Live data from Hacker News

Nostr

nostr.com

251–260 of 347 posts

Re: Nostr

#251
post #244

Earlier quoted context omitted.

I don't think you can say "this is complete nonsense" and "this has since been fixed" in the same comment. Also: don't use ECC signatures as MACs. Signatures are not MACs.

He says "this is complete nonsense" specifically about the statement quoted. Not about the whole report.

They're saying that about a concrete claim the paper makes that they concede in the next paragraph.

Re: Nostr

#252

Earlier quoted context omitted.

With "impossible" you mean you can't use Tor Browser and fire up Robosats to buy Bitcoin via Revolut or Wise?

What if I need to buy something on Coinbase Commerce?

That's like saying "what if I punch myself in the face, why does my face hurt?" Try different ways. Don't buy on Coinbase Commerce.

Re: Nostr

#253

Earlier quoted context omitted.

It is noteworthy that zapps are based on lightning (which is Layer-2 for bitcoin), and similar in privacy as monero (and instantaneous).

Does lightning work now? A few years ago, I remember they had quite some difficulties. Maybe I should brush up my knowledge.

[dead]

Re: Nostr

#254

Earlier quoted context omitted.

That's more or less how nostr works, except instead of websites there are notes (a generic type which can be anything - including website content), and instead of servers there are 'relays'.

Yeah the more I read about it, the more it does sound somewhat similar to what I was proposing. However, the copywriting there is not in this vein at all. IMO the metaphor of personal websites is a simple, universal one that most people can understand. Nostr seems unintelligible to anyone that isn't pretty technical.

Unfortunately there isn't a single good metaphor to use for novel thing like this. Some people would get the websites metaphor better, some people get twitter metaphor better, some people get "own your own keys" metaphor. People may be scared of doing their own websites and people have no idea what's involved in that... so help us find the right metaphors here :)

Re: Nostr

#255

The issue with all of these open social protocol is that they fail to grasp that they are built for entertainment, and hence the modulated emotional reactions are a feature not a bug.

Existing social platforms are built for profit, which modulates emotion for engagement (something kind of like entertainment, but I wouldn't say I'm entertained exactly by the rage bait I'm often fed by algorithms). Users of an open protocol might select for the same experience, or they might not, I think that's yet to be seen. This also assumes that this fantasy open protocol could also escape the pressures of maximizing profit.

Re: Nostr

#256

>apolitical communication commons Some people say that labeling yourself apolitical is 1, a polticial statement 2, a privilege itself which puts you into a certain socio-political position

I think the point is that nostr supports left wing, right wing, totalitarians, tankies, communists, lawyers, nazis, anarchists, javascript developers, liberals... everyone, without regards to their politics.

Re: Nostr

#258

Hope this doesn't come accross as rhetorical, it's a genuine question! Nostr users, how does this differ in your experience from Mastodon? At first glance it seems like the same idea but with the extra ingredient of blockchain, I'm not sure what this adds though, anonymity?

I was on mastodon, but the instance that was hosting my account got shut down, so I don't have my account anymore. That can't happen on Nostr. You need to make sure that you store your "private key" (sort of like password) safe.

Re: Nostr

#259
I love this:

>Nostr doesn't subscribe to political ideals of "free speech"

Under a tag that says “pro-censorship”.

I think I could maybe (?) imagine what they’re trying to say there, but “a lack of censorship is political and the presence of censorship is apolitical” sounds like something a person would say after a humongous bong rip of salvia or sustaining a life-threatening amount of blood loss

Re: Nostr

#260

Earlier quoted context omitted.

So, I was part of the Nostr community for quite a while and was the author of a popular Nostr extension for Safari, before eventually giving up on Nostr for various reasons. I haven't read that entire paper. Mainly, I skipped to the section you mention here: > The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (N…

If you read the entire paper you'll see that the paper presents a formalized set of security goals that acknowledge Nostr uses public keys as identities. They haven't misunderstood the system. Meanwhile: the cryptography is obviously unsound: it relies on unauthenticated CBC, and signatures that aren't verified, and provides attackers with the ability to coerce users into following links.

The cryptography was thrown together in the very early days as a proof of concept, that reached some level of adoption because of how nostr suddenly grew at the end of 2022. The community has since largely switched to a new standard (NIP 44) which has been independently audited, although there are some popular clients that haven't yet transitioned.
Post reply on HN