Avatar
Lady Mae - Growth Teacher
5729ad991a7e0cb88971ced2348758105790d51160a09b22d0d8f39ca762de11
Mental Wellness Coach and Hypnosis Practitioner | Explore Provocative Ideas, Challenge Perception and Grow Your Mind's Eye. I am a work in progress and I am excited to share my journey with you. Let us grow together! 👌😀❤️ Free Online Hypnosis 👉 https://tinyurl.com/3fpht299

nostr:nprofile1qqsyawyrzrttfmv4cmtx5w2m85702kdct7hv3amfrkhagpdf9cz46mgprpmhxue69uhkv6tvw3jhytnwdaehgu3wwa5kuef0qyghwumn8ghj7mn0wd68ytnhd9hx2tcpydmhxue69uhkv6tvw3jhytnwdaehgu3wwa5kuef08ankcmmzv9kr6ctvds20l3q3 - I am not sure who to reach out. I wonder if you know or have tested whether or not the nostr keystore like nsec.app or amber is not vulnerable to cache hijacking? Ty ☺️

@gel I would be very sad to see you go 😔. I guess Melvin already mentioned a possible long-term solution.

Let's try to do some process of elimination and some house keeping. If you already know this then ignore me. 🫂

1.) Have you figured out whether your nsec has been stolen? If yes, what made you believe so? Eg, have you seen any post that are not yours perhaps?

2.) a.) If not, perhaps it is impersonation. Therefore, we need to create a web of trust for you. Perhaps a secret word that only you and your connection would know. However, this would require you to have a different method of sharing this secure word or phrase exclusive to your trusted friends here. This maybe a tricky one but it is possible.

b.) Use a keystore like nsec.app or amber for android clients (I forgot the name for iOs) to login to nostr clients. This keeps your key secure. Think of it like a second auth. When you login to nsec.app or any keystore, it will ask you to store your nsec there. You need to have a master key of that keystore so every time you login to any nostr client, you will use a random link to login and you have to approve the connection — which client you want to approve. It is important to renew cachr and avoid re-using permission cache. I'd suggest to refresh it when using the web. To keep it safe from cache session hijacking (have not tested this theory yet). This is to make sure you are only allowing the client you granted permission to access specific client. You can customise what each client can do and cannot do.

3.) Use VPN and Password manager. On top of the keystore, it is best practice to always encrypt your traffic on transit (VPN). Password manager is putting all your keys and passwords, secret phrase encrypted online and offline. There are so many trusted vendor out there. I used Nordvpn for 7 years now.

4.) Encrypt your mobile phone and laptop.

If you need to jump on hivetalk to help you with this, let me know! 👌

Keep us posted! ☺️

To clarify, I have not tested or seen the cache jijacking theory using the keystore. #asknostr has someone tested this yet?

Replying to Deleted Account

Top o the morning nostrovians 🥳⛅️

This will be my last post from this specific npub

At this point, I am sure that a Minimum of 3 different actors have access to my nsec through exploits of my systems. So you’ll just have to trust my voice/pen right now.

A bit of a wild ride but I’ll try to explain…

The day Brazil banned X, I came to nostr. My favorite AI engineer content builds from Brazil.

My legacy socials have been shadow banned for years (roughly 2021). I’ve largely stepped away from the online world… but recently revived some socials to help friends out with their content. They are athletes, not computer whizzes. We mostly live in the dirt. Off grid as possible.

Motorcycle racing is a difficult industry and it’s costly… so when I arrived at nostr I immediately fell back in love with IoV. I used to contribute daily to projects like nostr. In fact, we used to have something like zaps on another platform but it got banned due to the regulatory crackdown of us in 2020. We were suddenly a “bank” and that was confusing when it came to KYC on centralized platforms. Weitse Wind is an incredible mouthpiece for kindness in this space and he waded us through an absolute mess. I’ve had great mentors. I owe them a lot.

Whenever I build a platform, I imagine it as a service to others bc I genuinely try to live by a service to others mindset. Hence open source projects

So, I follow a prototype to scale model… this npub is an outlier.

I started nostr from a computer but as I looked at the source I got scared for onboarding my friends and family. We’re still trying to digest 2FA in that world.

So I created a proof-of-concept… I didn’t realize it would scale this quickly.

I onboarded as though I know nothing about encryption. so I used my real face and a lot of other really real details. Also, some not real because I knew I was in a pit of vipers. We all are, on the internet, always.

I literally pasted my keys to a word doc… I built this as sloppy as I know my loved ones would. And then I downloaded the apps to my phone. And along the way tried to explain what was happening… I didn’t touch any code and I only changed a relay once, but I’m pretty sure at one point my real human IP was banned.

And here we are… multiple people have control of my account. You all have no way of knowing which signed events are actually a match to my face. You’ve witnessed both the burning of my books and a witch hunt in real time. And all of this data is stamped in history as though it is me. At the “block” level.

Proof-of-concepts are helpful because they give us visuals and immersive experience. Measure twice, cut once.

My next profile will be me in full authenticity, but those keys will be secured with biometrics.

Thank you for coming my extremely confused TedxTalk and namaste. 🙏🏼

@gel I would be very sad to see you go 😔. I guess Melvin already mentioned a possible long-term solution.

Let's try to do some process of elimination and some house keeping. If you already know this then ignore me. 🫂

1.) Have you figured out whether your nsec has been stolen? If yes, what made you believe so? Eg, have you seen any post that are not yours perhaps?

2.) a.) If not, perhaps it is impersonation. Therefore, we need to create a web of trust for you. Perhaps a secret word that only you and your connection would know. However, this would require you to have a different method of sharing this secure word or phrase exclusive to your trusted friends here. This maybe a tricky one but it is possible.

b.) Use a keystore like nsec.app or amber for android clients (I forgot the name for iOs) to login to nostr clients. This keeps your key secure. Think of it like a second auth. When you login to nsec.app or any keystore, it will ask you to store your nsec there. You need to have a master key of that keystore so every time you login to any nostr client, you will use a random link to login and you have to approve the connection — which client you want to approve. It is important to renew cachr and avoid re-using permission cache. I'd suggest to refresh it when using the web. To keep it safe from cache session hijacking (have not tested this theory yet). This is to make sure you are only allowing the client you granted permission to access specific client. You can customise what each client can do and cannot do.

3.) Use VPN and Password manager. On top of the keystore, it is best practice to always encrypt your traffic on transit (VPN). Password manager is putting all your keys and passwords, secret phrase encrypted online and offline. There are so many trusted vendor out there. I used Nordvpn for 7 years now.

4.) Encrypt your mobile phone and laptop.

If you need to jump on hivetalk to help you with this, let me know! 👌

Keep us posted! ☺️

I can 💯 relate. With the information overload, I noticed that knowing one self and going inward has never been more valuable. You cannot lie to those who are in tune to their inner self. ☺️ I never you get it right all the time. It only means to trust your gut even more. 👌

Love the "useless degree". I met some people who define their identity based on their education or number of qualifications as if it is an automatic evidence of success or merits financial freedom. 😔

#asknostr #occultstr

❓👁️ Is your third eye open? Or do you believe in "sixth sense"?

What was your vivid recollection or experience that led you to believe your sixth sense had been activated?

Share your stories 👇

#paranormal #creepyencounters

#asknostr

⚠️Have you ever been scammed in your life?

👉In hindsight, wjat do you think the reason why you fell to their bait?

Share your stories to raise awareness. 👇 🫂

#noscammers #scamvictims

Replying to Avatar purrs_for_Her

lol

omg 🙀🙀🙀

you ladies are so kind~!

nostr:npub12u56mxg60cxt3zt3emfrfp6czptep4g3vzsfkgksmreeefmzmcgsuye0ve, i'll consider it. maybe something shorter, though—this is something i've just started trying. thank you so much for the feedback~! ^__^

nostr:npub1n0pdxnwa4q7eg2slm5m2wjrln2hvwsxmyn48juedjr3c85va99yqc5pfp6, and thank you, too~! 😻😽

i have another short story that i posted awhile back, when i have a chance i'll post it as an article.

💜💜💜💜💜

tsk tsk tsk no pressure. we will wait LOL 🤣

#asknostr

When was the last time you stop consuming a product or services after you learned about the company or individual's values?

Simply put, you found out their marketing propaganda and you said, nah, I am not giving my money to this sh*t!

Name the brand or examples if you can. ☺️

Thoughts #nostr?

#consciousconsumerism