Avatar
espn βœ”οΈ
21b1b8c0e8f7647e4a668b87d42c0d044b6ca85f8e752bad1fb68479be4ac929
'If you're lonely when you're alone, you're in bad company.' - Jean-Paul Sartre -

πŸ‘€ COINBASE HACK WAS AN INSIDER JOB

Coinbase says a former support agent was arrested in Hyderabad, India

β€’ Breach happened in May 2025

β€’ Hackers bribed overseas support staff to misuse internal access

β€’ No code or blockchain exploit involved

β€’ Customer data was accessed (not private keys)

β€’ Attackers demanded a $20M ransom, which Coinbase refused

Now extrapolate to mobile operators, hospitals, banks and tell me your data is safe because we trust the bros that work there not to take bribes... πŸ€”

Can't wait to test this OS and/or the mobile, good timing too...

https://jolla.com

#Linux

#linuxOS

#Jolla

#sailfishOS

Done with 85K longs, now CEXs are going for the shorts at 92K...

Imagine a world with no CEXs, only DEXs... A world where bitcoiners do self custody and didn't trade/gamble their corn 🌽,...

#Bitcoin

#BTC

#Liquidity

πŸ‘€ Rate cut polymarket signal holding at 85%,

10 of December...

An usual catalyst incoming.

Those who sold #Bitcoin at 80K... Ouch

Where is the next stop? Will it be the ATH of the year?

#askNostr

#Bitcoin and the CEXs chasing liquidity game...

Cleanup shorts up to 89K, now chasing longs down to 85K...

Well USA has problems of their own but having the printing money machine for the most used currency in the world ( 60% of the countries currency reserves, going down but still the strongest), the americans will suffer, but less than the Europeans,

Example, job unemployment for the youth in Spain is above 50%, that is insane and on going for a decade, extrapolate to most european countries with lack of indistrialization and you get the picture, now expensive energy courtesy of inept war mongers have the few highly industrialized countries in Europe suffering, closing factories and moving abroad. The pain is just starting.

You want to move to EU...unless you are loaded, best not to

The mental gymnastics of the EU with their surveillance policies and most recently their military "build up" (read taxing excuse for the poor) and now "voluntary" military conscription (read it as propaganda and more decption to cover unemployment) to fight a potential war against the regional empire in 5 years (what a joke)

Those that do not realize the deception are way too naive...

Solution:

Keep buying #Bitcoin, it is a sale, goes a bit more down, so what, keep it off the CEXs, learn to be your own bank and safe self custody, DCA. Star progressively moving towards the #BTC standard, all currencies are going to zero against #Bitcoin

OPEN SOURCE IS MALICIOUS ACCORDING TO GOOGLE

Earlier this month, Immich's immich dot cloud websites were suddenly marked as dangerous by Google Safe Browsing. Users trying to access these sites were greeted with the fear-inducing "red screen of death."

If you didn't know, Safe Browsing is Google's service that looks to protect users by warning them when they try to access malicious websites or download suspicious files. The service is integrated into major browsers like Chrome and Firefox.

A single flag from this can make a website unavailable to most internet users

Do yourself a favor and opt out of everything Google

WhatsApp, a Messenger app that have become a default in some countries for daily communications. The lack of understanding from users is evident, but in my experience is more than ignorance,

is resignation, you explain the risk, they understand but keep using it for convenience or "need", choices, bad ones

https://www.trendmicro.com/en_us/research/25/j/self-propagating-malware-spreads-via-whatsapp.html

🚨 Apple on Monday backported fixes for a recently patched security flaw that has been actively exploited in the wild.

The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds write issue in the ImageIO component that could result in memory corruption when processing a malicious image file.

Replying to Avatar zk

Today, after a long discussion about best OpSec practices I thought it will be nice to share with the Nostr community, and read what others have to say about it,

There are many here in #Nostr that are #privacy advocates and believe they know enough, they use what they believe is a secure OpSec:

1. No corporate social networks, that includes LinkedIn or not sufficient decentralized ones (whatever that means for them).

2. No Messenger Chat app that requires a mobile phone number.

3. Linux of course; so they say; although the majority keep using iOS or Microsoft as their default OS... (I am guessing of course, but I am quite positive it is a good guess ... ).

4. A Pixel 7 or higher rooted with the right OS.

5. A VPN, one of the few that do not log (so they say) and you can pay cash or LN BTC or XMR. Most do this wrong BTW...

6. The right Private DNS, never a corporate one...

7. A private email address, so most will use Proton or Tuta... Odd how there are only few options with no KYC, if it is a niche, the fact that there are no more options is suspect, two companies only... they become a honeypot.

8. They use FOSS as much as possible for all their work and location apps.

9. GPS OFF as a norm. OpSec matters here, most people do this wrong.

10. A nonKYC eSIM with only data, few providers, silentlink being one of the favorites.

11. A powerful router with firewall and Pihole or adguard, plus built in support for VPN (most do this wrong)

12. Self hosted cloud, no commercial cloud never (most don't do this, they rely on the usual privacy oriented, the ones very well known, there are about 3...) Are you paying attention?

13. Their own BTC Node

14. A privacy oriented browser, there are not that many, Mullvad Browser, hardened with extension Firefox (requires work), hardened with extensions Brave. Most use the same extensions, for they are the recommend ones, Have you wondered why they are not built in already in the browsers?

14 Tor Browser for research, specially those that are devs or white hats... (no black or grey hats here, right...)

16. Keeping all your software and OS for all devices up to date, which is recurrent workload, failing to do that could lead to exploits and exposure to cybercrime.

And more, but this is a simple summary.

Now the best part:

All of the above, makes you, in a way, a target, for your digital footprint is of a minority, easy to identify, you are decently informed and therefore you follow the same rules and use the same tools as the rest of a small tribe, a very distinct one, not that hard to identify with the right tools that constantly analyze metadata.

Is there a better way?

In my opinion, yes.

1. If you keep your current OpSec, study and do it right, most do it wrong and generally due to lack of discipline and endurance of the annoyance of cyber security, which is very inconvenient, end up being not only known targets but vulnerable high end targets.

2. To be part of the large noise made by the clueless normies is the optimal play but that is an OpSec very few will have the discipline, time and knowledge to do correctly. Won't discuss the know how here. Hire a #cybersecurity expert if you want this and don't know how is done.

What are your thoughts?

#asknostr

Excellent post ZK, thanks for sharing

Welcome!

Few things you should know:

1. get a check mark in Nostr, there are few options, I suggest nostrcheck.me , once you get it, edit your profile and update your Nostr-Address, not having it will hide you in some clients

2. follow hashtags, a good way to find like minded people

3. think of your nsec as your Bitcoin private keys, act accordingly

4. chose a client that respect your privacy, meaning, you can sign in with a Signer protecting your nsec, it has TOR built in and above all, you can manage the relays you use. I suggest AMETHYST

5. add your lighting address in the profile so you can get zap, few options out there, I suggest MINIBITS for most people

6. last, don't marry one client, keep your options open, you achieve it by having your Nostr Address from one service and your wallet independent from your client, when you want to test another client you just configure your Nostr name and wallet on the new client. The client you are using may already be one that censors, one that is centralized...

have fun!

Welcome!

Few things you should know:

1. get a check mark in Nostr, there are few options, I suggest nostrcheck.me , once you get it, edit your profile and update your Nostr-Address, not having it will hide you in some clients

2. follow hashtags, a good way to find like minded people

3. think of your nsec as your Bitcoin private keys, act accordingly

4. chose a client that respect your privacy, meaning, you can sign in with a Signer protecting your nsec, it has TOR built in and above all, you can manage the relays you use. I suggest AMETHYST

5. add your lighting address in the profile so you can get zap, few options out there, I suggest MINIBITS for most people

6. last, don't marry one client, keep your options open, you achieve it by having your Nostr Address from one service and your wallet independent from your client, when you want to test another client you just configure your Nostr name and wallet on the new client. The client you are using may already be one that censors, one that is centralized...

have fun!

Welcome!

Few things you should know:

1. get a check mark in Nostr, there are few options, I suggest nostrcheck.me , once you get it, edit your profile and update your Nostr-Address, not having it will hide you in some clients

2. follow hashtags, a good way to find like minded people

3. think of your nsec as your Bitcoin private keys, act accordingly

4. chose a client that respect your privacy, meaning, you can sign in with a Signer protecting your nsec, it has TOR built in and above all, you can manage the relays you use. I suggest AMETHYST

5. add your lighting address in the profile so you can get zap, few options out there, I suggest MINIBITS for most people

6. last, don't marry one client, keep your options open, you achieve it by having your Nostr Address from one service and your wallet independent from your client, when you want to test another client you just configure your Nostr name and wallet on the new client. The client you are using may already be one that censors, one that is centralized...

have fun!

nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd68yvfwvdhk6tcpz9mhxue69uhkummnw3ezuamfdejj7qgswaehxw309ahx7um5wghx6mmd9u2mk7fe, maybe Amethyst own repository for F-Droid solves the F-Droid non sense...

Others have done as Samorai Wallet used to and nowadays Session does as well...

If people uses F-Droid they are savvy enough to add your repo.

Solid, IMO, SimpleX is still the better choice, but the fact that Keet Chat is serverless 100% is quite appealing.

SimpleX uses relayers, your metadata is sent to relayers and, after is received, the metadata is deleted, keetchat does not use relayers at all is 100% p2p and encrypted e2e. This seems quite appealing but it does add a reliability factor, your messages will stay in your device pinging the receiving party until delivery, this decreases efficiency and could be a negative factor in battery consumption, more test is required.

Spain going further on it's fascist controlling agenda, it's people have shown repeatedly they will not push back no matter what is done to them and the political class continue to squeeze them with more control and more taxes.

So many people wants to live in Spain, hint... don't

https://euroweeklynews.com/2025/04/28/planning-to-withdraw-cash-in-spain-you-could-now-face-a-e150000-fine/