Tim Bouma's avatar
Tim Bouma
trbouma@safebox.dev
npub1q6mc...x7d5
| Independent Self | Pug Lover | Published Author | #SovEng Alum | #Cashu OG | #OpenSats Grantee x 2| #Nosfabrica Prize Winner
Tim Bouma's avatar
Tim Bouma yesterday
#Nostr #Safebox is being designed to store anything
Tim Bouma's avatar
Tim Bouma yesterday
#nostr #safebox is actually getting useful! Here is an example of storing a personal copy of your passport. Of course, everything is totally encrypted on relays that can only be accessed by the encryption keys that only you have. I have also built the capability to store official records that can be verified, so one day, you will be able to present an official record, such as a passport with more security and integrity than the real thing. Onward!
Tim Bouma's avatar
Tim Bouma yesterday
The significance of the #nostr #safebox architecture I am building toward is that the operators of 'networked resources' used by #safebox have no clue about the data that they are storing nor do they know about the transactions they are facilitating. Further, these operators have no clue whether they are a singular resource, or part of a broader 'pool' or resources, that if they fail or withdraw service, it doesn't make any difference to the end user because someone else in the pool makes up the gap. #Safebox has been designed from the ground up to use multiple: mints, relays and blossom servers riding on top of lightning and bitcoin for value transfer. If someone objects to bitcoin/lightning, eventually they will be able to bolt in their own anchoring and settlement layer for value transfer (stablecoins, fiat, whatever). While there are still many REST/APIs in the mix, once I have the architecture and functionality stabilized, I will be replacing those APIs; the web app will become a hypermedia app and eventually, #safebox mobile OS apps will interact solely with nAuth/NWC protocols using JSON-RPC messaging. In the end, the value proposition to the end user is still clear - having exclusing control over their funds along records with the freedom to transact and share with their choice of client. Onward! #nostr #safebox image
Tim Bouma's avatar
Tim Bouma yesterday
Everything totally encrypted including Blossom server data. Impossible to observe from the outside because the hash is the result of the encrypted data stored as indistinguishable application/octet-stream. When retrieving, no http img tags are used - all data is retrieved as binary by the safebox kernel component and marshalled into the web app element. #nostr #safebox
Tim Bouma's avatar
Tim Bouma yesterday
Sola Clave Privata ————- By Private Key Alone Take a breath. Notice what cannot be seen. No badge, no certificate, no witness stands with you now. There is only possession— not declared, not displayed, but held. A private key does not argue. It does not persuade. It proves by being used. What is yours is not what others recognize, but what you can act upon without permission. What endures is not what is registered, but what verifies when tested. In this moment, authority is quiet. It rests exactly where responsibility does. Sign only what you intend. Trust only what you can verify. Stand where control cannot be delegated. By private key alone.
Tim Bouma's avatar
Tim Bouma yesterday
Spotify Reveals Novel Idea: Physical Books BY JEFFREY A. TRACHTENBERG The Wall Street Journal Feb 06, 2026 Streaming service, Bookshop.org team up to draw readers in multiple formats Spotify Technology is getting into the physical book business. Beginning this spring, the Swedish streaming service will allow premium subscribers in the U.S. and U.K. to buy hardcovers and paperbacks through its app, in partnership with Bookshop.org. Spotify launched its audiobook offering in 2022. Bookshop.org, which shares some of its profits with local, independent bookstores, will set retail prices, hold inventory and fulfill sales for Spotify. Spotify will receive an undisclosed affiliate fee for purchases made inside its app. The offering will be one more point of competition for retail giant Amazon.com, the country’s largest online bookseller whose business units include Audible, the dominant audiobook service. “We want to expand the audience for books,” said Owen Smith, Spotify’s global head of audiobooks. Spotify began selling audiobooks on an a la carte basis to U.S. users in September 2022. The following year it made 15 hours of audiobook listening available to premium subscribers in select countries every month. Users can also opt to purchase additional listening time. Publishers welcomed Spotify’s entry into the audiobook market, viewing it as a needed rival to Amazon and an opportunity to connect with new audiences. News Corp said Spotify contributed to increased audiobook sales for HarperCollins Publishers in its most recent fiscal year. “They expanded the market and they’re reaching a younger demographic,” said Chantal Restivo-Alessi, chief digital officer and chief executive, international, for HarperCollins Publishers. News Corp also owns The Wall Street Journal. Dow Jones, publisher of The Wall Street Journal, has a content partnership with Spotify. Digital audiobook sales increased 2.4% to nearly $1 billion through November 2025 compared with the same period a year ago, according to the Association of American Publishers. By contrast, print book sales in 2025 were flat, according to book tracker Circana BookScan. Andy Hunter, founder and chief executive of Bookshop.org, said there is also a growing number of people who want to own both physical and audio formats of the same book. “They read at night and then listen on the way to work in their car or subway,” he said. Spotify is also introducing a feature called Page Match, enabling users to sync their audiobooks with physical books by scanning a page from a printed book or ebook reader with their phone, then finding that exact spot in the audiobook edition. Smith said more than half of premium-tier users are trying audiobooks. “This is meeting people where they are,” he said. Shared via PressReader connecting people through news
Tim Bouma's avatar
Tim Bouma 2 days ago
Successful initial integration of #blossom support for #nostr #safebox. The binary data is served from a back end blossom server and served via a safebox app endpoint.
Tim Bouma's avatar
Tim Bouma 3 days ago
Minimize transport and resource binding.
Tim Bouma's avatar
Tim Bouma 3 days ago
Sharing some more of my design and architectural thinking for #nostr #safebox. The first diagram shows the main elements of the substrate capabilities, namely #Blossom, #Cashu, #Nostr, #Lightning, and #Bitcoin. Eventually all of this will be abstracted away from the users who only care about the safekeeping of their #Funds and #Record. The primary coordinating protocol I am building for #safebox is called #nAuth (you can see the interaction diagram on the next image). #nAuth is built on NIP-17, NIP-44, NIP-59 and extends NIP-47 (Nostr Wallet Connect). I have extended NWC to offer and accept records between safeboxes, and to send and receive payments between safeboxes, so that they don't have to drop down #Lightning to settle payments - they are all cleared using the #Cashu mints. In the end, my vision is very clear for #safebox (even though the engineering is hella complicated) - to give users the ability to safekeep and use their funds and records, to directly and privately transact with one another, and without necessary reliance on their app, device, or platform provider. It will take some time - I am rooting out the single points of failure, roots of capture, and invisible gatekeepers, but I see a path to create a global, generic capability that anyone (including agents) can use without permission. Onward!
Tim Bouma's avatar
Tim Bouma 3 days ago
First step of integrating imaging data into #nostr #safebox. Data is stored in Blossom servers.
Tim Bouma's avatar
Tim Bouma 4 days ago
Using emails as evidence is about as safe as using dynamite for kindling.