Avatar
Sid Shattuck
72f22deb08d9767c250aaab1979ebb46eaea08c86d9ac4c59e476f68545fa81a
Lightning network enjoyer Mentor at The Bitcoin Mentor

#GrapheneOS version 2024050300 released.

This update contains various hardening additions, fixes Google Fi eSIM activation (again) and changes OS infrastructure to prepare for an upcoming App Communication Scopes feature.

See the changes:

- remove special handling of the resolver activity ("Open with..." dialog) which was added to Android in order to support instant apps as preparation for our in-development App Communication Scopes feature

- fix Google Fi eSIM activation

- improve isolation of the eSIM activation apps

- improve GrapheneOS infrastructure for per-app state

- enable heap memory tagging for vendor processes by default, remove the user-facing toggle in the Settings and restrict toggling the value to debug builds

- disable most handling for instant apps in the package manager as attack surface reduction

- disable out-of-band APEX updates as attack surface reduction

- only allow first party app source and shell to update system packages

- improve robustness of original-package handling

- Settings: hide GNSS SUPL and PSDS settings on devices without GNSS hardware

- fix regression from our Android 14 QPR2 port causing Storage/Contact Scopes link to disappear after going back to the permissions screen

- improve setup wizard theme to more closely match the stock Pixel OS configuration

- backport mainline APEX module patches for Android Health, Media Provider, Network Stack, and Wi-Fi

- kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.212

- kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.150

- kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.80

- Log Viewer: use human readable UTC time for logcat timestamps

- GmsCompatConfig: update to version 109

- Vanadium: update to version 124.0.6367.113.0

- Apps: update to version 23

- work around our app repository client taking ownership of updates for the debug toggle we use to test new Android Auto releases

- fix debug build option for testing same versionCode package updates

Thanks final!

Complete long shot but any chance this ever gets addressed upstream do you think?

https://github.com/GrapheneOS/os-issue-tracker/issues/2927

Can anyone point me to a good resource outlining the bear case for DIDs?

#asknostr

Replying to Avatar JeffG

E2EE DMs are coming to Nostr 🔒

After being nerd sniped by hearing nostr:npub1az9xj85cmxv8e9j9y80lvqp97crsqdu2fpu3srwthd99qfu9qsgstam8y8 mention OTR for the millionth time on the Bitcoin Review podcast, I spent the last few weeks digging into OTR, the Signal protocol, and a grab-bag of other cryptography.

The end result is that I (am pretty sure at least) that I found a way to do E2EE (end-to-end encrypted) DMs on Nostr in a way that is both forward and post-compromise secure AND doesn't require any centralized servers.

Demo video: https://share.cleanshot.com/nMKk6cn0

Live demo app: https://drdm-demo.vercel.app

And finally, the NIP (for those of you with bikes in need of a shed): https://github.com/nostr-protocol/nips/pull/1206

Huge thanks to nostr:npub1klkk3vrzme455yh9rl2jshq7rc8dpegj3ndf82c3ks2sk40dxt7qulx3vt and nostr:npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft for the chats while I worked out the details.

Damn this is exciting. Thank you for your work

Replying to Avatar Samson Mow

Keep calm and HODL #Bitcoin.

Everyone seems to be overreacting to the Samourai arrests, the FBI PSA, and Phoenix leaving the US. Here's my attempt to break it down.

Samourai

You have to unpack all of the different elements. Could this be a state attack on self-custody and privacy? Maybe. Probably not.

There are a few components here that need to be evaluated on their own.

1⃣ Samourai was a self-custodial wallet

2⃣ Samourai was a mixer

3⃣ Samourai was providing normal people with privacy

4⃣ Samourai were knowingly marketing the service to criminals and flaunting that fact

Reading the charges, it seems like #4 is pretty cut and dry for this case. Their getting arrested for #4, doesn't automatically mean #1, #2, #3 are under siege as well. If Samourai was a taco stand laundering money and bragging about it, I'm sure they would be taken down too.

They may be accused of running a money transmitter now, but that may or may not stick. We'll find out in the trial.

All that said, we should always be vigilant to attempts to erode privacy and the ability to self-custody. It just does not seem that this fight is *that* fight.

FBI PSA

Seems pretty normal that the FBI would advise people to use compliant services, and the entire announcement seems to revolve around potential disruptions due to Samourai being taken down, and potentially others in the future. Given they took action, they have to post some bulletin about it.

Remember that when people lose funds or have funds stolen from them, they do go to the FBI for help. From their point of view, the best thing for people to do is use compliant services where they can potentially help.

The announcement concludes saying that services that purposely break the law will be investigated - so again we go back to #4 above. This is nothing new, and self-custody is not being criminalized.

Phoenix Leaving

As nostr:npub1sg6plzptd64u62a878hep2kev88swjh3tw00gjsfl8f237lmu63q0uf63m said, it's feels completely unnecessary. Phoenix obviously is not a MSB and they are not doing anything illegal. In my view, their exit from the US app stores is a complete overreaction.

Keep Calm

Could "they" come after wallets, developers, mixers, nodes, LSPs, sidechains, eCash, VPNs, encryption, etc? It's totally possible. But if you're not breaking the law, you have nothing to worry about.

To my knowledge, there is still rule of law in the US, property rights are still protected, and privacy is enshrined in the Bill of Rights (nostr:npub1trr5r2nrpsk6xkjk5a7p6pfcryyt6yzsflwjmz6r7uj7lfkjxxtq78hdpu).

It would be very difficult to change the law or stretch it to incriminate these things because it's all just information and software, which is speech. Some will try. But as they are trying, #Bitcoin is becoming more and more mainstream and integral to the world's financial system.

#Bitcoin is freedom technology and it will continue on.

Go outside this weekend and think about why you're here.

Important to note that Samourai were also charging a fee for the centralized coordinator service they were providing. Multiple references to this in the charges.

In the meantime, is there still a way to send from the ecash federation? Send UI appears to default to lightning channel.

Or elect to receive into LN beneath the 200k cap?

nostr:npub1t0nyg64g5vwprva52wlcmt7fkdr07v5dr7s35raq9g0xgc0k4xcsedjgqv, nostr:npub1u8lnhlw5usp3t9vmpz60ejpyt649z33hu82wc2hpv6m5xdqmuxhs46turz, nostr:npub1mutnyacc9uc4t5mmxvpprwsauj5p2qxq95v4a9j0jxl8wnkfvuyque23vg how does one go about transferring to lightning balance from an eCash federation?

I have plenty of inbound capacity but cannot find a way to do this in the UI.

I'm using Android APK latest version.

It's either Prince or MJ. There is no third best.

There have been a few of these apps over the last few years - most of them abandoned by the devs.

This is a fork of one of the originals and is still in active development.

Replying to Avatar calle

People told me that this episode of Citadel Dispatch with nostr:npub1qny3tkh0acurzla8x3zy4nhrjz5zd8l9sy9jys09umwng00manysew95gx was what made it click for them.

If you've been sleeping on Cashu and Chaumian Ecash in general, give this rip a listen. We go into depth of what this tech means for Bitcoin.

https://serve.podhome.fm/episodepage/CitadelDispatch/cd120-bitcoin-powered-chaumian-ecash-with-calle

Really great episode Calle, thanks for all your work.