Avatar
Matt
fea186c2a4678dbc437704eed2160846e8a781e5fb17056e9bb333840d5bdef2
GM, GN, and GFY.

It's incredible how often I've tried to support certain projects and giving them money was difficult or impossible for me. I've had this happen a lot.

All of these issues are why storing a seed phrase for example as an image on a phone is a dumb idea.

Encrypt what though? If you're encrypting a key then that means you had it in plaintext. Same security problem I've outlined. And they are still decrypting on a potentially insecure device, making rugging more likely if the tech were widespread.

I think the short answer is that you can definitely encode a private key into an image. Doing that securely and in a trustless way is beyond me though. I don't see how you could or what the point would be over just sending them a key or Lightning invoice.

It was always going to be more difficult as essentially an EU island. I think it'll be simpler once more do it. Decentralization has benefits, but usually more so in numbers.

You'd need some way of generating an image key that you don't have access to and that their client can somehow use. I don't see how to securely generate a key on your device that is still secure on theirs. You'd only be able to do this with people you trust absolutely, who use reasonably secure devices. So that's a very small list for me at least.

It may not be if you're both using E2E encryption. But if they just leave it on an image that has other security problems. They'd need to immediately send it to a key that hasn't been digitally exposed for it to be secure (and that assumes that their device is secure). E2E encryption isn't enough if something malicious is on the device. It just seems like more work than sending invoice QR codes or something for Lightning payments. I think an encrypted file containing the key makes more sense. But that doesn't fix the problem that you were exposed to the key as well. This could create a double spend issue. You send an image that you already got the code from, paid someone, got something, and then rugged it. That's one of the security problems with hiding it in an image.

This seems similar in concept to an opendime except as an image and a lot less secure. You could probably conceal a private key in an image. Making it a standard for something like a client seems super insecure to me though.

GOOD MORNING, CAP'N!

THE EARLY WORM GETS THE BIRD

That was my first thought when I saw it. I predicted there would inevitably be a token and the usual dump and run.

This is why I don't see how Nostr scales the way some people seem to think it will without an incentive for relays. It's only going to get more expensive, even if it's just limited to text and images. No incentive will leave a void where companies are needed to centralize and fund the services.

I wonder when Social.Gov will become a thing. For saving Democracy, of course.