Avatar
vesc
8675d87c375d9bbffb76c1bc549e6ed4ed0da95e6f240aa434bc9b1bd9b8cee7
Technologist

I think it's hipsters crying. I have used systemd for a long time now and wrote a lot of service scripts. It rules all major distros in the enterprise.

Read NIP-4 and had a question on the crypto algo choice. Why have elliptic curve derived key pairs for signing and verifying posts but yet use aes-256-cbc for encrypted DMs? Why not use an elliptic curve algo? This choice seemed a bit odd considering AES is not quantum safe. #nostr #asknostr #nip #nip4

Morning Abs #fitness

Morning Abs #fitness #fittrackerpro #getit

https://www.theregister.com/2023/12/15/hashimoto_departs_hashicorp/

Vault is hands down one of the best products for managing x509 trust chains. #infosec #cryptography

I did a little digging on this today. There is a crypto API that can be used clients side but the problem is key storage. You can store that in indexdb but thats not all that great. I am going to dig on this more and see if these apps are doing any of that or if they are storing it server side. If I get the time I'll do a write up on what I find.

Yeah there really is no secure way to make a nostra web app without tying into the browser certificate API and have the client side code required signing before sending the payload. I am interested to know if this is being discussed more or what is being implemented or leverage to accomplish a secure relationship with a nostra web app and a client.

I didn't plan to. Is #streamstr shady? It's listed on nostrapps.com

Why do #nostr webapps like #streamstr ask for your private key? #asknostr

Yesterday's workout #fitness #fittrackerpro