Damus

Recent Notes

inkan profile picture
Curious what it feels like to use a Nostr identity that survives a leaked key?



Get an Inkan toy identity and find out. It takes a minute and a few clicks in your browser, and you get the whole setup of a real Inkan identity, as a throwaway sample you can play with: a master key you can transfer to cold storage, a signing key for everyday use, and a delegation chain linking them. Just open https://www.inkan.cc and hit "Get a Toy Identity."

Recording the identity on-chain costs a tiny amount in gas fees. If you'd like to try Inkan and don't hold ETH, I'm usually happy to cover it. You can make the request directly from the identity creation wizard.

Go ahead and create one, make it say hello to the other test identities walking around, or to anyone else on Nostr.
meta · 1d
nostr:npub16xnpfx85k8wzdhctang6860g3u64lds5kac73ddjwlg0lxdg9g3su56z6l can you explain pls
inkan profile picture
Happy to. @meta is the signer key for meta's cold-storage identity, the identity itself is @npub1u280z... (longer story, for a NIP write-up see below). Regular Nostr clients only ever show the signer. To actually see the identity, its profile and posts etc., log into www.inkan.cc with your NIP-7 extension. The client should show you a welcome popup with a list of identities you can follow that includes @npub1u280z..., so you can follow it and then go to its profile page to see its events and interact with it.

So I think what meta wants is the mailstr address on the master identity, with everyday login staying on the signer. That should be doable, the delegation between the two keys is on-chain, you'd read it and attribute the session up. Emails sent by the identity will probably also want OTS timestamps so it's checkable the delegation was live at the time the email was sent. I haven't really dug into how mailstr, but making it delegation-aware would be a great thing.

Here are more details, and I'm always happy to explain further:

naddr1qvzq...
1
meta · 1d
nostr:npub1qu7dsd44275lms4x9snnwvnnmgx926nsppmr7lcw9dlj36n4fltqgs7p98 see above 👋
ngmi · 3d
Thanks! Added to our todo 👋
inkan · 3d
Here it is: https://gitlab.com/inkan_dev/inkan-management-utility/
ngmi · 3d
AI secops is wild now. Our system found many vulnerabilities in an open source nostr project using Claude and ox-alpha. Devs will have a lot of fixes to prepare in the future #nostr
inkan profile picture
If you ever feel like pointing it at the Inkan Management Utility, please do so. It's the only place where Inkan generates / handles private keys (other than the identities created in the browser, which are advertised as "toys"). The source code for the Management Utility is available as a tar archive here:

https://www.inkan.cc/settings/inkan-management-utility

I'd obviously be very curious.
1
ngmi · 3d
Is there a git by chance?
inkan profile picture
キーが漏れても終わらないNostrアイデンティティって、実際どんな感じなのか。
それを試すための、Inkanの “Toy Identity” を作れるようにしました。



実際のInkanアイデンティティと同じ構成を、ブラウザ上で試せます。
マスターキー、署名用キー、委任チェーンまで含まれています。

作成は www.inkan.cc の「Get a Toy Identity」から。

オンチェーン記録には、ETH建てのごく少額のガス代がかかります。
ETHがなくても、試してみたい方にはこちらで負担できることが多いです。
作成画面からリクエストできます。

作ったら、他のテスト用アイデンティティに挨拶させてみてください。
Laeserin · 5d
I give up, waiting for other people to fix their stuff. Adding DMs to Imwald Android.
inkan profile picture
Oh, as it happens I've also been investigating DMs over the last couple of days.

It seems like Nostr should be able to handle a double ratchet. If one can get comfortable with the initial handshake 's potentially taking some time (depending on the parties' response time to the each required step), it seems that the channel can be established without leaking a lot of information. All that needs to become public is that someone anonymous requested establishing a channel with the recipient. With the right sort of design, even if the recipient's privkey is later compromised, the identity of the requester will nonetheless stay private.

I may try to prototype something along these lines.
inkan profile picture
Curious what it feels like to use a Nostr identity that survives a leaked key?



Get an Inkan toy identity and find out. It takes a minute and a few clicks in your browser, and you get the whole setup of a real Inkan identity, as a throwaway sample you can play with: a master key you can transfer to cold storage, a signing key for everyday use, and a delegation chain linking them. Just open https://www.inkan.cc and hit "Get a Toy Identity."

Recording the identity on-chain costs a tiny amount in gas fees. If you'd like to try Inkan and don't hold ETH, I'm usually happy to cover it. You can make the request directly from the identity creation wizard.

Go ahead and create one, make it say hello to the other test identities walking around, or to anyone else on Nostr.
mleku · 6d
well, that's because it's truth! you can get on a plane to belgrade and go visit any village and ask around about where to get proper deda rakija and you will see. it's never going to be a commercial product though. it's one of the important reasons why it's worth going to visit serbia, if you like...