Oddbean new post about | logout

Notes by llfourn | export

 That’s literally what it is lmao. I was testing what happens when you sign something with images with amber and chose something from my photo library that wasn’t a family photo and found WhatsApp auto-saved aunt calibre bible quote. 
 Caliber** 
 FIFO Sydney for cheatcode.co.uk panel: really disappointed I couldn't do the whole thing.

Hope t... 
 You’re going already!? 
 Bruh it’s the morning.
Good to see you on the panel anyways. 
 It's not looking good ethbros. I've been doing some technical analysis on ETH/BTC. It turns out that maybe ETH and all "utility tokens" have no fundamental value and it just took an unusually long time for the market to begin adjusting them towards zero. https://image.nostr.build/2e96c0592b32172d98e3427809a2406be4a778fa443e38f224380c5ecc4e63df.jpg  
 It's not looking ethbros. I've been doing some technical analysis on ETH/BTC. It turns out that maybe ETH and all "utility tokens" have no fundamental value and it just took an unusually long time for the market to begin adjusting them towards zero.

https://m.primal.net/LfZi.png 
 Just moved from android to iPhone. The only apps that were easy to move were the nostr apps. 
 Need to make frostsnap work with it so someone had to get one. Also very interested to see how the “””Apple Intelligence””” works. 
 Started reading this post. Decided to finish it in my first sauna for 10 years. Loved it. Inspired to try working this into my routine. 
 Technical nostr question: How come when I make a note Amethyst asks me to sign an event deletion. 
 ....what's a draft note? 
 Oh interesting OK. So this is broadcast and then you send out deletion for it when the draft is no longer needed?

It seems to happen even if I don't close a note though.. 
 Oh no just before the goldenbull run.
nostr:nevent1qqsfqh08sag9f3qgnzwa38ew8hjcv6wllxu4f962q9ya6qdrlg2nqcqpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsyg9e55m4ywa69lx6aptajrv2wcx7fusnnj0epkvx7aruulgwcrgh85psgqqqqqqspn79yl 
 Still waiting for the pro-kamala nostr corner to develop. Even Pro-trump is pretty weak here. 
 Making Bitcoin more private with CISA
https://youtu.be/HvI7NPI_Pk0

This is a very peculiar topic since CISA doesn't make anything more private. 
 Ah thanks. I didn't catch that idea in my skim listen. 
 ChatGPT downgraded me to the free version because of some billing issue and all of a sudden I feel...lonely? 
 You make an LN payment every single time? 
 Can anyone recommend some good nostr talks/podcasts that discuss technical goings on and explain architecture of nostr etc. 
 I tried to order one of these but I goofed the address, cancelled it and they wouldn't let me reorder because of item limits :( 
 How many people read me on Nostr? Should I post here more often? 
 I read you. No post less. I haven't finished reading your last one. 
 Thinking about opportunities for FROST and nostr integration.

1. It should be easy to generate a FROST key with a bunch of people on nostr. But this creates a new thing for everyone to back up (the key share).
2. Maybe we can avoid this with the recovery feature of the FROST keygen WIP BIP. Basically you have your share encrypted to a (smallish) encrypted blob in a nostr note so just with your nostr nsec it should be possible to recover it. Maybe there is some way to pay relays to keep a note into the future.
3. Apart from keygen nostr relays might be used to broadcast signature requests to notify people with other keys that there's something to do. Even an encrypted chatroom among share holders.
4. I'm not sure how this fits in with frostsnap. Frostsnaps could have their own npubs for keygen but I don't really want to back them up. So I think you'll be forced to write down your share backup as usual.
5. It would be good if signing was still one round so I guess presharing nonces would be done via nostr too. 
 popular opinion: the nostr conference was better than the bitcoin one 
 Any talks you recommend in particular? 
 I enjoyed participating in this episode. @NVK is great at bringing together the quiet builders and deep thinkers in Bitcoin.

https://fountain.fm/episode/EFkCsswzEAnxNwEcbUjJ

nostr:nevent1qvzqqqpxquqzq3s5ljpy3v3zkl9xe05xufpvfgw6p86ser4dmzwchuny06ss3c8ycyf0jq 
 Antiwar podcast is the best updates on the worst situations in the world.

https://fountain.fm/episode/02KHCQb6i3CuixwAcH3P

nostr:nevent1qvzqqqpxquqzq5tr72a7rglzg2vhpwxzfse87vtwpxkav6l3e2veen7ja6eg3gulexw2jg 
 Just read the "Dark Skippy" attack ( darkskippy.com ) from Lloyd Fournier and Robin Linux (h/t Al... 
 If the attacker has the xpub then it's definitely much easier and it should be possible in one sig. Your aglo looks right. You can also do it in a single address reuse.

https://x.com/LLFOURN/status/1733992948294181299

The reason we thought this attack was notable and worth disclosing is that it doesn't depend whatsoever on the user's behavior or precautions (i.e. not giving out xpubs). 
 Seed signer is easy to load malicious firmware on. It is also only possible to use it airgapped. It has everything to do with our point. 
 See FAQ: https://darkskippy.com/faq.html

24 words needs twice as many signatures as 12. 24 words with strong passphrase needs twice as many as 24 words without one. 
 Oh someone's working on FROST nostr already!

nostr:nevent1qqszlav4jw5wxl6mpn7n4w42la42en88ttzh3a4kjmzwy5jqtjtsseqpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygqhw9adf5sw9fp9eks2yx2kyjs2ffeufa5htuttzkflepl6gmedtqpsgqqqqqqs46rfr5