Avatar
Bee Aye
524314bfcee6e82f86973ca054d2452a0cfd8a437e9feb9bb39403a5d1e30e55
Trying out nostr with no follows. just DVMs and client feeds.

well, this is via pokey. i use amethyst to post and all, but the notifications come in multiples for events via pokey.

some kinks to work, i got notified of this reply 8 times 😅

watched the witch last night, probanly will become my annual halloween watch. movie is scary af from start to finish.

#movies

i can handle that with a good explanation. alright i know what im doing ince the fam is asleep tonight 😂

yep :) although i get duplicate notifications for most things ...early days

does Pokey just solve notifications for nostr...just like that? is this what people talking about with building an ecosystem of clients with niche, spcific use cases?

#asknostr

trying pokey out, send me some things so i can see it work ? 🙂

#asknostr

Replying to Avatar hodlbod

**Security Update**

I've got some bad news for you guys. This morning, as I was adding error handling to flotilla, I discovered that Coracle has been sending user session objects to bugsnag when reporting errors.

Who is affected: Users who triggered an error in Coracle while signed in with their private key, since December 5th 2023.

What I've done:

- I immediately released a new version of Coracle, both to web and to zap.store

- I have deleted the affected apks from my releases

- I have deleted all my error data from bugsnag

- I have deleted my bugsnag project and rotated my api key, so lingering error reports will be dropped

- I have audited my code for use of the session object to ensure nothing else like this is happening

What you should do:

- If you're logged in with your private key, log out

- Hard refresh the page to ensure you have the latest version of Coracle

The bottom line is that if you signed in to Coracle with your private key, it has been shared with me and with bugsnag. In practical terms, your keys should still be secure, since they were sent over TLS, and have been deleted. But there is no guarantee I can offer that they are in fact gone.

I take my users' privacy seriously. My error reporting implementation doesn't record user IPs, it redacts identifying data, and it allows users to opt-out. I also warn the user when they attempt to enter an nsec into a text field. In this case, I simply screwed up, and I sincerely apologize. Reply to this note if you have any questions.

🫂

amber app should come with a 'sign in anonymously' function to make anonymous interaction/using burner nsecs on nostr standard to all clients.

#nostr

whats your one/ two sentence explanation to someone with no context?

is that new Bob Marley movie any good?

#asknostr

#movies