Bro, the Upgrade was a Decade Ago
Many developers can be reckless with API calls, because with stable connections and global CDN servers, the difference between proper design, and complete negligence, can be in milliseconds. So it's not even worth the effort for most corporate developers to even learn.
This is why despite the HTTP protocol being upgraded over a decade ago to HTTP2, the vast majority of Python tutorials still teach the requests library, which only has HTTP/1. And despite HTTP2's proven speed advantage for client re-use, most mobile apps using Flutter continue to erode that edge with the defaults of HTTP1.
Then because web bloat has become the accepted standard, everyone has to use a CDN, to pass all data to the same centralized mega-corporations, which break SSL through the fundamental nature of CDNs. So as an end-user, you have to accept snail speeds, or totalitarian privacy-invasion.
But what if it wasn't a stable connection? What if there was no Cloudflare? Most of our users are using Tor, plus a base-layer VPN, with crappy internet to begin with. But they still expect fast performance, so what can they do?
Even worse, the Tor developers kill adoption with their own policies. Their STEM library is garbage for receiving errors on bootstrap. It's a blackbox that gives no feedback, yet they’ve created pointless permission problems by restricting third party apps from creating Tor sessions on a given config, by default on most Linux distros. Yet when Tor browser itself is open, it can start the config, and then you can bind to it. So what is the purpose of restricting it, if when the primary use-case is open, that restriction is often gone.
Then Tor dev negligence is compounded by PySocks dev negligence, where even after decades of IPv6 being around, PySocks doesn't support it. And the STEM library docs don’t want to mention how to disable IPv6, their attitude is go read it on your own.
This combo is lethal, of black box swallowed errors, pointless permission problems, IPv6 errors, all combined with crappy library support. How can any privacy project succeed? Most don't, and that's why you see Cloudflare used even for Monero wallet APIs. Each party points the finger at the other, nobody takes responsibility for anything.
Now you have context to understand this 2-7-7 upgrade. I've been digging away for months to learn this, and today we are proud to roll out the upgrade:
Today's upgrade:
-Ditching HTTP1 for HTTP2
-Ditching Python requests for HTTPx
-HTTPx client re-use throughout the project. Way beyond simple for loops, but an entire infrastructure for persistent proxied connections.
-Ditched STEM for a Custom Tor Bootstrap with error detection for a variety of issues.
-It creates a custom HTTPx client to resolve DNS and verify SSL when Tor node DNS is blocked.
-Solved async over Tor. Now it grinds out concurrent requests
-Transitioned the database endpoints to reduce the quantity of API calls made
-Elaborate sync tracker to reduce API calls when nothing changed
With all these changes combined, we've smashed sync time from over 15 seconds, to under 5 seconds (depending on your connection.)
Although this may seem like a lot of technical complexity, I am on a simple mission. To make privacy so convenient, that you say "why not".
version 2.7.7 sha256sum:
3302a8a736141f2ca7322f16003c59640d2932db8bad530aae9b328f9c70c680
hydraveil.net
SimplifiedPrivacy.com
npub14slk...t5d6
A single use of most web browsers can permanently fingerprint you across different services. And Tor Browser breaks down on the real web with restricting Javascript & blocked IPs.
HydraVeil is our Revolutionary New Linux app that allows you to create different isolated profiles, to resist AI Browser Fingerprinting from Cloudflare & Big Tech.
Another feature of HydraVeil is routing your traffic though your choice of WireGuard or a Tor->Socks5 proxy (to evade Tor blocks), and to fool CDN packet speed tracing with different IPs for each profile.
Additionally, we provide VPN service for Android, iPhone, Windows, Mac, and Routers. Tune in to our Podcast to combat Big Tech surveillance. Help me, help you.
Hashtags: #Cypherpunk, Open source, #Linux, DeGoogled Phones, self-hosted services, #Monero, #Security, and more!
One of the most frustrating parts of Tor, is even if the website wants to allow Tor, often their DNS provider may block Tor's DNS nodes from resolving the domain. Without the website owner (or even the end-user) from being aware.
DNS Providers such as Namecheap, GoDaddy, and Orangewebsite will most definitely restrict high quantity Tor queries. I've seen it first hand with out our project. And upstreams such as Verisign and even Iceland's' .is ISNIC registry may be the real culprits. Everyone will claim it's to stop abuse, which is logical. But the end result is harming privacy.
Even diagnosing this problem is a huge challenge, let alone solving it. But where other people give up, is a good place to start. The fresh HydraVeil release, tries to sync over Tor, if it fails..
a) It first tests if Tor even works against the official Tor Project API.
b) If it does, it checks if DNS is the problem. Will just the domain resolve via a Tor node?
c) If that Tor-node-DNS fails, It resolves the DNS to a non-Tor DNS provider like Quad9 via DoH, but proxied through Tor.
d) Now with the IP address in-hand, it goes directly to the IP address of the web service through Tor, but without ANY DNS. Then pretends it used the domain, when it asks the website for an SSL cert. Finally, HydraVeil manually verifies the SSL cert against it’s own local copy of Mozilla’s tools for Let’s Encrypt certificate authority.
This gives you the benefit of SSL encryption & Tor, but without allowing DNS providers to restrict Tor resolution. And doesn't slow you to 6 hops to do onions just for DNS, to download browsers. Today's release is open source. And this same blueprint can be applied to any app in the future. Web browsers, Monero/Bitcoin wallets, Nostr clients, anything that wants to use Tor but not be slowed to 6 hops by an Onion, just to resolve the domain.
Release notes:
Improved Tor Sync & Error Handling | HydraVeil 2.5.7 | Simplified Privacy
Game changer feature drops very soon.
In fact, it's so good you'll be questioning whose funding me. And the answer is you.
Huge thanks to everyone whose be using the VPN service and/or SMS exchange. And another huge thanks to anyone who donated to the wallets on the website. I could not be more excited for this upcoming release.
There's a lot of discussion over Nostr & Bitcoin taking over
But ironically, the feature Nostr needs most, is more content unrelated to Nostr.
And the feature Bitcoin needs, is more businesses accepting it that are unrelated to the Bitcoin industry itself.
A real genius is able to explain complex concepts in the most basic terms.
So don't ever be intimidated when you're trying to learn.
If the guy can't make it sound simple, then he really is retarded.
FBI extracted deleted Signal messages, even after the app was uninstalled.
When Signal messages arrive, iOS stores push notification previews locally on the device. In this case, those previews stayed behind even after Signal was uninstalled.
- Only incoming messages were captured this way
- Disappearing messages that had already vanished inside Signal were still recoverable from the notification cache
-This is iOS behavior, not a Signal vulnerability. And likely impacts other ALL apps on iOS.
The quick fix, to turn it off:
Signal → Settings → Notifications → Show → set to "No Name or Content"
You'll still get a notification ping, but iOS just won't cache anything useful.
The real fix:
Switch to GrapheneOS
The original 404media source is paywalled,
https://cybernews.com/security/fbi-extracts-signal-messages-from-suspect/


404 Media
FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database
The case was the first time authorities charged people for alleged “Antifa” activities after President Trump designated the umbrella term a ter...
!! The SMS Exchange is now officially open for buyers !!!
We got sellers from the USA, Colombia, Ukraine, & more. You can get a non-VoIP SMS confirmation to register any account privately, for Monero or Bitcoin Lightning. It could be social media like Youtube/Twitter, messengers like Signal/Telegram/WhatsApp, business accounts like Yelp, or even financial accounts like Zelle/Paypal.
How it works is: you get matched with a seller by your choice of service/country, and it serves you the number, and if you want a burner email.
If it doesn't work, then the buyer gets 3 disputes, which triggers a match to a new seller and number.
If it does work, you have the option to "restore", which means paying again but skipping the matching process, and getting that same seller/phone number again. So if you lie, and falsely dispute, you lose the right to restore later in an emergency.
This is on the dot net domain:
Or Tor Onion:
http://privacyoyec4fmxxxuvysrg6ljna6blgotauud3rkvrtiavfbvyuagad.onion/
Important Message
Want to earn Bitcoin or Monero without KYC?
A big problem with digital privacy, is that some services require SMS registration, and many times block VoIP numbers..
Even worse, there are Crypto “SMS-confirm” services that buy blocks of phone numbers, but once Big Tech's security vendors find out what the block is, the entire block may get banned or labeled VoIP. Leaving many privacy-conscious users feeling frustrated and isolated from parts of the internet.
But not everybody wants to be anonymous. Some people don't care that much. What if there was a way that those who don't care that much, could sell their phone number to those who do?
That's why I'm excited to present to you a huge new project from Simplified Privacy, the SMS Exchange. You can register as an SMS seller, and get notifications via your pick of SMS, Telegram, XMPP, or Session. You reply to an automated system with the SMS registration code, and boom, you earn your favorite cryptocurrency in a few seconds.
Not only can these surveillance firms not stop a guerrilla P2P market like this, but it's a huge step forward for the circular parallel economy, to never be dumping Bitcoin or Monero on an Exchange, in order to pay for blocks of phone numbers.
Instead, this is an opportunity for some savvy cats to on-ramp without KYC. And even pay for their phone bills with an easy side hustle. I encourage you to check out this extremely short article with some of the details, and consider reposting this so we can help the Nostr economy succeed.
Crypto SMS Verify | Simplified Privacy
US government just banned "foreign made" routers from being imported.
Absolutely ridiculous, from Wikileaks years prior, it was revealed the US government was hacking home routers from the default ISP. Now they want to cut off your defenses.


9to5Mac
Your wireless router is now banned from sale in the US
Almost every new wireless router for use in US homes is now banned from sale within the country under a...
We are adding more nodes, and looking for operators. If you're interested in promoting Nostr, Linux, Bitcoin, Monero, open-source, Security, Parallel economies, and of course Privacy, even when they want to prevent you from being private, reach out.
View quoted note →
New Update!
Many misunderstand screen size fingerprinting.
They assume that when a website fingerprints their browser, that it merely gets the display 'category', such as '1200x800'. But in reality, it gets your unique size down to the pixel, such as 1202x799. Each window will fill the display slightly differently, which absolutely can (and is) tracked across services.
In 2024 with version 1.64, Brave completely deprecated screen size fingerprinting, because it so frequently broke websites. Which is exactly what I'm screaming about, that modern web browsers force you to pick between privacy and functionality.
Tor Browser attempts to hide unique screen sizes by blocking and restricting Javascript, which causes services such as Google, Reddit, and Cloudflare to haze you.
That's why I'm excited about HydraVeil's feature to instantly create a new display, that realistically looks to websites like the browser window is your computer's full screen dimensions. Here we can see deviceinfo-me compare Tor Browser to HydraVeil's profiles, and it does not percieve it to be spoofed.
But many HydraVeil users have complained that they don't want to deal with smaller windows. And that's why I'm excited about our new update today.
We are proud to present a new 'dynamic mode' for quick profile creation, which when enabled, presents many screen size options that are only slightly smaller than your host, in 50 dimension increments. This allows the user to effortlessly and conveniently get profiles that comfortably fill up their host’s display window, but each one is slightly different to fingerprinters.
Learn more from our release notes:
HydraVeil v2.2.5 SHA256 SUM:
eed46e20d1e8c8519030169fb931054e6b44abb09e499e2ad8107946718d5c5e
Tor Browser attempts to hide unique screen sizes by blocking and restricting Javascript, which causes services such as Google, Reddit, and Cloudflare to haze you.
That's why I'm excited about HydraVeil's feature to instantly create a new display, that realistically looks to websites like the browser window is your computer's full screen dimensions. Here we can see deviceinfo-me compare Tor Browser to HydraVeil's profiles, and it does not percieve it to be spoofed.
But many HydraVeil users have complained that they don't want to deal with smaller windows. And that's why I'm excited about our new update today.
We are proud to present a new 'dynamic mode' for quick profile creation, which when enabled, presents many screen size options that are only slightly smaller than your host, in 50 dimension increments. This allows the user to effortlessly and conveniently get profiles that comfortably fill up their host’s display window, but each one is slightly different to fingerprinters.
Learn more from our release notes:
Dynamic Larger Profiles | HydraVeil Release 2.2.5 | Simplified Privacy
Donald Trump murdered Iran's Leader.
The US airstrikes that killed Ayatollah Ali Khamenei are completely immoral and depraved. He's going against his own campaign promises for "no more regime change wars", and not even following the CIA's own evaluation of Iran's nuclear program. Trump did not even get Congressional approval for war with Iran, making his actions illegal.
The entire history of this kind of belligerence, goes back to 1979 when the US backed Shah machine gunned peaceful protesters to maintain power of oil.
And the entire pretext of endless war in the name of defense, is an immoral fraud. That ends up killing US civil liberties and privacy. They are tapping American's electronics and reading your messages, so Israel can seize more land.
If your app has amazing features, they'll tell you "normies will never use complex things".
If you have average features, they'll tell you "it's nothing special to bother".
One day, you'll realize that the only feature these people look for in an app, is other people's approval first
How any app can doxx Mullvad & Proton users WITHOUT sudo
Linux is flawed and any app can abuse the DBUS to rip down your VPN without any elevated privileges. To prove this, today our team presents both an original demo attack script to break through Mullvad & Proton, however these same concepts can apply to many others.
But there is no point in complaining, if you aren't going to do anything about it. And that's why I'm proud of our team to work so many sleepless nights and come through. We've already pushed to HydraVeil's distro, an original solution, that presents a much stronger resistance to these type of network interface attacks, but without any of the downside burdens of a virtual machine.
The link below has:
-5-min Demo Video w/ an easy to follow explanation
-Article version of the video
-FOSS script
-Solution already pushed to HydraVeil
But all the technology in the world, isn't going to do any good, if nobody is going to use it. That's true not just for our team's app, but building up all of Nostr.
That's why I'm asking for your help. Spend a few minutes looking at our materials. I've made it as easy to comprehend as possible. Realize it is real. And when you do, share & repost it.
Linux is flawed and any app can abuse the DBUS to rip down your VPN without any elevated privileges. To prove this, today our team presents both an original demo attack script to break through Mullvad & Proton, however these same concepts can apply to many others.
But there is no point in complaining, if you aren't going to do anything about it. And that's why I'm proud of our team to work so many sleepless nights and come through. We've already pushed to HydraVeil's distro, an original solution, that presents a much stronger resistance to these type of network interface attacks, but without any of the downside burdens of a virtual machine.
The link below has:
-5-min Demo Video w/ an easy to follow explanation
-Article version of the video
-FOSS script
-Solution already pushed to HydraVeil
But all the technology in the world, isn't going to do any good, if nobody is going to use it. That's true not just for our team's app, but building up all of Nostr.
That's why I'm asking for your help. Spend a few minutes looking at our materials. I've made it as easy to comprehend as possible. Realize it is real. And when you do, share & repost it.
Bareass Mullvad | Simplified Privacy