Oddbean new post about | logout

Notes by Aaron Daniel | export

 This framework explains so much. I know a bunch of these precarious elites. I clearly remember an... 
 Read Peter Turchin's "Ages of Discord" and follow up "End Times". Natalie references his theory of cliodynamics, which explains cycles of stability and instability within society by examining, among other factors, the overproduction of elites. 

Really changed the way I view and understand our current moment. 
 Zeus hodl invoices, just had to go into my mailbox and accept the zap. Thanks! 
 They exclude the three lowest and highest fee blocks of every 24 hour period from the payout calc... 
 
nostr:nevent1qqsfxcyq0wt9p66nvplpz05vmyl5ltu0rhxqt7f42ezryp42ll7mpyspzamhxue69uhhyetvv9ujumn0wd68ytnzv9hxgtczyrfs2t9ru02j8v0vspn3avdm5pgh5t6j9cv4w7xus0ws82xcfgtsuqcyqqqqqqg3mxq22 
 Diffie-Hellman Exchange:  favorite prog-rock band.
nostr:nevent1qqsf2q0gukkdsfcu8cupqa5j6v0ajhuvtjsh9y8vj924zg4l24zlmsspz9mhxue69uhkummnw3ezuamfdejj7q3qh8nk2346qezka5cpm8jjh3yl5j88pf4ly2ptu7s6uu55wcfqy0wqxpqqqqqqz72ztna 
 My alma mater, Emory University in Atlanta, is the first university endowment to allocate to Bitcoin (the ETF). 

Must be because the premier Bitcoin builder conference is nostr:nprofile1qqs0zqyq74avavecxlreqte2ugu5hc7q867qwg386pmeflmd00hdnhqpzdmhxue69uhhqatjwpkx2urpvuhx2ue025x248 https://image.nostr.build/2f29a074e65158cc788c56f03ff3eb848a7932ea3dabad88337c4460272b239f.jpg 
 
https://image.nostr.build/0a7d03216a51b1d77c0ec4fa4cc5ffb54c366c82ad0c0cc3b2492b8f95982e0b.jpg

https://www.bitcoinbrief.io/nostr-bitcoin-inscriptions-and-the/

nostr:nevent1qqsv46nwzzuww9ckvsfjy3n8u0ajm85xeplchnj6el35758uvjnzdaspz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygqyey2a4mlw8qchlfe5g39vacus4qnflevppv3yre0xm56rm7lveypsgqqqqqqs380que 
 1500 sats up for grabs!

nostr:nevent1qqstrd5wkluh5x9d6r9vtem9j0jevzmrr639nrknmwyyvkg8pkt5w6qpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygq7aanp6nna4lrlr9w2x29s6a55l6zrdcuurcpnd7qtclns0a6djupsgqqqqqqsg647dy 
 once again on the prowl for the simplest deploy code for a nostr relay 
 Have you checked out nostr:nprofile1qqszypfzctpjkwljjqrtya0zyjegt4jtkx0hn0dfq6v3hjecv8scedqpz3mhxue69uhhyetvv9ujuerpd46hxtnfduq3jamnwvaz7tmjv4kxz7fwdehhgetnw3skx6ewvdhk6qgdwaehxw309ahx7uewd3hkcqja0jz's https://relayrunner.org & https://relaywizard.com 
 LFG, congrats nostr:nprofile1qqsfyfhd5ynvvtjj4pmwsd6gt02hkpgfseamp3e3acsnwg7xdgdaurspzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgqg5waehxw309aex2mrp0yhxgctdw4eju6t0qyv8wumn8ghj7un9d3shjtnndehhyapwwdhkx6tpds762s4x!
nostr:nevent1qqswhlu6tumd4uwvmhe95awrvkjljhyqy9xmevjtu42h08fpr3shrqcpzamhxue69uhkzarvv9ejumn0wd68ytnvv9hxgtczypu8xwr40lp96ewdj2fef408wy70gd3carf9n6xu7hrnhq6whpglyqcyqqqqqqgwxjg7x 
 When a platform is built by a for-profit entity that has raised funds, it's easy for the state to target it and pressure founders. 

Open Source protocols can live past their founders. 

Nostr-native crowdfunding marketplaces like fundsolvr.com are necessary.

Build the change you want to see. https://github.com/Open-Source-Justice-Foundation/Fundsolvr


nostr:nevent1qqsv2w94wgrlj6xn6q9xylcclpsa6a8k4zfexwhpujwnj0tcg3mfpcgpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0qgsd3fhv7rped64g77dyf9l7ndmae9mkxdz37099cc6wyzr9jytxg7crqsqqqqqp8duz77 
 A note to all Primal users. We are working hard on making Primal much faster and more reliable. W... 
 Still blacklisted from the wallet for some reason...Strike I have onboarded no problem.  
 The only desktop app with integrated fedimint wallet support that I am aware of.

 https://github.com/nodetec/keystache 
 Great example of a "last mile" Bitcoin service. Zaprite doesnt maintain it's own lightning infrastructure or nodes. It focuses its resources on amazing invoicing and smooth payment gateways (payment "links").  

Now, LSPs, wallet providers, etc dont need to build the merchant interfaces, they just focus resources on robust infrastructure and integrate with Zaprite. 

Comparative advantage and collaboration. 👌
nostr:nevent1qqsz6uyg3xudud2qlu3s6x54sc62xva05a0mgnrehsa9wqhwnwvf6ggpz9mhxue69uhkummnw3ezuamfdejj7q3qclk6vc9xhjp8q5cws262wuf2eh4zuvwupft03hy4ttqqnm7e0jrqxpqqqqqqz84wn0k 
 ok folks, my 5 year old just lost his first tooth. how many sats does the tooth fair leave him? 
 Tooth fairy matches $5 bill with sats (whatever current exchange rate).  My 8 year old stacked hard during the bear.  
 My Square account got locked for some reason (probably having to do with my using CalyxOS) but I ... 
 Same happened to me when I issued my co-founder a payment request from company account. Square customer help line had no idea what happened, "escalated" it...and I never heard back. 

Had funds locked in square checking, disputed the deposit with the bank I made deposit from and got the funds back. 

It's dangerous out there on a fiat standard! 
 "The only thing scarcer than Bitcoin is time, so take it when you can get it." ⏳

@ODELL taking stage 15 minutes early to hold forth on importance of FOSS funding and investor incentives on a Bitcoin standard was a highlight.

 I and the other 11 people listening thoroughly enjoyed it. 🤣 
 🇺🇸The American Founders would have been Bitcoiners. 

Here’s my article from a few years back offering the historical proof. 

Happy Independence Day. 🎇

https://bitcoinmagazine.com/culture/independence-day-the-founders-and-bitcoin 
 The founding men and women of the United States would’ve really loved a #Bitcoin  🇺🇸 
 Here's my argument to that effect from a few years ago: https://bitcoinmagazine.com/culture/independence-day-the-founders-and-bitcoin 
 Why are this miner's own lawyers misinforming a District Court judge about the Bitcoin mining process?? (The order directly cites the miner's complaint.)

https://image.nostr.build/c457c6e44e039e64d5509781c549fca7b21ff20a438fa0f60a02b0fe3b1122e5.jpg

We need to do a better job of educating the courts. If you are a Bitcoin company that must litigate, hire Bitcoiners.

https://www.courtlistener.com/docket/68325488/48/block-mining-inc-v-hosting-source-llc/

 
 I'm finally going to try the Nostr Obsidian plugin, created by  nostr:npub10a8kw2hsevhfycl4yhtg7v... 
 Talk to @Doc Orange and @Chris, they authored the NIP and wrote the reference implementation for local desktop signing. 

* https://github.com/Resolvr-io/Keystache
* https://github.com/tvolk131/nip-55 
 Matthew Green's (cryptography prof at Johns Hopkins) take on Apple's "Private Cloud Compute":  https://threadreaderapp.com/thread/1800291897245835616.html?utm_campaign=topunroll


"So Apple has introduced a new system called “Private Cloud Compute” that allows your phone to offload complex (typically AI) tasks to specialized secure devices in the cloud. I’m still trying to work out what I think about this. So here’s a thread. 

1/
Apple, unlike most other mobile providers, has traditionally done a lot of processing on-device. For example, all of the machine learning and OCR text recognition on Photos is done right on your device. 

2/
The problem is that while modern phone “neural” hardware is improving, it’s not improving fast enough to take advantage of all the crazy features Silicon Valley wants from modern AI, including generative AI and its ilk. This fundamentally requires servers. 

3/
But if you send your tasks out to servers in “the cloud” (god using quotes makes me feel 80), this means sending incredibly private data off your phone and out over the Internet. That exposes you to spying, hacking, and the data hungry business model of Silicon Valley. 

4/
The solution Apple has come up with is to try to build secure and trustworthy hardware in their own data centers. Your phone can then “outsource” heavy tasks to this hardware. Seems easy, right? Well: here’s the blog post. 

5/
https://security.apple.com/blog/private-cloud-compute/
TL;DR: it is not easy. Building trustworthy computers is literally the hardest problem in computer security. Honestly it’s almost the only problem in computer security. But while it remains a challenging problem, we’ve made a lot of advances. Apple is using almost all of them. 

6/
The first thing Apple is doing is using all the advances they’ve made in building secure phones and PCs in their new servers. This involves using Secure Boot and a Secure Enclave Processor (SEP) to hold keys. They’ve presumably turned on all the processor security features. 

7/
Then they’re throwing all kinds of processes at the server hardware to make sure the hardware isn’t tampered with. I can’t tell if this prevents hardware attacks, but it seems like a start. 

8/
They also use a bunch of protections to ensure that software is legitimate. One is that the software is “stateless” and allegedly doesn’t keep information between user requests. To help ensure this, each server/node reboot re-keys and wipes all storage. 

9/
A second protection is that the operating system can “attest” to the software image it’s running. Specifically, it signs a hash of the software and shares this with every phone/client. If you trust this infrastructure, you’ll know it’s running a specific piece of software. 

10/
Of course, knowing that the phone is running a specific piece of software doesn’t help you if you don’t trust the software. So Apple plans to put each binary image into a “transparency log” and publish the software.

But here’s a sticky point: not with the full source code. 

11/
Security researchers will get *some code* and a VM they can use to run the software. They’ll then have to reverse-engineer the binaries to see if they’re doing unexpected things. It’s a little suboptimal. 

12/
When your phone wants to outsource a task, it will contact Apple and obtain a list of servers/nodes and their keys. It will then encrypt its request to all servers, and one will process it. They’re even using fancy anonymous credentials and a third part relay to hide your IP.

13/
Ok there are probably half a dozen more technical details in the blog post. It’s a very thoughtful design. Indeed, if you gave an excellent team a huge pile of money and told them to build the best “private” cloud in the world, it would probably look like this. 

14/
But now the tough questions. Is it a good idea? And is it as secure as what Apple does today? And most importantly:

I admit that as I learned about this feature, it made me kind of sad. The thought that was going through my head was: this is going to be too much of a temptation. Once you can “safely” outsource tasks to the cloud, why bother doing them locally. Outsource everything!
As best I can tell, Apple does not have explicit plans to announce when your data is going off-device for to Private Compute. You won’t opt into this, you won’t necessarily even be told it’s happening. It will just happen. Magically.

I don’t love that part. 

17/
Finally, there are so many invisible sharp edges that could exist in a system like this. Hardware flaws. Issues with the cryptographic attenuation framework. Clever software exploits. Many of these will be hard for security researchers to detect. That worries me too. 

18/
Wrapping up on a more positive note: it’s worth keeping in mind that sometimes the perfect is the enemy of the really good.

In practice the alternative to on-device is: ship private data to OpenAI or someplace sketchier, where who knows what might happen to it. 

19/
And of course, keep in mind that super-spies aren’t your biggest adversary. For many people your biggest adversary is the company who sold you your device/software. This PCC system represents a real commitment by Apple not to “peek” at your data. That’s a big deal. 

20/
In any case, this is the world we’re moving to. Your phone might seem to be in your pocket, but a part of it lives 2,000 miles away in a data center. As security folks we probably need to get used to that fact, and do the best we can to make sure all parts are secure. 

//fin
Addendum: “cryptographic attenuation” should read “cryptographic attestation”, but I’m sure folks will get the point."

#apple #privacy #AI 
 Has Fedi ever given a reason for their decision not to open source their wallet app? 

I am curious what the business rationale is.

nostr:nevent1qqsdh3escytm8c94vxv4vld3f4d5xp0sl20fz0xj7vwxfusus5yc4fqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzq7xwd748yfjrsu5yuerm56fcn9tntmyv04w95etn0e23xrczvvraqvzqqqqqqyk9rf08 
 🤣 
 Oh, I'm not making any judgments. I know it's very difficult to build a software company 100% open source. 

Just curious the business strategy there, because Fedi is targeting similar markets and users as Galoy, which is using an open source model to spread the tools where needed without restrictions. 
 I believe Fedi is currently the only closed source app indexed in zap.store , and this was by mis... 
 Has Fedi ever given a reason for their decision not to open source their wallet app? 

I am curious what the business rationale is.

nostr:nevent1qqsdh3escytm8c94vxv4vld3f4d5xp0sl20fz0xj7vwxfusus5yc4fqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzq7xwd748yfjrsu5yuerm56fcn9tntmyv04w95etn0e23xrczvvraqvzqqqqqqyk9rf08 
 To all those apps still asking for nsecs... no more excuses

nostr:note1lk9ctgk8e0h5j3yxycsxf3ldz... 
 So now users that want to use their nostr keys in two apps on Android mobile (one of the major value adds of nostr) must download a third app to sign in? 
 This jeweler is building explosive drones to safeguard her brothers and father on the frontlines. 

Technology is decentralizing devastating deadly force into the hands of everyday people. 


https://image.nostr.build/57edd6024304f14637e992533a739417ac75b9a423aee84d0abfc11a428b2d39.jpg


https://image.nostr.build/98a30c430b1cce7365a4737931a6c1f4f90bc1678655ad8aabeeaf0be0ad1af4.jpg

https://youtu.be/WipqeFgzdTc 
 Let me know how to help. I've been exploring a developer defense fund through @Open Source Justice Foundation, as well as an Open Source Defense Network of attorneys, firms, and experts. 

Also a 12-year appellate attorney capable of leading amicus work.  
 And privacy is a prerequisite for free speech :

“If a man's privacy can be invaded at will, who can say he is free? If his every word is taken down and evaluated, or if he is afraid every word may be, who can say he enjoys freedom of speech? If his every association is known and recorded, if the conversations with his associates are purloined, who can say he enjoys freedom of association? When such conditions obtain, our citizens will be afraid to utter any but the safest and most orthodox thoughts; afraid to associate with any but the most acceptable people. Freedom as the Constitution envisages it will have vanished.”
- Justice Douglas

“Among deprivations of rights, none is so effective in cowing a population, crushing the spirit of the individual and putting terror in every heart. Uncontrolled search and seizure is one of the first and most effective weapons in the arsenal of every arbitrary government. And one need only briefly to have dwelt and worked among a people possessed of many admirable qualities but deprived of these rights to know that the human personality deteriorates and dignity and self-reliance disappear where homes, persons and possessions are subject at any hour to unheralded search and seizure by the police.”
- Justice Robert Jackson 
 We need a lawfare version of opensats. Ready to deploy capital in the defense of those defending ... 
 Van Valkenburgh has balanced perspectives, usually. 

Dutch law seems far looser on criminal intent than US.

Respect for the First Amendment and freedom of speech is still strong.

But the chilling effect is real. Which is why @Open Source Justice Foundation is starting a Developer Defense Fund. 

https://image.nostr.build/b8308212f9907af113e8374bd07ab3e9b1f85bb9274965877fb31156c865cdfe.jpg 
 "In other words: the defendant, [co-defendant 1], and [co-defendant 2] are the designers, creators, and executors of [crypto-system]. As such, they are also responsible for the (consequences of the) functioning of this tool. The autonomous, immutable, and unstoppable nature of the smart contracts does not work in a way that exculpates them. After all, this is not a coincidental circumstance. These characteristics are the result of conscious choices by the designers. [Crypto-system] functions as it was conceived. In the opinion of the court, the defendant can therefore be regarded as the perpetrator of the money laundering operations carried out by [crypto-system]."

 https://image.nostr.build/c55edfe5e85954cbeb90047aa0e85d99ece57958594e54441dc129c1759c1689.png 
 The Dutch judgment concluded that open source developers can be convicted of money laundering because they knew the potential of their software to be used to launder money and accepted that risk when they released the software. 

(From casetext AI assistant)

https://image.nostr.build/421bc9d0e8446dab1551a0b69ba816dda0385c30cebe4dcfc44f02bfca118c10.jpg 
 I'm here, too. 💪

nostr:nevent1qqsgfqnrxpxwlqcae6r5wsmqlvhpuqfzpk4j4ja0jgzz5526wynd7dcpr3mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmqzyrggeycjnawvy54fq9al2tuss5rqkyrkvg993ntfy2dnrcmnalxf7qcyqqqqqqgqrqm7x 
 Anyone that want to protect open-source developers from prosecutorial overreach should consider donating to @Open Source Justice Foundation (OSJF.org). 

Help grow the Developer Defense Fund.  
 Dutch prosectors in Alexey Pertsev's trial consider deploying open source code actionable if it subsequently is used to commit crimes, despite the developers' inability to control its use after release. 

https://image.nostr.build/48d71074fb53ba908ae54a2b3a615f35039df4befe8af9d2d5b22c3a460c64c1.jpg

https://www.wired.com/story/tornado-cash-money-laundering-case-crypto-privacy/ 
 On macOS Sonoma, connecting either Mullvad or IVPN while Tailscale is connected blocks all web tr... 
 Tailscale and ProtonVPN don't play nicely on android, either. 
 Daniel Bernstein's attorneys (EFF's Cindy Cohn) advanced a secondary argument to the famous "Code is Speech":  

Speech that enables private, anonymous speech is "inherently imbued with First Amendment significance."

This is a coinjoin post.

#FreeSamourai
 https://image.nostr.build/09e98c14372ca632bc08a47b58935adb6c05d6d6b625351d785170a580fadb17.png

https://docs.google.com/document/d/1kfvBmD32jr-60xMgGz1Ucku8zE2GCRl6haMR4OgXr5Q/edit 
 The Diffie-Hellman Exchange sounds like a badass progrock band. 

@JeffG
@ODELL
 
 📣 Reminder! I’ll be chatting with nostr:npub1qny3tkh0acurzla8x3zy4nhrjz5zd8l9sy9jys09umwng00... 
 So rachet. LFG 
 Mash.com is shutting down. 

Mash provided an easy way to engage in #Value4Value content on the web through its custodial lightning wallet and integrations with many major web publishing platforms like Ghost. 

I used Mash on bitcoinbrief.io (BEFORE TFTC and @MartyBent, I might add!). 

Another casualty of the current regulatory overreach? 

https://image.nostr.build/3787049b9d32dd0f56ceceb61dbe0f1349c45046356dcf2b596aa98a22843e86.jpg 
 Same, they were super open to feedback from users. And they had recently brought in a digital media veteran from barstool, I believe, to take it to the next level. 

Hopefully they are retrenching and going self-custodial (nostr wallet connect, Bitcoin connect) or some ecash route (like mutiny's fedimint integration). 

Although, maybe nostr just eats that use case? Pretty easy to monetize content here. 💜 
 Investigator of Bitcoin Fog case and Roman Sterlingov. The Nigerian state is acting reprehensibly, but I'm not interested in an international incident to save this guy, who only has his binance position by hunting Bitcoin users and privacy advocates on behalf of another state.  
 IIRC, Sterlingov's counsel at some point during the case listed him as someone related to the case that was in the book "Tracers in the Dark", which discussed the Bitcoin fog investigation and which Sterlingov sought to introduce as evidence (or use as a basis for being able to speak publicly about the case). 

But perhaps he was never directly involved in Bitcoin fog, as I cannot find anything stating as much. 
 
 Investigator of Bitcoin Fog case and Roman Sterlingov. The Nigerian state is acting reprehensibly, but I'm not interested in an international incident to save this guy, who only has his binance position by hunting Bitcoin users and privacy advocates on behalf of another state.  
 nostr:nevent1qqsp8kzh5zkkxad6pg5u270s40rhuzwpaex2s0hcvp9jzummdevuy8qppemhxue69uhkummn9ekx7mp0qgsdprynz204esjj4yqhhaf0jzzsvzcswe3q5kxddy3fkv0rw0hue8crqsqqqqqpadtf9c 
 Who is working on @joinstr? 

Can this be implemented in wallets with nostr-integration? @ZEUS @OpenSecret

Can we make every on-chain spend a coin join? @stephanlivera

No time to waste. 
#asknostr 
 Use a personal server from  nostr:npub126ntw5mnermmj0znhjhgdk8lh2af72sm8qfzq48umdlnhaj9kuns3le9ll... 
 Building a DIY start9 machine this weekend. 💪 
 Which important Bitcoin, nostr and related freedom tech news, releases, research, guides or proje... 
 Launch of @Open Source Justice Foundation and it's development fund.  Seeking applications for grants now! 
 Exits are closing. 

P2P exchange is more important than ever. 

How do we make tools like Bisq and Robosats more accessible and user friendly?

More resistant?

https://www.nbcnews.com/business/personal-finance/prosecutors-examining-transactions-block-owner-cash-app-squarc-rcna147181?ref=tftc.io 
 The funniest and saddest thing to me is when people/media/officials comment on protests and say ... 
 Civil disobedience is a separate tool from protest. It's also speech, but by definition unlawful. First Amendment precedent has long allowed reasonable time/place restrictions on speech.

Leaders of change movements should use civil disobedience strategically, because it comes with consequences and often creates a negative image of the movement in the public eye (i.e., the majority inclined to status quo).

Whether any particular instance of civil disobedience is morally correct depends on one's own values and beliefs. So commentators voicing preference for protest, not civil disobedience, are usually expressing their view of the change movement's goals. 

 
 This is what seizure through coercion looks like.

Governments can't seize your Bitcoin, but they can seize YOU if you fail to surrender it.

I've been predicting that such coercion will be one way courts and governments overcome Bit okn's seizure resistance: https://bitcoinmagazine.com/culture/how-civil-justice-reacts-to-bitcoin-custody





https://image.nostr.build/94b14a240a5075fa6a84c9b8656fed3e731797d3e0b02de919c937494e327c4c.jpg 
 He didn't sell.

 It a "constructive" (legalese for imaginary) sale that happens by law when one renounces citizenship, triggering capital gains taxes on the value of assets held at that time. 

It's a wealth tax designed to deter citizens of means from renouncing citizenship (the US taxes citizens earning abroad). 

 
 I’d be happy to contribute to and use my public platform to bring attention to legal defense fu... 
 We've just launched @Open Source Justice Foundation this week. 501(c)(3) approved public charity dedicated to supporting and defending FOSS devs developing alternative systems (legal, financial, etc). 

We're exploring starting a legal defense fund to counteract the chilling effects of these absurd prosecutions. 

We'd welcome your support and advice. Happy to answer any questions and provide references. (aaron@opensourcejustice.org)


 
Event not found
 Interesting analysis of the news by cryptographer Matthew Green:
 nostr:nevent1qqsx9aw9msv9m6g2jm0ea73gklpv6rl3twz5v3supctc3laj8suwt2spzdmhxw309akx7cmpd35x7um58g6rsd3eqgsdprynz204esjj4yqhhaf0jzzsvzcswe3q5kxddy3fkv0rw0hue8crqsqqqqqp34jkf7