Live data from Hacker News

Flare, a video sharing site built on Nostr

njump.me

161–170 of 214 posts

Re: Flare, a video sharing site built on Nostr

#161

Earlier quoted context omitted.

Although i have heard of SQRL [1] which purports to be a frictionless way of securely logging in with public private key encryption. I've never seen it discussed here though so I'm unsure if there's significant downside [1]: https://www.grc.com/sqrl/sqrl.htm

This sounds a lot like passkeys https://developers.google.com/identity/passkeys - I'd be interested to see a more thorough comparison of the two. Both of these do a challenge-response style authentication with a particular website, and wouldn't really work as part of a decentralized system. You could use the same signing key ordinarily used to sign authentication challenges to sign nostr notes, but then you're back t…

SQRL is indeed pretty similar to passkeys. It was just invented before passkeys (before WebAuthn even) and designed to work without requiring any new web standards or changes to the existing web browsers at the time.

That greater compatibility came with some UX trade-offs though. Now that passkeys exist and are widely supported by web browsers there's really no need for SQRL anymore; passkeys are a far more polished version of the same concept.

Re: Flare, a video sharing site built on Nostr

#162

Earlier quoted context omitted.

> Which practically means unanimous agreement is needed among all relays in order to moderate anything. No, it means that the people will tend to congregate around the relays that work according to what they expect/want to see. You are thinking from the assumption that things are only acceptable if total compliance is enforced. Even on the highly-controlled and regulated Internet there is still abhorrent content out…

> The interesting question is: do you think that the majority of people don't see this side of the internet because of how effective the centralized control and policing is, or just because the majority of people are not interested in seeing this content in the first place? Both! Most people don't want to see beheading videos and would be very upset if one came across their Youtube recommendations. Fortunately, YouTu…

The point that I am trying to make and I am not sure you are getting: if we take the decentralized system as the Internet and the different social Networks as "relays with autonomy over their own content", isn't that already an example that that each subnetwork gets to enforce the policies that their own communities value?

The problem I am taking with your view is that shows a not-so-subtle hint of totalitarianism. It tries to use the abuses caused by people with freedom to justify that we all should lose our liberties (or accept that global subjugation to a common set of rules as inevitable.

Yeah, currently all platforms that promote "censorship-resistance" are predominantly used by those who got affected by large -scale censorship. Yeah, most of these people are doing or saying despicable things. But that should not be an argument to make the case that centralized platforms and worldwide gatekeepers are the best solution.

To repeat: you keep arguing like the enthusiasts of decentralized platforms are "anti-censorship", when in fact the fight is about claiming back some sense of autonomy and agency to let people be able to do the moderation/curation themselves (or to someone closer to them who understands their values and social context better)

Re: Flare, a video sharing site built on Nostr

#163
post #7

Congrats on launch! Login button: 3 times I see the word "Nsec" without any explanation, that would lose a lot of youtubers from transitioning But a bigger issue is that googling about nsec tells me it's a very bad practice: "Some argue that the user should never enter their nsec into an input field at the risk of being compromised by the service. Given the nature of nostr, users cannot recover from a leaked private…

It is correct that it is bad practice to paste an nsec, but a lot of nostr services allow it. The login DOES support "login with extension" which is far preferred and much safer. Your private key is stored in a browser plugin and is not transmitted.

Experienced Nostr users will understand this, but I totally agree with your point about making it easier for non-nostr users. Also, they should (at least) strongly encourage people to use a browser extension / wallet instead of pasting their nsec, and provide a guide on how to do that and why.

Re: Flare, a video sharing site built on Nostr

#164

decentralized anything never works at scale, this is what all the techie founders never grasp. what happens if someone uploads a child porn video or cartel beheading video on your website? because of your algorithm ll stack things by watch time it ll get to the front page in no time. What measures/controls do you have because your site explicitly says "we can't strike, shadow-ban, or demonetize you just because we di…

> decentralized anything never works at scale I'm pretty impressed by this thing called 'the internet'.

The internet isn't really decentralized and realistically it cannot be.

Submarine cables are owned by companies, T1 ISPs provide the majority of routing and you really cannot prevent any of this.

Centralized control is somewhat required because submarine cables cost money and transit costs money and small companies simply do not have the capital to do that.

Re: Flare, a video sharing site built on Nostr

#165

Earlier quoted context omitted.

It's so off putting I wouldn't touch it with a ten foot pole. I wouldn't even curiously browse a landing page of an otherwise interesting project beyond the point I notice that something is mildly "cryptocurrency-adjacent", or it becomes obvious that it has involvement from devs who also enjoy working on blockchains. Thanks for the heads up.

Can I ask why? Beyond the "crypto grift," a blockchain-based social network might offer some benefits: - permissionless - (no moderation) - means for auto solvency - (we are not the product) - interoperability - (multiple clients, forks, etc.) - privacy

You can't brush off the "crypto grift" though. That's the sticking point, and it's a very big one.

Re: Flare, a video sharing site built on Nostr

#166

Earlier quoted context omitted.

There's a reason why social logins, magic links and SMS login codes are so ubiquitous now - end users want 0 friction getting into their accounts. This increases friction beyond what is currently common practice. No, the public doesn't want nor care about using a key to log in.

Does public key necessarily have to be high friction? Couldn't there be a few-step UI similar to "Sign in with Google/Facebook/etc"?

For People who are already familiar with metamask, "Sign in with Ethereum" is so easy that makes people wish it was universal. It is even easy to generate new identities on demand: generate a new address/public key is literally a one-button operation.

The only thing that bugs me about is that is actually all your identities are still tied to same master passphrase, so if that gets compromised all of your identities get revealed.

Re: Flare, a video sharing site built on Nostr

#167
post #39
post #11

Earlier quoted context omitted.

> “Given the nature of nostr, users cannot recover from a leaked private key and must take greater precaution than they would with a username/password combination.” This is a complete dealbreaker for any end-user product. I don’t understand why crypto/blockchain fans still think it can work.

ah physical key has the same properties and end-users seems to have been accepting that just fine for hundreds of years

literally not at all similar to a house key

Re: Flare, a video sharing site built on Nostr

#168
post #71

Heads up, I have "block newly registered domains" configured in my NextDNS site, so I can't resolve flare.pub. For the future, might be good to register the domain a little while before the launch to avoid this.

Wasn't aware this is a thing. Thanks for the tip.

Re: Flare, a video sharing site built on Nostr

#169
post #90

I don't even know how to sign up... lol there's an "nsec" field which i have no clue what it is there's a "connect with nsec" button which again, i don't know what it is. and then there's "login with extension" button which does nothing.

Yeah, onboarding could use some love. This happens a lot with Nostr projects. It's built by Nostr nerds for Nostr nerds and to them "nsec" is super obvious. They really should NOT ENCOURAGE PASTING NSEC as it is not secure and explain how to generate an nsec and how to use a browser extension / wallet to log in.

Re: Flare, a video sharing site built on Nostr

#170

Earlier quoted context omitted.

Email is decentralized. The client provides the spam protection and moderation.

Email is a fantastic example of something that's technically capable of being decentralized but in practice has something like 70%+ of all traffic handled by three major companies (Google, Microsoft, and Apple). No one can stop you from making your own email client and using it, but your emails will most certainly get black holed and discarded as spam by most major services much more frequently.

Well it's still decentralized and scales in that there is significant competition participating in an open protocol. Even though most use the big 3, many smaller players have enough legitimacy to be whitelisted by gmail, e.g. fastmail and protonmail. But for fully custom, sure gmail is annoyingly aggressive these days, but it's not a black hole, the emails still send and more importantly receive. Does anyone other than spammers send cold email? I usually am receiving or replying. When I do send cold, it's to someone who is expecting it so they will check their spam or already have me in their contact list so it doesn't go to spam. It's not for everyone or for all situations, but fwiw I've found it very useful to exercise the fully distributed nature of email for personal and professional reasons, so I would still defend it as a fair example of a distributed protocol that scales :).
Post reply on HN