<oembed><type>rich</type><version>1.0</version><author_name>npub15758wuggl6u8umupz8ellvdjad7mjcchkn2vcelrmmeg55f48euspfpqkx</author_name><author_url>https://nostr.ae/npub15758wuggl6u8umupz8ellvdjad7mjcchkn2vcelrmmeg55f48euspfpqkx</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2021-11-23&#xA;📝 Original message:&#xA;so You propose Acinq / Blockstream / Lightning Labs do not have funds to&#xA;run a box or 2 ?&#xA;&#xA;contributions can be made towards each impl by ppl while the project still&#xA;do need put liquidity on mainnet to be a viable test before a public&#xA;sanctioned release.&#xA;&#xA;I find You choose misread what the text is supposed to convey - those with&#xA;the write credentials to repo, when do a public release could have been&#xA;tested, before, against the network, and that in no way hinders PR toward&#xA;said repo.&#xA;&#xA;On Tue, Nov 23, 2021 at 1:44 PM ZmnSCPxj &lt;ZmnSCPxj at protonmail.com&gt; wrote:&#xA;&#xA;&gt; Good morning x-raid,&#xA;&gt;&#xA;&gt; &gt; what i can imagine is each team should provide boxes and channel&#xA;&gt; liquidity as stake on mainnet for tests before announce a public realise as&#xA;&gt; to feel the pain first hand instead of having several K´s of plebs confused&#xA;&gt; and at worst have funds in channelclosed etc. but mostly for helping in&#xA;&gt; smooth transitioning into future envisioned mass.&#xA;&gt;&#xA;&gt; Not all members of all teams are independently wealthy, and cannot afford&#xA;&gt; significant liquidity on mainnet, or can afford good Internet connection&#xA;&gt; and keeping a device operational 24/7.&#xA;&gt; For example, for some time I was a C-Lightning core developer, yet did not&#xA;&gt; run a C-Lightning node myself, relying on sheer code review, because I&#xA;&gt; could not afford to run a node.&#xA;&gt; What you imagine would raise the barrier towards contribution (i.e. I&#xA;&gt; might not have been able to start contributing to C-Lightning in the first&#xA;&gt; place, for example).&#xA;&gt;&#xA;&gt; I think you misunderstand the open-source model.&#xA;&gt; If you have the skill, but not the money, you can contribute directly.&#xA;&gt; If you do not have the skill, but do have the money, you can contribute&#xA;&gt; that by hiring developers to work on the project you want.&#xA;&gt;&#xA;&gt; So, if you are using a particular open-source implementation and storing&#xA;&gt; your funds with it, either:&#xA;&gt;&#xA;&gt; * You have the 1337 skillz0rs: you contribute review and actual code.&#xA;&gt; * You do not have the 1337 skillz0rs: you contribute hardware and testing&#xA;&gt; reports and possibly money.&#xA;&gt;&#xA;&gt; If the several Ks of plebs are confused, they can aggregate their&#xA;&gt; resources and fund one or two developers to review and contribute to the&#xA;&gt; project they are using, and maybe some hardware and coins for boxes they&#xA;&gt; keep running.&#xA;&gt;&#xA;&gt; At my point of view, the Real Issue (TM) here is how to aggregate the will&#xA;&gt; of a group of people, without risking that some centralized &#34;manager&#34; of&#xA;&gt; resources gets incentives that diverge from the group of people and starts&#xA;&gt; allocating resources in ways that the group of people would, in aggregate,&#xA;&gt; disagree with.&#xA;&gt;&#xA;&gt; &gt;&#xA;&gt; &gt; If teams rather outsource the running of boxes with channels on mainnet&#xA;&gt; for impl release and rc versions they would of course be able to, but close&#xA;&gt; to home for managing analysis of the team impl themselves is what I would&#xA;&gt; recommend.&#xA;&gt; &gt;&#xA;&gt; &gt; Can also see that each box loglines are collected at one central point&#xA;&gt; whereby requests can be made for comparing interoperability per unix.ts&#xA;&gt; identified by box.&#xA;&gt; &gt; (thats alot of data You say --not really in Big Data terms, question is&#xA;&gt; where to set a proper cap in time for collections ? a week ? a month ?)&#xA;&gt; &gt; I think i might have a solution for the central point collector that&#xA;&gt; could be run by an outside of impl teams perimeter. (sponsored?)&#xA;&gt;&#xA;&gt; See, if the money on the node is my own, and not contributed by the group&#xA;&gt; that is going to receive the logs, I am not going to send the logs verbatim&#xA;&gt; to them, nope not nada.&#xA;&gt; I do not want to become a target, because logs leak information like who&#xA;&gt; my channel counterparties are and how often I forward HTLCs and exact dates&#xA;&gt; and times of each event, and thus can be used to locate my node, and&#xA;&gt; location is the first step to targeted attack.&#xA;&gt; I mean I use a frikkin set of 8 random letters, come on.&#xA;&gt; Possibly if the logs had sensitive information redacted (even dates and&#xA;&gt; times??), but we need to automate that redaction, and in particular, if the&#xA;&gt; implementation changes log messages, we need to ensure that changed log&#xA;&gt; messages do not leak information that gets past the automated redaction.&#xA;&gt;&#xA;&gt;&#xA;&gt; Regards,&#xA;&gt; ZmnSCPxj&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/lightning-dev/attachments/20211123/d7d693cb/attachment.html&gt;</html></oembed>