Constant's avatar
Constant 1 month ago
Nostr is not an 'escape', not a 'refuge', and going to Nostr is not 'fleeing'. This mindset/frame is not just unhelpfull, it is incorrect. Shelter is always shitty, and hopefully temporary. Nostr is the next thing, it is better, it is moving forward. People did not 'flee' television to seek refuge on the internet, they dude not 'escape' letters for e-mail. yeah yeah, i get there is a lot of development work still to be done, lots of areas completely unexplored and underdeveloped, and rough edges remaining in those areas that are better established. But we have to understand the fundamental enterprice here. Yes you give up existing established network effects, but you move towards a domain where the network effect potential is far greater. Yes you will probably struggle a bit feeling comfortable dealing with keys, but the flexibility you get among an application eco-system is liberating. Yes you will have to wrap your head around relays and event-kinds but the experience of freedom of association and unsilo'd data is far smoother. If you understand what is going on, you would not even want to stay in the legacy system, because you see if for the dead-end it is; those draconian governement laws are just nails in the coffin, the corpse itself already rotting. If you understand where Nostr is heading, you'd want to move over; not out of panic being stuck inside the decomposing body, but because you see the new horizon. Fortuna Nostr

Replies (29)

ZeroHash's avatar
ZeroHash 1 month ago
Nostr is not the next big thing. No matter how much you/me work on Nostr - it will always just be a super small niche project for hardliners.
Constant's avatar
Constant 1 month ago
Well, you can say that, but what is your thesis behind that statement? I can shortly re-iterate my reasoning, which is based on the fact that the (potential) UX is better (pick your app, pick your algo, not having to manage multiple accounts to access various silos of content, smoother paywalls). And that the horizontal network-effects throughout various social-graphs/usecases ultimately is more powerfull than the vertical social-graphs per use-case. I.e. we are not competing head on, we are ultimately on a different plane all together. (i did not mention timelines, i have no idea on the timelines. There are also various domains as wel as geographical and social groupings that may run on different timelines)
ZeroHash's avatar
ZeroHash 1 month ago
The fact that only 0.1-1 % of humans are intetested in censorship-resistance and privacy at all is one reason. The other is: the mainstream is fucking afraid of using 'keys'. They are not able to grasp that concept. They can't handle self-hosted things and they don't want to. They lose their fucking passwords and need someone to recover passwords for them when they are lost. BTW: The UX is ten times worse for normies. Try explaining to normie-internet-users that their data/posts are gone now cause a relay is offline and they should have run their own relays. Or that they can't use image-uploads cause someone needs to pay for the hosting. Or that half of the apps don't work very well and are only vibe-coded over one weekend and then abbandoned. I spent a lot of time showing the Nostr protocoll and different nostr apps to people. They mostly don't like it. Bad UX. Imo: Nostr is niche. And will always stay niche.
Constant's avatar
Constant 1 month ago
Alright, lets tackle this: First, privacy is not really a Nostr talking-point. Aside from apps not needlessly spying on you, and if they do want all your base to be are belong to them, you simpy use another app because you can. Nostr is first and foremost a publication protocol...i.e...public; it was not designed to be private. Second, censorship-resistance from its political angle indeed is not all too interesting to most people. But the internet itself is censorship resistant, was build for that purpose, and is very much the reason why it caught on because it also means fault tollerance. The fact that some content creator gets away from view because it gets (shadow)banned for whatever reason, or platforms simply stopping existence, or some AWS panick shutting everything you use down ARE reasons why Nostr is simply better; because it does not (necesseraly) suffer from those things. You don't need to self host anything, Nostr is delibaretly not P2P. To quote the intro of the ''white-paper'': "it does not rely on P2P techniques, therefore it works.". As for keys. Humans generally are perfectly capable of savekeeping things. It is not some foreign concept, we do it all the time. They are just not as familiar with cryptographic keypairs yet. This is just a concept that they need to develop intuition around, in order to addequately leverage the practices, tooling and systems we have and can come up with to mitigate some of the rougher edges. Saying ''they are not able to grasp that concept'' is frankly stupid if you look at a bazillion of everyday things we ''demand'' the general populace to ''grasp'' in order to function in daily life; you just never reflect on them because they are already normal to you. Data-loss is first up a bad relay setup; and second not some incomprehensible thing. What, are people suprized they lost their stuff if their house burned down? Same thing with the key stuff....do we have ''house rotation'' for the moment your house burns down? Are houses doomed and will never take off because a lack of ''house rotation''?Do people expect that magically their valuables, like photo-albums to re-appear and are they confused they are gone if their house burned down? Ofcourse not. All of this is such a cold take, because basically what you are complaining about is the fact that people have yet to develop an intuition around a completely new paradigm. Well...duh, obviously. Zoomers can't read analogue clocks anymore, is that because analogue clocks are some mysterious ultra-turbo-mega complex thing? How about you try to explain how to draft and post a letter to a zoomer, or how banking worked before the internet. You will probably have just as much of a hard time explaining that as you have explaining Nostr to newcomers. In first instance, this has nothing to do with Nostr as such, but just with the fact it is new, and therefor unfamiliar. They lack the concepts, the words, and some image on how things roughly fit together in order to incorperate it into their world-view. The thing is, non of this actually stopped any new paradigm from ultimately becomming normalized. So that brings us to the question as to why a transition to the new paradigm would occur at all. That, i already gave a brief outline for that.
ZeroHash's avatar
ZeroHash 1 month ago
Nice tackle. Your arguments sound really good to me personally and maybe some other ppl who like to take responsibility in their own hands. This human mind set is very rare. They don't want that responsibility. My personal experience is always the same: they try nostr with social media apps like Damus or Primal - it does not work as expected and it does not deliver useful algos and constant fresh content... while Instagram, reddit, 4chan or X does. I do hope you are right but I do not believe it anymore. Nostr is and will imo be only useful and positive for a very small group.
Constant's avatar
Constant 1 month ago
well, the thing with leading a charge is that you need vanguard people. The masses only come after the battle is already won, obviously. But, that said, onboarding individuals is basically pointless (unless they show up out of themselves by themselves). Combined with “A prophet is honored everywhere except in his own hometown and among his relatives and his own family.” as many Bitcoiner for example will have probably noticed in their journey. Far better would it if you can get a community leader to bring his flok over, but that is also non trivial. So in any event, it will just be a grind regardless. The point of my innitial post was to (re-)frame that grind from something negative (moving away from platforms), into a positive perspective (moving towards Nostr)
I think people expect Nostr to be the next (every)thing, but to me, after 2 years working at a Nostr startup (@npub15xd2...t3l3), trying to use it for virtually everything, I realized Nostr is "just" (forgive me @fiatjaf for the use of "just") the next big thing for identity management. There's people obsessed with building EVERYTHING on Nostr (I even saw a guy building an Operating System with Nostr). Who knows, maybe one day Nostr will be the everything tool, but at the moment it's a unique tool, a GREAT one to manage our identities in a sovereign way. Anything else should be built reusing technologies that have longer track records and are more efficient. Here's an article @npub1dtgg...up6m wrote about it. He called it "As Nostr As Possible":
Constant's avatar
Constant 1 month ago
"Anything else should be built reusing technologies that have longer track records and are more efficient." If you mean how it is done with for example GRASP/ngit, we agree. But i don't think we agree...
I am not familiar with that. I was talking based on my own experience building an events app. There are many things like selling tickets, checking people in, creating gated events, waitlists... That Nostr doesn't have to do within it's protocol, but should be tackled connecting payment processor systems (wether fiat or Bitcoin), create databases of attendees, etc. Things that don't have to be part of the Nostr code, since there will be other event apps that will offer some other features and, in the end, the market will choose which apps to use for each purpose. When we expect Nostr to become the everything protocol, we are fostering comunism, where there is one unique and universal truth, and whoever is outside of it is considered wrong.
True. Nostr is, and should always be, just one small tool in a wider ecosystem. It sucks because I can come up with a few really cool use-cases for it if people don't try to make it swollow the entire project whole.
Go back to playing in your AI slop little piggie oink oink I dunno man, I didn't see anything from you that seemed expecially new. You made a microblogging platform. You made a streaming site. Ok??? We already had Nostr backed microblogging platforms. And do streaming sites even need to be Nostr based?
Everything we have now is shit because it's a Nostr microblogger, not because they don't work. What you made is guarunteed to be just as shitty just because of what it is, not because of how good or bad of a job you did at making it.
weev's avatar
weev 1 month ago
My perspective: using services without sovereignty, where sovereignty is now available, is a form of snitching.
weev's avatar weev
I was one of the first two political bans on Twitter. Despite some people being unbanned, I am informed by people close to Twitter that I am on a list of people not allowed to use the Internet, and permanently barred from the service. I will not be getting unbanned. If you use centralized social media, as far as I am concerned, it is no different than snitching. You are encouraging your friends to use a platform that is inherently controllable by the state and actively moderated by multiple state and ethnic authorities. Those who have done time or know targets of law enforcement will be familiar with the concept of “dry snitching” — essentially, putting information that you know law enforcement will be interested in within public view or some sort of side channel, in hopes that you will be spared interrogation. Using centralized services is dry snitching. It’s controlled, it’s moderated, and those who use it at this point should be called rats that cede control of the social graph to every form of wicked undesirable imaginable. Yids, sodomites, trannies, filipinos, lawyers, hybernians — all of them can have you and everyone you know silenced and surveilled on Twitter and Facecrook. At this point, people are willfully enabling this, and I operate by prison rules. If you sit at the snitch table, you should be assumed to be a snitch yourself. 1 follower on Nostr is more precious than a million on ZOG platforms to me.
View quoted note →
I never said it worked, I said that it sucka for reasons unrelated to how well it worked.
I almost completely replaced all other social media with Nostr. You can find everything here. Most popular news networks and people on other platforms have automated feeds. No censorship and true content ownership are cherries on top. I love it!
Constant's avatar
Constant 1 month ago
yeah, its actually amazing how far you can come with a bit of effort currently.
I agree that trying to build "everything" on Nostr is a bad strategic error. Specially when these things are even more dependent on network-effect than a microblogging social network (like uber or Nostr, for example) or when they depend on private communications. People have been trying to do this since day one, though, it's just something wrong with the mind of developers. But I think tools that are "social" in nature and mostly involving publishing human-scale content in the open but don't require that the entire world is using them in order to be useful (like geocaching, for example) are good niches through which Nostr can expand.
Constant's avatar
Constant 1 month ago
I agree with this moral angle. Not that it is particularly effective in ''converting'' people, but i think it is true non the less. In line with that i can't really bring up any more sympathy for any content creator or whatever that gets rug-pulled. They are very much aware of their precarious situation, so it was also on them to do something about it. The only thing can give them is that these things take time, and that Nostr itself still requires a lot of work, and that they can't just abandon existing network effects because they ''business'' relies on it; but at the same time, all of those things would be massively accelerated if all of them would dedicate just 10% of their attention to Nostr. Instead i encouter a lot of apathy, so....fuck 'm
Strongly agree, with one important nuance / correction on this part: "Same thing with the key stuff...do we have "house rotation" for the moment your house burns down?" I need to point out here that a fully functioning key rotation / replacement scheme for Nostr currently exists. This is not an unsolved problem. It's fully implemented at Inkan and you can use it today. I've been using it for months. The fact that people aren't looking at it or trying it out doesn't mean it doesn't exist. It exists and it works. See below. View quoted note →
inkan's avatar inkan
The way it usually goes, your online identity is your private key. If the key is compromised, there goes your identity. Inkan fixes that. You keep a master key in cold storage and a signing key for everyday use. If the signing key ever leaks or gets lost, the master revokes it and delegates to a new one. Same identity, same followers, fresh signing key. If you'd like to take a look at the prototype: https://www.inkan.cc. Log in with your NIP-07 extension and say hi to the test identities already walking around. Or make one of your own.
View quoted note →
Constant's avatar
Constant 1 month ago
I understand, but you run into the same issue the moment your master key is compromised. You buy a rotation scheme and allowing for 1 key in cold storage, by paying for intepertation complexity/demands. Im not saying that is a bad thing per se; one could argue that for high profile ID's, like a president or something, this is warrented; those that want to run this extra type of verification know that they should irt this ID, and can be bothered to do so (perhaps, assuming). But as a 'general' scheme, i: 1: don't believe there will be one scheme that manages universal addoption. 2: think that should not even be the case to begin with, regardless of whether that is manageable/possible/achievable. To expand on 2 (i deem 1 to be self-explanatory): all (rigid formal) defenses like this that you implement turn against you and benefit the attacker the moment an attacker succeeds in penetrating them. If the running assumption is 'this master key is truth/my guiding star the moment there is appearent chaos', and that assumption is invalid, you just increased the problem. Frankly, i suspect i think that all rotation schemes should be abandoned, but like i said i leave the door somewhat open that they could be valid in certain instances (though i am almost convinced they are not....almost). Ive written an article on this, but in short: If all you can do is extend what is ultimately the same problem, i much rather just deal with it head-on, and accept that the only way to fix this is 'social recovery', i.e. leveraging 'side-channels' to re-establish the same 'identity' under a different keypair via the 'social' context of the old keypair. The more significant an ID is, the easier this probably is to achieve, so the risk is mitigated in that sense. Where we find eachother is our love for OTS haha, because i think OTS can be used to preserve your post-history under an old key, by stating under the new key until what date the posts are valid, and outside observers can, using OTS, determine what is part of that history/the validity of it, after the fact. Anyway, you will probably always going to find me countersignalling any (formalized) rotation scheme, but don't let me discourage you :)
"I understand, but you run into the same issue the moment your master key is compromised." If you pay attention to the handling of the master key, it's quite unlikely that it will get compromised. You can create it on an airgapped system and then store multiple encrypted copies on, for example, 5 (or more) USB drives. You can store these USB drives in different secure locations, like a bank deposit box, a personal safe, or somewhere in your basement. You don't have to keep the master key close at hand since you will most likely never have to access it again after its creation (replacement of signing keys can be done using intermediary keys in the delegation chain, so you don't need to access the master key to perform signing key rotations). "... intepertation complexity/demands." The "interpretation complexity" can mostly be automated away. The Inkan client represents a prototype for how to do this. For the most part, the complexity has to be dealt with by the developer, not the end user. There is some residual complexity that the end user has to handle, mostly relating to the key creation and key replacement ceremonies. Basically, end users must learn to set aside 30 minutes to focus on the steps for key creation and replacement, and to use an airgapped device for that. This will feel like a huge bother and annoyance to people who are not used to it and where there is not yet social proof for the practice. But it is in itself easier to get used to than, say, driving a car, doing long division, or going to the gym. When people complain about "complexity", one should distinguish "This looks like a headache to implement" from "This will be a headache to use". The first may be true to some extent, but it just reflects developer laziness ("I don't want to have to code this" is not really a convincing argument against a perfectly feasible protocol, and lots of commercially successful software implements far more complex methods). The headache-to-use point isn't actually true and it's being conflated with "I'm currently not accustomed to this and why should I be doing it when noone else is?" Again, I think the main challenge here is to get social proof for the practice and, and once that's been done, people will be less prone to confuse "I'm not currently used to this" with "This is difficult to use." "... a president or something ..." Nah, this feels like saying that only the clergy needs to learn how to read, what use could a peasant have for such skills. And this is much easier than reading. "1: don't believe there will be one scheme that manages universal addoption. ... i deem 1 to be self-explanatory" This isn't self-explanatory at all, in fact I think it's probably false. The reason it currently *feels* self-explanatory is, I think, again that there is not yet social proof for the practice. It's a bit like saying in the late 1970s that, at some point, there will be a personal computer in every home. "... all (rigid formal) defenses like this that you implement turn against you and benefit the attacker the moment an attacker succeeds in penetrating them. If the running assumption is 'this master key is truth/my guiding star the moment there is appearent chaos', and that assumption is invalid, you just increased the problem." I think it's preferable to put up better defenses rather than worse ones, especially if it's easy to do so. I wouldn't say that the master key is a "guiding star." But having a master key that you can expect with some confidence to keep over the long term may incentivize some people to invest more seriously in building online personas with large followings (e.g. 1 million followers) that attach to that key. The key will make these followers portable across the internet. Of course, there is still a risk of loss either due to compromise of the offline master key, or due to flaws in the implementation or in the underlying cryptographic algorithms. But this risk will be smaller than it is with the available alternatives, and that differential may persuade people that investing in an online persona is worth their time. "If all you can do is extend what is ultimately the same problem ..." It's not an extension of the same problem. The difference is that you can reasonably have *far* greater confidence in the integrity of a key that has never touched a networked computer. With proper precautions, you can have a very high degree of confidence that the device you used for key creation could not connect to the internet, and that the key you created has therefore not been leaked. You cannot, as a matter of principle, have any comparable amount of confidence that keys which sit "hot" on an internet-connected device have not been leaked. In other words, "ensuring that device X is properly airgapped and cannot connect to the internet" is a very different type of problem than "ensuring that key X, which sits hot on my laptop in a browser extension, doesn't get compromised." You have a great deal of control over the former, and relatively little control over the latter. "... don't let me discourage you" Can't be discouraged as long as the underlying math holds up. As long as there's asymmetric public key cryptography + blockchain timestamping, this type of permanent decentralized identity is far too intriguing as something that should be added to the internet's infrastructure. It sort of refocuses thinking about the internet, which is currently still conceptualized as a collection of "websites" on which users rent space and identity from platforms, to a collection of user identities that avail themselves at their own discretion of the communication infrastructure that the internet furnishes to them.