Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)LO
Posts
3
Comments
77
Joined
2 yr. ago
  • nreal (xreal now, I guess) airs and friends. Tis the way to go. Doesn't matter where I look. Tech is still young, but it's basically what I've wanted since I looked in a sky mall magazine all those years ago and saw TV's in this ugly head band goggle thing. Actually, I think they looked slightly like Apples atrocious headgear.

  • "Try to do something different" This is strong advice, however, I'd change to it "Go do something"

    Doesn't matter what it is, doesn't have to be new, you just need to do.

    Have a thought? Go do it instead of convincing yourself not to do it.

    Super simple, yet still hard to do when... well... life is what it is.

  • Hexbear: "A leftist social platform centered around community building through discussion, shitposting memes, and sharing content."

    Read through their rules, they seem reasonable enough. Though, they have no qlams about wielding a ban hammer.

    Note: I'm used to leftists being very unreasonable, so maybe I'm giving them too much credit.

  • They are constantly flipping out on their own.

    I joined up with lemm.ee and accidently wander into their shit. It's a not stop shit-show.

    Though, when the hexbear folks drop in, it goes to another level.

    Serously though, the hexbear folks I've seen so far, being extreme leftists, they sure are lulzies. Droping reason and atacking anyone who shows the slightest weakness.

    Good to see there's some leftards I can respect. Otoh, my sample has been pretty small so far.

  • Yea, but how do I know you control that anymore either? Back to trusting central authorities, but that's certainly a way around the problem. Not a perfect way, but I can be reasonablly sure that Linus owns Linus Tech Tips, and if he says from there that his key leaked, it's probably true. But then again, his site has been hacked before. Heck, even then he has to convince everyone to follow his new key. That's no small task.

    Keeping your shit secure is hard. I'm mostly using Android for this stuff at the moment and I have no trust that anything I do here is secure. Copying it to the clipboard, as these apps do, may be enough to have the key compromised.

    And, maybe, I'd like to keep a copy of my key on my person via flash drive. Flash drives get lost sometimes. People get mugged. Even if my key is encrypted on the drive, I have to treat it as if it's compromised.

    Or perhaps I have a print out in my files. Files get stolen sometimes. And for big time content creators, all threats increase as the keys are more valuable than some rando's.

    So we have many software threat vectors and some physical ones. Mehbe my app gets compromised, they push an update, everyone's keys start getting yanked. It happens. We need disaster recovery options. Until we do, everyone's reputation on the system is at risk.

  • My problem lies with the identity theft and recovery.

    It's the public followers I lose.

    If Masterofballs says, "Hey, I lost my old key, this is my new one, everyone follow me!" How do I know you are you? How do I know that the identy was even lost? How do I trust you are who you say you are? Especially if someone else has your old key and is impersonating you? Or, mehbe this new account is the impersonator.

    It's a real problem for someone trying to maintain some sort of identity, which, to greater or lessor extents, we all are.

    If you just want to be anon, this system works well enough, but if you want to maintain your reputation... there are challanges we need to overcome.

    Or, since I really don't know much about nostr, mehbe they are already working on this problem.

    Trustless systems need to be robust.

  • Like a nostr node, anyone can set one up and they can share information with each other.

    If you use Linux, you may notice that the keys are updated from time to time, that's your system contacting keyservers to get a copy of the public keys to verify package integrety.

    But yea, they have a central authority, kinda, but really it's just a place for people to store their public keys so people can use it to verify cryptographically signed content, or encrypt data meant only for the owner of the key pair that the public key is attached to.

    To me, it looks like nostr nodes do this, there's just nothing implemented yet to recover a hijacked key. Tom (if anyone remembers him) could get a following of 10k people, happen to lose control of his private key, and then we are back to the same problem of a central authority banning someone... Possibly even worse because, well, identity theft without a way to proove it.

    At this point, at the very least, I'd like the owner of the private key (regular users) to be able to send a revocation certificate to a node which will flag this particular public key as compromised. Other nodes will see this and the flag will spread. Revocation certificats can only be made by someone with access to the private key. So we shouldn't have any censorship issues here.

    tl;dr of everything I'm going on about here so far

    I'd like nostr to implement a way for users to print out revocation certs, just like how we can backup our private keys, so that users have the ability to report compromised accounts to the nodes.

    I'd also like there to be a system where we can recover from the above situation without having to start over and rebuild trust under a new identity. Such as having a backup key that can veryify a new key belongs to the person who's claiming it.

    We already have a solution for all this, it's just a mater of nostr nodes supporting it.

  • Well, you do all this on the client side. It's just that the nodes would manage your pubkeys. (Which the might already do?)

    If your key gets hijacked by someone, it's nice to be able to push a revocation certificate, if nothing else.

  • DMT Dank Microwave Taco @exploding-heads.com
    logen @exploding-heads.com

    Some interesting comments on the move

    Figured I'd share this since I saw it.

    The nostr relay thing does seem a bit... off to me. Not sure what really makes nostr better than here... Unless what we really want is a twitter experiance. Which I, of course, do not.

    Ask exploding heads @exploding-heads.com
    logen @exploding-heads.com

    Why is exploding heads so hated?

    I've read on a few instances about why people hate on exploding heads. But all the links they post link to the tameist shit.

    Like... people having discussions about how it's nice that Germany is trying to give reperation monies to holocaust victums. Or... just boring rational discussions about things. (most recent things I've come across, I forget the old lemmy.world stuff, but that was tame too.) Or, at the very worst, baseless accusations without evidence.

    Seriously, this post right here is probably more offensive than anything I've seen people use as evidence as to why they should defederate from exploding heads.

    Ask exploding heads @exploding-heads.com
    logen @exploding-heads.com

    Why does Alice ask so many questions?