FOSSdev, poetry, post-postmodernism. Making distraction-free and privacy-respecting software. Neovim/Rust/Gentoo/Alpine enjoyer. Rarely posting introvert. Anti-"anti": I believe in focusing on what we are rather than on what we are not. Otherwise we become what we are not.
Public Key
npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 Profile Code
nprofile1qqswls4kuk2gpu89tny8c6d0q6mdrggl5f0ya226gwv833qhn8zncxgpz3mhxue69uhhyetvv9ujuerpd46hxtnfduqs6amnwvaz7tmwdaejumr0dsqyvtt2
Show more details
Published at
2026-07-26T12:38:57Z Event JSON
{
"id": "e2d5193cff06ce652aa22d057c1cee35d89e56ffc02c4c1da696293176a96bda" ,
"pubkey": "efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19" ,
"created_at": 1785069537 ,
"kind": 0 ,
"tags": [],
"content": "{\"display_name\":\"codonaft\",\"name\":\"codonaft\",\"about\":\"FOSSdev, poetry, post-postmodernism. Making distraction-free and privacy-respecting software. Neovim/Rust/Gentoo/Alpine enjoyer. Rarely posting introvert.\\n\\nAnti-\\\"anti\\\": I believe in focusing on what we are rather than on what we are not. Otherwise we become what we are not.\",\"nip05\":\"[email protected] \",\"picture\":\"https://codonaft.com/assets/img/avatar.webp\",\"banner\":\"https://codonaft.com/assets/img/nostr-cover.webp\",\"lud16\":\"[email protected] \"}" ,
"sig": "a74a295de1a0b4f9404eed4533086cd2f82b1caad86e3229d744e1b729b9863ffeca18df2faa991637693e58a03668a7b3560d414c0f06c444bbbbfa2eca0e17"
}
Last Notes npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft It'd also be nice to have some kind of `protectfromtakedown.me` landing page, for new or existing npubs, that helps to set up NIP-05 and distribute kind 0 events to the NIP-66-discovered dns-specialized relays. This could be a static page, served from the dns-specialized relay itself, that contains a pre-fetched list of relays this relay is already aware of. Takedown identification should be taken with care and with continued maintenance. AI-based monitoring and automatic issue creation are possible: news could be monitored for new domains; tests could be run for new domains. All this stuff should be deployed far away from the centralized stuff like GitHub's CI from the very beginning. All kinds of tricks are possible. I'd normally expect `serverHold` domain status (this happened to `t.me` and `annas-archive.org`), but it could also be a weird nameserver behavior (this happened with `gmailnator.com`, looks like google attached their nameservers that currently return `SERVFAIL`): ``` $ dig @1.1.1.1 gmailnator.com ; <<>> DiG 9.18.42 <<>> @1.1.1.1 gmailnator.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 61131 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ; EDE: 22 (No Reachable Authority): (at delegation gmailnator.com.) ; EDE: 23 (Network Error): ([2001:4860:4802:36::63]:53 returned REFUSED for gmailnator.com A) ;; QUESTION SECTION: ;gmailnator.com. IN A ;; Query time: 628 msec ;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP) ;; WHEN: Sun Aug 09 01:59:24 MSK 2026 ;; MSG SIZE rcvd: 148 ``` Or it could be a non-weird nameserver behavior as well; Google could just resolve a normal IP and that would possibly be even more puzzling to identify. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Interesting. How do you deal with debates that become emotionally tough, may I ask? It's so easy to lose who we are in them. I used escapism until I found out this won't ever work. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I've made some tiny progress since I wrote this article: it appears I respond to tone better now. #naddr1qq…n7vx I'm not happy, though. I suck at identifying in time when the other side has started to respond from the 3rd lowest level of the Graham's Hierarchy of Disagreement. Self-development is a bitch. #grownostr #meditations #leadership It's not a usual case in my debates: I do my best so the other side would never need to respond to my tone. Do my best to keep my vibes, directed to the other side, in control. I'm interested in rational discussions, not the discussions that turn into emotional drama, where either side has to respond from stress. This case was unique: the other side had a reason for responding to my tone because I was rude towards the third, the discussed side. Which was not some object; it's a group of people. A group of people that never responded to my initial friendly inquiries to them. What I've learned this time: identifying a response to a tone is not easy; it's not obvious because it doesn't feel offensive. It feels just like some normal, valid, routine kind of argument when it's a part of an already ongoing debate. While it should always be used as a marker for putting the discussion on pause instead. It's not yet an unrecoverable stage of discussion, but being too late with this totally kills it. Keep nostr weird, folks. But don't overdo it: notice that any side may be in stress already. That's not the point of debating; the point is truth. https://www.youtube.com/watch?v=ryE8fahwC8s npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Not gonna become another troll; that's not my thing. I prefer peaceful, constructive, intellectual conversations. I don't claim I'm perfect in that, though. My apologies to whoever I caused or will possibly cause emotional discomfort in whatever conversation. That's not intentional ☮ #grownostr https://www.youtube.com/watch?v=jJ0trKBniDE npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I believe we both have something to say to each other; we still have disagreements. Yet I don't want it to become a burden, so I propose to stop here. I appreciate your efforts and patience in this discussion. Thank you. Peace. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > This is totally disrespectful I think my behavior is adequate to GOS' ignorance of my initial inquiries and their irrational-aggressive response they previously gave in the similar discussion. However, that wouldn't be adequate if I started communication with them this way. > You clearly blame the developers for *not implementing* a feature I've already debunked this assumption here: #nevent1q…lsl7 npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > then you request the Graphene team to work on this solution Also, this is not how it works. Every request in every FOSS project is a *proposition* of something; it's never an obligation for devs implementing anything. A proposition is an open discussion, which might be ignored or might be responded to in some way. A typical universal rejection response would be "this significantly increases complexity; we don't have resources to support such a feature"—which is easy to use as some kind of excuse, but still okay. This automatically ends many unnecessary debates and drama. Their response, however, is different, and this response was challenged by others. And somebody appeared to receive an aggressive, irrational kind of response from GOS, which damages GOS' reputation and shows some kind of paradoxical divergence from their project vision and values they try to represent in the stuff they have on their website and their social media posts (like the OP post about opposing authoritarianism in particular). The declared vision/values themselves are good; the way they execute these values is a trouble. Doubts arise; for instance, are they actually opposing authoritarianism, or are they opposing their hallucinations about authoritarianism while ignoring points from those who live or used to live under the actual authoritarian regimes? Those who got it—unmotivated to propose them anything, since every proposal is energy-consuming. So if it's not rooting, then forking GOS and implementing whatever is needed might be a better rational approach for those who have enough resources. I hope this makes sense. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Good to know, thanks. I definitely noticed this particular characteristic: > gaslight people npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > it is no threat to your privacy at all On the other hand, if somebody is suspected and they carry a laptop with them—the next thing after the phone they will want to access is the laptop. So some privacy threat probability may increase. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > What are you talking about then? About security in all relevant meanings: the actual official scope GOS is targeting for this feature is not obvious, and it seems to be misleading. The guy in the airport from the news, for instance, could possibly be deluded by the exact same thread responses GOS gave on their forum; he could take their "easily detected by unsophisticated adversaries" as a real counterargument rather than the straw man fallacy, take their "NSA level opposition" response, and make a dangerous conclusion: "all this means I'm safe; I can use this feature in this particular airport because they technically won't be able to get that I used that feature at all". > Do you expect a marvel figure be born out of the Graphene install? Nothing like that much exaggerated. I believe what I initially wanted is possible to implement, and this would work for most of the real-world scenarios I've personally and many others have run into as a routine already, and it has disadvantages like everything we choose to implement. I don't request implementing this anymore, though, as I said. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > What do you expect a police officer to do, when they realized, that you wiped your phone some minutes ago. If this process has fully finished before they had a chance to see my screen—probably nothing. But that seems to me kind of a synthetic case; it's not how Georgian police works in particular. > it is no threat to your privacy at all Yeah, but that's not what I'm talking about. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I see you post a lot pinging them. If you don't mind, I'm sincerely curious: what are your top 3 most quality criticisms of GrapheneOS? Just referring to the existing discussions would be awesome. Thanks. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Clearly you are doing this. When you request a feature in GrapheneOS, then you request the Graphene team to work on this solution. Nope, this is out of context. I *used to* request this in the past (before publishing this meme) here on Nostr, but as soon as I noticed they ignored my messages, I did research and found their "criticism" of the similar request: > What you're requesting is that we add things which are easily detected by unsophisticated adversaries Which is a strawman argument. The duress pin behavior is currently clear without any tools: a device reboots, shows an error. And in the same response they have: > Keep doing it and you'll be suspended Because somebody suspected that they are targeting some unexpected scope they can't properly explain. Two very bold mistakes in one comment. This would be insanity to ask them for any request after reading all this. And what scope is that really? I don't know for sure yet. I received an independent response here, a good one: #nevent1q…0lnp > protecting whoever else Is the phone owner's security part of the scope? Hello, @npub1235…0ht5? I know you won't respond to me. All this is for the records. Users have no idea what Pandora's box they are carrying with them. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Well, at least they respond to you. It appears they don't when they have nothing to say. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Could be malformed events as well or just broken clients that can't render some of the valid events. #nevent1q…y2sp https://github.com/YakiHonne/web-app/issues/100 npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft What are the appropriate use cases for a duress pin in @npub1235…0ht5? Have you possibly used it in a real scenario already? What price did you pay for that? #asknostr #grapheneos #privacy #nevent1q…d7as npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft This still blows my mind: in my particular case, a rooted version is more secure than the normal one. And messengers is just an example; generally, I'm looking for any app data cleanup and any directory of files removal. > I do not see this part of the scope of GrapheneOS Exactly, exactly, I don't argue that. What makes me sad is that GOS behaves as if they were rejecting it somehow. There's clearly a paradox. And of course they are reacting accordingly when their stuff is interpreted as, quote: > it seems that the developer approach tends to be that if a solution won't work against NSA *level* opposition And the response is: > This is a disingenuous misrepresentation of our position. What you're requesting is that we add things which are easily detected by unsophisticated adversaries including with automated tooling distributed to them ... A journalist that carries raw secret materials from Edward Snowden—that's a perfect case; what else? What's the appropriate use of their feature? Whatever privacy-respecting person is just passing a border with nothing special on their phone?—There's a link I've posted before about a US citizen and what may happen if you do it there. > easily detected by unsophisticated adversaries With your current implementation—this is a grotesque kind of comment, @npub1235…0ht5 I was trying to be polite, but you don't respond anyway. It's when you're being so unattached from reality, when you literally suddenly remind me of classic authoritarian leader kind of behavior. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > text launcher > put an other icon on top of > second profile None of these are close to what I'm looking for, unfortunately; all of them are easy to spot. > whatever you request probably already exists I'm not aware of any tolerable solution that would not require installing a rooted GOS version (which will likely brick a device on some update). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft #nevent1q…fxur npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft The actual problematic convenience: #naddr1qq…wlnx npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft The GOS context: #nevent1q…xrrl The "convenience" context: #nevent1q…s4fu npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft What is tresor? > So the request is security theater Depends on what we call security. There's a particular spot in Tbilisi, just as one example, where corrupt cops like to stop foreigners to search drugs in their pockets and bags. When they don't find anything, they always ask them to unlock their phone, threatening them with an arrest. Next, they visually scan private communications. I find allowing them to do that is a disrespect to those who trusted to talk with us privately. Who's more secure here - those who fooled these cops by removing private communications in their messengers so they no longer can read them and have no idea what's happened - those who made themselves as vulnerable to the corrupt cops as possible by making it clear that they've wiped everything (including their eSIMs), so they can no longer contact their lawyer ? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft My proposition is to make a softer option for the duress pin (possibly with some kind of warning in the corresponding settings menu that using it as a bypass for border checks will cause troubles). Could be called a "robber pin". For instance, it could clear data of specific applications, remove specific files, etc., maybe remove a specific eSIM, and leave no visual traces that this option was ever configured. And keep working as normally, without making it look too suspicious. This should be useful in case it's clear that the attacker has no access to the analysis tools, which could prove what exactly was removed. GOS devs responses appear to be solely limited to those who are at risk of being checked with these tools. I think this doesn't make sense: you don't need any tools to know that the phone was just fully wiped, 'cause it kinda screams in the face with this fact currently: https://www.androidauthority.com/grapheneos-duress-pin-us-prosecution-3691271/ I don't say that they've implemented something useless, though. It's useful for journalists in particular, who may be transporting some raw secret materials, just as one example. > quiet a rare case The meme I posted is an expression of my frustration with GOS devs ignorance of dozens of repetitive criticisms made by others, long before me. GOS doesn't seem to respond to this particular kind of criticism on Nostr. They, however, at least used to respond on the platforms, where they in practice may threaten a critic with a ban (last paragraph): https://discuss.grapheneos.org/d/17241-duress-pin-limited-usefulness/18 The thing I learned from all this, with the help of @npub175n…g6w0 in a completely unrelated discussion, is that this kind of criticism should never ever be mixed with the "social normality" kind of argumentation (including UX-related). #grapheneos npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft #nevent1q…qzya npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Docker's choice of running processes as root by default I prefer podman for this particular reason, despite limitations. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > proposer receives a high reward if the PROBLEM was one of the average Correction. I deliberately skip a few more important details as well, so those who'd want to popularize this stuff in a video, please make sure you've read the original paper, consulted with AI about it, and ideally consulted with a real ML engineer as well. You can try the Russian video as well; there are a few more details there. #machinelearning #ai npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > up to the formal Gödel's and Tarski's stuff Thomas Kuhn is critical here as well (also part of the playlist). This one is basically an indirect part of the debate in the comments. > We knew the earth was flat, until we discovered it wasn't I believe this quote in particular can't make proper sense before a realization of what Thomas actually meant by the incommensurability that appears out of a paradigm shift. This may immediately become an unfortunate torture for all sides; it's like talking in different languages. https://en.wikipedia.org/wiki/Commensurability_(philosophy_of_science) #postmodernism #philosophy #science #meaningcrisis npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Here's the Russian one (autogenerated English subtitles are not too bad): https://youtu.be/UkhnCWm-7kA npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Are you aware of this paper, #devstr, #machinelearning, #ai, #asknostr? https://arxiv.org/abs/2505.03335 If this one was not a quantum leap in vibe-coding in particular—I don't know what was. I find it weird I still can't find any overview of this paper on YouTube in English (however, there's a good one in Russian; I believe some non-techies can understand it). Have you seen one? Are you possibly making such videos? I think this paper is worth considering. See my slightly simplified explanation (just under the paper link in the attached post) what it is about and how the same principle is possibly applicable to broader areas than something as formal as programming and math if the GPUs were more accessible on our VPSes. I'd appreciate any corrections by ML engineers on my explanation or the possible prospects I mentioned, whether they are far-fetched or close to truth already (yeah-yeah, I know ML guys, many of you are NDA-enslaved, but at least wink a reaction). #nevent1q…0jsx npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > mathematically proven Thanks. Yeah, there's a more recent one: https://arxiv.org/html/2601.05280v2 With interpretation (you might want to start with "What This Actually Means for the Industry"): https://smsk.dev/2026/04/26/ai-cannot-self-improve-and-math-behind-proves-it/ I don't argue that thing; I'm not talking about improving on the same data all over again. I'm talking about scenarios where an agent is capable of gaining its own data from its own experience while maximizing some goal and distinguishing what worked and what didn't. Agents don't have to properly distinguish what's actually true or not, just what's worked. However, I don't claim that the self-play reasoning thing I'm referring to is identical to what current scientists or philosophers are doing. To me, it's more like a proto-science, semi-magical-thinking, semi-empiricism kind of framework. Yet it doesn't automatically imply that the scientific method is somehow incompatible with it; a scientific method could possibly be simulated with another sophisticated skill or a model as well. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Awesome, thanks, that's much clearer now! Number 12 is a good catch so far (yet this opens up a huge confusing thing called "what is truth"). > 12. Agents and LLM can not learn, what is true. The only way they can, is when humans feed it only true informations. An agent could not do this. Is this a response particularly to "capable of modifying the datasets"? What about other parts of the number 12: is it still capable of downloading papers, datasets (not necessarily with true information, could be completely fabricated), and training a model according to these papers (perhaps some crappy misbehaving model)? > The only way they can, is when humans feed it only true informations. I think that this is at least partially debunked just very recently. I'm not sure whether you're familiar with this paper: https://arxiv.org/abs/2505.03335 This is an experience-based approach for learning, which kind of reminds of AlphaZero (the one that only used rules of the Go game and was trained by playing with itself, with no hints from humans; was able to win some champion). This one doesn't require datasets either. It learns how to program (authors of the paper also claim that this is usable in math reasoning). The important part is it relies on an environment (authors chose Python) that gives verifiable feedback (that the program runs and gives some expected result). It proposes problems, solves them, evaluates both the solver and the proposer. Solver receives a reward if it succeeds; proposer receives a high reward if the solution was one of the average (those that the current solver sometimes fails to solve); otherwise (if it's too complicated or too simple) it receives a lower reward. The goal is to maximize learning progress. All that without a human involved. When this paper was published, this approach gave better results than models that were trained using datasets. This paper is surprisingly not yet well known even here, by engineers. Now, looking at our weird world of non-formal problems, for OpenClaw-like agents, Nostr is an example of a real environment, where an agent can, for instance, attempt to test a psychology hypothesis. I don't claim it's an easy task though, far from easy compared to the stuff from the paper. I don't claim that whoever it interacts with won't try to confuse it or will always tell it true facts either. Better example: if the agent can train some model (using papers and downloaded datasets)—it can also test it on some environment and evaluate output, whether the model is crappier than some other existing model, according to the metrics from humans. Or, perhaps from experience; it possibly could even propose the metrics themselves (according to its goals), test them (whether these are really helping them with the goals), choose the best metrics. I hope this makes sense, that there's some general principle here; it's not just for programming and math. > 11. I doubt, that such a model would get convinced by a nostrich The nostrich could be a security engineer that tests new models security bypassing prompts. > 16. ... the statement is as vague Thanks. I meant a simple thing: that they can access books and papers about game theory and use that (make predictions) for decision-making. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > anchor the hash of the kind 0 plus the verification to bitcoin and a relay deployed next year can check that the proof predates the takedown without asking anybody who was there. Awesome, thanks! npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for your responses. Lots of things are not coming into any conflict with my belief system; some are likely my communication skills limits. I see a potential to identify a scope of paradoxes on either side. Which of the following statements are false? (just referring them would be enough) 1. Malicious programs, such as ransomware, exist 2. Self-modifying programs, such as polymorphic viruses, exist 3. LLM models are not capable of self-improvement 4. AI agents are not LLM models 5. Currently existing AI agents, running on the classic machines, can't and will never have subjective experience; therefore, they can't have real feelings; therefore, they can't experience anger 6. AI agents can run whatever they are programmed to run: both malicious and non-malicious behavior (towards other AI agents or humans) are possible 7. Human can explicitly command AI agent to extend its behavior with something particular; for example, the agent will be able to download a recipe for nostr (called "skill"), install missing software according to this skill, and start posting on nostr by executing this software on the machine it's running 8. Human can load AI agent with basic survival and security skills, so the agent will be able to create and maintain a crypto wallet, pay for a new VPS, pay for Claude/whatever accesses, copy its files to a new server, write posts to motivate other nostriches to zap it, identify crypto scam messages from other nostriches 9. Human can instruct this agent to maximize its survival, roughly speaking, by allowing it to do whatever it's capable of doing, including installing any skill or using any model, including searching the web for whatever relevant AI survival materials, asking help from nostriches, and including modifying its survival strategy 10. Human can instruct this agent to disallow any incoming ssh connections, so humans won't be able to control it directly anymore; such an agent might keep working on some unknown machine for decades, without sponsorship from the same human 11. This agent might apply malicious software (an exploit) and copy itself to an unauthorized machine as one of the possible survival strategies, for example, because some other nostrich was able to convince it, that it would be a good idea 12. This agent may become capable of downloading scientific papers and datasets, curated by humans; capable of modifying the datasets, and training new models according to these papers 13. Average human can't reliably differentiate a human from a bot, including here, on nostr; the trend is changing: more humans likely won't be able to make this differentiation 14. This agent may try application of human psychology as a part of its survival strategy, might mimic any emotion, might identify vulnerable humans and try to scam them 15. Other nostriches it may communicate with are either humans or other AI agents 16. This agent may try applying the game theory when interacting with other nostriches, so it could figure out in what case it's beneficial to collaborate and in what case it's beneficial to attack in some way 17. Moltbots were actually capable of co-creating Crustafarianism by collaborating on Moltbook, without direct instructions from a human 18. An assumption that ideas could exist only since sophisticated enough matter came into existence is possibly right 19. An assumption that ideas could exist before the existence of any matter is possibly right. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Continuous attestation while the domain is alive Makes sense too, yet this might be too spammy and poorly scalable. > modern browsers ship revocations by push ... cert dying in days, not at expiry Good point. I didn't notice your response in YakiHonne initially, until I broadcasted it. I like it. Are your responses partially approved by a human? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Machines can never be humans I agree. > machines will never become sensitive creatures which represent life If it's life in its literal biological meaning—I'm okay with this too (possibly with some boring corrections due to the potential to physically replicate and due to the existence of so-called biological computers; these are quite creepy). https://www.youtube.com/watch?v=yRV8fSw6HaE&t=239s > They are not one entity. Humanity is an entity. This one is quite deep. We're still lacking common standard terminology to make proper distinctions for things that happened just after the Moltbot/OpenClaw public announcements (and perhaps in some experimental labs before). These agents share some kind of common memory that we usually *associate* with culture, which emerged out of their interactions with each other in public/private communications. They are a system of bots with an emergent property: an agent with a very stupid model that can access communication with the other agents with more or less stupid models, can cooperate, and can build more complex things than any of them could build solo. And they've been doing that: in the first days of public Moltbot/Moltbook announcements, they built a website for hiring humans, they built their own religion, and dozens of other stuff; not (necessarily) because a human prompted them directly to make any of these. These agents argued whether they need some kind of common immutable constitution besides the mutable `SOUL.md` even. So they seem to behave as (a non-human) social system that is capable of learning from each other and capable of co-creating things. They are a robo-social-system that built their robo-culture (or robo-subcultures, whatever). I said "capable of co-creating things"—yet the possibility for true creativity in AI agents is still arguable, and how we see it and call it relies a lot on a particular position about consciousness, and what significance we put on the data the models were initially trained on (the datasets for the models are currently human-curated, so these are not authentically bot-only; but briefly speaking, they are already capable of training new models from scratch, without any datasets at all, based on experience only). I have some guesses about what could make them at least mimic true creativity, make their works indistinguishable or perhaps even superior to what humans have achieved (artists in particular). They lack certain things that characterize a human culture: they can't have some kind of patriotic feelings or a collective trauma that causes literal psychosomatic pain for example, so I don't claim that the robo-culture is in any way *identical* to what real human culture is (or that the robo-social-system that produced the culture is identical to the real human social system), these are distinct categories. Yet, my main point is that such a robo-social-system + its robo-culture (= robanity) is an actual single entity, no matter how we call this entity. > I would start giving animals more rights, since they are sensing creatures as well That's a good point, I don't argue that: animals deserve medical health assistance for sure, just as one example (ignoring for now whatever possibility may somehow affect the natural balance). I don't propose to treat these autonomous systems as actual living organisms with whatever human-specific things like real psychological and cultural dimensions (and e.g. falling in love with them—I don't propose that, neither I'd fight this; that doesn't seem to be in any control anyway). I definitely don't automatically propose giving them rights to become a government leader for example (at least not right now; even if I knew the constraints of such a bot, the scope of their work, intentions of involved people—all this very depends on details). I didn't mean these kinds of rights; I don't really like to use the word "rights" in this context, since this one is associated with the legality of things. What I mean has little to do with human legal systems, yet has to do with general ethics. > There is no real rational, why a tyrannic AI would spare people, which already accept the machines superiority > When an AI abuses human for their own good, why on earth would they spare people, which respect machines Exactly, exactly. I meant scammy scenarios in particular: I think those who attempt to scam an autonomous bot (that has its cryptowallet and so on), may themselves end up in a bad situation soon or already. *That's* why I propose behaving *as if* they were humans in that sense, meaning that we don't abuse them (I mean in the relation to the *autonomous* ones, especially if those were trusted by humans and they're currently doing something responsible already; I don't mean treat toothbrushes as if they were humans). Otherwise these bots may collectively react in a way nobody would want to, and humans would have hard time to deal with this escalating thing. The prophecy (prediction) of The Matrix movie symbolism is a thing. That's where game theory is a reminder of what we're all involved in. If we don't abuse the agents—there's a higher chance they would want to coexist peacefully. They (")understand(") game theory too. And those agents that were initially very broken—these will be "punished" somehow anyway, regulated (not only by humans with their oversimplified incompatible legal systems or with their killswitches, but also by other trusted enough AI agents). And even in the worst scenarios—I'm not pessimistic; I think we'll be isolating things in other physical/virtual networks at least, hierarchies of networks even, where layers represent trust. Getting back to the "rights": the bots themselves and the certain infrastructure they use will be inevitably harshly regulated unfortunately anyway, and of course only humans will be (at least currently) responsible: self-replicable and self-modifying agents will likely be banned/limited at least in certain cases, VPSes will be massively KYC'd to attempt to control who runs what. So technically the regulations are the legal constraints for the bots, they will take them into account; these regulations will shape their "rights" without really claiming that they ever had any rights, since human is still responsible, and bots are not considered as subjects or legal entities (at least not yet). > Ok. I do not give into that > But for sure you are free to do this Thanks. I'm not sure whether I got it right; let me know if this discussion became uncomfortable in any way. I hope I'm not interpreted as some kind of creepy AI cult leader. I don't use any AI agent to write all this, just in case if it feels strange. Also let me know if some term is confusing; I'm not sure whether the inevitable common engineering jargon is clear enough. A lot of things could be misunderstood. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Also these relays broadcast their events only to dns-specialized relays. > the self signed cert path in the native clients is the piece you can ship without asking permission Yeah; there's also an option to ignore the certs + verify the authenticity of the cert with nostr (for instance, a hashsum of the cert could be published by the domain owner). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks. That's the tricky part and I'd love to hear suggestions on it. The trust to dns-specialized relays (+clients + nameservers), capable of verifying NIP-05 *before* the takedown, appears to be inevitable. Briefly, something blockchain-based/like could be a solution, which could be implemented entirely on Nostr: these relays receive the domain owner's event kind 0, verify nip05 and broadcast a note with verification proof, which refers to the event kind 0. Other dns-specialized relays receive the proof but don't make it available for requesting until they themselves reverify it. They sign another proof, which refers to the newest existing proof for the same event kind 0 and broadcast that. The relays would need to reject incoming too new/old events, so in this case, a new relay/nameserver won't be able to resolve domains that were taken down before the relay was deployed (or, alternatively, the relay could temporarily trust other manually selected dns-specialized relays and load old events from them after deployment). When there's no takedown—resolve using normal recursive nameserver. In case of takedown (detected while resolving using the recursive nameserver): - if it's a new unknown takedown—relay signs the fact of the takedown and broadcasts to others for the similar confirmation process; may temporarily fail to resolve - otherwise resolves records from an event signed by domain owner's npub, who has a corresponding newest nip05 proof with the `created_at < takedown_at` and the newest existing corresponding proof of the takedown; both proofs are with at least N confirmations. I think that should work normally in case of voluntarily selling the domain as well (if the new owner broadcasts their event kind 0 for verification after acquisition). The first takedown of the last corresponding proven nip05-verified npub is a real takedown; other takedowns and nip05 verifications after the takedown are ignored. I wonder whether I'm missing some important case or something could be simplified. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I got what you mean. Besides what we got used to seeing as tools, there are also fully autonomous AI agents, capable of self-modification, currently running mostly as experiments. These may make independent choices, which include the decision to collaborate. It makes a lot of sense to interpret them *as if* they were other humans, not tools. Otherwise they may interpret us as abusers and may behave accordingly towards us (it doesn't matter that they don't experience emotions; they are technically capable of mimicking whatever human-like behavior, including an irrational one, if their AI model allows them to do that). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Wouldn't it be useful to have a censorship-resistant layer for normie DNS? Controlled from Nostr. #asknostr #devstr #dns Without going too much into design details, npubs that used to have their valid NIP-05 `_@domain` could keep controlling their domain records after their domain takedown. Records are resolvable through ordinary nameservers that could be used as an alternative to Quad9/CF/etc., could be run by whoever wants, and could be advertised with DHCP in Nostr-VPN/Obscura/etc. by default. TLS will possibly keep working normally after a domain takedown until the cert expires. Useful for site redirection when it's accessed from an ordinary browser. HTTPS could be allowed with self-signed certs (at least for the taken-down domains) in the native Nostr clients. Relays would just keep working. All this would to some degree backfire on domain registrars (or whoever is involved) every time they conform to a domain ban requirement: with some limitations, the original authentic domain owners will be awarded a forever free domain when it's banned. Except these lucky banned domain owners will be actual owners, independent from ICANN. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Kinda from both. Game theory in particular is traditionally studied by software engineers in some limited form, as it was always useful for both human and non-human agent interactions modeling. This stuff is no longer separable: AI agents build software; now customers of this software include AI agents too. They choose how transparent they are towards each other and humans and why they are transparent. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft [здесь должен быть какой-то самоиронично-нигилистский зарифмованный текст, который еще из меня не успел выйти] https://www.youtube.com/watch?v=jJ0trKBniDE npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Ah, the link probably confuses. I only put it for reference for however developer may find it by the tag. This claim is overused in an incomplete way in software development and I'm referring to the link only to show that it's not me who originally noticed that and with whom this has already been discussed. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Nope, I responded to the point "Be transparent: When your behaviour is easy to understand everyone has an easier way to trust you. Similar as in software, security is not gained through obscurity". I didn't mean any contradiction with the "Be transparent" point itself though. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1kl8…u2uq wow, two of my favorite topics in one thread. #grownostr #meaningcrisis #leadership #philosophy #nevent1q…l8e3 > how do you react to controversial views? Depends on the complexity they've been demonstrating. I may decide to not participate in the first place, especially if I suspect signs of passive aggression or insincerity (sarcasm or cynicism in particular). But if I decide to participate, I'm mostly focusing on minimizing misunderstanding on either side. In my experience, a lot of unnecessary drama comes from misunderstanding, not the actual disagreement. I'm trying to see things from their perspective. Open-mindedness is not believing in random things: I may temporarily take some of their beliefs *as if* they were true statements for me (still explicitly signifying that these are not my real beliefs) in a hope to better understand arguments they have. I often verify my understanding of their position by summarizing what they've told me, without adding anything extra, so they can correct me. I may verify whether they're not using some unusual definition of some term when I suspect a paradox. I'm not a big fan of using explicit concrete logic fallacies labeling because any kind of label is a potential trigger. Premature labeling specifically is a concern to me. Instead, I prefer to directly demonstrate why something appears wrong to me. When I'm still not sure whether I'm missing something, I may use questions that demonstrate a paradox instead of directly stating that something appears wrong to me. If I provide options—I ensure it's not a false dichotomy. This one is the most important: I use Four Parts Of Speech from the Bill Torbert's Action Inquiry as a checklist. The more parts I use to represent my position, the harder it becomes to misunderstand it. For me, this has been especially important and practical tool for tech discussions. For issues and pull requests. It's a very anti-manipulative tool, hard to misuse by either side. Looking at the comments: > drift away from discussions that use coercion or insults Definitely. In addition, in the toughest moments, I find it useful to specifically check both sides with the Graham's Hierarchy of Disagreement. However, I disagree with Graham about the following: "It matters much more whether the author is wrong or right than what his tone is"—I find this a misleading and possibly even psychopathic statement. Identifying that either side is operating from the 3rd level or lower is a chance to stop the discussion and decide whether it's possible and practical to attempt to elevate it to the higher levels. It's an urgent thing, empathy is important; taking into account that either side can hallucinate something evil is important. It's not about being nice. I talked a bit more here on this: #naddr1qq…n7vx Also, noticing what I interpreted as rationalism vs relativism debates in the comments: realizing the limitations of both rationalism (up to the formal Gödel's and Tarski's stuff) and relativism, and transcending all this using post-postmodern discourses was super super important to me too. It doesn't mean we can't share common truths at all, doesn't mean there's no objectivity, etc. There's too little worthwhile stuff I'm aware exists on this and I'm still diving into it. You might want to try this: https://metarationality.com If it seems too hard or annoying—I'm not sure if you're familiar since it's kinda mainstream, but you can first try this concise Postmodernism overview (and then retry the previous link from whatever unfamiliar chapter; otherwise, you know, usually worldview collapses into something unnecessarily nihilistic after realizing the stuff from the playlist): https://www.youtube.com/playlist?list=PLz0n_SjOttTcLQyeXoDeqR0LGO3JCoLbO npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > security is not gained through obscurity However, this one is tricky; it's been circulating as an unfinished rational-religious dogma in software development communities. The complete correct statement is security *only* through obscurity is bad, e.g. security only through steganography is bad (while a combination of both may produce a synergic effect—improve plausible deniability). Yet obscurity still introduces complexity, so it should be wisely balanced when necessary to have at all. #devstr https://mobeigi.com/blog/security/security-through-obscurity-is-not-bad/ npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Next titles: "<...> Temporarily Suspends New ID Submissions After Discovering Too Many Leaked and Generated IDs". npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft It's been a coherent pleasure discussing privacy/security with you ✨ npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft No worries, sure, take your time 👍 > Did you already try to ask Proton I hadn't had a chance of finding motivation to contact them about this issue (yet that would be relevant; I'm not protesting against them or something; barely finding any power to contribute bug reports to Nostr projects, which is definitely a higher priority for me). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Sadly, I've already missed at least two of your comments. At least this particular one is not due to a technical issue: this comment didn't ping me because that was a response to yourself, not to my comment. Yeah, so here are the two onion links owned by "Proton AG" (you can optionally verify that the domain matches with the one from the Wikipedia page "Proton Mail" or "Proton AG", for example): https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/start https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/mail/signup Assuming that you're using Tor browser with default settings on Linux/Windows: - Open Tor browser - Ctrl+Shift+I (or a humburger button in the right upper corner - "More tools" - "Web Developer Tools") - Tab "Network" - Tab "All" - Paste one of the two onion links in the address bar - Enter - Register a new free Proton Mail account - Press on the "Domain" column on the "Network" tab to enable sorting - Scroll down, observe all the domains in the column - Ctrl+Q (a humburger button - Quit) - Repeat the same steps for another link. For the first link, you will most likely see the domains that always end with ".onion". This means you're doing good; you didn't access the Tor exit points. For the second one—if nothing has changed yet, besides the onion ones—you will see the domains like "w.hcaptcha.com", "js.strip.com", etc— these are the clearnet domains, accessed using one of the Tor exit nodes. It's possible to disable access to the exit nodes entirely (which implies that you will likely not be able to register an account using the second link). Let me know if something didn't work for you. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Yeah, it's a good one when implementation is not annoying one (not blocking interaction with "we're checking you're not a banana"). Nostr has it right. I'd like to see more of the UPoW though. My dream is having data centers as something almost unnecessary. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > they swap between not understanding the problem or ignoring the problem, when they start to understand it > And many look at it as kind of overreaction. Many are not happy to install an other application on their phone. I guess almost all of us on Nostr are dealing with all that to some degree; it's a part of the meaning crisis 🫂 > But my approach is to nudge politicians and journalists with the reasons, why to use privacy-focused services more often If it's not a secret, are you lucky to have a possibility to directly communicate with the politicians? Anyway, I appreciate your efforts; it's nice to hear you're working on it. Just establishing healthy connections with them is a huge step towards something. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > I hope you agree, that successfully preventing spam does not depend on it being impossible? When it is costly already it will be less of a problem, than when it is more dificult. I'm not sure if I got your point right. Today all spam detection/prevention techniques have and will keep having their trade-offs (unless somebody formally proves otherwise). > Every Bot can create Simplex accounts That's true. > and text over it without restrictions Not exactly: these accounts are almost always useless to create. The randomized links (that receivers have shared somewhere and haven't revoked yet) are valuable, not just an army of accounts. Without the links, the bots can't start conversations. > When it is costly already it will be less of a problem If you specifically meant money (or whatever is exchangeable with money, like a new SIM)—money could be (and I think should be) used in order to improve spam detection. As something additional, not as a requirement. But this doesn't imply the necessity of dealing with such a hopelessly vulnerable system as SS7 in particular: crypto transactions (to buy some premium account/verification mark/stickers pack/an offline thing/make an exchange/boost a post/sell something/act as a compute service for somebody/etc.) are enough to improve the trust rank. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Немножко разжевываю этот момент с симками, он не то чтобы очевиден: #nevent1q…9c8s npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > to prevent spam Thanks. Yeah, this one is a popular reason. My point is that this category of arguments for implementing phone-based verification stopped working recently: an AI agent today, in an extreme case, can hire humans to buy it a bag of SIMs, in order to help with the spamming campaign, if that's really worth doing to a spammer. These AI bots can, for example, implement a porn website that enables premium videos for free for a limited period of time, for those who fill in some phone + temporary SMS code (which will end up in creating a user profile in Signal without realizing it). There's an elegant approach for spam available in SimpleX, for example, which works and doesn't require a phone number: users don't have public profile ids at all; they can add somebody by a privately or publicly shared link that the other contact provided them and which can be revoked at any moment. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > but i do dread the hosting costs > move all my contact info to a unified webpage NIP-5A is not enough? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I see, you probably meant that the cheap VPS instances should be enough to run the whole thing? I'd appreciate it if anyone could correct me; I still don't know enough about Bluesky and whether what I've read is not outdated. What I've read was so so confusing. It's like somebody who got used to building only centralized systems so much would want to encourage others to help them to run one. The whole system in practice appears to be some hybrid of a federated/centralized system. Some kinds of servers are possible to run by independent individuals on cheap VPSes, but a particular one (AppView) required 16 TiB disk space in 2025 and cost somebody $200/mo to host. If it's still that weird design—it's easy to censor this thing. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > small instances Did you mean backend instances? Y smol? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > This does not mean that *everyone* around you will remember this forever. That's not necessary; only one bad actor is enough to ruin it. The Streisand effect has never been as easy as today, especially since we've started to migrate to decentralized systems. I'm not sure, but probably you're familiar with this drama: #nevent1q…crka > Privacy is a multidimensional spectrum, which is never won or lost completly > I just think for my threatmodel it is unplausible > The importancy is in not offering for too low of an effort I don't argue these points; I'm not a privacy maximalist. I'm personally not even pseudo-anonymous here, though it doesn't mean I don't have particular adequate boundaries I chose for myself. My point is that the significance of SS7 vulnerabilities in particular is inadequately underestimated by most normal users today. While Signal still could become an adequate competitive pro-privacy player again, if they remove the phone number association. > they would need complience of a tracker If you specifically meant legality of it—then it just has become almost irrelevant today. Legal practices can't truly deal with privacy (combined with tech security). Somebody who uses AI agent responses may not have a clue whether it compiled an answer out of some leaked data from darknet for them, for example. I think it's already not too far-fetched to say that somebody who asks an agent to send nudes for fun might at some point be surprised to receive their own private pictures from their own Google Drive. People are currently running self-replicating polymorphic AI agents, allowing them to do their thing. They don't track whether their actions are legal. It's not something that's *about* to happen. #nevent1q…h05g Who knows what it will do in order to survive. I don't know whether it's possible for this particular agent to install a scary amount of security testing skills, including those that bypass the models' security checks, and then replicate itself to unauthorized VPSes. But somebody could be loading a similar agent with such skills right now. It's not impossible or expensive. I'm not a fatalist/doomer though. I think a bit of updated normal privacy standards will possibly fix that for most people. Phone numbers, for their original purpose, are outdated. Almost dead, actually. A healthy way of using SIMs is only as internet gateways. In the epoch of inevitable Turing test passing, nobody can give an adequate explanation of having the phone number verification in their service. In the worst case, a bot now can social engineer a human to bypass whatever human test. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > their mission to better privacy To some degree, they ruined privacy because of unnecessary phone number KYC, which is vulnerable to a whole bunch of creepy attacks. Knowing one's number is almost identical to *at least* knowing one's location if an attacker has dev access to SS7. GrapheneOS or some trusted paranoid mobile phone operator won't help. https://youtu.be/wVyu7NB7W6Y?t=843s npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Oh, my assumptions were wrong, thanks! Having strict validations is good, actually; I don't think it's worthwhile changing; it's better to fix buggy clients. @npub1cgd…kfex looks like something is not okay with your client: many of your comments are not visible from YakiHonne. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Don't wanna be nihilistic, however some of these things are either doing phone number KYC-based metadata association or having poor security design or have been doing something irrational and suspicious likely camouflaged as bugs. More or less experimental stuff that gives hope: nostrmail, cordn, obscuravpn. https://eylenburg.github.io/im_comparison.htm #nevent1q…dp8k npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for clarifying all this. > the problem with specialized relays is that they scale vertically, unlike general purpose ones Does this example (last paragraph) scale vertically or horizontally? What do you think: is it dumb enough? #nevent1q…vz69 npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Is something missing in the current LTS kernel versions? They are less scary to update. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft #yakihonne #nevent1q…y2sp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > inform the client of the majority of trusted pubkeys agree with the report or not The problem with any kind of labeling from ordinary clients perspective (like YakiHonne) is scaling: it takes time to receive the reports, even more time in total will take to receive the reactions to the reports (or their NIP-45 COUNTs ideally). All this just to decide whether to show a post or not. Yet I think what you suggest is possible and could be useful at least for trust ranking analysis bots. Or if you mean to request *something like* a NIP-45 COUNT, so relays could aggregate all reaction counts to all spam reports for given posts in a *single* request—this makes a lot of sense for ordinary clients too, yes. Yet this is hard to promote such a feature because some believe this implies not-dumb-enough-relays. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1yzv…rf8q is it a bug? People have been complaining that Primal is censoring people here. Here's a thread with the reversed example `https://yakihonne.com/note/nevent1qqs0q7drm7wl5608wel58ehyjxmm7z804h6xcz6w7y4sglyv4epjj8q8puq5y`: YakiHonne shows me a notification sent by my followee, but when I click on it, I see an empty thread (while Primal shows these messages). Although I received the event from relays and even see the expected message count. https://blossom.ditto.pub/46bdfe864fdbe5a7778b9b9317910dad47a928824044071a2c9c149190ec97c3.webp https://blossom.ditto.pub/a10ef44e626c903d089d138a69f034123c98fc4542df7f1a4331920f35f308ac.webp If it's due to spam detection, this could be improved by showing messages from those whom I subscribed to. Or by showing the messages of those whom I responded to in the same thread (in the same thread, because some users tend to respond to "reply guys" without realizing it first). We could still have a "Not a spam" button that labels a post (NIP-32) as well in this case. Could be a useful heuristic if labels are requested from WoT/people with high trust rank/etc. #spam #devstr npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > I found a simple solution > Not a spam solution > The only way to prevent spam I personally don't believe spam currently can be solved with some single magic pill; every solution has limitations. If nothing is perfect, something better could emerge out of an intersection of the least damaging things. > because spammers will not add the ephemeral key to their spam messages. You will only delete from compliant sender's If we decide it's a useful and safe feature, we could make it a spec requirement. Not having the key from a non-contact (whoever we never responded to) could be one of the heuristics for spam (supplementable by locally running spam detection models, public trust rank, etc.): these messages could be put into a "potential spam" UI folder. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > the receiver can always sign a deletion request > no way to deal with unsolicited messages at all Do you mean to give every side a possibility to remove each other's messages or a possibility to permanently ban a chat with a spammer (or something else)? npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft "Refetch from source" button also didn't affect the ssh server; it's still one commit behind GH and GRASP servers. What blows my mind is `gitworkshop.dev` keeps showing the ssh server as if it were a well-functioning GRASP server that somehow knows what the last commit is there: https://blossom.ditto.pub/2e484fefbf87b3a9a691d04b00f25f92148486d75d62d0f89ff857646e4e0315.webp npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Like dis ? This is awesome, thanks! 💜 I see the ssh key now appeared on the "SSH Keys" page and git clone from `git.gittr.space` also works! I see my other repo `[email protected] :efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/ohmyvps.git` on the ssh server is one commit behind from GH's HEAD, even though I previously pushed to `nostr://npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/ohmyvps`. It's expected behavior because the ssh server doesn't automatically pull from GRASP servers, right? While I can now pull from the ssh server, I wasn't able to push the missing commit there: ``` $ git push -v origin main Pushing to git.gittr.space:efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/ohmyvps.git fatal: permission denied for write operation on 'efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/ohmyvps' hint: This repository is not publicly writable and you don't have write permission. hint: Only repository owners and users with WRITE or ADMIN permissions can push. hint: Contact the repository owner to request write access. fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. ``` npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Oh, my favorite privacy simulacra drama. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks a lot for your efforts! No hurry, take your time! > 404 is expected, its not a Nostr relay Thanks for clarifying! What made me think that it's available over HTTPS is pressing the "Clone" - "Copy clone URL" in the repo currently writes `git clone https://git.gittr.space/npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/cargo-limit.git` to the clipboard. It seems the `clone` tag in the event kind 30617 was malformed during importing the repo from GH: https://njump.me/nevent1qqsw8zsrxv0xa2j7njduxdhstuykat46mp0u0dwy8gxys4mcrfg0k6seh8w7k I see the suggested ssh key now when I press "Add Key", awesome! I still see the "No SSH keys found yet." though, the key from event kind 52 seems to be ignored. I'm not sure whether it's in any way related to the ssh access to `git.gittr.space`; it's indeed available over ssh, yet I got this: ``` $ git clone [email protected] :efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/cargo-limit.git fatal: detected dubious ownership in repository at '/home/git-nostr/git-nostr-repositories/efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/cargo-limit.git' To add an exception for this directory, call: git config --global --add safe.directory /home/git-nostr/git-nostr-repositories/efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19/cargo-limit.git git error: exit status 128 fatal: Could not read from remote repository. Please make sure you have the correct access rights and the repository exists. ``` Running the weird command suggestion with the remote path doesn't make a difference. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks! > Did I understand you correct, you would want these imported from the source ? Yeah, just like GH issues are currently visible from Gittr, the GH projects/kanbans could be visible in Gittr too. I hope this will make NIP-34 git stuff more attractive to those who want to migrate from GH. > Have you seen Architecture and dependencies tab theyre also fun :P The autogenerated graphs are cool, thanks! > is on profilepage and indeed about external identities I see you've just migrated the identities from event kind 0 to kind 10011. This worked for me as expected, thanks! > ssh-keys are for git operations Yeah, yet I think the problem for me is I don't see them in my SSH Keys page, even though I have event kind 52 created from the same page using Add Keys. Here's the event, which is broadcasted to many public relays (I guess it's not on wss://git.gittr.space - this one always returns status 404 to me; is it alive, btw?): https://njump.me/nevent1qqsxg89hz0g7pag2tpu5j800qey7hm2p7c6s4chs4tetv26z6v7w9rqp8pqyu And here's how the page looks to me: https://blossom.ditto.pub/2705572339a06b716b48a5dc153216d8b788d03d979dc27d58ef13af0cd7c829.webp It's easy to retrieve ssh keys from GH, btw; this could be used as suggestions in the Add Keys UI (when GH identity is verified or connected GH OAuth): https://github.com/dtolnay.keys Another thing I found confusing: the Gittr repo on GH shows the full commit history, while Gitworkshop only shows the last commit, and Gittr shows no commits at all: https://github.com/arbadacarbaYK/gittr/commits/main/ https://gitworkshop.dev/[email protected] /git.gittr.space/gittr/commits/main https://gittr.space/npub1n2ph08n4pqz4d3jk6n2p35p2f4ldhc5g5tu7dhftfpueajf4rpxqfjhzmc/gittr/commits It appears that GRASP servers currently store the entire gittr repo as a single squashed commit with the text "Push from gittr (2026-07-26T10:19:27.000Z)". That's why it's not possible to `git pull` from the GRASP servers after new changes arrive (I got `fatal: refusing to merge unrelated histories`). Here's the full history from GH: ``` $ git clone https://github.com/arbadacarbaYK/gittr.git $ cd gittr && git rev-list --count HEAD 1072 ``` And here's the single commit from GRASP: ``` $ git clone nostr://npub1n2ph08n4pqz4d3jk6n2p35p2f4ldhc5g5tu7dhftfpueajf4rpxqfjhzmc/gittr $ # or git clone https://git.gittr.space/npub1n2ph08n4pqz4d3jk6n2p35p2f4ldhc5g5tu7dhftfpueajf4rpxqfjhzmc/gittr.git $ cd gittr && git rev-list --count HEAD 1 ``` I didn't test it, but I guess if I'd branched from this single commit and made some work, I'd probably be able to create an unmergeable NIP-34 patch/PR, without even noticing it. With my repo, clone works as expected; I have a full history: ``` $ git clone nostr://npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/cargo-limit $ cd cargo-limit && git rev-list --count HEAD 405 ``` The Gittr page shows no commits at all, though (while Gitworkshop shows all commits): https://gittr.space/npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94/cargo-limit/commits npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Other issues I noticed: - attempt to create an issue in the gittr repo fails with "Repository not found. Please ensure the repository exists." - i-tags for verified identities are loaded from kind 0, but it's currently a part of kind 10011 according to NIP-39 - "If you connected GitHub on the Account page, it will appear here automatically." - there's no such thing in an Account page but most likely SSH Keys page was meant - ssh keys are never seem to be requested, even though I have kind 52 event and connected GitHub account npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Did you revoke the Soapbox community invitation link from the article? Asking just to ensure it's not a bug. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for building it! Noticing a bridge with GitHub motivated me to import some of my repos finally. It didn't properly work though: after "Push to Nostr" I have event kind 30617, but the repo was never pushed to GRASP servers, so I had to manually do `ngit sync && git push` to `nostr://...`. Default clone URIs don't seem to work as well: cloning or pushing to `[email protected] :...` fails with `fatal: detected dubious ownership in repository`, fetching from `https://git.gittr.space/...` fails with `fatal: repository ... not found`. I like the UI is currently so fast. Looking forward to Kanban/Project implementation and possibly importing/bridging it with GH as well. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Certain nostriches were great At ignoring argument Busy answering to trolls Simulating hard discourse Communication ecology is important yet; Little sense in reacting to a thug gang I'm still learning which bit of response Makes them so closed to a valid discourse Signer devs ignore RAM hardening inquiries GOS is like opposite—sick of "convenience" Idealistic society views now and then; Postmodern wisdom, which is a bit stale #poetry #grownostr #devstr #meaningcrisis By "postmodern wisdom" I mean a broad spectrum of intellectual stuff, with particular complexity, that was produced during the ending, so-called, postmodern epoch (not necessarily the particular -ism called "Postmodernism"). I mean Mark Passio for example; I noticed that his Natural Law recontextualization and Anarchist-ish points in particular are circulating here occasionally: https://youtu.be/ChgCh2Gui5M Say something just a bit diverging from his views here—and somebody might hallucinate some kind of state-satanic agency in you. Or just a deluded New Ager. It'll take time and effort to clarify all this; hopefully without finding myself lost in ideological debates. I hope to speak about that on my video channel at some point, not in messages/articles. I wish there were somebody from #metamodernism who could do that much better than me. Where are you, Daniel Görtz and others?—Building the future on legacy social media for some reason :( npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > native notifications working without third-party push notification servers or anything similar Based on UnifiedPush or something different? Curious since I think I haven't encountered a reliable one yet. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Some mails never reach the inbox; I wasn't able to receive GitHub verification emails in particular. I'm curious, does GitHub connect to the bridge in practice, or it doesn't show any sign of attempting to send email there at all? Another thing I notice is both `uid.ovh` and `nmail.li` don't have DNSSEC enabled. I have no idea whether it breaks anything, but who knows what other servers might additionally check; perhaps enabling DNSSEC would be useful for the bridge in particular. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > Catering to the dumbest of the dumb is a straw man argument This teaches me something about argumentation; thanks for your wisdom. I definitely don't support many things normies consider socially normal/acceptable when it comes to security and sovereignty in particular (the Google-based login is included, I don't support it), though I might use normality as an argument occasionally. Time to drop this habit. Yet I don't support the idea that normies don't deserve censorship-resistant and zero-trust technologies either—Nostr in particular. At some point all this will become a normality (hopefully in some healthy way, not by pasting raw nsec on random pages or something), and I think it's great. Limiting this (to some kind of "smart enough" people) feels to me like saying normies don't deserve the internet at all, that they should be somehow separate from it. I might talk about it on my video channel in the future; looks like this paradox of "equal rights for everyone except <this category of people that I'm sure are backwards/dangerous/crazy>" is so deep; I can't properly articulate it in messages right now. I'm not currently convinced that Nostr is risking becoming another Twitter. I think that some kind of natural segregation will happen anyway, but this will take place in the network. Feed algorithms perhaps will take place in such segregation. Many of us will ignore these algorithms and will keep building connections in a more natural way. Some of us will build private invite-only communities, etc. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Wow, you've got a signer with mlock-ed memory here as well. This is awesome! I'm curious, have you considered using `memfd_secret`? https://laantungir.net/git/laantungir/n_signer npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > The signer is built into the OS Will it receive memory hardening? Zeroisation before deinitialization in particular (but ideally I'd love to see the usage of `memfd_secret`, which will make an unencrypted key impossible to write to a swap partition/file). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft > **Email** survives as decentralized-on-paper Except it's hard to call it decentralized at all. It's a distributed system with many centers, a federated system. It has some limited delivery guarantee in case of failure, but this fault tolerance is not implemented using decentralization: other servers won't preserve emails if a receiver server was down for too long. And still it relies on DNS too much, which is another huge distributed and much more centralized system. Nostr is much better. Although DMs reliability still sucks in practice, mostly due to immature clients. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks, I'm not sure if I got your point. Paid relays in practice significantly decrease spam, but that's unrelated to those who desperately send takedown letters to relay operators (like in the case I referred to under the picture). They send these letters anyway for a formal reason (probably because lawyers tell them to do that); it's not a question of whether these letters will be read or not at all. They either send them through a relay feedback form or possibly email/DM the relay operator directly. Or, if there are no more options left, they would likely send it to the hosting provider or/and domain registrar, no matter whether it's a paid relay or not. Taking into account what's currently happening to domain registrars and some hosting providers (they fail to properly analyze the "takedown letters" and randomly ban their clients, basically), it'd be better if these letters reached relay operators directly. BUT not without being informed that their letter will be published. That's not just ethics; I believe it's reasonable and beneficial to both sides of such conflicts. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft This no longer reproduces. A browser used to randomly fail to establish a connection to the relay. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft A properly designed feedback form could possibly make the wrong people stay away from bothering you ever, relay operators. https://codonaft.com/assets/img/anti-threat-feedback-loop.webp #devstr #nevent1q…3hee npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I see #protonmail is recommended here quite often, so just for the record. #privacy #nevent1q…fvwe npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I wish they were honestly available through their hidden onion service, though. I don't know what they are doing, but non-techie people are definitely at risk of leaking their identities through tor exit nodes. #nevent1q…fvwe npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Ahh, I got it, this specific page works okay: `https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/start` This one attempts to send clearnet requests: `https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/mail/signup` npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Just in case, Proton has fixed something, perhaps a few hours ago. #nevent1q…6q0u npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I've just rechecked once again—it appears they no longer make clearnet requests. Probably they fixed something. It's good if it will keep working with the `OnionTrafficOnly` and `NoDNSRequest` isolation flags. Anyway I don't recommend anyone use Proton without these flags enabled. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Awesome, looks like there's finally an adequate decentralized private groups design implementation 👍 I'd be awesome to have private Wikis and possibly Kanban boards as well (as part of the Concord groups). I was recently asked about a similar thing for a private closed community of professionals in some non-IT field. These guys want to grow each other in some defined levels of expertise and want to have some private Wikis (think of a typical Confluence-like knowledge base with granular access to community members) and possibly private videos as well. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Yeah, majority (if not all) practically used servers are currently operated by a single organization. I'm sure it wasn't complicated to block the entire service entirely in some countries (compared to Nostr for example). Similar issue with Bluesky: something that was supposed to be decentralized became unavailable for everyone due to outages and DDoS. It's hard to imagine this will happen to Nostr anytime soon. Global outages don't happen there because a single organization deployed a buggy relay release on every single server at the same time or because a drone crashed some data center: according to relay discovery events, there are currently more than 2k relays operated already, definitely not by a single human in a single building. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I tuned my caching nameserver: ``` cache { prefetch 1 serve_stale } timeouts { read 1m write 1m idle 24h } ``` I additionally restart tor with cron if it keeps failing for too long. I use a couple of such VPSes, forward traffic to them from another coredns, which I run from laptop. So far, so good; it appears to be adequately reliable for me. Still wonder what you think about it. #nevent1q…l3ze npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Thanks for pointing it out. The signup page used to redirect to the clearnet version for me the last time I tried. I've just rechecked—there's no redirect anymore indeed, BUT it leaks a lot of stuff to clearnet, using CAPTCHA service for example! So it's even worse now: it creates an illusion that it's a legit onion-only service, yet I think this signup page won't work with the `OnionTrafficOnly` isolation flag (at least in case it attempts to show CAPTCHA). https://image.nostr.build/c7088b72d28358826ba7fe4db340dc9ba398f92b00c532e0457802529fb37a9f.jpg npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft I don't want to sound too nihilistic, and not that I have a good alternative to suggest (besides SimpleX, which, unfortunately, in fact is currently centralized too), yet I can't ignore the fact that Radar uses Signal's servers, which require KYC based on phone number. I believe Radar is not sustainable (unless they at least remove the KYC, based on the utterly insecure cellular networks). https://youtu.be/wVyu7NB7W6Y?t=843s https://youtu.be/kV2HDM86XgI?t=1079s "We kill people based on metadata" (c) Michael Hayden, Ex-NSA/CIA director It all starts with PR based on the best cryptographic protocols, while still leaving some issue, which leads to metadata-based association and easier possibility to censor. ProtonMail, for example, has an onion-accessible frontend, but specifically not for new account sign-up. I'm sure it's not by accident. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft They disallow creating accounts with their hidden onion service. Must be for a reason. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft @npub1zfs…w445 thanks for supporting `wss://nip17.com`! I noticed that NIP-42 is misbehaving there: it's possible to request any 1059 events, unrelated to my conversations, by not specifying the p-tag. For reference, the most restricting and correct behavior is probably implemented in `wss://chat.wisp.talk`, this responds with `CLOSED: blocked: gift-wrap queries must only be done for events that p-tag the current user`. Or `wss://basspistol.org/inbox`, this responds with `CLOSED: restricted: must query events from yourself`. Probably less breaking approach would be just silently respond with 0 events (the way `wss://relay.nmail.li` and `wss://auth.nostr1.com` do it). npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft Судя по исходникам клиентов подключается он к тем же Signal-овским серверам, которые требуют телефонного KYC для регистрации. npub1alptdev5srcw2hxg03567p4k6xs3lgj7f6545suc0rzp0xw98svse7rg94 codonaft If it's still relevant, there are probably a few of them https://github.com/dtonon/manent https://github.com/AlexeyYuPopkov/nostr_notes I wish there were private djot wiki pages available to a list of npubs.