I’m wondering what vulnerability’s Nostr has and how it could be attacked. I suppose kicking it off the Appstore and Google Play would be the most obvious move. Any other ideas?

Reply to this note

Please Login to reply.

Discussion

Kicking clients of the stores is what I mean. Like Damus.

Again not trying to give any body ideas, but should we also worry about relays sharing data with advertisers for money?

Or ads on relays?

Good one. Time will tell I suppose. Curious where we are in 6 months and if it still is this clean.

Or worse sharing data with governments 🤦‍♂️

What data could they be sharing with governments that they don’t get from social media companies right now?

What ips are associated with what npubs ,then looking at their content to see if they shared any “anti government propaganda” 🤦‍♂️

Still, they can do that with Twitter, Facebook and Instagram as well. Difference is, they can’t cencor you or throw you off the platform because you will just hop on to a different relay.

There are multiple points of failures in this approach though, 1 /1000 relays compromising data, associated with a lot of the network vs 1/3 social media companies, it’s easier to keep the 3 companies in check.

There could be solutions to prevent this before it starts to happen though.

👇

#[3]

I don’t see this as a thread but as a strength of Decentralized Social Media

Decentralisation is definitely a strength, but we must work to minimise threats like these .

And on top, what data could they share that they can’t query publicly? It’s an open protocol and by open, I mean super open.

This👆

Also thanks for the 50 sat drops 💜⚡️

Cheers pal! Appreciate the interaction

What ip address does this nostr pubkey belong to. Which can lead to many other levels of identification, this isn’t queryable data on the internet.

#[0] any thoughts about this?

👇

#[1]

Biggest threat now is getting fresh blood and not scaring them off with global spam. No users = no growth no matter what we build.

Nostr for now is too techy for a lot of fresh bloods

What could be done to solve it?

I think by simplifying public and secret keys explanation, a lot of people I talked to only understand email and password as universal login credentials. A lot don't understand the importance of holding your own private keys, many willing to let big corporation take care of the private keys because it's too 'techy' for them. Global feed on nostr excluding spam only discusses technical stuff, those deter new users that I already tried to bring over. NIP verification also threw a lot of people off. That's from my experience so far.

Agreed, open source software are generally a little further behind in gauging the problems of the lay person. As in Linux Vs Windows. But they do give a platform for awesome products as in Android via Linux. As in the dream to make Twitter a nostr client someday.

Looking forward to that day realized 🫡

Onboarding experience is terrible.

The old kick it out of the app stores trick is harder with Nostr. While it would definitely slow adoption, unlike Twitter, Facebook, etc. Nostr web clients work really well even on Mobile. If enough people support the network, then they would use web clients and side load on Android.

As for relays being bad actors, I think of them like Bitcoin nodes. I believe this would be punished by the community instantly because even normie users dislike intrusive advertising. They have tolerated it to this point because the only other option was to not use technology.

Nostr and the clients being built on top of it are showing people there is a better way where value is exchanged directly between producers and consumers without rent seekers and government in the middle. I think it’s hard to put that genie back in the bottle when paired with freedom money.