Oddbean new post about | logout

Notes by ec0114a5 | export

 Man I love yubi keys. Feels great being able to lock things down with a physical device. 

But no... 
 Requires physical access and latest series not affected

https://www.yubico.com/support/security-advisories/ysa-2024-03/ 
 I know mullvad takes bitcoin, but is there a trusted place I can use LN to get a voucher? need to... 
 Hard to tell what to search for. The font makes the name hard to read. Perhaps give them the Zeus Wallet website link. 
 Observing the amount of people who use the Primal wallet and are commenting here 
 Say no to KYC. Route around. There is nostr:nprofile1qqsq4qcw4c0z3jq3nlselj46qxumysl8hndd8sgy89r6nxq2c8jlspspzpmhxue69uhkummnw3ezumt0d5hswfsp0w or Bisq.

Learn more

RoboSats learn.robosats.com
Bisq https://bisq.network/getting-started/ 
 I just learned that nostr:npub1j9qyxka5lck4tw50v7qfrs6gdwczz5ydt7ugqy6nhuva9p6dpy5q8rs2yg has sil... 
 nostr:nevent1qqsrkpakzlpu45vstjq25y4wk8nsv3pjc9kaqrz8js6q9cachcdujscpzemhxue69uhhyetvv9ujumt0wd68ytnsw43z7q3qtr4dstaptd2sp98h7hlysp8qle6mw7wmauhfkgz3rmxdd8ndprusxpqqqqqqz2ah68u 
 Why doesn't libsecp256k1 expose its internal sha256 implementation? 
 @Vitor Pamplona Perhaps npubs should be of a different color than other content. And, opening links to external pages should prompt the user with a warning. 
 Not Gonna Lie I hate how most Devs don't want to address this on the Relay protocol level and the... 
 @Gigi @ODELL @OpenSats


I think it is worth adding Tor natively into apps and not rely on Orbot. @Vitor Pamplona You have insight into this. What would it take to add Tor natively? What is missing? I know Samourai and Sparrow both have Tor and are written in Java. 
 The Tor foundation could offer some answers or guidance. Depending on what the friction points are, it might be worth funding something more streamlined. Like an equivalent of BDK, LDK, and NDK fordevelopers to integrate Tor.

Or, even just documentation on their end. Perhaps you gather a list of questions you have and ask other developers such as ( @jb55 @Mike Dilger ) if they have any Tor questions. Pass the questions to the people working on Tor and use their answers/guidance as a starting point for development docs. 
 If you upload a picture or video to a social media, do you expect geolocation and other metadata ... 
 Both clients and servers should default to strip. To include the metadata should be explicit opt-in. 
 On the bright side, as far as I can tell, no one who was using Whirlpool actually lost their mone... 
 Whirlpool coordinates the collaborative transaction between users. Whirlpool never takes custody of funds. 
 Uhh how the hell does nostr:npub12vkcxr0luzwp8e673v29eqjhrr7p9vqq8asav85swaepclllj09sylpugg do no... 
 This is what I found. It looks like Primal is using Strike.

Section 4. Sharing Your Information

"Primal’s Hosted Wallet Service is offered in partnership with our affiliate Zap Solutions, Inc. ("Strike"). In order to provide a legally compliant service, we are required to share your information related to the Hosted Wallet Service with Strike."

https://primal.net/privacy 
 I'm not familiar with the process. Would like to know more. Besides email, did you need to fill in any name fields? What are the payment methods? 
 Wondering if a prepaid card would work 
 Do you think a 24-word list is a way better to store/transmit your private key than our current n... 
 UI/UX split for new user or existing user. New user gets a fresh 12 words. Old user inputs 24 words/nsec.

Old user can choose to migrate after reading (UI/UX) warnings about what data would be lost if the user chooses to to migrate to 12 words. 
 You should push for signature verification to be implemented into Obtanium.

nostr:nevent1qqswehak0rjukxhxvne7908t4hlzx890tjfytwg3rp636hjhz7f0gvqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzp5x7h70mzt00s86r6lrfg2dm0pyp9tq7f5k48gszmd42cl4yk3nvqvzqqqqqqy7fjueq 
 Doxxed nostr:note10qutnwk6gt6h4wvddk6xutu90aqqethh0wvfaxsps2z4ut00e9cs64c2z8 
 Sorry to hear that.

@Vitor Pamplona @jb55 Nostr clients should have UI to warn the users that strangers can find their location and offer suggestions on how to mitigate such as VPN/Tor. 
 Route around and find a no KYC bitcoin seller to do trades with. I would recommend looking into the Bisq and RoboSats community. You can move off the platforms once you are comfortable with the trade partner. 
 I just tried to deposit some funds into nostr:npub1mutnyacc9uc4t5mmxvpprwsauj5p2qxq95v4a9j0jxl8wn... 
 You can choose from 3 formats (Unified, Lightning invoice, and Bitcoin address) when you tap receive.

Under the QR code, after tapping to receive, you can tap choose format. Many senders do not yet recognize unified. You will want to choose the Bitcoin address option. 
 @craigraw What do you think of automating subsequent downloads and signing? Like how Bisq does it. 
 Do Cash App now 
 I meant that he has Cash App on his nostr profile and is dunking on Strike for having restrictions 
 Easiest way to buy bitcoins? 
 WHY DOES BLUE WALLET SUGGEST FEES AND THEN SAY THE FEE IS BELOW THE MININUM? #ASKNOSTR 

SO MUCH ... 
 I highly recommend having an Android phone (preferably running GrapheneOS) so that you can use Samourai Wallet. I have found it to be the most stable, reliable, and enjoyable UI/UX wallet. 
 Say no to KYC. Use RoboSats @0a830eae

Learn more at learn.robosats.com

There is also Bisq https://bisq.network/getting-started/ 
 Yes. You can use Zelle for both Bisq and RoboSats. Bisq can also do money order and cash by mail 
 used nostr:npub1ex7mdykw786qxvmtuls208uyxmn0hse95rfwsarvfde5yg6wy7jq6qvyt9 to zap 21 sats on nost... 
 Say no to KYC. Use RoboSats @0a830eae

Learn more at learn.robosats.com 
 nostr:npub1getal6ykt05fsz5nqu4uld09nfj3y3qxmv8crys4aeut53unfvlqr80nfm when are you going to drop ... 
 Say no to KYC. Use RoboSats @0a830eae

Learn more at learn.robosats.com 
 What is your best way to buy #Bitcoin  KYC free? Trying to put a more thorough list together. ... 
 Stop asking for permission. Use RoboSats @0a830eae

Learn more at learn.robosats.com 
 Put more simply: you will only be able to request DMs sent by you or sent to you. 

This is a fir... 
 nostr:nevent1qqsr4akn4ueyyszm80fspje0f2nchwdek7nnezj7e8g7js4vmygctlspr3mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmqzyrye3ftnnuz00lljqtz5jc4227ptxnktzrt0j9dalht4s2trh7ghzqcyqqqqqqg8kyvmd 
 So I have started to get some small amount of bitcoins (via bity) and am thinking to save more of... 
 You can use RoboSats @0a830eae

Learn more at learn.robosats.com 
 Someone posted an image of my encrypted nostr DMs on Twitter. Of course I know that it's possible... 
 nostr:nevent1qqsr4akn4ueyyszm80fspje0f2nchwdek7nnezj7e8g7js4vmygctlspp4mhxue69uhkummn9ekx7mqzyrye3ftnnuz00lljqtz5jc4227ptxnktzrt0j9dalht4s2trh7ghzqcyqqqqqqgk3hfwa