Last Notes
That makes sense. An organisation that revolved around information is most secure, as it can be encrypted. Second it must be distributed. But indeed, then we get to meat space, where we're still vulnerable.
Could you expand on that? What do you mean?
Good thing you know everything about everything.
BCHNostr.com, the thing this ocean of bots are all raving about
Are you talking about a particular client? There are tons, many open source. & I think they'll all let you bring your own keys...
Most developers are pretty naive, use their real names everywhere and have GitHub accounts. Easy targets to arrest and prosecute. Plus you could just arrest one, then the rest would self-censor.
People who can't handle nostr will just move offline when reality on the internet is impossible to parse
Not even wot or any verifiable way nostr does don't believe anything anymore
Would use blossom for that. Are the linked pdfs all public domain? Then we could easily upload them and distribute over blossom
what about pdf/epub storage?
Currently the list of books is hardcoded. But could be a simple nostr list where one could add kind 30040 events. And then the service would just hold that list and fetch everything on it.
Was just a quick experiment 🙃
@npub1zth…xm56 🐳 zapped @npub175r…ef5g 21,000 sats
💬 Zap!
https://blossom.primal.net/f697b3eeb618dcf6cc5d15f6399ee59e57665e9e345f2d8ffe1f3fdf07b0928f.jpg
https://www.nostrzap.com/api/badge/12ee03d11684a125dd87be879c28190415be3f3b1eca6b4ed743bd74ffd880e6.png
https://aaro.cc/human_machine.jpeg
https://www.nostrzap.com/api/badge/f5073ea24832d8e6246d22ec0b5a75bbf4a12558e3ac67cb07360b3474e5a40e.png
this is sick. how does it handle updates?
https://5m3ottuosw72hzipb0xnoeqtjxd2x9ir24fh67rxsvmpt4jkfycypherpunk.nsite.lol/#/
published a copy there and also the books as nostr events where possible according to https://nostrhub.io/naddr1qvzqqqrcvypzplfq3m5v3u5r0q9f255fdeyz8nyac6lagssx8zy4wugxjs8ajf7pqy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqqgde4ky6ts95crzcdwpf2
cc @npub1zqs…cqrs
this is great idea! i'll look into expanding this as another feature.
How else would it work? It is listening for events to sign. That's not insecure. It is a necessary layer of obfuscation, IMO.
Wisp is pretty much entirely vibecode. I like utxo and wisp, but I'm not going to trust ANYONE'S vibecoded slop with my nsec. I value that more than my stack.
To confirm that the event_id at the link matches the nevent in the screenshot:
$ nak encode nevent cce3ad3583968ccba5e47ed92296343aa2c9aaf7f8267455986f616358679fbe
The main value is so you can proactively have a exit strategy upon compromise, and not necessarily lose all your old posts and associations. The keyset would even include previously used npubs and specifically define them as compromised and no longer used, old posts remain associated but new events made under it.
Your npub would only be sort of static. It could have signed events proving another key or set of keys had control over the nsec at some point
The main benefit over the old full recycle method is keeping posts associated with your new key(s) in clients.
Relays can refer to the keyset to decide if deleting old posts is not legitimate, perhaps arbitrarily requiring N of N keys to delete. These permissions COULD be defined inside the keyset, as a kind of security model, where some keys are defined as more authoritative or simply that relays and clients should only trust N of N keys.
The keyset would include a list of npubs and signatures from each of them to prove ownership.
There's still a time problem because some relays accept posts timestamped in the past. How do you define old legitimate posts without resigning everything? Defining that posts before "created_at" time works, but it's still on relays to honor the keyset.
Anyway. This is how key retirement should probably be done.
> users can decide
Users can already decide without any signing at all, you dimwit.
As simple as possible. It should be transparent. So you can see on posts (1 of N or 2 of N keys used to sign). The list of pubkeys associated is updateable as just a simple event and list. If there's a conflict between 2 keys in a set signing changes without each other, it would split the identity in clients. Both would remain "followed" and users can decide which is the "true" owner.
The compromised key will sign the abandonment of all the other ones. You didn't think this through did you.
It’s a good idea but nothing implements it and it sits as a draft so it is still technically true to say nostr doesn’t have it.
https://blossom.primal.net/1c496a70aa6d8aa8ccb18ec64a87ae68448e9af60c918ae1ffe2cf2b424bfead.gif
It's easy. Just trash your whole social graph and start over.
Nostr is missing a proper PKI. Delegation, rotation and stuff like that.
what do you mean by key management? there are many ways to manage your keys just fine on nostr.
Yeah what the fuck.
We had 50 thousand active users yesterday and only 200 are real people.
🤔
I hope key management becomes the problem to be solved rather than dogpiling devs for implementing something so natural
These are only users that've received on-chain tips (a VERY new Nostr proposal/feature), so there’s not many, the site is a cautionary tale against on-chain tips, I hope that number doesn’t increase much further.
It's an AOSP distribution like Android, but I guess for sake of where this is posted I can see why this is separate. Great to see so many people using it.
Were you threatened by the joos and consequently take THEE juice?
We are having some issues. If you search for wisp don't you see the update?
not sure what's going on with zapstore, been down for days, pls try github
I believe this is all true, but these can be discovered along the way, riding along as bonuses for something else that is powerful enough and weird enough to attract people.
Primal is doing important work. I've expressed my opinion about LightSpark and there's no need to so further.
We absolutely do prompt our users to backup their wallets
i speak truth, and i wish for no one to be in pain, including you 🙏
no permission needed to build or play.
It’s only temporary till all money is phased out
I am in no way ahead of you; I am as green and muddled as a baby goat just born. But I get what you meant.
Great. So you're way ahead of me. My mistake for understanding something different.