I'll be shocked if nostr:nprofile1qqs8suecw4luyht9ekff89x4uacneapk8r5dyk0gmn6uwwurf6u9ruspzpmhxue69uhkumewwd68ytnrwghszxthwden5te0wfjkccte9eekummjwsh8xmmrd9skctcpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhs2juazd made any moves to remove. I asked if he'd be willing to step down after the BTCClock debacle and even the suggestion was too much for some people last year.
NVK would be a crybaby if trademark law was used to rightfully take down his infringement though.
I must be fair here, the risk is way lower than you think.
Buses like USB and NFC are pretty simple under the hood and arenât the cause of attacks.
Usually, it is the OSâ fault for trusting any device what it is (like a keyboard), or trying to go too fast, using things like DMA which if misconfigured can be exploited.
On microcontrollers it is pretty easy to audit the entire stack.
It is impossible to execute an attack via USB/NFC/whatever alone and requires either a high attack surface by the firmware developer or a backdoor.
The Frostsnap device has no secure element and my interactions with the authors make me feel like that they do not fully understand security.
Their security model is the same as assuming a paper backup.
There are ways to exfiltrate data through a QR or SD card airgap. SD card is easiest; write to hidden blocks.
QRs can be modulated in other ways such as delay time, intentional error faults, or other choices.
There is also the fact that anything that exists emits EMI, and the Coldcard is no exception. This can be abused to create signals that contain your seed + can be detected at quite a distance using a box the size of a Pi.
The secure elements in the products have had attacks done on them several times. The maker of the SE chips only released incremental updates that do not fix the fundamental flaw.
The original company that made the SE IC is long defunct too. Itâs like maintaining an old codebase with no one around.
There are also several critical flaws in the design of the Coldcard that allow undetectable supply chain attacks.
Itâs not devs. Itâs shitfluencers that are building a walled garden so they can sell you their overpriced products
Not all blossom servers are capped at a 100MB upload size limit, only some. Albeit, some do start to struggle with handling larger file sizes, I think as a result of hash calculation? But, I could be wrong on that and I think nostr:npub1ye5ptcxfyyxl5vjvdjar2ua3f0hynkjzpx552mu5snj3qmx5pzjscpknpr is working on optimizing the protocol for handling larger files.
There is a simple solution
Chunking
First I need to finish my documentDB
Like, you could have an aggregator relay that lets you filter by language.
Don't know, if nostr.land has considered something like that. He's working on an AI-translation service, so nostr:npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj has the tech stack for it.
There is a suite of relay.events relays coming up đ
Meant for public use funded by donations. NWC, signers, ephemeral events, relays for devs.
it was registered 8 months after SeedSigner the project and intentionally redirected to a fearmongering site
Time for the occasional disclosure:
1. I have not signed any agreements that restrict me from sharing my own opinions.
2. I have not accepted any form of funding, donations or investment that had conditions, written down or informal.
3. I am the sole operator of this account and all content posted here is solely mine.
nostr:note1atm5f3m5rgmpwe6kflft962c0dfpxrnudqz02lgtu6dlawqtq56s6hps25
Though many influencers canât say who did it because they have been forced to sign non-disparagement agreements in exchange for đ°
Because there is no push notification needed to wake up the app
NWC and built in wallets are the same speed. They both send requests through a server.
That is because when you zap Primal users from Primal it is just changing a number in a DB. And more use Primal than not.
I also think that they show the zap symbol first, and the zap happens in the background
Yes to wake it up for a few seconds
It also is the only way it can actually work
The amount of domains I have found is at 11 and that is only 50% of TLDs checked.
Follow/mute based social graphs are more useful as interest.
WoT does not represent trust, but it does provide *some* information about the quality of the content being decent.
But it doesn't mean it isn't AI generated slop, for example.
That doesnât mean I have to put my standards in the NIPs repo. Amethyst for example implements several Damus specs that are not NIPs and somehow it still works.
the beauty of Nostr is that you can do that right now yourself
The reason it says that is an extension that could access the website JS could also log your passwords, âread your historyâ by logging every visit, etc.
There are entire accounts here dedicated to stealing content that earn more zaps than many Nostr devs.
The uploader tool you are using is the cause, I have not been able to reproduce this issue with yt-dlp
For certain tasks the local/cloud LLM gap is still large.
Considering the costs of maintaining my own server if I only use it 1% of the time, plus the value of my time, I do not care enough to run many things locally.
You seem to be busy asking ICANN for permission to get those IP addresses of yours, while completely not realizing ccTLDs exist...
Primal and Damus are charging fees for their services just like Synonym will start charging people money to host their own homeserver or get extra premium hosting or some crap.
At Nostr.land I charge a fee to host content. Like it? Pay for it. Don't like it? Self host your own, no one forces you to use a paid service
at most 3 hashtags
or if hashtags are generic and redundant at the same time
Communism works when all actors are ideal and do not have an incentive to abuse the system, aka never
Not to mention there will always be underperforming people and those need to be selected out by some means. Fairness and equality are not the same
You use a search tool to find books.
You go to a library to read the book.
If you care you add it to your own collection as well or share it with your friend group.