spacestr

đź”” This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.

Edit
hodlbod
Member since: 2025-03-31
hodlbod
hodlbod 12h

This was really fun

hodlbod
hodlbod 12h

Nostr was mentioned on my favorite cryptography podcast today, Security, Cryptography, Whatever — they didn't spend a lot of time on it, but here are some highlights: > It’s federated and it’s European. I bet it sucks. > It’s some Ayahuasca inspired initiative from. From Messrs. Dorsey et al. > Yeah, sure, it’s decentralized and federated, but like their proposal for encrypted end to end encrypted DMs was just bad by itself. > When I reviewed this, my description of this was it looks almost exactly like Nebuchadnezzar [https://nebuchadnezzar-megolm.github.io/], which is like a fractal of things that could have gone wrong with like a complete ecosystem of like a secure messaging system. They found flaws in almost every component of that system and then tried to leverage them as far as they could. You can read/listen here: https://securitycryptographywhatever.com/2025/07/29/vegas-baby/ They also mentioned a talk that's going to be delivered at blackhat on August 9th which sounds super interesting: > In this session, we unveil the first comprehensive security study of Nostr and its popular client applications, demonstrating how subtle flaws in cryptographic design, event verification, and link previews allow an attacker to forge "encrypted" direct messages (DMs), impersonate user profiles, and even leak the confidential message from "encrypted" DMs. Here's the link to the agenda entry for the talk: https://www.blackhat.com/us-25/briefings/schedule/#not-sealed-practical-attacks-on-nostr-a-decentralized-censorship-resistant-protocol-45726 I'm looking forward to learning how we've screwed up — there aren't a lot of cryptographers here, and I know that open protocols make security even harder to maintain. Maybe we've screwed up irretrievably, but I'd rather know now than later.

#not
hodlbod
hodlbod 12h

If you haven't already, give flotilla.social a try

hodlbod
hodlbod 12h

it looks like nostr.wine is asking for auth without sending a challenge. Tested in coracle and snort:

hodlbod
hodlbod 12h

you asked what I thought of WoT relays, I didn't have a chance to answer. I think they're cool, but they have to be used correctly. Archiving is great, uncle jim-ing outbox is also a good use case (although I imagine they wouldn't work for dms or inbox). Also good as custom feeds, curated by people whose taste you like (although you could just load that up directly by requesting based on someone's follow list). I think all of these use cases are pretty weak, since there are other heuristics for finding the same content in most cases.

hodlbod
hodlbod 12h

Thanks to for a great conversation

hodlbod
hodlbod 12h

Never underestimate the extent to which what we want determines what we believe

hodlbod
hodlbod 12h

Hey , want to come on sometime and talk about socialism?

hodlbod
hodlbod 12h

Remember how I was writing a book? Well, I gave up on it. But then I wrote a different one: https://building-nostr.coracle.social/ This book is both practical and philosophical. It ellides a lot of the details you can otherwise get by reading Nostr NIPs, focusing instead on all the things I've learned over three years working on nostr. It includes a number of contrarian opinions which may be partially or completely wrong. Feel free to disagree, or even tell me where I'm wrong. I'll be releasing updates to the book as I have time and inclination to repent of my mistakes and omissions. The book is free, with epub and pdf versions available for your reading pleasure. If you like the book, you can send me bitcoin via nostr or at https://geyser.fund/project/buildingnostr, and if people like it enough I may publish a version that you can touch with your fingers.

hodlbod
hodlbod 12h

Capitalism isn't bad, monopolistic corporations are Government isn't bad, unaccountable government is Technology isn't bad, externally imposed systems are Just thinking out loud here

Welcome to hodlbod spacestr profile!

About Me

Christian Bitcoiner and developer of coracle.social. Learn more at info.coracle.social. Merch is available at

Interests

  • No interests listed.

Videos

Music

My store is coming soon!

Friends