How concerned should I be that Jade isn't reproducible? Is this FUD or legit? #asknostr nostr:npub1jg552aulj07skd6e7y2hu0vl5g8nl5jvfw8jhn6jpjk0vjd0waksvl6n8n
Try rebuilding. The issue in their public issue tracker is open:
https://github.com/Blockstream/Jade/issues/26
I did not personally investigate yet. The diff Mohammad shared in our review looks hard to tell what to make of it.
But luckily holding off on hardware wallet updates is always an option. Just watch the issue and update once it's resolved.
If you already updated to this version, it's a bit more complicated but then, too, keep an eye on the issue. My bet is it will be found to be some benign diff.
I feel like nostr:npub1az9xj85cmxv8e9j9y80lvqp97crsqdu2fpu3srwthd99qfu9qsgstam8y8 added a space before his name just to piss me off.
Snort handles it interestingly. In the full mention, it doesn't chomp but in a shorter mention ... I had to check if it's the same NVK and it appears to be ... it shows just @NVK.
https://void.cat/d/XtoJ5ky9p5Mtuqe1FukeV4.webp
Also, to my surprise, the search when typing @ finds him flawlessly.
Amber looks easy enough to keep your nostr keys secure on Android. No more exposure of the nsec to all these apps you want to try.
I'm just not yet sure if I trust greenart7c3 ...
i dont find that
interesting tho you replied to me as i was just looking at https://github.com/Giszmo/NostrPostr/tree/master/nostrpostrlib
i have thought nostr needs more libraries, why have you stopped dev?
It started to get complicated I guess. The relay in that repo didn't work well and I did not primarily want to build a relay at the time. I then switched to doing a PWA which I later also gave up, too.
It's all open source, so if you want to pick up the slack ... I'm here if you have questions.
And if you now want to watch this movie, it's available here:
Why not?
If you merely want to refresh your memory on some video you have seen before, you might want to go x10. Not understanding most of the words would still recall all of the ideas in sequence.
Also there is speakers that are still very understandable *and* slow at x2.
That would suggest that half of humanity can do faster. If it were 95th percentile ...
If you don't know this 1967 movie, it ends with the professor fleeing from the vampire castle, by accident carrying a vampire with him on his sleigh. Highly recommended!
Twitter is full of very funny fake videos of lk99 replications. The fact that the tiny flake in the original video does not actually levitate has me very skeptical. We'll see what others will make of this. And the claim that this would instantly give us quantum computers ... I'm curious to learn why that would be, too.
I want an inline mention search feature much like Snort does it but ... one that actually finds all the accounts I follow, their follows and their follows follows. And it should sort by follows, too. Direct follows, first.
And then I want to be able to choose if the user gets notified and if the user should show up in the text, allowing to notify without mention and to mention without notification.
Currently in Snort I can use the @ symbol to open an inline search but it results in a notification. I need to know my NIPs to turn it into a plain mention without notification but snort won't let me do a plain notification at all. Astral does but it's discontinued I suspect, with no commits in months.
All of them ...
I think we need feature lists for nostr social clients and good names for those features.
Solved ... I'm constantly hesitant to "mention" accounts as nostr:npub1v0lxxxxutpvrelsksy8cdhgfux9l6a42hsj2qzquu2zk7vc9qnkszrqj49 's Snort still doesn't show if the mentioned account is the one I'm following or not.
But even if I don't follow them, I want a trust heuristic. Maybe show how many of my follows follow them.
That said, while mentioning Kieran worked, Snort doesn't find Edward Snowden even though I follow him. :(
That's a good question.
At the moment of analyzing it, nostr:npub1tg779rlap8t4qm8lpgn89k7mr7pkxpaulupp0nq5faywr8h28llsj3cxmt 's BitBox02 impressed me a lot as they put quite some thought towards using a so called secure element - a category of chip I had deemed evil for their requirement by NDA to not publish the code that runs on it - without the down-sides other hardware wallets have from using an SE. They only store a key encryption key on the SE and not the key itself. Neither do they trust the SE with the creation of the key's entropy.
nostr:npub1jg552aulj07skd6e7y2hu0vl5g8nl5jvfw8jhn6jpjk0vjd0waksvl6n8n 's Jade takes a similar approach - instead of an SE inside the device, the same security measure is done with a remote server. In both cases, the black-box nature of SE and server only adds to the security as the ultimate control of the funds cannot get around the published and hopefully audited source code.
In both cases, the backup is important as we cannot analyze if those black boxes might at some point just refuse to assist in restoring access to the private keys but so the backup is important in any other hardware wallet as these devices are not immune to breaking or getting lost.
For the other extreme - the most comically flawed - those are usually tiny projects with some hundreds of installs but I have seen products that are claimed to protect your private keys in military grade cold storage but also let you backup the keys where the question was if the provider openly had a copy of your keys, resulting in plausible deniability for both the user and the provider should funds move.
How long until the camera across the room can derive your pin from your body motion?
PIN is not cool.
"perfect" ...
Add these to the plus side:
* cheap ingredients
* trivial to make
but I'm not sure about the achievable currents and until this is peer reviewed, I'm waiting for some major catch with this anyway.
Oh, as a job it's probably boring as hell but you could charge grown men good money to play with this, following clear instructions.
$100 for 10 minutes. If you manage to sort things right, you get another 10 minutes for free. If you get into the top 10 percentile, you get another 20 minutes for free!
I reviewed literally thousands of Bitcoin wallets for https://walletscrutiny.com/ and at least half of the providers claim some superlatives about their products. It's so tiring to read lines like "the Most Trusted Name in Cryptocurrency™" on some product with 5000 downloads on Google Play.
That I can get behind. UASF has something of a liberation.
PSA: If you want to advertise nostr clients, provide a link. I come across so many mentions of clients and then would give them a spin if they were a click away but they are not and I don't know if .com .org .social ...
Also not all clients linkify any string that is a valid url. They need the https in the beginning.

