jb55's avatar
jb55 _@jb55.com 3 months ago
I like how people building systematically harmful things to bitcoin just find it funny. Thats when you know they are just larping for bitcoin grant funding or something

Replies (62)

jb55's avatar
jb55 _@jb55.com 3 months ago
Its not even that. It also doxxes the senders utxos and future utxos the receiver mixes into (their existing coins). Its so bad
Ok, that's a point then. But with on-chain subs, it still could get dangerous because of chainalytics. Bitcoin's blockchain is much more monitored than Nostr. At least, that's what I think.
Technically, it is harmful. 1) people receive sats they don’t even know they received. 2) nsecs are not that secure, all of them are hot, and we are just adding more layers of risk on a single string of text. 3) it’s very bad for privacy. 4) it will create a large amount of utxo dust Lightning can handle 100K sats. So not really helpful to do this.
Do I want to give my mother onchain bitcoin? Onchain is simpler, the UX as I said is 10/10. Alex do you really, truly, believe people will send $5+ zaps?
Tbh I already receive sats I didn’t know I received daily and it’s public to everyone when I do haha. I think people like me are much more at risk than anyone here. I was clueless (still kinda am, I’m very beginner) & confused about how to track them as someone trying to deconstruct & navigate over. I wouldn’t have even attempted it if I didn’t have my hand held, which majority don’t and won’t. IMO if we want to help other mainstream users bridge over & do it permanently so they can make changes- this is seriously a step in the right direction to do it. Things can be changed back or evolve over time to something better, but we see clearly users are not coming if they stay the same! I’m just a whimsy sprinkle with a lot of internal rage going through the process herself rn 🤘🏽🔪🧚🏼‍♀️
I do like the idea of peer-to-peer transacting made easier, and I can understand how it's a lot simpler to implement than zapping via lightning or cashu. And fee arguments aside, they could have used silent payments or BIP 42. Vanilla on chain transactions linked to an identity is *the* dumbest implementation possible imo.
So this option is/was BS? Honest question, because I've pointed this option out when people claim that zaps aren't private. image
It’s not BS. Anon zaps / Invoice only: fully private Private: private to everyone but recipient Public: visible to anyone For sender. Recipient detail is always public except for “invoice only”
weev's avatar
weev 3 months ago
Sounds like Bitcoin is kind of antiquated, and it takes a bunch of kludges and layers of abstraction no normal and reasonable person wants to use to make it useful and private money. I can’t receive a bolt12 payment on Nostr! I have to accept the usage of a centralized domain name to receive a lightning payment! There’s not even a desktop wallet on my platform that supports bolt12! But don’t worry, there’s a useful private alternative called Monero! FCMP++ is really impressive, read the paper. Maybe at this point you should consider beginning to accept payments in Monero, because you seem very upset that you are receiving Bitcoin.
Constant's avatar
Constant 3 months ago
all i am wondering is....they have a coding super computer at their fingertips and somehow they are still bored enough to do this type of sillyness
Default avatar
deleted account 3 months ago
> I like how people building systematically harmful things to bitcoin just find it funny. I thought Bitcoin was "decentralized".
How do you think people should use different nsecs then? Of course, there can be multiple nsecs for different purposes. But using a different nsec for each post? This improves privacy, and I have made apps myself that do this when not logged in with an existing profile. But without having a seed for this, saving them all manually is nearly impossible.
People not realizing that revealing your UTXO is fundamentally a safety issue is bonkers. I will use the client that chooses to not implement it, as I believe they have their users best intentions in mind.
So purpose-based, right? I still could use my profile here for sharing things publicly? But... the same way you publish a Lightning address to your kind 0 profile data, why not also put in a Bitcoin address field? This could support single-key addresses (like P2TR, P2PKH etc., still bad for privacy, but not tied to your nsec), but also PM8T (BIP-47) or silent payment addresses. You want ro see these as well, right?
Just gonna make your other sats more valuable… What a waste though
Too true 😭 Problem is, I’m not hopeful that people who can’t afford more than a 2 cent zap will be able to afford sending a real UTXO 😂
It seems people don't understand your point most of the time, at least from what I gathered you weren't saying onchain zaps are a no, you are saying onchain zaps like this are a no. With silent payments it would be more acceptable. Unless I also don't understand you, but I think that's what you have been saying this whole time.
jb55's avatar
jb55 _@jb55.com 3 months ago
yes its completely fine if it were silent payments. That way the public can’t track sender and receiver utxos. I don’t really care about dust issues, as i think onchain zaps would be better for larger amounts and commerce. zaps would still be preferred for small amounts.
It's essentially a dust attack (on the recipient). Chain analytics companies have historically been accused of doing that (I haven't verified), now the people do it for them. Sweet. And a privacy footgun for the sender to boot. And if the recipient is smart enough to resist temptation, now the nsec is worth hacking, as you point out. Though if you assume that high profile accounts correlate with large on chain zap amounts, those are already valuable nsecs just for impersonation or extortion.
Silent Payments are better, but the public nature of zaps means you could look at timing correlation, especially if those on chain funds are later combined. But at least that requires some effort. Lightning fixed this.
If the zap (receipt) includes transaction hash, sender input and recipient output, then even doing a silent payment inside a coinjoin doesn't add privacy. Then "effort" is limited to manually writing a few lines of analytics code in case Claude refuses :-)
jb55's avatar
jb55 _@jb55.com 3 months ago
Yes i was thinking the public amounts would probably need to be blinded, and have more detail in a giftwrapped private variant of the zap only for the recipient.
One thing I think worth pointing out is that zaps on lightning are all public; sure. But when you then send those sats somewhere else, still on lightning, there's no continued visible trail. This is not the case on chain. It then becomes something the user is either proactively taking steps to break the trail on, with something like a coinjoin, or swapping it into lightning, or more likely, given that we'd be looking at these for the LEAST savvy users who don't have lightning set up, just left there to track absolutely everything about that UTXO. I do totally get coding things just to see if you can. And it's sort of cool that you can. I just think this is one of those things that, upon realizing it can be done, probably still shouldn't be.
That's one transaction. Not a look back at that input and where it came from, and where the output goes from there. I think this just takes people who already are at risk of running into things in the dark and puts them in a room with legos on the floor while they're barefoot.