Avatar
Cpt. Charisma
50f1e4619bac816a6cfcaf613a2d5b501d4635deceaafe21ed917c66e24f6aff
Niche Internet Micro Celebrity, Genius, Hacker, Cypherpunk wannabe, New Media Pioneer, International Arms Dealer, Clandestine Astronaut, Billionaire, Bitcoiner.

All the coolest people are the first to use revolutionary new technologies. The problem is that everyone wants to use revolutionary technologies. The solution is to make something new and amazing in a few years.

P.S. The Metaverse will never be cool.

Also, because he sold the chairs, so standing is the only option 😃

SeedXOR looks cool, but it is not widely supported yet. It also doesn't offer any redundancy or allow for requiring multiple people to sign something. I'm not sure what the advantage is vs. multi-sig.

Passphrases are okay, but offer less security than mult-sig.

One Time Pads can be very secure, but are not standardized. They also don't seem to offer advantages over multi-sig.

To save money, maybe you should drop your Wall Street Journal subscription.

An analogy will help. All Bitcoin and Ethereum addresses already exist for the same reasons. Here is an example with explanation:

https://keys.lol/

Looks good. What exactly does it use nostr for? It looks like all the articles are just linked to standard websites.

Replying to Avatar Derek Ross

**What the fuck is going on with Derek's private key - A recap**

TL;DR - This is long so I wrote a short summary at the top in hopes to help new Nostriches and noob Nostriches alike. Please share. Thanks.

1) Read what events you are signing with your private key. Do not just authorize the event because you initiated it. The client may be doing something that you are not expecting.

2) Do not allow websites to use your signing extension forever. You don’t know what they’re doing in the background.

3) Maybe don’t use Nostr.com as it will overwrite your LUD06 Lighting address on your profile.

—

Yesterday, one of my followers DMed me, saying that they bought me some drinks for my upcoming trip to Costa Rica! Awesome! I checked my Lighting node and I saw that 50 sats came in an hour ago. That didn’t seem right to me, so I asked some questions. We ended up determining that they sent sats to the wrong Lightning invoice address somehow. I noticed that my profile on Astral.ninja and metadata.nostr.com both had an incorrect LUD06 LNURL address. It was an LNBits address. I do not use LNBits. Something was definitely wrong.

I had been careful with my private key, at least I thought. After my first day on Nostr, I started using the nos2x extension and used it for everything. I didn’t authorize sites ā€œforeverā€ as I wanted to see when they would request read/write data with my keys. I used burner keys when testing various Android clients. I was very confused how this happened. I doubt my private keys were burned. I kept telling myself that this has to be a misbehaving client!

I started tracing my steps back. I had just used a brand new client, Ananostr, yesterday morning. I thought, could this client have done something accidentally? I signed in with nos2x and authorized the transactions as normal. The developer was super helpful here. He offered to take down his site and retrace his tool set that he used, to make sure nothing fishy was being utilized in his application. Thank you for your help <3

Today, using the nostr.band search tool, I saw that I had numerous events from January 16th to January 27th that updated my profile and changed my LUD06 address to a different LNURL. Something or someone was changing my Lightning tips address on my profile and I had no clue what was doing it.

I started looking at my Nostr post history and file download history. I had first tried Amethyst on January 16th. I had very little doubt in my mind that Amethyst could be causing the issue here, but you honestly just do not know. It’s scary entering your private key into brand new Android applications. Because of this fear, I used Amethyst originally with a burner account. Once I felt comfortable, I switched to my private key.

**After talking with numerous developers and plenty of Nostriches, I believe I have figured out what has been happening with my profile metadata and specifically, my Lighting LUD06 address. I also believe several mistakes were made on my part.**

About 10 days ago or so, I visited nostr.com and signed in with nos2x. I authorized the transactions and played around with the site for 10 minutes. I saw at the bottom that the site was built on Anigma. That freaked me out because Anigma was a site that was vulnerable to XSS attacks around December 20th. I immediately went into my local storage and nuked the storage for that site, deleted cookies and did not return to that site again.

Apparently, nostr.com automatically sets your LUD06 Lightning LNURL to an automatically generated lnbits.com Lighting wallet for you when you sign into this client. I did not know this. This overwrites any existing Lighting configuration on your profile.

**My first mistake was not reading the kind 0 event that popped up by nos2x**. I never read them. I always felt that if I was the one that clicked a button and generated the event, then it was safe to authorize it. If I had taken the time to read what was actually happening, then I would have seen that this client was making changes to my profile!

**My second mistake was then keeping nostr.com as an authorized forever entity inside the options of nos2x**. I remember adding it as authorize forever, because it kept popping up and annoying the fuck out of me and I wanted to get it off of my screen so that I could check out the client. I should have 1) not done this and 2) removed it after I cleared local storage for nostr.com.

One thing I do not understand though. How was this able to continue to happen over the last 10 days? Are relays just that slow to process events? Were these events re-broadcasted to new relays and that’s why this kept happening? If that’s the case, could someone go and re-broadcast an older profile metadata change event and change my LUD06 address back to this unwanted address?

I truly believe this is what happened and my private key is safe, I just do not understand how it continued after I stopped using that client. For now, I’m not abandoning this key pair. I think this is a large lesson for all of us.

A super special thank you to #[0] and #[1] <3

THANK YOU FOR HELPING ME FIGURE THIS OUT!

#[0]

Replying to Avatar Derek Ross

**Welcome new Nostriches! How do you find people on Nostr?**

Over the past few days I've seen a lot of people ask this question. They join Nostr, because they near how it's the place to be, the hear it's where the signal is at, but when they get here, they don't hear anything! How do you find people on Nostr? How do you find the signal that we're always talking about?

**Use pre-built lists of power users and signal boosters.**

* https://snort.social/new - This Nostr client comes with a list of Nostr power users to keep your feed always busy and allows you to search for and easily follow all of your Twitter friends.

* https://bitcoinnostr.com - This website consists of Nostr Users that are Bitcoiners. You'll recognize them from Bitcoin Twitter.

* https://nostr.directory - This website contains a vast directory of Twitter, Mastodon, and Telegram users that have connected their Nostr public keys.

* https://nostrplebs.com/directory - On this website directory you'll find familiar faces from Bitcoin Twitter and plenty new faces from Nostr. (Shameles Plug: I founded this Nostr services provider.)

**Find users inside your Nostr client.**

* Hashtags - If your client supports hashtags, I recommend you take a look at #Plebchain. This hashtag comes with plenty of Bitcoin Plebs and Nostr Plebs looking to connect with one another.

* Global Feed - Many clients include the "Global Feed" which allows you to easily find people that you're not already following. (Beware of spam.)

* Global Channel - If your client supports channels, you can check out the Global Channel in your client and new find people looking to chat and learn about Nostr together.

Do you have another way to find Nostr users? Shill it below so that others can find one another. Thanks!

If someone posts their nbub somewhere, most clients will allow you to search for it. npubs look like this:

npub12rc7gcvm4jqk5m8u4asn5t2m2qw5vdw7e640ug0dj97xdcj0dtlst0yztj