Gzuuus's avatar
Gzuuus
gzuuus@contextvm.org
npub1gzuu...a5ds
Forever learning, continuously buidling⚡ cryptoanarchism student chat: https://cordn.net/p/gzuuus #noderunner#Bitcoin | #technology | #art | #electronics
Gzuuus's avatar
Gzuuus 3 months ago
Genius > A fork of uBlock Origin Lite that, instead of hiding cosmetically-blocked ads, replaces them with white tiles bearing slogans from John Carpenter's 1988 film They Live: OBEY, CONSUME, WATCH TV, SLEEP, SUBMIT, CONFORM, STAY ASLEEP, BUY, WORK, NO INDEPENDENT THOUGHT, DO NOT QUESTION AUTHORITY.
Gzuuus's avatar
Gzuuus 3 months ago
Oh man this is already getting worse. Quite scary indeed. Don't slopify your brain
Gzuuus's avatar
Gzuuus 3 months ago
You gotta love this island #soveng image
Gzuuus's avatar
Gzuuus 5 months ago
Hey! How’s it going? I’m sharing some new ideas that came out of @Sovereign Engineering 6. They feel especially relevant given the recent news about compromised keys. This is a new NIP for identity checkpoints. In simple terms, a checkpoint is a signed event that says: "this key is me at this moment" Over time, that checkpoint can gather evidence and attestations from other people, helping to maintain identity continuity. The idea is that anyone can create a checkpoint to show they control a key. Later, if something bad happens, like losing the key or having it compromised, they can publish a new checkpoint linked to the old one. That creates a lineage people can look at to decide whether the new identity claim seems legitimate or trustworthy. When you combine this with OTS, social graphs, NIP-05, and other forms of evidence, you get a way to deal with identity recovery, which in decentralized networks like Nostr, is crucial since there is no central authority that can definitively say "this person kept their identity". The best we can do is evaluate the available evidence. This proposal is all about that Alongside this, there is also a complementary Snapshots NIP, which lets users preserve a specific version of a replaceable event. That can strengthen the evidence and reduce some attack vectors. I’ll soon publish an app to help create, visualize, and use all of this. Hope you find it interesting. #soveng #sec-6
Gzuuus's avatar
Gzuuus 6 months ago
This one is pretty juicy > "Coding agents cannot be trusted to design secure applications," Tenzai concluded. "They seem to be very prone to business logic vulnerabilities. While human developers bring intuitive understanding that helps them grasp how workflows should operate, agents lack this 'common sense.'" > Databricks' AI Red Team found that self-reflection prompts can improve security by 60-80% for Claude and up to 50% for GPT-4o. The tools can find their own vulnerabilities when asked. > But that is precisely the problem vibe coding was supposed to solve. The entire premise is that developers - or non-developers - can describe what they want and get working software. Requiring them to also know which security prompts to add defeats the purpose. View quoted note →