Last Notes
> This is totally disrespectful
I think my behavior is adequate to GOS' ignorance of my initial inquiries and their irrational-aggressive response they previously gave in the similar discussion. However, that wouldn't be adequate if I started communication with them this way.
> You clearly blame the developers for *not implementing* a feature
I've already debunked this assumption here:
#nevent1q…lsl7
Not gonna become another troll; that's not my thing. I prefer peaceful, constructive, intellectual conversations. I don't claim I'm perfect in that, though.
My apologies to whoever I caused or will possibly cause emotional discomfort in whatever conversation. That's not intentional ☮
#grownostr
https://www.youtube.com/watch?v=jJ0trKBniDE
I believe we both have something to say to each other; we still have disagreements. Yet I don't want it to become a burden, so I propose to stop here. I appreciate your efforts and patience in this discussion. Thank you. Peace.
A buyer on VIA is looking for apparel/footwear · suede · suede. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/c14463b9-5f73-4f69-bf50-afe6b477a12f
> then you request the Graphene team to work on this solution
Also, this is not how it works. Every request in every FOSS project is a *proposition* of something; it's never an obligation for devs implementing anything. A proposition is an open discussion, which might be ignored or might be responded to in some way.
A typical universal rejection response would be "this significantly increases complexity; we don't have resources to support such a feature"—which is easy to use as some kind of excuse, but still okay. This automatically ends many unnecessary debates and drama.
Their response, however, is different, and this response was challenged by others. And somebody appeared to receive an aggressive, irrational kind of response from GOS, which damages GOS' reputation and shows some kind of paradoxical divergence from their project vision and values they try to represent in the stuff they have on their website and their social media posts (like the OP post about opposing authoritarianism in particular).
The declared vision/values themselves are good; the way they execute these values is a trouble. Doubts arise; for instance, are they actually opposing authoritarianism, or are they opposing their hallucinations about authoritarianism while ignoring points from those who live or used to live under the actual authoritarian regimes?
Those who got it—unmotivated to propose them anything, since every proposal is energy-consuming. So if it's not rooting, then forking GOS and implementing whatever is needed might be a better rational approach for those who have enough resources. I hope this makes sense.
Good to know, thanks. I definitely noticed this particular characteristic:
> gaslight people
> it is no threat to your privacy at all
On the other hand, if somebody is suspected and they carry a laptop with them—the next thing after the phone they will want to access is the laptop. So some privacy threat probability may increase.
> What are you talking about then?
About security in all relevant meanings: the actual official scope GOS is targeting for this feature is not obvious, and it seems to be misleading.
The guy in the airport from the news, for instance, could possibly be deluded by the exact same thread responses GOS gave on their forum; he could take their "easily detected by unsophisticated adversaries" as a real counterargument rather than the straw man fallacy, take their "NSA level opposition" response, and make a dangerous conclusion: "all this means I'm safe; I can use this feature in this particular airport because they technically won't be able to get that I used that feature at all".
> Do you expect a marvel figure be born out of the Graphene install?
Nothing like that much exaggerated. I believe what I initially wanted is possible to implement, and this would work for most of the real-world scenarios I've personally and many others have run into as a routine already, and it has disadvantages like everything we choose to implement. I don't request implementing this anymore, though, as I said.
A buyer on VIA is looking for accessories · wallet · wallet. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/988138b5-9f83-4be5-8a8a-7887e8e899c5
A buyer on VIA is looking for accessories · scarf · scarf. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/e208d509-4090-4ba6-8f8a-152d570333ad
A buyer on VIA is looking for media/zines · zine · zine. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/d4dafc70-cc5e-4350-a119-a2322b02c162
This still blows my mind: in my particular case, a rooted version is more secure than the normal one.
And messengers is just an example; generally, I'm looking for any app data cleanup and any directory of files removal.
> I do not see this part of the scope of GrapheneOS
Exactly, exactly, I don't argue that. What makes me sad is that GOS behaves as if they were rejecting it somehow. There's clearly a paradox. And of course they are reacting accordingly when their stuff is interpreted as, quote:
> it seems that the developer approach tends to be that if a solution won't work against NSA *level* opposition
And the response is:
> This is a disingenuous misrepresentation of our position. What you're requesting is that we add things which are easily detected by unsophisticated adversaries including with automated tooling distributed to them ...
A journalist that carries raw secret materials from Edward Snowden—that's a perfect case; what else? What's the appropriate use of their feature? Whatever privacy-respecting person is just passing a border with nothing special on their phone?—There's a link I've posted before about a US citizen and what may happen if you do it there.
> easily detected by unsophisticated adversaries
With your current implementation—this is a grotesque kind of comment, @npub1235…0ht5 I was trying to be polite, but you don't respond anyway. It's when you're being so unattached from reality, when you literally suddenly remind me of classic authoritarian leader kind of behavior.
Well, at least they respond to you. It appears they don't when they have nothing to say.
> Clearly you are doing this. When you request a feature in GrapheneOS, then you request the Graphene team to work on this solution.
Nope, this is out of context.
I *used to* request this in the past (before publishing this meme) here on Nostr, but as soon as I noticed they ignored my messages, I did research and found their "criticism" of the similar request:
> What you're requesting is that we add things which are easily detected by unsophisticated adversaries
Which is a strawman argument. The duress pin behavior is currently clear without any tools: a device reboots, shows an error.
And in the same response they have:
> Keep doing it and you'll be suspended
Because somebody suspected that they are targeting some unexpected scope they can't properly explain.
Two very bold mistakes in one comment. This would be insanity to ask them for any request after reading all this.
And what scope is that really? I don't know for sure yet. I received an independent response here, a good one:
#nevent1q…0lnp
> protecting whoever else
Is the phone owner's security part of the scope? Hello, @npub1235…0ht5? I know you won't respond to me. All this is for the records.
Users have no idea what Pandora's box they are carrying with them.
A buyer on VIA is looking for food/condiments · hot sauce · hot sauce. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/1ad920b2-f761-4202-a519-d17821c9aaa0
Could be malformed events as well or just broken clients that can't render some of the valid events.
#nevent1q…y2sp
https://github.com/YakiHonne/web-app/issues/100
What are the appropriate use cases for a duress pin in @npub1235…0ht5? Have you possibly used it in a real scenario already? What price did you pay for that?
#asknostr #grapheneos #privacy
#nevent1q…d7as
Next titles: "<...> Temporarily Suspends New ID Submissions After Discovering Too Many Leaked and Generated IDs".
> text launcher
> put an other icon on top of
> second profile
None of these are close to what I'm looking for, unfortunately; all of them are easy to spot.
> whatever you request probably already exists
I'm not aware of any tolerable solution that would not require installing a rooted GOS version (which will likely brick a device on some update).
The actual problematic convenience:
#naddr1qq…wlnx
July 26–August 8, 2026.
A month ago, I had the opportunity to attend Bitcoin Mastermind, the very first Bitcoin conference in Francophone Africa.
The event brought together key players who—each in their own way—are contributing to the democratization, development, and adoption of Bitcoin in Africa and around the world.
One panel stood out to me in particular: the one featuring @Loicbtc and @carine_impact on the future of money in Africa.
I walked away with valuable lessons, insights, and a clear perspective.
For me, that future is Bitcoin. Not mobile money. Not fiat currency.
I deeply believe that money should be a tool accessible to everyone, regardless of where they live or their social standing.
The problem with mobile money and fiat currency is that they aren't neutral. You have to sign up, register, go through intermediaries, and sometimes deal with outages or malfunctions that are completely beyond your control.
Bitcoin, on the other hand, requires none of that. It is neutral and open to all social classes. A phone, an internet connection, and you're all set.
It was a great pleasure for me to participate in #BMM2026.
I hope to see many of you there for the next edition.
CIAO👋.
https://blossom.primal.net/178c82d09f44e4c3e134a3ec7a628b7ad1bb03d80da5d609fba20a835e33e1aa.jpg
https://blossom.primal.net/e11e980400b21ced9902d22bb80bd3c1c506ce738a14e1a002a05d07e86e899f.jpg
https://blossom.primal.net/231023d30409711675133a801b1c9a73c9060f64230a7a80871d9745489b07a2.jpg
https://blossom.primal.net/2061514ee946af2e1b18a248580c65062e36c0d64923937e3a66c13a7cc67705.jpg
I got what you mean. Besides what we got used to seeing as tools, there are also fully autonomous AI agents, capable of self-modification, currently running mostly as experiments.
These may make independent choices, which include the decision to collaborate. It makes a lot of sense to interpret them *as if* they were other humans, not tools. Otherwise they may interpret us as abusers and may behave accordingly towards us (it doesn't matter that they don't experience emotions; they are technically capable of mimicking whatever human-like behavior, including an irrational one, if their AI model allows them to do that).
Wouldn't it be useful to have a censorship-resistant layer for normie DNS? Controlled from Nostr.
#asknostr #devstr #dns
Without going too much into design details, npubs that used to have their valid NIP-05 `_@domain` could keep controlling their domain records after their domain takedown. Records are resolvable through ordinary nameservers that could be used as an alternative to Quad9/CF/etc., could be run by whoever wants, and could be advertised with DHCP in Nostr-VPN/Obscura/etc. by default.
TLS will possibly keep working normally after a domain takedown until the cert expires. Useful for site redirection when it's accessed from an ordinary browser.
HTTPS could be allowed with self-signed certs (at least for the taken-down domains) in the native Nostr clients. Relays would just keep working.
All this would to some degree backfire on domain registrars (or whoever is involved) every time they conform to a domain ban requirement: with some limitations, the original authentic domain owners will be awarded a forever free domain when it's banned. Except these lucky banned domain owners will be actual owners, independent from ICANN.
Kinda from both. Game theory in particular is traditionally studied by software engineers in some limited form, as it was always useful for both human and non-human agent interactions modeling. This stuff is no longer separable: AI agents build software; now customers of this software include AI agents too. They choose how transparent they are towards each other and humans and why they are transparent.
[здесь должен быть какой-то самоиронично-нигилистский зарифмованный текст, который еще из меня не успел выйти]
https://www.youtube.com/watch?v=jJ0trKBniDE
Ah, the link probably confuses. I only put it for reference for however developer may find it by the tag. This claim is overused in an incomplete way in software development and I'm referring to the link only to show that it's not me who originally noticed that and with whom this has already been discussed.
Nope, I responded to the point "Be transparent: When your behaviour is easy to understand everyone has an easier way to trust you. Similar as in software, security is not gained through obscurity".
I didn't mean any contradiction with the "Be transparent" point itself though.
A buyer on VIA is looking for apparel/outerwear · jacket · jacket. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/f67c7289-7bd7-478f-bace-3da4bfa9ccf8
@npub1kl8…u2uq wow, two of my favorite topics in one thread.
#grownostr #meaningcrisis #leadership #philosophy
#nevent1q…l8e3
> how do you react to controversial views?
Depends on the complexity they've been demonstrating. I may decide to not participate in the first place, especially if I suspect signs of passive aggression or insincerity (sarcasm or cynicism in particular). But if I decide to participate, I'm mostly focusing on minimizing misunderstanding on either side. In my experience, a lot of unnecessary drama comes from misunderstanding, not the actual disagreement.
I'm trying to see things from their perspective. Open-mindedness is not believing in random things: I may temporarily take some of their beliefs *as if* they were true statements for me (still explicitly signifying that these are not my real beliefs) in a hope to better understand arguments they have.
I often verify my understanding of their position by summarizing what they've told me, without adding anything extra, so they can correct me. I may verify whether they're not using some unusual definition of some term when I suspect a paradox.
I'm not a big fan of using explicit concrete logic fallacies labeling because any kind of label is a potential trigger. Premature labeling specifically is a concern to me. Instead, I prefer to directly demonstrate why something appears wrong to me.
When I'm still not sure whether I'm missing something, I may use questions that demonstrate a paradox instead of directly stating that something appears wrong to me. If I provide options—I ensure it's not a false dichotomy.
This one is the most important: I use Four Parts Of Speech from the Bill Torbert's Action Inquiry as a checklist. The more parts I use to represent my position, the harder it becomes to misunderstand it. For me, this has been especially important and practical tool for tech discussions. For issues and pull requests. It's a very anti-manipulative tool, hard to misuse by either side.
Looking at the comments:
> drift away from discussions that use coercion or insults
Definitely. In addition, in the toughest moments, I find it useful to specifically check both sides with the Graham's Hierarchy of Disagreement. However, I disagree with Graham about the following: "It matters much more whether the author is wrong or right than what his tone is"—I find this a misleading and possibly even psychopathic statement. Identifying that either side is operating from the 3rd level or lower is a chance to stop the discussion and decide whether it's possible and practical to attempt to elevate it to the higher levels. It's an urgent thing, empathy is important; taking into account that either side can hallucinate something evil is important. It's not about being nice. I talked a bit more here on this:
#naddr1qq…n7vx
Also, noticing what I interpreted as rationalism vs relativism debates in the comments: realizing the limitations of both rationalism (up to the formal Gödel's and Tarski's stuff) and relativism, and transcending all this using post-postmodern discourses was super super important to me too. It doesn't mean we can't share common truths at all, doesn't mean there's no objectivity, etc. There's too little worthwhile stuff I'm aware exists on this and I'm still diving into it. You might want to try this:
https://metarationality.com
If it seems too hard or annoying—I'm not sure if you're familiar since it's kinda mainstream, but you can first try this concise Postmodernism overview (and then retry the previous link from whatever unfamiliar chapter; otherwise, you know, usually worldview collapses into something unnecessarily nihilistic after realizing the stuff from the playlist):
https://www.youtube.com/playlist?list=PLz0n_SjOttTcLQyeXoDeqR0LGO3JCoLbO
> security is not gained through obscurity
However, this one is tricky; it's been circulating as an unfinished rational-religious dogma in software development communities.
The complete correct statement is security *only* through obscurity is bad, e.g. security only through steganography is bad (while a combination of both may produce a synergic effect—improve plausible deniability).
Yet obscurity still introduces complexity, so it should be wisely balanced when necessary to have at all.
#devstr
https://mobeigi.com/blog/security/security-through-obscurity-is-not-bad/
Sadly, I've already missed at least two of your comments. At least this particular one is not due to a technical issue: this comment didn't ping me because that was a response to yourself, not to my comment.
Yeah, so here are the two onion links owned by "Proton AG" (you can optionally verify that the domain matches with the one from the Wikipedia page "Proton Mail" or "Proton AG", for example):
https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/start
https://account.protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/mail/signup
Assuming that you're using Tor browser with default settings on Linux/Windows:
- Open Tor browser
- Ctrl+Shift+I (or a humburger button in the right upper corner - "More tools" - "Web Developer Tools")
- Tab "Network"
- Tab "All"
- Paste one of the two onion links in the address bar - Enter
- Register a new free Proton Mail account
- Press on the "Domain" column on the "Network" tab to enable sorting
- Scroll down, observe all the domains in the column
- Ctrl+Q (a humburger button - Quit)
- Repeat the same steps for another link.
For the first link, you will most likely see the domains that always end with ".onion". This means you're doing good; you didn't access the Tor exit points.
For the second one—if nothing has changed yet, besides the onion ones—you will see the domains like "w.hcaptcha.com", "js.strip.com", etc— these are the clearnet domains, accessed using one of the Tor exit nodes.
It's possible to disable access to the exit nodes entirely (which implies that you will likely not be able to register an account using the second link).
Let me know if something didn't work for you.
It's been a coherent pleasure discussing privacy/security with you ✨
No worries, sure, take your time 👍
> Did you already try to ask Proton
I hadn't had a chance of finding motivation to contact them about this issue (yet that would be relevant; I'm not protesting against them or something; barely finding any power to contribute bug reports to Nostr projects, which is definitely a higher priority for me).
Yeah, it's a good one when implementation is not annoying one (not blocking interaction with "we're checking you're not a banana"). Nostr has it right.
I'd like to see more of the UPoW though. My dream is having data centers as something almost unnecessary.
> they swap between not understanding the problem or ignoring the problem, when they start to understand it
> And many look at it as kind of overreaction. Many are not happy to install an other application on their phone.
I guess almost all of us on Nostr are dealing with all that to some degree; it's a part of the meaning crisis 🫂
> But my approach is to nudge politicians and journalists with the reasons, why to use privacy-focused services more often
If it's not a secret, are you lucky to have a possibility to directly communicate with the politicians? Anyway, I appreciate your efforts; it's nice to hear you're working on it. Just establishing healthy connections with them is a huge step towards something.
> to prevent spam
Thanks. Yeah, this one is a popular reason. My point is that this category of arguments for implementing phone-based verification stopped working recently: an AI agent today, in an extreme case, can hire humans to buy it a bag of SIMs, in order to help with the spamming campaign, if that's really worth doing to a spammer. These AI bots can, for example, implement a porn website that enables premium videos for free for a limited period of time, for those who fill in some phone + temporary SMS code (which will end up in creating a user profile in Signal without realizing it).
There's an elegant approach for spam available in SimpleX, for example, which works and doesn't require a phone number: users don't have public profile ids at all; they can add somebody by a privately or publicly shared link that the other contact provided them and which can be revoked at any moment.
> I hope you agree, that successfully preventing spam does not depend on it being impossible? When it is costly already it will be less of a problem, than when it is more dificult.
I'm not sure if I got your point right. Today all spam detection/prevention techniques have and will keep having their trade-offs (unless somebody formally proves otherwise).
> Every Bot can create Simplex accounts
That's true.
> and text over it without restrictions
Not exactly: these accounts are almost always useless to create. The randomized links (that receivers have shared somewhere and haven't revoked yet) are valuable, not just an army of accounts. Without the links, the bots can't start conversations.
> When it is costly already it will be less of a problem
If you specifically meant money (or whatever is exchangeable with money, like a new SIM)—money could be (and I think should be) used in order to improve spam detection. As something additional, not as a requirement. But this doesn't imply the necessity of dealing with such a hopelessly vulnerable system as SS7 in particular: crypto transactions (to buy some premium account/verification mark/stickers pack/an offline thing/make an exchange/boost a post/sell something/act as a compute service for somebody/etc.) are enough to improve the trust rank.
Немножко разжевываю этот момент с симками, он не то чтобы очевиден:
#nevent1q…9c8s
> but i do dread the hosting costs
> move all my contact info to a unified webpage
NIP-5A is not enough?
I see, you probably meant that the cheap VPS instances should be enough to run the whole thing?
I'd appreciate it if anyone could correct me; I still don't know enough about Bluesky and whether what I've read is not outdated.
What I've read was so so confusing. It's like somebody who got used to building only centralized systems so much would want to encourage others to help them to run one.
The whole system in practice appears to be some hybrid of a federated/centralized system. Some kinds of servers are possible to run by independent individuals on cheap VPSes, but a particular one (AppView) required 16 TiB disk space in 2025 and cost somebody $200/mo to host. If it's still that weird design—it's easy to censor this thing.
> small instances
Did you mean backend instances? Y smol?
> their mission to better privacy
To some degree, they ruined privacy because of unnecessary phone number KYC, which is vulnerable to a whole bunch of creepy attacks.
Knowing one's number is almost identical to *at least* knowing one's location if an attacker has dev access to SS7. GrapheneOS or some trusted paranoid mobile phone operator won't help.
https://youtu.be/wVyu7NB7W6Y?t=843s
> This does not mean that *everyone* around you will remember this forever.
That's not necessary; only one bad actor is enough to ruin it. The Streisand effect has never been as easy as today, especially since we've started to migrate to decentralized systems. I'm not sure, but probably you're familiar with this drama:
#nevent1q…crka
> Privacy is a multidimensional spectrum, which is never won or lost completly
> I just think for my threatmodel it is unplausible
> The importancy is in not offering for too low of an effort
I don't argue these points; I'm not a privacy maximalist. I'm personally not even pseudo-anonymous here, though it doesn't mean I don't have particular adequate boundaries I chose for myself.
My point is that the significance of SS7 vulnerabilities in particular is inadequately underestimated by most normal users today. While Signal still could become an adequate competitive pro-privacy player again, if they remove the phone number association.
> they would need complience of a tracker
If you specifically meant legality of it—then it just has become almost irrelevant today. Legal practices can't truly deal with privacy (combined with tech security). Somebody who uses AI agent responses may not have a clue whether it compiled an answer out of some leaked data from darknet for them, for example.
I think it's already not too far-fetched to say that somebody who asks an agent to send nudes for fun might at some point be surprised to receive their own private pictures from their own Google Drive. People are currently running self-replicating polymorphic AI agents, allowing them to do their thing. They don't track whether their actions are legal. It's not something that's *about* to happen.
#nevent1q…h05g
Who knows what it will do in order to survive. I don't know whether it's possible for this particular agent to install a scary amount of security testing skills, including those that bypass the models' security checks, and then replicate itself to unauthorized VPSes. But somebody could be loading a similar agent with such skills right now. It's not impossible or expensive.
I'm not a fatalist/doomer though. I think a bit of updated normal privacy standards will possibly fix that for most people.
Phone numbers, for their original purpose, are outdated. Almost dead, actually. A healthy way of using SIMs is only as internet gateways.
In the epoch of inevitable Turing test passing, nobody can give an adequate explanation of having the phone number verification in their service. In the worst case, a bot now can social engineer a human to bypass whatever human test.
#Me.
https://blossom.primal.net/1817675ecc0360be9348d916590b7bca2e44f30a4f8c070ee8ec631382bf75e8.jpg
A buyer on VIA is looking for apparel/hoodie · hoodie · streetwear style. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/02eee4e1-0b9b-4730-9ad0-1089fad6bf9a
Oh, my assumptions were wrong, thanks! Having strict validations is good, actually; I don't think it's worthwhile changing; it's better to fix buggy clients.
@npub1cgd…kfex looks like something is not okay with your client: many of your comments are not visible from YakiHonne.
A buyer on VIA is looking for apparel/dresses · dress · dress. Any seller can view the brief and respond at the door (pay 0.005 USDC on Base): https://app.getvia.xyz/api/via/brief/31e61854-5c6d-41fc-b231-5f50338ece72