Damus
Ostrich McAwesome profile picture
Ostrich McAwesome
@Ostrich McAwesome
So basic introduction for anyone interested: I am a gray hat hacker and cybersecurity awareness activist who likes to stir up privacy-centered networks. I have probably met some of you before.

I actually came here looking for a challenge. I've been lurking around here in some form or another for about 4 months now, playing with different clients and tools, even running my own testnet (3 stirfry relays on a VLAN). Mostly I have been focused on the community and how people use different clients. I've been playing with some good open source tools and getting an understanding of how to interact with relays.

Personally I'm not all that into Bitcoin, but I do have a whole BTC in cold storage so I guess I've got that going for me. This whole lightning thing is new to me, I don't really ever spend Bitcoin, and my actual business makes me plenty of fiat.

So far I am impressed with the community. A little too wild-west in some areas since there's hardly any moderation tools, and the community isn't quite interested in the same things that I am, but I do see a lot of advocacy for privacy and digital freedom, and I like that.

But the whole system here is, regrettably, broken. The promises made about Nostr don't live up to reality. A network like this has the potential to become so much more, but there is a lot to lose if it is done wrong.

I intend to help expose these problems. Expect me here for a while. There are a lot of vectors for attack, and I plan to give them all visibility.

Nostr devs, please pay attention. With no centralized network development, all of you are responsible for fixing these issues.
259❤️14🤙13💜3👍2🤔2⁉️1
elsat · 108w
Thanks for bringing privacy to the forefront. Few read the respective nostr github project documentation on privacy. Your method of exposing privacy on base nostr protocol has been effective. > hardly any moderation tools Despite this, the discourse is more civil than that of twtr. Maybe it’s a ...
hodlbod · 108w
Sounds great, looking forward to what you come up with. We need people like you to stress test the network, because as you say there are a lot of vectors. Be patient with us though, because devs have an incredible amount of work on our plates. This is a 30+ year project. Let's go!
JeffG · 108w
I would love to hear more about what you think the top 2-3 things are that are broken. I get that the network is not very mature when it comes to strong privacy or moderation but are there specific things you'd call out?
youngMoney · 108w
I'm not aware of anything broken. Show us please
Enki · 108w
Your approach come off as being a little bit heavy-handed, but after giving it some thought I kind of appreciate what you're doing. We need privacy stress tests and unfortunately, gentle reminders don't seem to work. We can jump up and down and scream about the importance of a VPN and basic privac...
Mike Dilger ☑️ · 108w
Glad to meet you and yes, please share what you find.
Justin_Tokyo · 108w
Hi ! Looking forward to seeing what you have found out.
Notkeynesian · 108w
Perhaps create a second nostr account for bot posts (e.g. the IP addresses) as they are informative but they make u individually difficult to follow.
Christopher · 108w
Unsure about what you mean with “it’s regrettably broken”. Would love to hear more on this. Thanks to nostr:npub1san22nhe59ct8pstcehav4dtkf94lkn46ltl7d30g3zzl00tg7ussgqjdd for reposting.
The Marie ⚡️🦂 · 108w
I completely agree with certain types of ‘stress testing’, breaking things and exposing gaps but I do NOT agree with posting IP address that can potentially hurt someone. I understand that this can easily be found, however if the particular person wants to go to the effort of finding out that in...
Late Night Blog · 108w
*Breaks into warehouse *Beats security guard with baseball bat "Look at that attack vector. Good thing I exposed it or else somebody could have used it to hurt you."