should be within the people that consumes it the most.&lt;br/&gt;&lt;br/&gt;i wrote a paper about it: &lt;a href=&#34;https://github.com/gozzip-protocol/gozzip&#34;&gt;https://github.com/gozzip-protocol/gozzip&lt;/a&gt;
    </content>
    <updated>2026-03-10T08:30:17&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspnhjasg603l34u4s3pefn7g8jt549nzkdgee8dh48unakpsr9ezczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp58pw4ya</id>
    
      <title type="html">pretty clear breakdown, core argument is strong. relay-based ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspnhjasg603l34u4s3pefn7g8jt549nzkdgee8dh48unakpsr9ezczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp58pw4ya" />
    <content type="html">
      In reply to &lt;a href=&#39;/naddr1qqyrvenrvv6rqcnxqgsrhuxx8l9ex335q7he0f09aej04zpazpl0ne2cgukyawd24mayt8grqsqqqa28ln2yvf&#39;&gt;naddr1qq…2yvf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;pretty clear breakdown, core argument is strong. relay-based filtering is the right structural incentive. the &amp;#34;tragedy of the commons&amp;#34; point is an angle that i had hard to imagine: if filtering is purely local, you&amp;#39;re offloading the mess onto everyone visiting your threads. relay selection as social responsibility makes sense&lt;br/&gt;&lt;br/&gt;that said, want to push on something: what happens if we take the relay-filtering model seriously but ask what a &amp;#34;relay&amp;#34; could actually be?&lt;br/&gt;&lt;br/&gt;right now clients are dumb readers, relays are smart filters. users pick relays with good policies, system works because operators have infrastructure and incentives to filter well. pyramid, pow.relays.land, paid relays, all proof this works today&lt;br/&gt;&lt;br/&gt;but theres a gap. relay operators are a dependency surface, they decide whats stored, for how long, what rules apply. even the best-intentioned operator is a single point of policy. if inbox.yakihonne.com changes its algo or goes offline, every user with it as a read relay is affected&lt;br/&gt;&lt;br/&gt;part of why this felt inevitable is that clients used to be genuinely constrained. storage expensive, bandwidth metered, battery a real concern. making clients dumb made sense. but that assumption is aging, phones today have hundreds of gigs, always-on connections, processors that would&amp;#39;ve been server-grade not long ago. the gap between client and server is narrowing, even if the protocol still treats them as categorically diferent&lt;br/&gt;&lt;br/&gt;what if some clients started behaving more like relays? not replacing what you describe, complementing it. a client that forms bilateral storage agreements with wot peers, i store yours you store mine, with roughly matched volumes so neither side is freeloading. both sides have skin in the game which is what makes it stable, if you stop holding up your end i stop holding up mine and we both lose a storage partner&lt;br/&gt;&lt;br/&gt;the filtering part comes almost for free. content only propagates within a trust boundary, say 2-hop follows, so spam from throwaway keys never reaches you. not because a relay filtered it but because nobody in your social graph stored or forwarded it. same wot principle pyramid uses, distributed across participants instead of centralized in an operator&lt;br/&gt;&lt;br/&gt;the part that makes it not just a nice idea is how you actually find stuff without a relay index. you&amp;#39;d want something like a tiered approach, check local storage first, then try known peers who responded fast before, then fan out a blinded request through your wot if needed, and only hit traditional relays as a last resort. relays become a fallback layer rather than the primary path, which is basically embedding your model as a component&lt;br/&gt;&lt;br/&gt;the question is wether both models coexist and reinforce each other. relays handle filtering and inbox routing (works today, should be default), wot-based peer storage adds an availability layer and alternative discovery path that doesnt depend on any single operator. periodic challenge-response checks between partners keep the storage honest without needing anything as heavy as proof of work or staking&lt;br/&gt;&lt;br/&gt;curious if you see something structurally incompatible about the two coexisting, or if you thinkk the relay model already covers this ground
    </content>
    <updated>2026-03-09T18:22:57&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqsfp3e44s3r8l9zy5kx8jcftmqlczlgjr3cgcdg5cjms0uem975qzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5aw5jmu</id>
    
      <title type="html">irony: censored in nostr-protocol github 😇 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqsfp3e44s3r8l9zy5kx8jcftmqlczlgjr3cgcdg5cjms0uem975qzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5aw5jmu" />
    <content type="html">
      irony: censored in nostr-protocol github 😇 &lt;br/&gt; &lt;br/&gt; &lt;img src=&#34;https://blossom.primal.net/927678f028eb2b6489d0f269fa179bbc25b314f4b2a5bf20cf742c03dfab729b.png&#34;&gt;  
    </content>
    <updated>2026-03-08T00:59:21&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdh05qhnpzyp74wjvz36x45xcl3mx2hd5evvlwlrvptq6wr2454rgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5k6eeva</id>
    
      <title type="html">haha! nice set up! if you read from your phone, you don&amp;#39;t ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdh05qhnpzyp74wjvz36x45xcl3mx2hd5evvlwlrvptq6wr2454rgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5k6eeva" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0j79mq9jusru5cxkd6eqwh6usfpu982qm8mzf62mztkxprnty7gq5qpyhx&#39;&gt;nevent1q…pyhx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;haha! nice set up!&lt;br/&gt;&lt;br/&gt;if you read from your phone, you don&amp;#39;t need much light. try this paper:&lt;br/&gt;&lt;a href=&#34;https://github.com/gozzip-protocol/gozzip&#34;&gt;https://github.com/gozzip-protocol/gozzip&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;an additional layer to nostr for decentralized storage and retrieval. i think your ongoing browser nostr effort could use it!
    </content>
    <updated>2026-03-07T23:45:05&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfh26sffcemp9k2drrg78jcme3gn3uyhfqquhr3tsk33en059smzszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp55czmlf</id>
    
      <title type="html">i don&amp;#39;t know if you made it on purpose, but it shows you ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfh26sffcemp9k2drrg78jcme3gn3uyhfqquhr3tsk33en059smzszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp55czmlf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsz30cymp8s25qusq2ujh3a4j7anknckl3xeekvju4ezpl2v09m4hc4954vw&#39;&gt;nevent1q…54vw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;i don&amp;#39;t know if you made it on purpose, but it shows you still write your own messages hahah!
    </content>
    <updated>2026-02-27T17:22:51&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr6yn32zz27lutuxchlkycugrp5x9mwttand8hdr89u8apqk06khczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5y20dd2</id>
    
      <title type="html">link is wrong! can you check?</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr6yn32zz27lutuxchlkycugrp5x9mwttand8hdr89u8apqk06khczypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5y20dd2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswq9tqpcm5z2u5ydcll8rj9gk9marn93xgqr6wyxheun94sk5c4gssye7hz&#39;&gt;nevent1q…e7hz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;link is wrong! can you check?
    </content>
    <updated>2026-02-27T17:13:19&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd8z9n45mak463ajwa5fal4ku4ekhttzyh7c0g60ndhhwwqnh2mcszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5aptkyy</id>
    
      <title type="html">tomorrow introducing Nostr WoT at #WoTathon! ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd8z9n45mak463ajwa5fal4ku4ekhttzyh7c0g60ndhhwwqnh2mcszypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5aptkyy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs880tkqlqtfqfuml44ypg5kxjdhhlqy7tscwwhtvkkgjdr222hl5qwc6t5e&#39;&gt;nevent1q…6t5e&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;tomorrow introducing Nostr WoT at #WoTathon!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://nostr-wot.com&#34;&gt;https://nostr-wot.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#NostrBuild #DecentralizedTrust #WebOfTrust #Nostr #Bitcoin&lt;br/&gt;&lt;blockquote class=&#34;border-l-05rem border-l-strongpink border-solid&#34;&gt;&lt;div class=&#34;-ml-4 bg-gradient-to-r from-gray-100 dark:from-zinc-800 to-transparent mr-0 mt-0 mb-4 pl-4 pr-2 py-2&#34;&gt;quoting &lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Article&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/nevent1qvzqqqqqqypzp0nm7h0qdrqasshdxjnuyuzs0my5pa0229n3elgx9227n5y5yrg2qy2hwumn8ghj7un9d3shjtnyv9kh2uewd9hj7qgawaehxw309ahx7um5wghxy6t5vdhkjmn9wgh8xmmrd9skctcqypem6as8cz6gz0xladfq29935ndalcp8juxrn46m94jyng6jj4laqxphev9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;nevent1q…hev9&lt;/a&gt;&lt;/span&gt;  &lt;/div&gt; Reminder that our 15th #WoTathon weekly call is 2 days away on Thursday, February 26, at 4 PM UTC, 11 AM Eastern. We look forward to hearing updates on the progress each team is making!&lt;br/&gt;&lt;br/&gt;Any specific topics you&#39;d like to add to the docket? Reply below!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://nosfabrica.com/wotathon&#34;&gt;https://nosfabrica.com/wotathon&lt;/a&gt; &lt;/blockquote&gt;
    </content>
    <updated>2026-02-25T20:09:10&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0pw2j6ghpa73z6p52xn353ws3aquxk0uwpu5zatl4y8xf57kxgmgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5s3qgjh</id>
    
      <title type="html">i hear you. i think every user should be able to choose what ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0pw2j6ghpa73z6p52xn353ws3aquxk0uwpu5zatl4y8xf57kxgmgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5s3qgjh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxn6kgveuv5pn3hjekr5pqnwdkj5cnegaynlpy0megqsds7udut9qqsp7lr&#39;&gt;nevent1q…p7lr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;i hear you. i think every user should be able to choose what level of security they add to their key stash. today, they have little options, and every user experience is broken on this regard.&lt;br/&gt;&lt;br/&gt;if i feel comfortable remembering things, under a scheme like this one which cannot be brute-forced, i may go for this approach. i may even feel comfortable enough as to not create a backup, because i know that if i want to keep the history of my account, i can just create a new one and use the old password (very interesting approach to handling keys hey).&lt;br/&gt;&lt;br/&gt;there&amp;#39;s another guy that wrote about publishing instead of a passphrase another key that you should back up. so you can have 2 back ups, and one of them is the one you use in your hot nostr client, the other you use it under an emergency to rotate your key. &lt;br/&gt;&lt;br/&gt;if the relays start working together on adopting a model or several of these strategies to prevent bad actors, and on top of that little trust, you could have levels of order and completeness that will give you a safety net (OTS or straight an OP_RETURN), then this sounds interesting.
    </content>
    <updated>2026-02-25T12:07:04&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdv9g5m9p9fkw2v6p4uv2klla99dxyjnu8gpn7mwu3et5e4a2mswgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5dfej8r</id>
    
      <title type="html">hey David. every existing proposal has the same flaw: if an ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdv9g5m9p9fkw2v6p4uv2klla99dxyjnu8gpn7mwu3et5e4a2mswgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5dfej8r" />
    <content type="html">
      In reply to &lt;a href=&#39;/naddr1qpfxkete94ex7arpw35k7m3dv9hxgtthv43z6mmx9468yatnwskhg6r994ekjmtsd3jhxapdwphhxumfvfkx2ttndak82arfdahz6ar094sj6urjv4ehx6twvukhqun0vfkx2mgzyrjjwt0fzj7nq964csum3rnftxjre8fxvjp37zfu285u0xdpdggz7qcyqqq823cq3xcp0&#39;&gt;naddr1qp…xcp0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;hey David. every existing proposal has the same flaw: if an attacker has your nsec, they can publish the same migration event you can. you can&amp;#39;t prove who did it.&lt;br/&gt;&lt;br/&gt;i am proposing below a scheme that fixes this using a hash commitment published on day one, a sha256 of a passphrase that lives only in your head (a password or something). &lt;br/&gt;&lt;br/&gt;attacker can&amp;#39;t rotate without knowing it. if they try, the fraudulent rotation is cryptographically distinguishable from a legitimate one.&lt;br/&gt;&lt;br/&gt;key theft becomes detectable, not just disruptive.&lt;br/&gt;&lt;br/&gt;draft NIP: &lt;a href=&#34;https://github.com/nostr-protocol/nips/issues/2237&#34;&gt;https://github.com/nostr-protocol/nips/issues/2237&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;check it out, and let me know your thoughts!&lt;br/&gt;&lt;br/&gt;#nostrbuild #keyrotation #cryptography
    </content>
    <updated>2026-02-24T20:10:55&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswrnjgmet8t640m5d2p7ef049d56wwrsvpqca7er8py83lwjz5u9czypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp56m5c8y</id>
    
      <title type="html">will work on it, and release it soon. thanks for the heads up!</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswrnjgmet8t640m5d2p7ef049d56wwrsvpqca7er8py83lwjz5u9czypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp56m5c8y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspxc8hvgfs9j83h5ydwz9n8kml6k07qslpngpvay9pnrzn8gk08cqpp4mhxue69uhkummn9ekx7mqlhyt3g&#39;&gt;nevent1q…yt3g&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;will work on it, and release it soon. thanks for the heads up!
    </content>
    <updated>2026-02-16T00:24:18&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdt57uf36jawufllfcr0ksd7j2mzzv5suyqj3tndtzgu8mgrtycqgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp54fvfug</id>
    
      <title type="html">Centralized platforms tell you who to trust. You don&amp;#39;t get to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdt57uf36jawufllfcr0ksd7j2mzzv5suyqj3tndtzgu8mgrtycqgzypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp54fvfug" />
    <content type="html">
      Centralized platforms tell you who to trust. You don&amp;#39;t get to see how or why.&lt;br/&gt;&lt;br/&gt;𝐈 𝐛𝐮𝐢𝐥𝐭 𝐍𝐨𝐬𝐭𝐫 𝐖𝐨𝐓 𝐛𝐞𝐜𝐚𝐮𝐬𝐞 𝐲𝐨𝐮𝐫 𝐧𝐞𝐭𝐰𝐨𝐫𝐤 𝐬𝐡𝐨𝐮𝐥𝐝 𝐰𝐨𝐫𝐤 𝐟𝐨𝐫 𝐲𝐨𝐮, 𝐧𝐨𝐭 𝐚𝐠𝐚𝐢𝐧𝐬𝐭 𝐲𝐨𝐮.&lt;br/&gt;&lt;br/&gt;Your follows anchor your trust. Their network extends it. Distance becomes signal. You set the thresholds.&lt;br/&gt;&lt;br/&gt;See the actual shape of your network. Control what reaches you. Own your filters.&lt;br/&gt;&lt;br/&gt;𝐍𝐨𝐭 𝐭𝐡𝐞𝐢𝐫 𝐚𝐥𝐠𝐨𝐫𝐢𝐭𝐡𝐦. 𝐘𝐨𝐮𝐫𝐬.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://nostr-wot.com/&#34;&gt;https://nostr-wot.com/&lt;/a&gt;&lt;br/&gt;&lt;a href=&#34;https://nostr-wot.com/playground&#34;&gt;https://nostr-wot.com/playground&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;𝐀 𝐛𝐫𝐨𝐰𝐬𝐞𝐫 𝐞𝐱𝐭𝐞𝐧𝐬𝐢𝐨𝐧 𝐭𝐡𝐚𝐭 𝐠𝐢𝐯𝐞𝐬 𝐲𝐨𝐮 𝐛𝐚𝐜𝐤 𝐜𝐨𝐧𝐭𝐫𝐨𝐥.&lt;br/&gt;&lt;br/&gt;#decentralizedtrust #wot #nostr #weboftrust #grownostr #decentralization #buildingonnostr&lt;br/&gt;
    </content>
    <updated>2026-02-15T23:34:45&#43;01:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsypnm93uh0quzhnm45p322f23n0pgfj580f70fn88c73uhtpt9y9szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5q9fys8</id>
    
      <title>Nostr event nevent1qqsypnm93uh0quzhnm45p322f23n0pgfj580f70fn88c73uhtpt9y9szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5q9fys8</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsypnm93uh0quzhnm45p322f23n0pgfj580f70fn88c73uhtpt9y9szypqekl0skpcph36u0gg9wgj5nhgkygxyrag708vjka5h6mn3ysvp5q9fys8" />
    <content type="html">
      inspire, love, effect 🌱
    </content>
    <updated>2026-01-30T14:40:55&#43;01:00</updated>
  </entry>

</feed>