Oddbean new post about | logout

Notes by anton | export

 I looked into it a bit. The biggest change is that my local card shop pretty much only does Comma... 
 Legacy is a bit expensive to get into but it’s my favorite format and there isn’t that much card rotation. 
 You can also just go do FNM if you’re into that sort of thing! 
 Can we do a version of Nostr where you follow somebody's xpub instead of the pub key? 

In that w... 
 The issue with exposing your xpub is that xpub + any child priv = xpriv 
 I was thinking in the context of nips 41 and 109, and around how to improve key safety. Imo master key should never touch a mobile device - if you don’t let the master key touch a mobile device or other low trust environment, but you do let a child key, then if you expose your xpub, it undermines the whole security model of having a well protected master key. 
 A more clumsy but functional option is to list child keys signed by the master key 
 I see. It still reduces the key security overall but I understand what you’re going for. 
 Any good matrix rooms for #privacy or #infosec?
#asknostr 
 You should check out our somewhat unusual distro https://codeberg.org/stagex/stagex 
 What’s the status of subkeys / revocations on nostr? Was the idea killed? Doesn’t feel right to not have a way to revoke a compromised key or the ability to use subkeys signed by a master key. I imagine the conversation happened somewhere, just not sure where… anyone have a link? 
 Hey been some time 🫂 
 I was just doing some testing on mobile nostr clients and it seems some don’t delete the npriv when the app is deleted. Please fix this if your client has this issue. @primal is one example. 
 iOS 
 Seems like a good moment to share this since GitHub is down. There are open source alternatives to GitHub like Codeberg and self hosted options like Forgejo and Gitea. In the spirit of decentralization and OSS let’s try to ditch M$ products. 
 Not that I’ve seen. I remember that there was a bounty at some point. 
 Is anyone in Canada looking to grab Ergodox blank key caps? I bought them by accident instead of the ones for a Moonlander. Can sell them for CAD $80 + shipping. 
 What are the best relays rn? 
 I just gave a friend an update on what Nostr is and showed a bunch of apps in the ecosystem. Show... 
 Definitely! One thing that’s been bugging me is the tribalism I sometimes see on nostr. We need a welcoming environment, not a condescending one. Let’s get more peeps in here 🫂 
 Congratulations! Looking forward to seeing more from your team 🫂 
 instagram allows you to voluntarily tag your content as ai-generated. ai still confuses a lot of ... 
 It’s a good idea. AI will keep getting better. It will become very difficult to distinguish reality from AI generated soon and in some cases it’s already tricky to tell them apart. 
 If you want to help build an off-grid and decentralized mesh network, check out https://meshtastic.org/ 

For $30-$100 you can get a node that has excellent range (sometimes up to 100km), and it doesn’t require a HAM license.

We have done a great job decentralizing quite a few things, and this is a great way to do the same for our infra.

Check out nodes globally using this map: https://meshmap.net/

I recommend this hardware: https://shop.uniteng.com/product/meshtastic-mesh-device-station-edition/ 
 I officially kicked Twitter today in the interest of supporting OSS and decentralization. I unfollowed everyone on there and pointed to Nostr and Mastodon.

Has anyone had success bridging Mastodon and Nostr? I came across Mostr but so far it isn’t working well. Seems like it would be a big win if we can integrate these networks more. 
 Maybe but at least it’s federated, and we can annex users from there. They are a perfect target for upgrading to nostr, and atm they have a stronger/larger community so finding a way to bridge them over is a win. 
 There are a lot of ideologically aligned people on Mastodon that left Twitter for a good reason. Showing them a better alternative would be great. I want people to have choice. If a subset of those users want to create their own relays and socialist them up - let them.

Outside of that, most of the infosec community moved there and I like to have access to that info as it’s relevant to my work so that’s a very practical issue for me. I’d rather have the problem of having to curate than not having the data available where I want it. 
 Basically the entire infosec community moved from twitter to mastodon, so I’m not sure where you were looking.

But anyways, you don’t think making it easier for users from another platform to come here by making integrations across them is a good idea? 

Btw I’m not trying to have a discussion with you about which protocol/platform is superior, we agree on that. 
 Sick deal. Thank you 🤙 
 I was looking at it but @openvibe seems like the thing I want 
 I mean.. who knows, but it certainly makes it easier. Good to understand that you aren’t interested in growing nostr though. 
 How do they compile the compiler nostr:note1vqlwwvzh8jzt8x64vah9694vzrntwh5lvyzmchxrypezzfzs28aqq... 
 Ohayo gozaimasu. 🌞 
 People come and go, #bitcoin stays 😉 
 Bitcorn is forever 🌽 
 Just cut a new release of StageX. It’s a fully bootstrapped build toolchain focused on determinism/reproducibility.  

https://codeberg.org/stagex/stagex

Best use cases are high risk environments where you want all of the software used multi reproduced with minimal deps, but you can use it anywhere you like, for example as a drop in replacement for alpine rust - which there is a nice example for in the readme. 
 Goedemorgen. Hoe gaat het allemaal? 
 Alles is goed. Werken aan een disaster recovery systeem! Jij bent nederlands? 
 Leuk! Ik kan spreek een beetje omdat ik heb in Amsterdam gewooned 
 Does anyone have an invite code for getalby? 
 No sweat, appreciate you 🫂 
 Thank you for the hookup! You da real mvp 
 Why do so many companies feel it’s okay to leak their user emails through the signup flow? AWS Cognito actually has this issue baked into their product.
https://m.primal.net/Jjil.jpg 
 Whew, thought I lost my key but past Anton did a nice backup 🤙 
 The Sovereign Individual by Davidson and Rees-Mogg feels like something Yuvel Harari would have written if he was smarter. 
 Totally. I really enjoyed both Sapiens and Homo Deus. 
 He just missed out on drawing so many “obvious” conclusions 
 GM! Going for a 100k step today for the first time. Hoping my legs don’t give up, because I won’t. 
 Heyo, thanks for the nice welcome! Unfortunately I only made it to 60k steps because my right foot got injured last week and that flamed up again but I’ll try again in a few months! 
 We started at 6am. You basically gotta walk all day. I bailed around 4pm, and my buddy finished around 11pm. 
 Stories like this are such a cool part of history and a look into the mindset that’s needed to bootstrap a new technology

nostr:note16zshe8wy034mnar9grc80cwtaj5qmkcyz49mdn6t4u4tn5rtc5tsaze2aa 
 Trying out primal. V-nice so far 🙌 
 3.125 
 We just released StageX, a containerized software build root, 100% auditable and deterministic, bootstrapped from 256-bytes of assembly. Every package is built, attested, and signed by multiple independent builders, and of course everything is open source. 

https://codeberg.org/stagex/stagex 
Event not found
 Isolating environments is the way 🤙 
Event not found
 Self-hosted FOSS is where it’s at 🤙 
 Absolutely, I always find it funny (and disturbing/sad) when people assume that proprietary closed-source software is more secure