Avatar
Josh πŸ‡ΊπŸ‡²
598e1ab9fd57ade0a7fe0d6f47c2f3b9557191f670587b9b51262203c591453c
Tech Enthusiast

It really depends where though. I lived there for 5 years. Don't miss it.

Maybe the whole world needs to get with the program 😜

This is my argument. Bitcoin is a store of value. A fancy scheme (someone has to buy the top to make my value go up). No one takes it day to day at least north of Costa Rica. I view it as a high yield savings account. Good for storing savings and cashing out when you need them. Not good for every day transactions.

A lot of drama in here these last couple of days.

Is this for everybody or something you did? I haven't seen this prompt.

Sounds like it's a good time to come visit Japan.

Created a random burner email on Outlook. Never used it on any service. Login today - 91 spam emails. How???

What's up with all new movies/shows having the darkest scenes possible? It's almost impossible to watch anything during the day. Even with the brightness at 100% all I see is pieces. Seems like the art of scene lighting is dead.

Immaculate was the absolute worst movie I've seen all year.

No I'm talking about using the same account on multiple phones at the same time. If you go into a "secret" chat (encrypted) it only shows up on one device. They're not doing it like WhatsApp yet where it relays the messages.

They could dump every message onto a file just like Snapchat if they wanted. I'm not talking about encryption in transit. So their claim that they're secure and private is bogus.

Interesting that they don't enable encryption by default 🀣

I was watching it and I'm like "ok guys, if you guys die, the captain, pilot, chief engineer, and doctor are all dead. Who's in charge of the other 3000 people alone on the ship?"

My biggest problem with the Star Trek universe is that every episode basically involves the Captain and other Senior Officers abandoning the entire crew to participate in some risky life or death escapade.

Replying to Avatar Luxas

Let's talk #phishing on #nostr

The art of the catch is in being as deceitful as possible and mimicking something familiar that your target takes the bait.

Nostr clients (at least the web ones) allow you to login to someone else's account as read-only mode.

You can see their notifications and even see who has messaged them. It's even possible to know who the target replied back to, as standard message bubbles give it away.

https://imgur.com/a/uraDw64

Of course, the contents of messages cannot be read, as they're encrypted.

But, if you're farming for victims to pwn, and you see they DM'd an "influencer", it'd be easy to create a clone account of the influencer, register a near-match domain, get it NIP-05'd and then send your targets a DM.

I'd venture to guess not many (at least not many of the technologically inept) would take the time to validate the pubkey.

It would be great if there could be some sort of secondary auth for viewing notifications/messages when in read-only mode. Not the privkey, but a password or something else only the account owner would know.

This way, the account can remain in read-only mode without the ability to sign messages, but the things that should remain private, stay private and less susceptible to being used as phish bait.

As the saying goes, "trust, but verify". Stay vigilant #nostriches and ensure whoever DMs or replies to you is really who you think it is. There will always be malicious actors, but you can prep to combat them!

This is the one thing I hate the most about Nostr. The fact that there's no real privacy when it comes to messages. Especially when you get messages from random people and they keep stacking up with no way to delete them.