Nostr: Notes and Other Stuff Transmitted by Relays
nostr.net
nostr.net
Imagine you're running a relay on your machine, and somebody posts some CSAM, or stolen CC data, or hate speech, etc through your relay.
Unlike an email client, your relay actually makes that message available to anyone.
Unlike an email relay, you are not forwarding the message to someone else like a dumb pipe; there's no final destination.
Unlike a torrent / DHT node, you do not know beforehand what you are going to make available.
Unlike a Tor exit node, you do not deal in encrypted fragments which you don't store locally.
Unlike an IPFS node, you do not store fragments of files while not even having a full set of such fragments for a given file.
Even though the message is signed, you can't reasonably prove that you do not possess the private key used to sign it, or have not possessed.
So, if you are an anti-censorship activist, and your machine gets searched (which may be even easier to do in the case of a VPS), you, the runner of the relay, may have some pretty unpleasant time. Even if you manage to convince everyone that you only forward these messages and do not inspect or endorse them, and the authorities will not even fine you, it will cost you time and trouble.
Worse, it becomes easy to send something incriminating from a throwaway or stolen client through your relay, and report you to the police. This can of course be done with email or any IM, but these will immediately show you what you've got, so you can e.g. immediately delete it. They do not allow perfect strangers quietly put random stuff onto your disk.
Of course the point of the protocol is to resist censorship, so any content deemed criminal by someone cannot be entirely blocked. But the publishers and the receivers of such content make their choice, while those running a relay seem to remain unprotected from from consequences of that choice which they did not make.
There are ways to address all of these problems if and when they occur.
I think one of Nostr's biggest contributions is its culture of pragmatism and speed. Do something simple, quickly that works instead of sitting around worrying about every edge case (which is a what a lot of "decentralized" projects do). If you have no apps and no one using them, none of the problems you mention exist. If you come up with something ridiculously complicated (think some recent w3c proposals), you've built a massive barrier to contributors and to developer and user adoption.
It's not the kind of censorship resistance which opposition in country with an oppressive regime might need, and in general not a solution against censorship by state-level actors.
Well, fair. Also, fun and lightweight, no browser needed.
Whether you think that's a good or necessary thing probably tracks very closely with your beliefs about whether money and its expenditure is protected speech. Obviously that's something about which the highest courts and legislative bodies in the USA already have complex and sometimes-contradictory views, so I certainly won't claim there's a single correct answer...even if my personal beliefs fall very much on the "money is a modern social fiction in no way connected to fundamental human rights" side of the spectrum.
Not sure what you expect?
Which I guess is kinda fine if you're building slow go-karts to do friendly races with your neighbor in their backyard - but instead you're already letting those out on the open roads on day 1.
Similar to software architecture, you do start by defining the preferred characteristics and then working your way to the other parts.
On purpose. You can't build a car today that ignores these learnings, and safely deploy it on the open roads; just like you can't build what's effectively an open relay like it's 1997 and expect to stay safe against the threats outlined by nine_k.
Your analogy fails at the mere fact that no physical harm can result from Nostr not solving this one thing you think is 100% necessary.
The fact that Nostr is up and running and working is the undeniable fact that you don't NEED to solve every single problem known to humankind before you write some lines of code.
I've never denied this. You can also DIY a go-kart and drive it on an open road.
> Your analogy fails at the mere fact that no physical harm can result from Nostr not solving this one thing you think is 100% necessary.
Notice how you've specifically used the term "physical harm" to differentiate from other forms of harm. Harm is harm.
> The fact that Nostr is up and running and working is the undeniable fact that you don't NEED to solve every single problem known to humankind before you write some lines of code.
...Where did I try to deny this? My analogy is very specific in that you can do all of these things, and with enough luck, nothing bad will happen.
The problem with luck is that it doesn't scale well, especially on the open road. I mean, Internet.
That is an assumption that you made and strikes as FUD. An equally valid assumption is that nobody can reasonably prove that the person has the private key used for signing the files. Assuming the stated nature of relays and their intended purpose, there is more ground to assume that a relay is a service provider without reasonable way to inspect the contents of encrypted data.
This would be entirely correct were the data encrypted %)
The data are signed, but otherwise plaintext.
For reference, kids in the US got arrested for possessing nude pictures of themselves on their phones [1], because mere possession of a nude picture of an underage person is restricted by law. Talk about who are you going to convince that some shady stuff just happened to pass your server.
[1]: https://www.cnet.com/culture/teen-arrested-for-having-nude-p...
For example; certain nodes on Secure Scuttlebutt have been known to push porn, and this gets replicated onto your store. That node was traced, and blocked by many on the sphere.
The majority on ssb were against that.
Now, a social network populated with crypto bros? Nah... pass.
Relays can be authenticated. If you don't want your relay to accept data from anyone, don't leave it open. Same with any other Internet protocol.
Also, per the spec or convention, relays SHALL NOT talk to each other. Each relay is a separate island, but the protocol permits and recommends clients to publish on multiple relays. This is the basis of their censorship-resistance.
See also my other comment: https://news.ycombinator.com/item?id=34530876
Also, it seems naive to think that a ban on blocklists in the spec will keep real free humans from doing exactly as they’ve done on email, Mastodon etc and share block lists.
You're probably right about shared blacklists eventually becoming a thing though.
The "XMPP camp" is doing well and very busy: https://xmpp.org/newsletter/
We're lacking a nostr bridge if anyone wants to work on that...
That has no bearing on an attacker.
I don't get it. What's the point then?
You can mirror one relay to another easily:
echo '["REQ", "mirror" ,{}]' | websocat wss://source | jq -del '.[1]' | websocat wss://dest
No protocol can prevent a piece of software from doing whatever they want.
The "shall not" is not absolute: the spec assumes and expects relays not to talk to each other. Nothing prevents you from creating a relay that connects to another relay, of course, but that would not be in the spirit of what Nostr is trying to achieve.
If I can store multiple messages on a relay I can distribute arbitrary files. So being text-only doesn't really limit anything.
Like email.
> Unlike an email client, your relay actually makes that message available to anyone.
On the contrary. Public mailing lists work exactly like this. You send a "subscribe" message (or enter your email address and click on a "subscribe" button, or whatever), and the server starts forwarding all the messages to you.
But all those attempts have failed. One presumes that this is because people like email the way it is... simple to use.
> mailing lists are very defunct for any sizeable group.
Hmm... I still subscribe to at least half a dozen mailing lists, some of which have hundreds or thousands of members.
And people choose to live in tyranny? No, it's because it's a coordination problem involving literally billions of people, thousands of pieces of software and would break compatibility.
> I still subscribe to at least half a dozen mailing lists
And I still use a radio to hew packets to connect to a BBS.
I wouldn't want to run the risk of being the first one it does happen to.
I think something like ipfs offers better resistance to such attacks for node owners. I wonder how the two compare because I don't know either in detail.
But sharing unencrypted content from others could be an issue for many reasons. Copyright too.
Especially because this protocol is aimed at content blocked or censored from other platforms, as others have pointed out.
Sure, you can block others from using your relay but then what's the point? Just host your stuff on your self hosted web blog.
Relays also don't host media, it's meant for text-based comms.
iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEWbueItP/xuAAAACklEQVQI12NgAAAAAgAB4iG8MwAAAABJRU5ErkJggg==
If I were to run such a node in Germany, and someone would use it to distribute CP with it, I face from 1 to 10 years in prison.
Yeah, no thanks.
When you run a Mastodon instance though, you don't actually need distribute this content at all. In fact, you probably would at least ban proxying media for communities like Pawoo, and honestly, probably, any NSFW-oriented instance if you want to be safe.
I hate to break anyone's innocence, but this stuff is literally everywhere on Twitter, and a lot of the rest of the Internet, too. Is it legal? Depends on your jurisdiction. Is it moral? ¯\_(ツ)_/¯. Only one thing's for sure: it's on your Internet, along with plenty of other things that you can also find on Mastodon somewhere. Such is the reality of federation and scale of the Internet. The stuff that goes through email relays unencrypted is not so different, other than the fact that it doesn't get broadcasted, and that it's probably worse in many cases.
If some instance was broadcasting outright CSAM on Mastodon, it would no doubt become quickly blacklisted by basically everyone and then probably also shut down off the clearnet.
Social media seemed novel af but it’s resolution was the extent of what our computers and networks could handle at the time. Not some finally destination.
Especially with future hardware, RTX 6000, or whatever they call it, and beyond making novel content generation via ML a thing anyone can do, social gabbing in filter bubbles seems even more likely to be on its way out.
Compared to the others, Nostr is optimized for innovation - it is easy to build new features on top and we'll see a lot of growth and evolution because of that. I really like that about it.
The problems I see with it right now are 1. Timestamps are easily forgeable 2. Difficult to control spam 3. Little incentive to run relays 4. Difficult to search the whole network
There are ideas on how to solve all of the problems, like POW on messages, like super relays(basically a mempool), there's a NIP for timestamps.
My guess is that it will evolve towards something that looks a lot like a blockchain. Decentralized Social is one of the few places where a blockchain actually makes sense. This will be interesting because the founding group is ideologically opposed to using a blockchain for anything but the holy BTC.
What do you mean by completeness?
Timestamping seems like the most difficult of those to solve
Verifying completeness requires a blockchain of one type or another, where new transactions/messages reference a hash of past transactions/messages in some way.
I registered, and while the registration was delightfully painless, it autocreated a wallet for me at legend.lnbits.com.
https://github.com/nostr-protocol/nostr#very-short-summary-o...
>Everybody runs a client. It can be a native client, a web client, etc. To publish something, you write a post, sign it with your key and send it to multiple relays (servers hosted by someone else, or yourself). To get updates from other people, you ask multiple relays if they know anything about these other people. Anyone can run a relay. A relay is very simple and dumb. It does nothing besides accepting posts from some people and forwarding to others. Relays don't have to be trusted. Signatures are verified on the client side.
The FAQ on the same page also answers questions about why Nostr instead of other options like Mastodon, Secure Scuttlebutt, etc.
There's also a recently launched podcast that talks to some developers building on the protocol:
So at least I made some money from this. :)
I'm following the project/protocol, it seems interesting. Here are some NIPS https://github.com/nostr-protocol/nips
It’s not tamper proof, ie signed, unlike GCM
> Some modern modes of operation combine confidentiality and authenticity in an efficient way, and are known as authenticated encryption modes
https://en.m.wikipedia.org/wiki/Block_cipher_mode_of_operati...
I’d also add: CBC requires padding and GCM does not. Minor convenience.
And GCM does not ‘add’ a signature per se.
> And GCM does not ‘add’ a signature per se.
Your own comment to which I replied said "It’s not tamper proof, ie signed, unlike GCM". Wouldn't most people consider something "signed" as having a signature?
It's not a "twitter alternative", it's not "federated like mastodon", it's not even social networking. It's just a spec for a signed message format and a relay server, that's it. It's very, very simple, you generate a key, sign a message, send it to whichever relays you want, it serves them to requestors or not, depending on what it wants to do. That is literally all it is.
Nostr's relays are simply servers that push and receive structured data. So it's a sort of an email or http like protocol that's by default cryptographically signed? I don't really see the magic that makes it censorship resistant or particularly decentralized. The same networking and economic laws that consolidate internet traffic or mastodon servers are at work here too. Relays get popular, produce a lot of traffic, this spawns "nostr as a service" for economic reasons, and that's about it.
If people want to ban you they'll just blacklist your public key across popular instances just like someone on the fediverse does, companies won't host your stuff, and so on. If anything tying everything to a single global identity makes it more trivial to blacklist anyone.
I think when you sub to someone you're also sent a list of nodes that a person uses. So when I'm banned you already have my node in your list, so you won't even notice.
The problem with Twitter is that unlike RSS, it shows content from people you did not subscribe to (e.g. you get replies, you see strangers' replies to your friend's posts). The content is public, so unlike e-mail, receiving abuse is not just your private problem, but a problem for the network's image and reputation.
But in either case, when normal users (not righteous keyboard warriors) find some content to be horrible, they don't want to see it. If they keep being bombarded with unwanted content, they leave. For Mastodon/Twitter/Gab that may be "political" content, but the problem in general is similar to spam.
Can you point to the part on the SMTP RFC that specifies the spam deletion behaviour?
> XMPP servers will kick out spammers and harassers
Nothing prevents nostr servers from kicking out based on account or IP address or message content
> The problem with Twitter is that unlike RSS, it shows content from people you did not subscribe to.
This is not Twitter, any client can decide which content to show. And there are clients that do not show any content from people you don't explicitly follow.
It could be a community run closed system where only citizens are given access to the system.
It doesn't (and I think shouldn't) have any crypto features built in. That's up to the client builders to handle.
There's no algorithm that will curate your feed for you, it's up to you to choose who you follow.
Don't like what someone is posting? Unsubscribe.
> NNTP is an application protocol used for transporting Usenet news articles (netnews) between news servers, and for reading/posting articles by the end user client applications.
nostr relays are not supposed to connect with other relays (I think to avoid the inevitable concentration of centralized hubs), which is a small but very significant difference
Update: It seems to be partly a twitter alternative perhaps using lightning network in some way. I set up an account on astral.ninja, created keys, username, saw that there were relays that were defined already. I couldn't see any posts in my feed, and when I tried to make a post it just hung and never posted anything. Suffice to say my initial experience started off okay, then dissapointment.
It's like a very minimal version of ActivityPub. It takes an hour to go through the whole spec and addenda.
Then Jack Dorsey got interested, gave the project a big grant (in BTC), and a lot of crypto hype flew into it. But while it is a convenient excuse to say "crypto, therefore bad", the protocol is itself completely unrelated and IMO quite neat. There is a lot of potential for systems that anyone can comprehend in their totality in an afternoon.
A Nostr account is identified by a public key, you follow accounts by following public keys and the ability to post as an account is controlled by the corresponding private key.
This tool lets you broadcast your pub key on twitter using a specified format, and the app will add you to the directory, and you can use it to find others that have also done that.
Also, if you go to https://snort.social/new, you can enter your twitter handle, and it will find everyone from you're twitter follows that you're not already following and let you sign up to follow them all.
It looks great, works well, the code well-written and super easy to hack on.
It seems to work a little differently to other clients by aggregating all the content on one relay first before sending it to the client, but I prefer this as it is faster and uses less bandwidth.
Fiatjaf who often posts here also stated that he would like to nostr to be used by non bitcoiners and even people who are antagonistic to bitcoin.
> If nobody wants to hear you spewing your stuff then you'll soon be screaming into the void but what you post will still be viewable on the web and to those that subscribe to you.
People who are de-platformed are almost always people who others WANT to hear. Think of all the famous people deplatformed from big tech social media...10s of millions of followers each. It wasn't that "no one" wanted to hear them, but that the people that controlled the platform didn't want others to be able to hear them.
> So I don't get what Nostr is trying to do.
It took me a while to get my head around it as well. The intro and faq on the github repo really helped me.
More accurately, it was because they repeatedly broke the terms of service and the companies were no longer willing to use their resources to provide free amplification for them. They had legal agreements with the platform and despite many warnings and leeway which isn’t extended to most people, chose to break the contracts.
They have platforms they could go to. Parler, Rumble, Truth Social, their own blogs/websites, running a Polermo or Mastodon instance.
Twitter was a giant public pool. For the most part everyone was chill. And then the trolls arrived and started shitting and peeing in the pool. Swimming in that pool (the algorithmic timeline and such) became horrible.
My idea that it was less about the "powers that be" deplatforming people and more not owning the platform you post on. I love the federated social movement and the push for people whom I agree with and disagree with to own their platforms I am just saying that the "wo is me, my megaphone was taken away from me and now I have no way to access the hordes of other trolls that think and spew the hate that I do" is a false narrative because nothing was stopping them from creating their own platforms with off-the-shelf tools or spinning up websites like the Drudge Report or blogs or going to the other places where they like the alt-right or other fringe folks.
Have you ever looked at the replies to a Trump tweet, an Ilhan Omar tweet, a J.K. Rowling tweet, or a Briahna Joy Gray tweet? The degree of bullying, invective, and threats coming from people who support deplatforming is intense.
Anti-Trump responses make sense. He's the most polarizing US President in recent history and almost everything he's done has been bad for the US (ok of course this is arguable but hold on while I make my point). Him leaving the platform was good for Twitter and for democracy. If he comes back as a candidate then he'll likely come back to Twitter, his account has already been reinstated.
Omar, if she breaks Twitter rules, can, and should, have her personal account suspended. As a sitting congresswoman she is entitled to her official handle. Unlikely to get deplatformed, so not an issue.
J.K. Rowling's takes on the transgender community is not even something I want to touch. It's too toxic and complicated to do so. That being said if -- see a pattern here? -- she runs afoul of the Twitter rules (whatever they may be) her personal account can be suspended or banned.
Briahna Joy Gray -- of course there are extremists on the left -- but if they don't oh I dunno -- incite a violent riot to overturn an election -- then I doubt she'll be deplatformed, though if she calls for violence or ... which would run afoul of rules ... see I am starting to see how the pool analogy really does work.
I know my stance on censorship is not a popular one. I have struggled with it myself. But I think it is self-consistent and I stand by it: let the wierdos, racists, nazis, hate filled folks scream into the void of their own making on servers they own to others that subscribe to their bullshit. As for me and the rest of the civilized world we'll continue to swim in clear, shit and pee-free water. ;-)
A tiny minority. The majority listens to public health (in the case of Covid) and doesn’t want to read conspiracy theories or research analysis by someone unqualified.
In Portugal, the group of medical experts assembled by the government was ignored after they opposed the political decision for injecting children: https://www.publico.pt/2021/07/20/sociedade/noticia/comissao...
It is wrong to dismiss the opinion of experts on this topic just because it goes against what mainstream media and political groups decide to impose.
Certainly there is an argument that children will be harmed if we do nothing. It’s a difficult decision because children a small number if children die from Covid, but it’s still not zero. The best way forward is to proceed with caution.
After two years before the injections existed exactly 3 cases of COVID-diagnosed deaths across a population of +700 thousand children in Portugal. Now the number of children with heart problems related to the injections is visible on news at plain sight.
The experts were ignored. Those supporting the experts on social media got banned or shadowbanned. This is not science, unless you consider medieval practices to be science.
edit: Additionally, the reasoning is fallacious - all people are minorities in many ways, so a few dozen tiny minorities can add up to an entire population. You may not disagree with the government about covid (although the government has disagreed with itself about covid), but you might disagree with the government about something else.
You're making the case that all social media should simply agree with the government line (because the people who disagree are minorities.) That's a dangerous case to make if you ever want to replace a government democratically.
Scientists work for the government. If something is wrong we should fight to fix it. But almost all of the scientists outside of government agree with the scientists that work for the government.
This is an important point. Free speech is really as much about the rights of the listener as the rights of the speaker, if not more so.
I think this is a good way of framing the censorship debate, because while it may be easy for some to dismiss the rights of a few dozen famous people that they hate, it's way harder to argue that the millions of people who follow those celebrities shouldn't be allowed to hear what they have to say, even if they want to.
(To be clear, I'm making a generalized moral argument here, not a legal one, so let's skip the whole "but it's a private platform" debate this time.)
Nobody is making that argument. The actual argument is that a private company should not be compelled to provide free hosting for them. They can and have used other hosting services but many of their followers apparently prefer not to use those alternatives.
This is untrue.
Not only are people making that argument explicitly, but there have been any number of orchestrated attacks on private companies in order to force them to remove content. And if they refuse, attacks on their vendors and distributors (such as app stores), including by the federal government and congresspeople openly demanding that they be banned, surrounded with completely unveiled threats of investigation and new legislation.
> They can and have used other hosting services but many of their followers apparently prefer not to use those alternatives.
Those alternatives are under constant attack by people making that argument that "nobody is making." The ones that have secured revenue or financing that is difficult to attack (i.e. Substack, Rumble) are thriving.
I think if that were true a certain social network would have at least 70m more American users.
Nostr fixes those problems. You can never lose your ID because it’s derived from your public key. You can be blocked from a relay, but it doesn’t matter because you can just switch to another one, and you are always connecting to multiple at the same time anyway. Following is managed on the client side, so it cannot be manipulated or disrupted.
Sure that's not a feature?
The Alex Jones’s and Trumps and Fuentes’s and Kayne’s spewing their bile into a vacuum or even an isolated room into themselves (much like what Truth Social or Parler is) is a feature. They get to spew hate and dumb ideas and the rest of the civilized world need not hear or read it. Best of both worlds.
Edit: Then this Nostr will gain the same rep as Polerma as a haven for right wing wierdos for better or worse. Or maybe it will take off and who knows.
There is no algorithm or feed pushing content on you , so those people are by default completely invisible to you.
You can post on as many NOSTR relays as you want. Get banned on one, you are still publishing on the others.
You can also, along with your messages, suggest to "subscribers" your preferred relays, so people that really want to follow you as you get banned all over the net always know the best place to reach you. This process of course would be automated by the clients.
The point is that you have only one Mastodon API endpoint vs potentially infinite Nostr relays for each account you own.
The point is you don't have that issue with nostr
This seems like a good area to improve since things like code signing could also benefit. One of the big problems I see is bootstrapping your network initially and also solving the lost phone problem without setting up a system which phishers and spammers would have a field day with.
Mastodon is clearly inferior to Nostr when it comes to having a decentralized identity.