Avatar
semisol
52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd
👨‍💻 software developer 🔒 secure element firmware dev 📨 nostr.land relay all opinions are my own.

in a market where people don’t verify marketing claims anything can happen

well, technically yes

in practice no

And everyone keeps sourcing their SEs from a company (Microchip) which had made 3 revisions of their chip with only ROM changes and still has not fixed the root cause of flaws in the ATECC508A, 608A and 608B (used in a lot of HWWs) which is that there is no light sensors or self-terminate mechanism in the case of an attack

Their way of rating chip security is via the JIL rating system which is a very low bar to pass and involves the vendor coming up with their own numbers on how hard it could be to attack it, which they conflate with EAL5/6 because that is a lot harder and expensive for what is supposed to be an IoT SE nostr:note1upvg0s73kj57387rpq3zq55jm29fsrf838vnps79k3zzk3ypaldshhpnft

The inherent culture in this protocol means the people that have proper experience with large scale infrastructure are either not here because most of the devs are clowns, or they are here only for personal gain.

And without them you will never scale. nostr:note1nfsjr9kt4j58p43dac6djdrgnp0epwte5dv72jxw2dtk8tratr0q3s09v3

While developing an HWW, I have started to realize that 90% have no idea what they are actually doing and they think that adding a secure element is a silver bullet to all security issues

I’m working on some things that again need something more than a mnemonic… and arguably mnemonics are just shit, being a pain in the ass to implement in hardware

No. It’s some ordinals shenanigans. I should have checked the address histories more

Communities are needed but not when they centralize onto individual relays and everyone has to pay just to start one because they can’t use an existing relay by a friend or a public one

Actually if you hate manually going to their profile on Twitter to verify, there is a spec to link profiles on different platforms to Nostr and even PGP keys

That does not matter

We are verifying that their Nostr identity is linked to a known good identity (their twitter handle with a lot of followers)

If you can’t verify then don’t say shit I guess

The end result will be nostr getting a reputation for fake and scam accounts