Avatar
Viktor Vsk
8a699686811889186df398c7253e8c4417ce73fe814edeae7ecd81dbde9536ac
Building #saltivka 🇺🇦 Nostr Friendly Relay (https://saltivka.org) Building #Knowstr — smart Nostr events aggregator (https://github.com/viktorvsk/knowstr) Working to enable people have more activities through the word of mouth between friends, friends of friends and more 🤝 with https://recar.io and https://valent.network

Yeah thats exactly what bitcoin cultists say. But if you DYOR (it seems not many ppl know what it stands for today) you will find out there are cults without leaders

I always challenged the saying “if a person is talented in one then they talented in all”

But I’m almost there to start believing “it a person is publicly dumb at one then they are totally dumb in everything”, its just too many proofs out there

UN doesn’t make sense after USSR collapse, there is no sense to sponsor it actually, but “network effect” will fuel them for a long time probably

For some reason no one cares when UN was celebrating rusia language day on the day when rusia terrorists killed tens of civilians with a precious strategic missile strike

Because there is no such thing as a free speech

And what happens after a leader of one tribe defeated? Tribes merge, run democratic elections and live in peace in prosperity and with another?

There are many secure password generators and many apps require stronger passwords but the majority of passwords are “qwerty123” and alike

The point here is, you must introduce complexity into your password and different mechanics (mnemonics, special characters, secret words etc) can’t render this fact unnecessary

LeaderA defeats LeaderB and TribeA must accept committing suicide because its leaders will. Got it. Perfect system for slaves.

JFYI your post is too dull to be a joke and too joke to be considered as “a thought”

Human natures is to take what we have for granted and always being unhappy with it.

I personally assume nature made former to let us be more efficient (i.e. not spend all the time being astonished on how the sun is so shiny wow but for everything around) and latter to force us progress

So nothing unusual in this article. Another guy could read it and say “hey dude I’m trying to get kids for 30 years straight with my wife and would give everything for just to be at your place”

Replying to nobody

I wonder what most people’s minds would do if they ran netstat on their home computer, sitting at an idle. I ran pihole at one point and blocked over 100k random connections going out of my home in one week, and those were just the ones it caught.

As for IP addresses being PII under GDPR - I literally have nothing nice to say about that piece of legislation. I would literally rather geoblock the entirety of Europe than deal with their incompetent attempts to legislate technology into the ground.

I’m not willing to live my life at that level of paranoia. Nostr clients deserialize JSON objects into POD data types. There is a minimal attack surface. If you’re worried about IP address exposure - run a friggin VPN. Almost every Nostr client loads images and videos by *default* exposing your IP address to a random collection of servers - often run by companies with spotty privacy records, like google - even if you run a locked down list of relays.

IP addresses may be PII to a government or a big corporation, but the idea that they are *private* is laughable. It is by its very nature exposed to everything you do online. If nostr clients were executing code downloaded from relays, I would begin to worry. Web clients - especially ones that allow content embedding - are the most likely attack vector, not the relay itself.

My relay keeps no persistent IP logs, as disclosed in my terms of service here: https://github.com/TheSameCat2/thesamecat-relay-tos but even if a relay does, if your threat model indicates that IP address retention is a problem for you, that should have been mitigated on your end long before you got on Nostr.

I’m sorry if this comes off hot, but I keep hearing the same things harped on over and over again, like we need to plug a pinhole in the bottom of a ship that’s had a hole blown in it. When nostr decides culturally that they’re going to take blocking Google, Imgur, Spotify, et al. from collecting our IP addresses seriously, I’ll be concerned about my IP address being leaked to some relay operator.

Regarding GDPR I would say its far from perfect obviously because the topic is complex. But do you want to say its a bad thing govt make corporations put users in control of their data? Is it a bad think I can request all my data from Facebook they have on me? Is it bad they have to put efforts to control this data not be breached?

Regarding everything else regarding IP sorry I’m not following clearly - this is my exact concern that my IP and other sensitive information could get to ANYONE just because I open a nostr client. And yes I’m much less concerned about Google knowing a lot about me than my neighbors or boss

Anyway, there are decades of software development and web software development and they have basic things in common. And all we discuss here assumes that nostr is so special that we should avoid all that experience

Browsers don’t make arbitrary requests. They open site you ask them too and follow links from that site are trusted. And also they put tremendous efforts to make it as safe as possible. And when some of the links leads to untrusted site its called XSS

As you said, clients should put users in control - I’m not against this feature, I’m just saying this feature must be implemented responsibly

If bob suddenly changes relay I want to know it. And if it happens he posts to nsa.gov from now on I want to be able to say bye ye Bob