Avatar
semisol
52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd
👨‍💻 software developer 🔒 secure element firmware dev 📨 nostr.land relay all opinions are my own.

People do not view the state as a problem too, so they are unlikely to care either way

on the topic of signers what if you had a signer that was a security key

many corporate backed OSS projects fall into two categories: products, or “standards”

products almost always get rugged with BSL or some other license anyway, example MongoDB, ScyllaDB, Hashicorp stuff

“standards” are one company having a problem, solving it, and open sourcing it in the hopes they get other adopters

this then gives them free contributions

examples are FDB, a bunch of the forks like OpenTofu/OpenBao, Kubernetes, Envoy, etc.

Cashu may as well be a signed event, like zaps.

LNURLW is not proof (it is an offer to pay, not proof of payment)

I just remembered that I reported an SQL injection vulnerability to LNbits on March 2022 and they did not release a fix until February 2023.

Compared to for example SeedSigner with a hypothetical FROST implementation with paper backups, what would be the benefit of this device?

Spend limits sound cool, but they can’t be securely enforced without a SE. And not a simple PIN-protected secure memory, but one that can run arbitrary code.

Also, how is key reconstruction handled when changing for example the quorum size?

A lot of media hosts do no moderation. So that fails.

You need to design for a hostile environment and you can trust no one unless you have reasons to do otherwise

nostr:npub1n0sturny6w9zn2wwexju3m6asu7zh7jnv2jt2kx6tlmfhs7thq0qnflahe’s Nostur is the only client that worked for me on E connection

The time it takes to implement an API-key based solution, which has the same trust level as Cashu, while being easier to use is 1/3rds. That also includes being able to withdraw any credit you don’t use.

I had been working with Cashu since the early days, but the start of people misrepresenting it, and the crappy mint software quality made me quit.

(There were no DB transactions, for fucks sake!)

You could make a lightweight LN implementation that adds a slight bit of trust (for in flight payments, and provable disputes) but is still mostly self-custodial to run on them

Devs of Nostr:

What would you do with a secure element that is easy to write software for, required no NDAs and had an open source development toolchain?

(Please renote for visibility) #asknostr

Help please nostr:npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj nostr:npub18ams6ewn5aj2n3wt2qawzglx9mr4nzksxhvrdc4gzrecw7n5tvjqctp424 I signed up a while ago on NostrPlebs but now I'm getting a "blocked" when using your relay - see 2nd photo. The info in the 1st photo is correct. The only thing changed since sign up is that I changed from Alby to Coinos. How can I get this fixed?

#asknostr

Try editing your profile and to then remove a character, ensuring you are writing to Damus and nos.lol relay. Then wait 10 mins

This will be improved pretty soon

Sounds complicated until you try to store TBs of events cached all across the world, while maintaining high throughput, low cost, and supporting features like SmartCache and IA.

So yes, you can dump TBs of (public-domain) books into it, and it won’t care.