Oddbean new post about | logout
 I can keep going on! 
 Hard to tell if this is sarcastic, tongue-in-cheek, or a wake-up call... 
 The downsides are big on here ! We all know about it and you it 😉
Another one IP leaks to the whole internet that makes everyone target ! It’s funny that none profits and VCs are very bullish on nostr haven’t put any bounties to fix the real flows but instead prioritize their investment future strategies! Fuck it ! 
 No lies detected in anything you've said.  The deliberate IP leaks are something that I bang on about, for example the spyware in njump dot me and nostr dot com.  The elite devs are mainly simping there, I would agree.  You can see many devs being groomed in realtime, many simping and sloganeering.  There is so much LARPing going on.  There is a king maker effect, but that could be fixed from the clients, for example primal, which I use has various dropdowns for trending, but most give the same engagement thirst.  Building has gone done alot, and become more centralized, including the NIPs, yes.  But I dont find myself as pessimistic.  We're builders, we can fix it, these centralized artificats are expected (although sometimes disappointing) as a project grows.  We just recognize them and route round.  As you say, nostr is a last refuge.  It was really hard work to get this far, and we're probably not going to make it again.  We can still make nostr the happy place, imho, it just takes longer, and being honest about our falings helps! 
 Nostr is a toy ! Wake me up when it will be something that not will through people under the bus by those who are trying to dictate the development 
 No lies detected.  It is indeed still a centrally controlled toy.  It needs to transition to a transparent, community driven, FLOSS project. The problem is that the elite devs have persuaded themselves they've done that already, but they have work to do, and no one wants to do it. 
 Of course I agree and can understand this train of thought very well, but please don't forget that we are still very early in this matter and something like this develops over a long period of time. If you think in a limited way and can't see this potential it's just natural and perfectly acceptable, Rome wasn't built in one night either. To give a simple example, I will come up with "wavlake" and if you have noticed how these large centralised companies exploit the people they select for themselves, talent falls by the wayside.... Far too much talent is being wasted by a flawed system. If we are completely honest and look at it from a bird's eye view, we have no choice and have to take it as it comes, but we can influence how it comes. I have realised what a blessing this protocol is, because we can stop it if something doesn't suit us. But this is only possible if we all work together and realise that we have to free ourselves from this social parasitism. 

Let's look for solutions to the mistakes that shouldn't exist! 
 Having a permanent public record of all my npub's activity, plus associated metadata (IP address, timing) - it feels like a disaster to happen.
Not having an option to roll over your identity into a new npub is a major issue for.

It's like constant address reuse in Bitcoin. 
 Completely agree.  I mean npub + nip05 + key rotation as it evolves with time.  IP address should not be stored.  Only the fields the user wants. 
 but the relay operator can always log incoming connections and IP addresses, no? Outside of the Nostr protocol. So they are huge data collection honeypots 
 Yes, unfortunately that is the case.  It happens far too often on nostr, for example fiatjaf's njump dot me and benarc's nostr dot com contain spyware that deliberately send your ip address and browsing history to certain VC (bad guys imho), without gaining user consent.  I try to raise awareness of this, but there is very little action, sadly.  Nostr needs to develop good reputations for those that respect privacy.  Most currently do not.  Sadly. 
 Wow I didn't even know that. Really bad.

But in general, the Nostr protocol is just not private, but pseudonymous - and thus succeptible to the same dragnet-style surveillance as Bitcoin. You just need to collect enough metadata.. 
 What spyware are you referring to?