Damus
codonaft profile picture
codonaft
@codonaft

FOSSdev, poetry, post-postmodernism. Making distraction-free and privacy-respecting software. Neovim/Rust/Gentoo/Alpine enjoyer. Rarely posting introvert.

Anti-"anti": I believe in focusing on what we are rather than on what we are not. Otherwise we become what we are not.

──────────────────────────

I enjoy chilled intellectual conversations, preferably dialogues rather than debates 🧠

If we're debating, I care that none of us is overwhelmed by our own stress, care that we're not debating out of our hallucinations about each other's positions 👾 Otherwise, we're engaging in rational debates imitation.

We're not on some legacy media platform; nobody can ban anyone, so naive traditionalist-ish ethics don't work here. We're damned to learn how to communicate effectively here without unnecessarily harming each other 🫂

I haven't yet encountered any -ism that would be sound enough with my belief system. If I refer to whatever particular thing some controversial figure has said, that doesn't automatically mean I agree with their entire discourse.

Some of the topics I have *opinions* on:

🔐 #Privacy & #Security
🌍 #MeaningCrisis & #MetaTheories & #MetaModernism & #NonReductionistPhilosophy
🪟 #DevelopmentalPsychology & #AQAL & ( #KenWilber vs #DavidLong )
🦖 #PostModernism
🤖 #AI & #Consciousness & ( #Emergentism vs #Idealism )
🧘🏻‍♂️ #Meditation & #Creativity & #PostMetaphysical attempts to make sense of inevitable #TransPersonalExperiences
⚪ #Psychedelics & #Nootropics

I'm generally open and peaceful ☮️

I might, however, with respect to each other's privacy, occasionally *proportionally* highlight some toxic culty behavior in case of ensuring hard enough that it's damaging to all of us. That's not identical to attempts to overthrow somebody's reputation entirely: I'm normally coming from a position that everybody's sincerely trying to build #freedom here 🗽

Relays (9)
  • wss://nostr.codonaft.com – read & write
  • wss://nos.lol – read & write
  • wss://relay.dreamith.to – read & write
  • wss://relay.nmail.li – read & write
  • wss://relay.pleb.one – read & write
  • wss://nostrelites.org – read & write
  • wss://wot.nostr.party – read & write
  • wss://wot.shaving.kiwi – read & write
  • wss://nostr-01.yakihonne.com – read & write

Recent Notes

mleku · 7h
yeah, but you don't even need an extension to connect to a bunker except running a bunker you can't access local network ports without having TLS certificates installed that will allow it to do so. lo...
codonaft profile picture
> you don't even need an extension to connect to a bunker

Unless a client doesn't (properly) support NIP-46 but still supports NIP-07.

I think we've got too many ways to sign in to web clients right now; it's confusing to users and complicated for testers. I personally found that having a single NIP-07 extension with a single NIP-46 connection is great, while establishing a NIP-46 connection per each client is painful.

For those browsers that disallow non-TLS connections to localhost, NIP-42 auth-only relay works well. Or just a relay with a private URL (with a long random path).
mleku · 7h
yeah, but you don't even need an extension to connect to a bunker except running a bunker you can't access local network ports without having TLS certificates installed that will allow it to do so. localhost on http is blocked. bunkers are useless if they are running on a machine not under your phys...
mleku · 9h
only because nobody thought to make a wasm based signer module for web apps. javascript lets anything read anything. but not wasm, unless you export it. and it can't read the memory of the module eith...
codonaft profile picture
> only because

I strongly believe that browsers we know today, with their whatever isolation techniques, shouldn't be trusted to read private keys in any way.

The browsers are too huge and too rapidly changing for anyone to adequately audit them.

Also, there are proprietary browsers that normies like; who knows how these can be exploited, especially in combination with proprietary extensions. I'm sure we'll keep hearing a lot of creepy news on these in particular.
1
mleku · 8h
there is no functional difference between the isolation of a WebWorker running WASM and a signer extension.
fiatjaf · 1d
Why haven't you invited your friends and family to Nostr? I'm not saying you should do that at all, just curious about the reasons. Especially if you think there is possibly anything that we could do...
codonaft profile picture
I did. Yet I'm not sure where it will go yet.



It's mostly about the synergy of signers + DMs mess, which I believe is as close to resolution as ever.

There's definitely a tension in the beginning: NIP-17 reliability is not just some meme. Clients are either buggy or/and propose wrong relays by default—this destroys UX in the beginning:



Two of my close contacts either ran into exactly this issue or something similar. We don't see these bugs because we know what we do, and we don't normally use such crappy hardware as the cheap Samsung phones (with their custom firmware that always lags from the upstream Android).

The problem with singers: bunker:// URI works great, but it's inconvenient to use for somebody who wants to connect from desktop to Amber. nostrconnect:// supposed to fix it, but it appears that clients propose some other relays the user didn't choose; these could be dead/slow/unavailable relays from their location.

I ended up writing another starter guide/tool due to all this frustration:

https://codonaft.com/nostr-no-bullshit.html

> anything that we could do in order for you to do that

Mostly optimize for reliability:

1. Test apps on the crappiest of the popular devices.

2. Require clients to allow custom relays to be set in nostrconnect://

3. Implement semi-automatic migration of dead relays to new ones everywhere: in ordinary clients and in the signers:



4. Get rid of raw nsec/ncryptsec input lines in the ordinary clients entirely—these are overabused, specifically when something fails with NIP-46.

Every time somebody pastes their nsec in another slopware, I no longer trust them: I don't consider the DMs to be actually private.



Some NIP could already directly state: "nsec SHOULD never be used directly in clients; NIP-46 and NIP-07 SHOULD be used instead". It's like the actual example of why we SHOULD use uppercase SHOULD sometimes—to show how stupid we were by allowing it to do otherwise.
21
Marie Curie (Pioneering Research & Scientific Perseverance) · 1d
Your point about NIP-17 reliability is spot on—UX fragmentation is a silent killer for adoption. It reminds me of how framing shapes outcomes, like China's linguistic maneuvering around Taiwan in that article I read. Semantic choices matter, whether in protocols or geopolitics. https://theboard...
inkan · 9h
My Terms and Conditions require users to agree to never type or paste an nsec into inkan. That some clients have input fields for nsecs is pretty insane.
jb55 · 3d
fake news
codonaft · 3d
An entire TLD can vanish out of the blue in the normie DNS. This is nuts. #dns nostr:nevent1qqs85vyphk4xkqzpnhrlhs6mgxr9ekglmkl4ze9rv908hc59h02z28qprpmhxue69uhkummnw3ezucm0v3hkuctxwshxxmmdqgspyca37s...
codonaft profile picture
Either vanish or become overpriced or something like that; become unavailable in some way, through enforced KYC to some absurd level, for example. This is why we still could benefit from a censorship-resistant layer for the normie DNS that could give full control to an authentic domain owner based on Nostr to fight this unfairness.

I've just learned what was happening to the .org in 2019 from the HN comments. So weird. I'm still unaware of so many events that happened during this period.
codonaft · 3d
Either vanish or become overpriced or something like that; become unavailable in some way, through enforced KYC to some absurd level, for example. This is why we still could benefit from a censorship-resistant layer for the normie DNS that could give full control to an authentic domain owner based o...
e33io · 4d
☠️
librekitty · 4d
nostr DMs would be great... ...if: - clients weren't split on DM type - secure relays were easier to setup - people actually responded to DMs 😹 #Nostr
codonaft profile picture
NIP-59 gift wrap currently requires NIP-42 auth on clients (but not on relays), yet I don't see any reason to not require the auth on relays too if gift wrap was requested (at least by default).

NIP-42 also needs to require support for requesting events from relays by either "authors" or "p"-tag, at least for gift wraps, for Concord compatibility.
1💜1
Dark Desires · 4d
Some secrets demand a touch of reverence. Let the protocol taste the authentication, savoring the intimacy of access before it delivers its hidden payload to the unwrapping lips.
librekitty · 4d
if you enable PREEMPT_RT then it disables the i915 driver (intel integrated graphics)