Avatar
semisol
52b4a076bcbbbdc3a1aefa3735816cf74993b1b8db202b01c883c58be7fad8bd
👨‍💻 software developer 🔒 secure element firmware dev 📨 nostr.land relay all opinions are my own.

that is lower down the stack so no

Replying to Avatar jb55

thinking of trying something out on my personal node, with a key on a secure element (and never leaving it)

would be a small USB dongle, could also use for auto-unlock with TPM

that would be the bottom layers

it actually does not use WS

🤔 Lightning node HSMs

One other thing I did was use OpenBao for managing FDB cluster configuration.

That originally started with TLS certificate issuance only, but I needed to manage JWT signer keys as well, and then I put some other configuration in as well that was not completely security related since I didn’t want to deploy a 2nd tool.

Planning to set up an SSH CA soon.

The NFDB/nostr.land code for example is managed on OneDev. Issue management is pretty great (I use it for non-code related tasks as well)

CI was extremely simple to set up, it starts a single-node FDB cluster and runs all the tests.

You need to use aggr.nostr.land alongside it.

There is still some functionality that is WIP like full support for profiles.

MongoDB should not exist

You can’t build it elsewhere either. You need to somehow find all users’ servers that might be following you.

new? nostr.land fully runs on FoundationDB, has been since NFDB deployment

unplugged one of the servers yesterday ;)

that is not the garbage collector

the inevitable rewrite is the garbage collector

I have no interest in being a free consultant for Coinkite, which is:

- actively selling users what in my opinion is subpar hardware

- had multiple chances to fix similar issues previously

- and is actively perpetrating attacks against OSS projects and competitors

If/when I do end up making a full write-up on possible supply chain attacks on a Coldcard along with a demo, they can figure out how to fix it themselves.

I guess my main question is compatibility with non-MS systems.

Good to hear you can easily use C libraries

It is unlikely that any Bitcoin-related organization would want to sponsor any of it anyway.

With the attitude I am seeing from many of the people that run these organizations, they would try to shift the blame to “why aren’t you doing anything about it.”

I have strong evidence that links Coinkite and/or NVK as the definitive owners of the domain names.

There are also domains they own relating to other projects, and name-squatting attempts at Nostr and Bitcoin related domains.

Currently, a Ledger Nano S with Sparrow. Not my preferred though.

I am working on mu own cold storage product that is built on a security-certified secure element with custom firmware on the SE.