Replies (66)

More people should get hacked. This is fantastic stuff. As @david pointed out here, be sure to report the old account to help knock it out of the GrapeRank WoT!
david's avatar david
Given Brainstorm as it is currently implemented, if a handful of people use NIP-56 to report this nsec, it will only take a small handful of reports to knock the GrapeRank score down to zero, which will prevent this profile from showing up on profile keyword searches in the future, once we have a few search engines using the GrapeRank metric to filter results. Unfollowing helps too but as a general rule, you’re never going to get enough people to unfollow a compromised nsec. Muting will also reduce the 🍇-Rank score but not as much as reporting. NIP-56 does not specify a reportType for “compromised” — maybe we should update the nip? For now, reportType “other” would work best; or just put “compromised” as the reportType even if it’s nonstandard. https://nostr-nips.com/nip-56
View quoted note →
If we keep using shoe-on-head verification, it’s just gonna create a massive videos dataset for training Ai and shoe-on-head verification will end up being the easiest kind to fake.
I just realized something else funny about this… I have no idea what you look like. So you could just be a total scammer putting a shoe on your ahead and I’d have no idea 🤣🤣
Phil's avatar
Phil 4 months ago
Our latest #nostr solemate 🍻
Can you explain how you lost your accounts? It would be helpful for systems to be improved so that laypeople don't have to go through the same thing.
As a developer I test a lot of stuff and do unsafe things that most people won't and shouldn't ever do. I'm also specifically targeted by hackers because of the nature of the service I provide.
With the Coinos account I straight up uploaded the nsec to GitHub by accident. With this personal one I'm pretty sure it's because I had it loaded into a Coinos account with a weak password on it that an attacker was able to brute force to decrypt it. We don't store encrypted nsecs anymore since adding support for remote signers so no one else should have this issue, it was just in one of my old accounts.
Adam Soltys's avatar Adam Soltys
With the Coinos account I straight up uploaded the nsec to GitHub by accident. With this personal one I'm pretty sure it's because I had it loaded into a Coinos account with a weak password on it that an attacker was able to brute force to decrypt it. We don't store encrypted nsecs anymore since adding support for remote signers so no one else should have this issue, it was just in one of my old accounts.
View quoted note →
markonyte's avatar
markonyte 4 months ago
npub1nzhym2fxc3cuy073950tm4vrnw5zj9a65cvwrp8qexgkmy7u7nmssuz7rp
Lol. No, you have bad security practices. You should be able to do any "stuff" you want without compromising secrets. Learn to use Qubes OS or get more computers.
honestly it's not going to be super helpful. The rank of the old npub will remain higher than the new for some time, but then the new will flip it, so search results and stuff will once again be correct. It's a very very hard situation to deal with
A solution to this would be a "designated survivor npub" NIP. Immutable. Attached to your current NPUB. If you get hacked, engage designated survivor mode and it functions similar to a 301 redirect to your new NPUB. Thoughts @semisol ?
Adam Soltys's avatar Adam Soltys
With the Coinos account I straight up uploaded the nsec to GitHub by accident. With this personal one I'm pretty sure it's because I had it loaded into a Coinos account with a weak password on it that an attacker was able to brute force to decrypt it. We don't store encrypted nsecs anymore since adding support for remote signers so no one else should have this issue, it was just in one of my old accounts.
View quoted note →
Just a bit careless with my nsecs online
Adam Soltys's avatar Adam Soltys
With the Coinos account I straight up uploaded the nsec to GitHub by accident. With this personal one I'm pretty sure it's because I had it loaded into a Coinos account with a weak password on it that an attacker was able to brute force to decrypt it. We don't store encrypted nsecs anymore since adding support for remote signers so no one else should have this issue, it was just in one of my old accounts.
View quoted note →
=========================== #2 🔥 Community Highlights =========================== 1. The latest episode of Revolution.social: Great discussion among Rabble and David Bollier View quoted note → 2. Nostr is the best and neutral for everything View quoted note → 3. Follow the new npub of Adam Soltys View quoted note → 4. Spend time with your family and loved ones to not have regrets in the future View quoted note → 5. Let’s wish this pleb to get better and be able to fly again soon View quoted note → 6. Yes, Nostr has just a small scale for now. But the signal is high View quoted note → 7. Let’s build the Nostr village together View quoted note → 8. A question from the head creator to the Nostr community View quoted note → 9. A Nostrich is trying to boost his professional skills with his first photography book View quoted note → 10. This is the way to get healthy View quoted note → 11. Lovely couple celebrates their first anniversary View quoted note → 12. She knows the famous secret View quoted note → #community_nostr_recap
Analogue Dog's avatar
Analogue Dog 3 months ago
I have seen the same guy irl with the shoe on his foot, if that helps.
Coinos.io is down, gives me a "connection timed out" error. Please let us know when the website is back on. Thanks