Oddbean new post about | logout

Notes by Vitor Pamplona | export

 im gonna prune my relay list tonight
nostr:nevent1qqsq5zhvp0xkelk33vly8awfq063zkx8629el04qfkp605d... 
 Today's amethyst still depends on more relays because of the legacy model, but that will change soon.  
 My next goal is to get users to reduce their relay lists from an average of 20 to 3. 

You don't need to trust 20 relays. You just need 1. But 3 adds redundancy in case 2 of them are busy at the same time.

And remember: Relays can see what you are looking at in real time because the app is requesting the post, likes and replies from them as you scroll. They can even count which posts captured more of your attention. 

So, make sure you trust your relay operators.

GM. 
 All of them, just keeping nostr.wine and my relay.  
 The general section, and thus the relay recommendation section, won't even be there.  
 No. And if you use Tor, then not even your IP is available.  
 That's why I said 3 :) 
 Which note?  
 The app received 4k times as post that was duplicated. 
 Humm.. because it is spam, it will not be cached locally. So, if you are going back to one of the hashtag views, it will keep asking for it. I will check when I get back home  
 Nashville and Memphis couldn't be more similar and more different than one another 
 nostr:npub1gcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqlfnj5z any chance for a more satis... 
 I just don't know how primal can be sure it's going to work before running all those steps. Maybe they just assume it works even when it doesn't? 
 Jesus, the new progress bar component for Android is completely borked. 
 It's more like Google changing the component without telling devs kind of bad design.  
 nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd... 
 On the general list, yes. You can click on the arrows. The outbox and inbox lists have their own rules. Outbox/Home relays are always read/write, inbox is always read and write if the post tags you.  
 Hello nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daez... 
 Yeah, we try to avoid it, but sometimes the AI just overrides the process and translates the link itself. Happens here and there on the Google translate web version as well.  
 My hastag follows keep getting wiped out in #amethyst. Is this a known issue or is it just me? 
 Do you use any other client? Clients that don't implement hashtag following will clear it as soon as you follow somebody over there.  
 TIL that Gossip supports private lists and Amethyst supports viewing public lists (not private no... 
 Hum.. strange, we have been decrypting private lists from listr.lol for years now.. I will check if there is a new bug in it.  
 nostr:nprofile1qqsxwfs62yctaz9km9wm6254pg5ac2s6y06rzk67g0n0e05xc6v4megpzdmhxue69uhhwmm59e6hg7r09ehkuef04zyx3t nostr:nprofile1qqs84tl4j6zmhwut9l20yaav40yev066du79k2v29gccmw3wqyh6ytsppemhxue69uhkummn9ekx7mp03ne8rt nostr:nprofile1qqs9nla7rlyznhk0jpj4gw9a9he60d6xaa9qgc6dfm579q9mdnjlznspr3mhxue69uhkummnw3ez6vp39eukz6mfdphkumn99e3k7mgpr3mhxue69uhkummnw3ez6vpj9eukz6mfdphkumn99e3k7mgpremhxue69uhkummnw3ez6vpn9ejx7unpveskxar0wfujummjvuvp3kft

https://image.nostr.build/a8ae9e3dd0e5fb8068fe2d12e2d92ebff80ecb85de2f4b6e3dfdb1c945479461.jpg 
 Fixed! 
 So sorry. 
 nostr:npub1acg6thl5psv62405rljzkj8spesceyfz2c32udakc2ak0dmvfeyse9p35c At one time I was able to s... 
 Humm.. I don't we I have migrated yet, but I did add the parser for nip04 and NIP-44. There might be a bug somewhere. I will check. 
 Wen eCashApp nostr:npub1ds3hmzemzgp9rsuvyvxqdk0y3uxnq9m903dktjxrvyfwk9w99t4sc2hzcn 
 Wen Nostr-based eCash App nostr:nprofile1qqsxcgma3va3yqj3cwxzxrqxm8jg7rfszajhckm9erpkzyhtzhzj46cppemhxue69uhkummn9ekx7mp0qyvhwumn8ghj7un9d3shjtnndehhyapwwdhkx6tpdshszyrhwden5te0dehhxarj9emkjmn9atgqhm? 
nostr:nevent1qqsdzqrf8z3gu2dv0vx55qzgzaslm0qpt9nn46pqujwkqj8scp95yhqppemhxue69uhkummn9ekx7mp0qgsr9cvzwc652r4m83d86ykplrnm9dg5gwdvzzn8ameanlvut35wy3grqsqqqqqpxlj9d7 
 Under the security settings, I'm unable to view my blocklist, spammers, and hidden words list in ... 
 Using Amber or with the nsec directly into amerhyst? 

I am hunting for this bug. It's some form of decryption that went wrong.  
 nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd... 
 We did it.  
 If my bitaxes win a block I will zap 3,125,000 sats to my frens 🐸 
 Before or after paying income tax? :) 
 Has anyone built something along the lines of a solomining collective with BitAxes along the line... 
 Isn't that what pools do? 
 NASHVILLE, I AM IN YOU. 
 Landing in 1hr. 
 I am trying to video record how slow Tor is on a plane, but the loading is faster than me pressing the button. 😅 
 It's noticeable, but barely. 
 Interesting. Is your ISP or VPN blocking Tor connections?  
 Did we give up custodial nsecbunker providers? What else do we need on that front? nostr:npub1l2v... 
 More stable Amber support for NIP-46  nostr:nprofile1qqs827g8dkd07zjvlhh60csytujgd3l9mz7x807xk3fewge7rwlukxgpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhszrnhwden5te0dehhxtnvdakz7qgswaehxw309ahx7um5wghx6mmd9usjfpck and a desktop signer to do the same. 
 I am not sure if it's a good use of your time.

But if you want...  
 Using Tor for everything at 30,000 ft. 

Cool. 
 I thought this was an Ad. 

I was like WTF. What did I do? Which library is doing this? WTF!  
 NoStrudel needs nip17 (private DMs) support! There is a bounty of $300US so far to get it integra... 
 Decrypt all from the past week. Then load the week before as the user scrolls the list down.  
 ? How does any of this lead you to a Cybill attack?  
 Sure, but that's just spam. It's true for the whole of Nostr and the old nip04. Any key can send you a DM. 

But a Sybill attack is about using fake identities to gain majority power. The fake identities on Nostr don't give the attacker extra power/influence in the network.  
 Correct. Which is great if you don't want servers censoring you. :)  
 Did you know that NIP-17 was designed to keep metadata private even if devs make mistakes in their apps? 

Designing a DM protocol where you control the server and app on a single codebase is very different than designing something anyone can code flawlessly from scratch.  
 Why do banks on a business account provide excel export and then use different number formats in ... 
 Devs are never competent. 
 We are starting a trend.
nostr:nevent1qqsp9x0qf3tgj8qj4qqwyd8w0mszqec49ck098u7z7mmf7te7huvqagpz9mhxue69uhkummnw3ezuamfdejj7q3qye5ptcxfyyxl5vjvdjar2ua3f0hynkjzpx552mu5snj3qmx5pzjsxpqqqqqqzg0gyhc 
 This is why you must add DM relays to your list... The incognito becomes active by default and no one can see who you are talking to. 
nostr:nevent1qqsx8g553v99e6559lrg9sa6vv79spfl7mutgsnlydpkp7a8vw4a5ecpzemhxue69uhkummnw3ex2mrfw3jhxtn0wfnj7q3q64r4kfyyre2w2yy85zdsvlyk8xl2rj99xqjk4r65zfvfeqycu8zqxpqqqqqqzpyvsmq 
 If the incognito icon lights up, you both are good. 
 That's great. The reporter deserves it. :) 
 If it wasn't, the 0xchat is not setting the DM of your friend per spec. Or there is a bug somewhere.  
 Either way, Its not a good idea to not know which relay is being used if the DM relays aren't there.  
 0xchat, amethyst, Coracle, gossip and Coop 
 Get him to add DM relays to his account.  
 Yep, the incognito will light up if the receiver's DM relay list can be found.  
 SimpleX servers know more about you than DM relays. 
 The protocol uses channel IDs and generated keys that are visible to the servers. Those can be used to track you around. Especially if both users use the same server, which is common for the default setting of the app.  
 Zaps are identifiable. If they start using zaps, most of the privacy is gone.  
 In theory, all NIP-17 implementers must use it. At least 0xchat, amethyst, coracle, gossip, coop use them.  
 No idea. I think they use their own relays when the DM relay is not set, without setting the DM list for the user. Which is bad, imo.  
 Are those things the default now? Last time I check they were still opt-in. And since most of those servers were been run by the same entity, in practice people can still be traced. 

But yes, this is way better than their version from last year.

Do you know why they decided to not use Tor sessions to do proxying and masking? 
 To me, servers should not even know which messages go in which queues.  
 Yeah, that's a major problem to me. The company should not even run any server. It's too easy for court orders. 
 This is why you should use a private dm relay 

nostr:nevent1qqsx8g553v99e6559lrg9sa6vv79spfl7mut... 
 And giftwrapped DMs. 

All of those are NIP 04.  
 Recent direct message activity:

nostr:npub1v7k63c6y2vktlqhsuupywt3yc7ykursujc34at964f9cv9s9y9csj... 
 This is why you must add DM relays to your list... The incognito becomes active by default and no one can see who you are talking to. 
nostr:nevent1qqsx8g553v99e6559lrg9sa6vv79spfl7mutgsnlydpkp7a8vw4a5ecpzemhxue69uhkummnw3ex2mrfw3jhxtn0wfnj7q3q64r4kfyyre2w2yy85zdsvlyk8xl2rj99xqjk4r65zfvfeqycu8zqxpqqqqqqzpyvsmq 
 Anyone using #nostr or #amethyst lost all of his bookmarks? 
 So you didn't lose all bookmarks but only the ones from the last 2 days?  
 Ohh yes. Most definitely the list got deleted at some point or the relay that had it got busy, was offline and didn't send on time. Then Amethyst started a new one when you added a bookmark.  
 Reminder that if you are using DM relays like inbox.nostr.wine or auth.nostr1.com and no other relay for DMs, you are so private that our own Push Notification system can't see your DMs to send you those notifications :)

We haven't figured out a way to allow push systems into that level of privacy yet. 
 I don't know... People already complain we use too much battery today. Keeping a service running will definitely make things worse.. 
 Interesting. Maybe we can start to develop it to see how it goes. 
 If only those two relays are there, we don't even know when you have a new event. :) 
 Ohh yeah, I need to implement the dynamic markers thing...  
 We have embed tor that reason. If people want they can protect themselves. 
 We did operated a proxy. But then I realized that I not only had all the locations for our users but ALSO all their image and content requests. And I could easily associate both. The proxy doesnt only knows your location but know what you are looking at in real time. 

To me, the proxy is WAY worse from a privacy standpoint.