Damus
supersu profile picture
supersu
@supersu

Founder of holesail.io, an avid reader and a Linux enthusiast.

Join me on Keet.io - Holesail.io (invite expires on 2024/6/13 5:01 UTC)

pear://keet/yrbaxx3qmntmqgpfwi9ddo7ehqcjwm6nznt41r59u1tnmfz3o93y5m54pmiakkpksq6mjod8otqtj3jyut3ppxgg3idzcryqneekhrhhnpc9pedg

Relays (7)
  • ws://superpi.local:6969 – read & write
  • wss://nos.lol – write
  • wss://nostr-pub.wellorder.net – write
  • wss://offchain.pub – write
  • wss://relay.beta.fogtype.com – write
  • wss://relay.damus.io – write
  • wss://relay.primal.net – write

Recent Notes

supersu profile picture
Hey, Apple does not let Holesail run in background for long. I am currently looking into solutions for this and open to suggestions, but the best way to solve it for now is to integrate Holesail into your appplications.

supersu profile picture
Looks pretty good. Yes, if Zeus can interact via tailscale, it can intersct via Holesail.

supersu profile picture
I am at the Plan B conference in El Salvador, come by and say hi if you are also there.

You can find me in the Keet booth or roaming around all over the place.

supersu profile picture
To access anything self hosted when you arr not home, here are a few that I personally use:

1. Immich
2. Vaultwarden password manager
3. Expense Manager
4. Paperless ngx
5. Portainer
supersu profile picture
Unpopular opinion: Absolutely terrible idea

Nostr-web-services is just ngrok / cloudflared with extra steps and more concerns about safety.

1. The things you expose are public; hackers can find you and see whatever you are hosting.

2. You DO NOT OWN your web service if the name servers are not under your control.

Whoever owns the name server is the prime authority, and they can inject whatever they want into your website.

Imagine out of 10 relays, even one of them injects your website with a code to steal passwords and you happen to use that relay (YOU ARE COMPROMISED!!)

It is as dangerous as port forwarding / dynamic DNS with extra concerns about integrity.

When I say "as dangerous as port forwarding", I think I am explaining it casually, but in reality, this is far more dangerous and concerning.

Just two days ago when I was looking into issues with port forwarding / dynamic DNS / Nostr-web-services, I discovered:

1. THREE THOUSAND (3k!!!!) Tesla with open information about their home coordinates, their kid's school, drop location, their workplace, their exact address, if their Tesla is active or not.

2. 6K + Camera with a full recording of the whole month, installed in people's personal—-BEDROOM--, baby monitor.

There is no excuse for self-hosting irresponsibly; it should be done to increase your privacy and security, not to increase the risk.

Holesail provides a way to achieve this peak self-privacy and security. You expose only what you 🫵 choose, and only the person you want can access it, with no chances of a man-in-the-middle attack from a random relay and their DNS hosting.

I like how enthusiastic people are about Nostr and Nostr-based services, but we should NOT overlook the security and risks some of these ideas might bring!



@npub1h8nk2...

@note12vy8l...