Gitstr: Send and receive Git patches over Nostr
github.com
github.com
https://en.wikipedia.org/wiki/Nostr
(Because the linked page doesn't describe/link to a description either, AFAICT)
And if you do have a website where you publish your private key, why wouldn't you just publish your content there?
How do you manage public keys you trust? Is this something a client implementation should do?
What happens when all relays you write to go down? You lost all your followers? How would they learn of the new relays you write to? Doesn't really make sense in terms of free speech. Sure, you can still write/publish but if no one knows where anymore isn't that the same as having disappeared/been banned?
I do understand that "nostr is just the protocol" but what makes this usable at all in practice?
You manage pubkeys you trust by signing a message with a list of pubkeys you trust, simple as that.
People can learn about what relays you are on by (again) signing a message that states which relays you are publishing to.
If all relays go down you just send your messages to any other relay.
FYI, a signed message is just a simple json object with string of content, list of tags, time, your pubkey and a signature. “Notes and other stuff”
How would anyone reading that message know that this was actually signed by you and is your public key? There has to be a trusted exchange of the public key before or the relay could just spoof your message. Some messaging apps do a thing where you meet in person and scan the other persons QR code for example. Otherwise, you have to trust the relay. But as I understand it that is not the idea of it.
Again, if you sign a message with a list of pub keys, what if the relay disappears? How do you get around that problem at all without hosting your own relay?
About the relays disappearing, how will people find you on a new set of relays you choose unless they are reading from those already? Relays don't communicate with each other.
Other protocols like ActivityPub ultimately have the same problem. You have to host your own mastodon server to address these things.
I understand the signed message. But this is not P2P, the relay is the (untrusted) middleman. So how is that in any way different than just sending someone an email and signing it? Or publishing signed messages in any other place online? Is it about the convenience of very quickly being able to switch to another relay without a hassle?
It can be a Twitter bio, a (gulp) keybase page, or a personally hosted page.
And if you have a homepage, why do you need Nostr at all? You can just sign content and publish it on your website then, no?
I'm starting to think that the main thing with Nostr is convenience. Should you run into an issue with any relay(s) you simply change to different relays without much work involved, i.e. without "your operations" having to pause. But that doesn't solve the discoverability issue with relays.
It's actually not much different than if you signed your tweets and then if you got banned just moved to facebook. Just more convenient.
Check archive.org or against the secondary page I have set up on MostPopularNetwork#2, if security-minded.
The engineering behind this is neat, but I have no idea why this is useful.
Bitcoin was developed just barely before ed25519 was finalized, which is probably why it uses secp256k1. Unless intended mainly for government users (FIPS), almost every new cryptographic system uses ed25519 -- except Nostr.
I always assumed Nostr chose secp256k1 so you could send bitcoin to another Nostr user without some extra "payment address request protocol" bolted on the side. Very surprising that this was not the motivation!
I was shocked to find out that the Lemmy instance I signed up on was blocking dozens upon dozens of other instances, which defeats the entire purpose of a federated network.
It took me signing up for Lemmy to realize why Lemmy is still a completely dead network.
We are having this conversation in a more mainstream way now because more people found out how precarious their online cultural foundations are. Your Facebooks and Reddits and Twitters will get ruined by changes of ownership or on the whim of billionaires. You data will be sold out from under you. You will be squeezed for every penny.
The point is to either host your own instance, or use the instance of someone you trust and/or whose moderation policy you align with. It's not to amass a large user base and watch your charts go up.
This should be the goal but will never happen with an activity-pub-based fediverse. It just doesn't scale to everyone or even every small group having their own instances because. Current fediverse software is also too complicated and too resource hungry for even most technically inclined people to self host.
You really need a better foundation that is designed for efficient communication between millions of hosts from the start.
Fediverse instances being too trigger-happy in blocking other instances means the network as whole is less open in comparison to a centralized social network. So, why bother? You have little to no control over whom you can connect to.
Also, "switching" is an alien concept to normal social media users. You never have to "switch" and you never lose your content or followers, exceptions aside when you get yourself into serious trouble.
Then there is the fact that you once you choose an instance your identity is bound to that instance. Why would anyone invest in such a dead end network.
There is another side of the Fediverse that operates on the principles you are talking about (eg. Poast, Baest, Spinster, Gleasonator, NoAgendaSocial, NicecrewDigital, et al). That part of the Fediverse, like Nostr, is covered in Lolicon, gore, and Nazi memes because that's the userbase you get when you promise that nobody can stop you from posting whatever you want.
More and more I am learning that the people who desire censorship-free social spaces are the kind of people that others rightfully exclude from polite social spaces, because these are people who lack respect and want to say and do horrible things without opposition.
The mistake is believing that all instances behave the same and block the same. The whole point of federation is that every instance chooses who it wants to block.
Now at least there could be (in theory) regional blocs of federated servers that share content. I heard some people are proposing a common account interchange format, so you could migrate accounts? (not being in the fediverse yet, I don't really know...)
1) I, as an admin, have never been pressured by anyone to do anything and can federate with whoever I want. Thousands of instances are the same. The only ones who are pressured are the biggest ones, who also happen to host the worst content (xenophobic, racist, gore, pedo content).
2) You are not owed an audience. Not everyone wants to ear what you have to say. Moderation at scale needs to happen if we want marginalized communities to thrive, and unfortunately since the internet is mostly hostile to those the most efficient way to do this is to block. But if you're not ok with the blocking policy of your instance, change it. That's the whole point of federation. You'd do the same with Nostr: you disconnect from a relay if you don't like what comes from them, connect to another one, except with Nostr you can't totally be sure the bad content will be filtered out.
Right, it absolutely isn't. Some form of censorship is vital. This claim becomes more agreeable when substituting "censorship" with the almost-synonymous word "moderation".
With nostr, your identity is just a pubkey, and you can publish to / read from several nodes simultaneously. So if some node refuses to puplish certain content, you can just get it from another node without having to create a whole new identity.
Bias and financial interests in speech and content are more rampant, now, than they have ever been. I don’t trust anyone but myself to “save” me from seeing what I can only describe as “wrongthink”.
https://www.newyorker.com/news/letter-from-silicon-valley/th...
Despite that, usernames and their corresponding IPs get blocked routinely and we still see spam regularly even if only for a brief time.
Any forum will have the same problem: get popular and whacking spammers becomes a full-time grind. Allow people to upload files and you’ll have the FBI asking why you’re facilitating transfer of pirated movies, CSAM, etc. Have the wrong people decide to use private messages and now the FBI is back asking if you knew they were planning terrorist attacks.
None of those are completely impossible, of course, but they end up being expensive and burning out volunteers. Limiting anonymity helps, but only so much - it’s just an expensive space to be in.
[0] https://people.kernel.org/monsieuricon/patches-carved-into-d...
https://scuttlebot.io/apis/community/git-ssb.html
Git-ssb went far beyond just sending and receiving patches. You could actually clone, pull, and push a repo between your friends and your friends friends.
Does this Nostr based approach solve the problem as well or should they be looking at git-ssb and extending it?
It seems extremely likely governments and courts all across worlds will be increasingly threatened by code in the next decade, so pretty important that a censorship resistant infrastructure is built asap.
That’s not strange, given that it’s architecturally similar.
However, blockchains are solving global consensus problems. Nostr doesn’t give a shit. To me, that’s good. One piece at a time. Also, what’s so important about consensus? It’s extremely slow and expensive and mostly matters for financial applications. The less financial speculation the better, imo.
Time will tell I guess if the architecture holds, and also if there are interesting easy-to-use applications on top of it. But I like the simplicity of it a lot. Feels retro and refreshing at the same time.
The only high level differences are (1) Nostr does not have a persistence layer (much less one with global consensus) and (2) applications live “outside” the system whereas in the crypto world they’re either hard coded (say bitcoin) or through smart contracts that live “on-chain”, ie as part of the system.
Maybe I’m missing something though. It’s just my observation.
Regarding why this might be useful. Remember when youtube-dl got taken down from GitHub? I think it’s now back after all the outcry. But the point stands, if you develop something that someone powerful might not like, a Nostr based git solution for that might make sense.
The vision though would be to build something that feels a lot like one of the centralized git services, just built on top of Nostr. So, it’d be some kind of a frontend that you may be able to run yourself if it’s open source which you could point to a set of relays to get the ‘git notes’ from. Couple this with the integrated payments functionality, and I think it becomes an interesting proposition.
If I recall correctly some time ago Jack Dorsey pledged some amount of BTC to make that a reality.
What I'm actually eagerly waiting for is GitLab instances being able to federate using ActivityPub, allowing remote forks and auto-updates, merge requests, issues opening and commenting, following users and projects… all that without having to open an account per instance.
See https://docs.gitlab.com/ee/architecture/blueprints/activity_...
I suppose gitstr would have the benefit that you'd already have the public key of whatever person you'd want to send the patches to? Because you learned of the existence of their repos via nostr, or so?
It seems it's mostly used by bitcoin people. I have no interest in bitcoin.