zap.store is in the works sir 🫡
This is hilarious
nostr:note1lhxc9sr6rz88p8v5lgayksdasyypf8wj959n5wss8fn2f6kdg77snje5dm
Fascinating conversation about software integrity verification on the latest bitcoin.review pod
There is a huge issue with phishing specifically with apps like nostr:npub1hea99yd4xt5tjx8jmjvpfz2g5v7nurdqw7ydwst0ww6vw520prnq6fg9v2's Sparrow Wallet.
nostr:npub1qny3tkh0acurzla8x3zy4nhrjz5zd8l9sy9jys09umwng00manysew95gx suggested adding a known set of hashes in a trusted place and enforcing TOFU (trust on first use: all versions have the same signer) to Sparrow which would help mitigate attacks during updates.
Shout out to nostr:npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft for bringing up zap.store in the conversation! I'm building it to fix this exact problem: verifying packages stored anywhere using webs of trust. Trust is inherently social so the nostr social graph is a perfect fit.
And agree with nostr:npub1az9xj85cmxv8e9j9y80lvqp97crsqdu2fpu3srwthd99qfu9qsgstam8y8 that current app stores do serve a purpose, curation and reputation will always be important, but having a free market for it is just as important.
For those interested I wrote about this topic at length: https://stacker.news/items/404908
nostr:npub14slk4lshtylkrqg9z0dvng09gn58h88frvnax7uga3v0h25szj4qzjt5d6 here are some thoughts on the problem
Our privacy eco-system is flawed
Developers sign binaries with PGP keys, but we trust Microsoft’s Github and government domains to deliver to us accurate public keys to begin with. This means we’re trusting the very mediums of communication that we’re encrypting against, large Big Tech cloud firms.
Getmonero.org is on Cloudflare, linked to a Github PGP key. The same Github that took down Tornado Cash in a crisis. The same Cloudflare that hazes Tor.
Whonix.org and it’s Public PGP key are on Hetzner, the same cloud company that compromised an XMPP server at the request of the German government.
KeePassXC.org is on Cloudflare, please, I got everything I own in there
BleachBit.org is on Cloudflare, c’mon mate, I’m deleting sensitive data with root access
There must be another way.
Now SimplifiedPrivacy.x will offer an uncensored free public directory of PGP keys for popular open source software on IPFS using unstoppable domains. This will act a neutral third party verification tool, not tied to a physical location, like traditional domains. Anyone can compare the PGP keys on the IPFS site to Github binaries and confirm a match. There’s no sacrifice made, since the developer’s original website still remains.
How Unstoppable domains work is that an Ethereum wallet updates the DNS record to an IPFS website file, outside the reach of government control because it’s not bound to a physical location. Now I dislike Ethereum. And know a lot of my readers also dislike Ethereum, but keep in mind that you don't need to touch ETH to look at this website and anyone buy Unstoppable domains for Bitcoin. They just use Polygon for the DNS...
Because it’s visible to everyone on the Ethereum/Polygon blockchain when the domain is re-assigned, and then visible to the IPFS network when new files are pushed out, it makes quick trickery with PGP keys more difficult to disguise.
I reject government domains as a legitimate source of truth, and I stand for the principle of encryption as identity. Now you can verify with an uncensored third party and not trust the infrastructure of our enemy. You can check our guide on how to use IPFS with Brave Browser:
https://simplifiedprivacy.com/ipfs-brave-browser/
I love you & I won’t give up,
SimplifiedPrivacy.x
I'm working on a solution to this problem leveraging nostr
You're right, you said it in your comment above. I don't know what I read.
it used to be the idea behind highlighter.com if I'm not wrong? nostr:npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft
People with a cheese "addiction" have health problems and their body craves it to compensate for a lack of some nutrient present in there. Of course, that Domino's junk is not even cheese
Cheese (or even sugar for that matter) is not addictive or cocaine-like, there's a reason the body is asking for it
so food quality doesn't matter as long as you keep a calorie budget?
This is why America has an obesity epidemic.
https://video.nostr.build/041dd8afc2bf1bbb8b7263991f417163adf1d26f75cc4763097a99932fd45719.mp4
Yeah, because that is not real cheese. All that "food" with a brand in the USA is fake
the taliban shutdown the queer.af domain, killing the queer.af mastodon instance. users of the queer.af mastodon server just lost their entire social graphs. nostr is different. nostr is superior in this regard. if a nostr relay or client operated on the queer.af domain and the taliban shut that down, users could just start posting to a different relay or start using another client, continuing their social usage with just a little bit of a hiccup. nostr is truly decentralized and truly censorship resistant.
https://www.404media.co/taliban-shuts-down-queer-af-domain-breaking-mastodon-instance/
who would've guessed...
piped is better! Invidious is good but hits google servers directly
So many developers giving their private keys to Microsoft
What could go wrong

OPEN SOURCE HAS A BIG MONETIZATION PROBLEM AND WE WILL FIX IT

Things getting weird in Argentina, and Milei standing his ground
Another great update by nostr:npub19ahgq780mhas2kxrx9q4s9gtxe5pfpch0g666ypjrxxme3nzhlzsfcxn5t
nostr:note1tp5luc2g5ddmfdha5tgf8tfqss24r2ysvavrt7kqhewrzmvh3zjqxvzyrv
use nostrudel or primal
Apple is against us even before starting 😂
