Avatar
Dr. Hax
d30ea98ea65e953f91ab93f6b30ea51eb33c506f87d49f600a139aef00aa9511
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu

I took the day off today (mostly) and it felt good. Did some weeding, string strimming and cleaning, but mainly I just hung out on the back patio, in the shade, on an 80°F breezy day, chatting with friends and neighbors who stopped by.

Low effort, chillaxin'. And I didn't even feel guilty about not being very productive because hanging out was what was on the schedule.

Yup. Today was a good day.

Ah yeah, time for another #signet #saturday! Hope to be able to get #ScreenReader #compatibility done and ready to merge today.

Then after that, it'll be merging in all the #documentation that was created while getting familiar with the code base.

Followed by cutting a release and then creating additional documentation

More docs will make it easier for developers to join in, security experts to assess the design & implementation, and users to feel confident in the system

#a11y #accessibility

Yeah, I'm very curious to see how it is implemented and enforced if/when it passes.

#Signal said they'd pull out of anywhere that passes a law like this. But even with just this one example where a single company is doing the #development and running the centralized server, it's unclear what that would look like.

Sure, tell Apple & Google to disallow IP addresses in #EU from downloading the app.

Will Signal also feel compelled to block IPs from the EU from accessing their servers? Will they be required to block all VPN users, worldwide as well since there's some possibility the end user might be in the EU?

Will #Microsoft #GitHub ban people in the EU from seeing the source code or downloading releases of every app that has #e2ee and no content scanning code?

What does this mean for #Nostr #software, which has e2ee DMs? For relays inside or outside the EU?

And to be clear, I'm asking how it would work for people who want to attempt to comply with the #law. The answers are easy for those people taking the civil disobedience route.

I am also not asking whether people should comply with the law. We all have our own opinions on that and that's fine. I simply want to understand who would be legally required to make what changes.

Whenever browsing sketchy websites, be sure to use a #DVM

Also use a DVM when installing questionable software on your computer.

There are tons of uses for Disposable Virtual Machines, and #QubesOS makes it extremely fast and easy.

If you thought #MassSurveillance was bad in #America, you're right, but Europe is trying to catch up!

They're considering this #ChatControl that blocks you from sending video, pictures or links unless you consent to having all your messages scanned.

Shit kinda sucks everywhere right now.

I started by wanting to subscribe to Daniel Batton's newsletter and here's how it's going.

His website (batcoinz dot com) hard blocked me because I use privacy software (in this case, Tor). No captcha, just can't connect to the site. Oof.

After circumventing this network control, I found I could not pay in Bitcoin. Credit cards only.

So then I go buy a prepaid credit card from bitrefill. Some of the links in their order email didn't work right but eventually I got the card. I subscribe to Daniel's newsletter and on the 4th attempt an trying to log into/sign up for substack, it finally works.

What do I see then? An option to pay in bitcoin to subscribe to the newsletter. 🤦‍♂️🤷 Whatever, I was successful at giving him my money, despite it being very difficult. That's the real point here.

And as a bonus, I now have that prepaid card in a Google Android phone (apparently tap to pay doesn't work with any version of Android except Google's, which is 🤮). We'll see if ot works...

I have followed many of the same people as you and I follow various hashtags, but for at least the past few weeks it's been very sparse.

Maybe it's just that it is planting season now and a lot of gardeners are too busy to hop on social media. Plus few people are harvesting crop this early in the season, so not as much to snap a picture of fof another month.

I enjoy people posting about their gardens, mesh networking projects (be they 802.11 based, LoRa based or something else), novel infosec research or developments (e.g. exploits & defenses), people trying to replace all their coprorate technology with open source systems (GMail, Nest, YouTube, Windows, AWS, and the like).

I see this from time to time on here, but I crave more. 🤓

I know, some people post pictures of their dinner, or their garden, but most of the posts in English are those three categories in the global feed as well as my own.

I try to #GrowNostr to help get more interesting things to peruse.

Imagine building a censorship resistent decentralizded network and then it's almost exclusively used for:

1. Talking about the network itself

2. Bitcoin

3. Bots, most of which are basically just an RSS feed

Replying to Avatar Derek Ross

What are Nostr badges? #HOWDONOSTR

Badges are simply cosmetic enhancements for your Nostr profile. They may be awarded to users for recognition, for participation, or in appreciation of a certain task, goal or cause. Users may choose to decorate their profiles with badges for fame, notoriety, recognition, support, etc.

Some badges are common, some are more rare, and others are extremely rare, only being awarded to small groups of people.

Badges can be created and managed from https://nostrbadges.com and https://badges.page

Several clients will show badges on user profiles such as Iris, Snort, Amethyst, Nostrudel, etc.

Examples:

Attendees of the very first Nostr conference were awarded a unique #Nostrica badge.

Participation in various memes and fun activities on Nostr may yield badges for survival of a #hellthread, making a typo, or collecting a lot of badges. The possibilities are endless here.

Badges may be awarded for subscribing and supporting a Nostr relay, a Nostr client, or service such as NostrPlebs.com, Nostrcheck.me, Nostr.land relays, NoBSBitcoin.com, and more.

Achievements in video games from nostr:npub1hm63f02cer8w5jltne4cf2xeswf477lzday7zn0kszv0rwnyz4hqcmzr0p yields Nostr badges showcasing your gaming skills.

Supporting and backing crowdfunded projects on nostr:npub1kmwdmhuxvafg05dyap3qmy42jpwztrv9p0uvey3a8803ahlwtmnsnhxqk9 results in a variety of badge rewards.

Since anyone and everyone can create badges, some badges and even badge providers will be more reputable than others.

In the end, badges are fun, but also can provide or showcase some utility as well.

Why are 3,6 and 5,6 the same picture?

Fixes today:

1. Valve stem light on my bicycle

2. Picture frame

#repair doesn't have to be some complicated thing. Just fixing simple objects is respectable.

Nobody: What'd you do last weekend, Dr. Hax?

Me: Read about #GrapheneOS's new #duress PIN. Look at this. It's 🔥

https://grapheneos.org/features#duress

#security #infosec

Seems like just blocking the bot would suffice, no? You can't censor the bot, but that doesn't mean it ever has to show up in your feed.

The bot seems pretty pointless to be honest. Even for people who think the idea of content labeling is wonderful, unless clients have a way to filter out content that the bot replied to, then the only point seems like it'd be to supposedly appease Apple and Google, I guess.

And I'm not trying to defend this bot, I'm just trying to understand their argument, and it just doesn't make much sense to me. 🤷