Avatar
artk42
bcbeb5a2e6b547f6d0c3d8c16145f7bb94f3639ec7ecbcfe50045dbb2eede70b
Private keys eat the world || Cybersec UX maximalist || Research on self-custody edge cases at @vault12

Google and Cloudflare portals, store passwords in plaintext within the HTML source code of their web pages, allowing extensions to retrieve them.

https://www.bleepingcomputer.com/news/security/chrome-extensions-can-steal-plaintext-passwords-from-websites/

When people are blaming @Apple as a totalitarian dystopia builder, they just miss how business and evolution cycles work. That's a pretty bold privacy move to put all user's interactions with the "keyboard" into Secure Enclave blackbox: https://twitter.com/ChristopherA/status/1665849832966168582

nip-05: Mapping Nostr keys to DNS-based internet identifiers - **case-insensitive**???? wtf🤯🤯🤯

#[2]​ good to see nostr-deepurls to work at least in damus, though why the nostr://@username doesn’t resolve(?

nostr://npub1hjlttghxk4rld5xrmrqkz30hhw20xcu7clkteljsq3wmkthduu9sr6hplz

Replying to Avatar fiatjaf

Zulip

gm

cryptography cons happen in zulip

@jack​ look at how we designed our bitcoin multisig hw wallet with the same approach to threshold recovery https://youtu.be/9tUJGyMhU4E

Unfortunetally, we were ahead of time for threshold auth and moreover covid crushed us. But it was amazing to see the same logic and resulting diagrams in your build posts. We would be happy to contribute for next versions of bitkey