Damus

Recent Notes

Paul Miller profile picture
noble cryptography v2 is out. Improvements include Schnorr implementation in 5kb noble-secp256k1, hybrid pq algorithms, OPRFs, friendly wrappers around native WebCrypto, better security, and much more.

Live on GitHub, NPM & JSR.
32❤️1🤙2🚀1
Colby Serpa · 31w
Add Falcon 👀 I see Kyber, Dilithium and SPHINCS+. Falcon has the smallest signature size.
Rizful.com (zap tester) · 31w
testing zaps for this note… your profile only specifies a nip05 nostr address, but not a lightning address, so we tried to zap your nip05 address.... we made six attempts to⚡zap this note, at [email protected], over a period of 6 minutes. in each case, we found that your lightning address serv...
nostrich · 95w
What happened and why did people change their name to "fiatjaf"?
waxwing · 116w
Interesting, thanks. Cool that you can swap it out for everything including signing! Curious whether you have benchmark/ test code that you could run against that swapped out for secp,
Paul Miller profile picture
2023 progress on JS cryptography:

- noble-hashes: 400K => 1.7M downloads per week
- noble-curves: ~0 => 0.9M, got 2 audits
- noble-ciphers: 0 => 25K
- Finally adopted by ProtonMail, MetаMасk, Rainbow, Rabby, ethers, web3.js, viem

Takes time, but we’re getting there.
1❤️3🤙2
Newton · 119w
Thank you very much. Gonna check it. 🫂
vnprc · 112w
I disabled my PIN after reading this.
frphank · 119w
Don't implement yourself, use the actual SimpleX client and server. "Each relay becomes a SimpleX server" means the relay and server are on the same host, different ports. The server may need some mod...
Paul Miller profile picture
> We're sacrificing almost all the values we stand for

I'm not sure what are you talking about. SimpleX is not a silver bullet. It's trivially decrypt-able by quantum computers. It's also not popular, which means, if/when it becomes popular, only then we'll see how it holds up.

Again - if you think simplex would work - go ahead and implement it. If you can convince the community your solution is better, everyone will switch to it.

nostr is open for everyone. We're just a bunch of folks who've spent some time on the issue we thought was important. No one paid us for it.
trustno1 · 119w
Lmfao bro, don't make fun of your fucking ass
Newton · 119w
How do you "may be bedlam broken" SGX, nostr:npub10jcnehsxwrjepupvh602pl83up0dh3wv3fqfwv062smygqvpeuwsk03kag? This is an extremely crucial claim for us, Signal users. Please help us understand.