privacy

Nostr NIPS 21

NIP-21 nostr: URI scheme draft optional This NIP standardizes the usage of a common URI scheme for maximum interoperability and openness in the network. The scheme is nostr:. The identifiers that come after are expected to be the same as those defined in NIP-19 (except nsec). Examples nostr:npub1sn0wdenkukak0d9dfczzeacvhkrgz92ak56egt7vdgzn8pv2wfqqhrjdv9 nostr:nprofile1qqsrhuxx8l9ex335q7he0f09aej04zpazpl0ne2cgukyawd24mayt8gpp4mhxue69uhhytnc9e3k7mgpz4mhxue69uhkg6nzv9ejuumpv34kytnrdaksjlyr9p nostr:note1fntxtkcy9pjwucqwa9mddn7v03wwwsu9j330jj350nvhpky2tuaspk6nqc nostr:nevent1qqstna2yrezu5wghjvswqqculvvwxsrcvu7uc0f78gan4xqhvz49d9spr3mhxue69uhkummnw3ez6un9d3shjtn4de6x2argwghx6egpr4mhxue69uhkummnw3ez6ur4vgh8wetvd3hhyer9wghxuet5nxnepm Source: nostr-protocol/nips/21.md version: 0c1dfa9 2024-07-28T15:36:31-04:00
Yahoo Data Leak: A Cautionary Tale of Online Privacy

Yahoo Data Leak: A Cautionary Tale of Online Privacy

In 2013, Yahoo experienced one of the largest data breaches in history, resulting in the personal information of over 3 billion users being exposed. This breach was a major wake-up call for users about the dangers of sharing personal information online and the importance of online privacy. The Yahoo data breach was caused by a state-sponsored hacker who gained access to the company’s systems and stole sensitive information such as names, email addresses, phone numbers, dates of birth, and security questions and answers.
Data Breaches: A Rollercoaster Ride of Hacks and Leaks

Data Breaches: A Rollercoaster Ride of Hacks and Leaks

In the world of technology, data breaches are becoming more and more common. From large corporations to small businesses, no one is safe from the prying eyes of cybercriminals. In this article, we’ll take a wild ride through some of the most famous data breaches of all time and see just how much information was stolen. Buckle up and let’s get started! Yahoo (2013) - This massive breach affected all 3 billion of Yahoo’s user accounts.

OpenSSL vs. BoringSSL: A Comparison of Security and Performance

OpenSSL and BoringSSL are two of the most widely used cryptography libraries in the world, both providing essential encryption and secure communication services to millions of websites, applications, and devices. While both libraries are widely trusted, they differ in important ways when it comes to security and performance. In this article, we’ll take a closer look at the two libraries and compare them in terms of vulnerabilities, performance, and source code.

OpenSSL: A Hall of Shame for Cybersecurity Vulnerabilities

The most famous OpenSSL vulnerabilities OpenSSL is a widely used open-source cryptography library that provides secure communication for many websites and applications. Despite its widespread use, OpenSSL has suffered from a number of critical vulnerabilities over the years, exposing sensitive information and putting the security of millions of users at risk. In this article, we’ll take a look at some of the most famous OpenSSL vulnerabilities. Heartbleed (2014) - One of the most famous OpenSSL vulnerabilities of all time, Heartbleed allowed attackers to steal sensitive information, including passwords and encryption keys, from memory.

BoringSSL: A Record of Vulnerabilities and Security Concerns

The most famous BoringSSL vulnerabilities BoringSSL is a fork of OpenSSL, created by Google, that aims to provide a more secure and performant cryptography library. Despite its focus on security, BoringSSL has suffered from a number of critical vulnerabilities over the years, exposing sensitive information and putting the security of millions of users at risk. In this article, we’ll take a look at some of the most famous BoringSSL vulnerabilities.
WhatsApp Data Leak: The Importance of Staying Safe on WhatsApp

WhatsApp Data Leak: The Importance of Staying Safe on WhatsApp

WhatsApp is a popular cross-platform instant messaging app that has over two billion monthly active users. It is known for its end-to-end encryption, which promises to protect the privacy of users’ messages and calls. However, the security of WhatsApp has been called into question after several data breaches have been reported in recent years. One of the most significant data breaches involving WhatsApp occurred in May 2019, when it was revealed that spyware was used to infiltrate the phones of human rights activists and journalists.

Nostr NIPS 50

NIP-50 Search Capability draft optional Abstract Many Nostr use cases require some form of general search feature, in addition to structured queries by tags or ids. Specifics of the search algorithms will differ between event kinds, this NIP only describes a general extensible framework for performing such queries. search filter field A new search field is introduced for REQ messages from clients: { // other fields on filter object... "search": <string> } search field is a string describing a query in a human-readable form, i.
Protecting Your Privacy: Understanding Apple Data Leaks

Protecting Your Privacy: Understanding Apple Data Leaks

Apple is known for its strong commitment to privacy and security, with the company often highlighting these features as a selling point for its products. Despite this reputation, there have been several high-profile data breaches involving Apple over the years. In this article, we’ll take a look at some of the most well-known data breaches affecting Apple, what information was leaked, and what you can do to protect your privacy.

Nostr NIPS 33

NIP-33 Parameterized Replaceable Events final mandatory Renamed to “Addressable events” and moved to NIP-01 . Source: nostr-protocol/nips/33.md version: ca3c52e 2024-08-20T12:56:05-03:00

Nostr NIPS 45

NIP-45 Event Counts draft optional Relays may support the verb COUNT, which provides a mechanism for obtaining event counts. Motivation Some queries a client may want to execute against connected relays are prohibitively expensive, for example, in order to retrieve follower counts for a given pubkey, a client must query all kind-3 events referring to a given pubkey only to count them. The result may be cached, either by a client or by a separate indexing server as an alternative, but both options erode the decentralization of the network by creating a second-layer protocol on top of Nostr.

Nostr NIPS 18

NIP-18 Reposts draft optional A repost is a kind 6 event that is used to signal to followers that a kind 1 text note is worth reading. The content of a repost event is the stringified JSON of the reposted note. It MAY also be empty, but that is not recommended. Reposts of NIP-70 -protected events SHOULD always have an empty content. The repost event MUST include an e tag with the id of the note that is being reposted.

Nostr NIPS 42

NIP-42 Authentication of clients to relays draft optional This NIP defines a way for clients to authenticate to relays by signing an ephemeral event. Motivation A relay may want to require clients to authenticate to access restricted resources. For example, A relay may request payment or other forms of whitelisting to publish events – this can naïvely be achieved by limiting publication to events signed by the whitelisted key, but with this NIP they may choose to accept any events as long as they are published from an authenticated user; A relay may limit access to kind: 4 DMs to only the parties involved in the chat exchange, and for that it may require authentication before clients can query for that kind.

Nostr NIPS 19

NIP-19 bech32-encoded entities draft optional This NIP standardizes bech32-formatted strings that can be used to display keys, ids and other information in clients. These formats are not meant to be used anywhere in the core protocol, they are only meant for displaying to users, copy-pasting, sharing, rendering QR codes and inputting data. It is recommended that ids and keys are stored in either hex or binary format, since these formats are closer to what must actually be used the core protocol.

Nostr NIPS 40

NIP-40 Expiration Timestamp draft optional The expiration tag enables users to specify a unix timestamp at which the message SHOULD be considered expired (by relays and clients) and SHOULD be deleted by relays. Spec tag: expiration values: - [UNIX timestamp in seconds]: required Example { "pubkey": "<pub-key>", "created_at": 1000000000, "kind": 1, "tags": [ ["expiration", "1600000000"] ], "content": "This message will expire at the specified timestamp and be deleted by relays.\n", "id": "<event-id>" } Note: The timestamp should be in the same format as the created_at timestamp and should be interpreted as the time at which the message should be deleted by relays.

Nostr NIPS 36

NIP-36 Sensitive Content / Content Warning draft optional The content-warning tag enables users to specify if the event’s content needs to be approved by readers to be shown. Clients can hide the content until the user acts on it. l and L tags MAY be also be used as defined in NIP-32 with the content-warning or other namespace to support further qualification and querying. Spec tag: content-warning options: - [reason]: optional Example { "pubkey": "<pub-key>", "created_at": 1000000000, "kind": 1, "tags": [ ["t", "hastag"], ["L", "content-warning"], ["l", "reason", "content-warning"], ["L", "social.

Nostr NIPS 35

NIP-35 Torrents draft optional This NIP defined a new kind 2003 which is a Torrent. kind 2003 is a simple torrent index where there is enough information to search for content and construct the magnet link. No torrent files exist on nostr. Tags x: V1 BitTorrent Info Hash, as seen in the magnet link magnet:?xt=urn:btih:HASH file: A file entry inside the torrent, including the full path ie. info/example.txt tracker: (Optional) A tracker to use for this torrent In order to make torrents searchable by general category, you SHOULD include a few tags like movie, tv, HD, UHD etc.

Nostr NIPS 20

NIP-20 Command Results final mandatory Moved to NIP-01 . Source: nostr-protocol/nips/20.md version: 37f6cbb 2023-11-15T21:42:51-03:00

Nostr NIPS 28

NIP-28 Public Chat draft optional This NIP defines new event kinds for public chat channels, channel messages, and basic client-side moderation. It reserves five event kinds (40-44) for immediate use: 40 - channel create 41 - channel metadata 42 - channel message 43 - hide message 44 - mute user Client-centric moderation gives client developers discretion over what types of content they want included in their apps, while imposing no additional requirements on relays.

Nostr NIPS 27

NIP-27 Text Note References draft optional This document standardizes the treatment given by clients of inline references of other events and profiles inside the .content of any event that has readable text in its .content (such as kinds 1 and 30023). When creating an event, clients should include mentions to other profiles and to other events in the middle of the .content using NIP-21 codes, such as nostr:nprofile1qqsw3dy8cpu...6x2argwghx6egsqstvg. Including NIP-10 -style tags (["e", <hex-id>, <relay-url>, <marker>]) for each reference is optional, clients should do it whenever they want the profile being mentioned to be notified of the mention, or when they want the referenced event to recognize their mention as a reply.

Nostr NIPS 26

NIP-26 Delegated Event Signing draft optional This NIP defines how events can be delegated so that they can be signed by other keypairs. Another application of this proposal is to abstract away the use of the ‘root’ keypairs when interacting with clients. For example, a user could generate new keypairs for each client they wish to use and authorize those keypairs to generate events on behalf of their root pubkey, where the root keypair is stored in cold storage.

Nostr NIPS 25

NIP-25 Reactions draft optional A reaction is a kind 7 event that is used to react to other events. The generic reaction, represented by the content set to a + string, SHOULD be interpreted as a “like” or “upvote”. A reaction with content set to - SHOULD be interpreted as a “dislike” or “downvote”. It SHOULD NOT be counted as a “like”, and MAY be displayed as a downvote or dislike on a post.

Nostr NIPS 22

NIP-22 Comment draft optional A comment is a threading note always scoped to a root event or an I-tag. It uses kind:1111 with plaintext .content (no HTML, Markdown, or other formatting). Comments MUST point to the root scope using uppercase tag names (e.g. K, E, A or I) and MUST point to the parent item with lowercase ones (e.g. k, e, a or i). Comments MUST point to the authors when one is available (i.

Nostr NIPS 15

NIP-15 Nostr Marketplace draft optional Based on Diagon-Alley . Implemented in NostrMarket and Plebeian Market . Terms merchant - seller of products with NOSTR key-pair customer - buyer of products with NOSTR key-pair product - item for sale by the merchant stall - list of products controlled by merchant (a merchant can have multiple stalls) marketplace - clientside software for searching stalls and purchasing products Nostr Marketplace Clients Merchant admin Where the merchant creates, updates and deletes stalls and products, as well as where they manage sales, payments and communication with customers.

Nostr NIPS 16

NIP-16 Event Treatment final mandatory Moved to NIP-01 . Source: nostr-protocol/nips/16.md version: 37f6cbb 2023-11-15T21:42:51-03:00

Nostr NIPS 14

NIP-14 Subject tag in Text events draft optional This NIP defines the use of the “subject” tag in text (kind: 1) events. (implemented in more-speech) ["subject": <string>] Browsers often display threaded lists of messages. The contents of the subject tag can be used in such lists, instead of the more ad hoc approach of using the first few words of the message. This is very similar to the way email browsers display lists of incoming emails by subject rather than by contents.

Nostr NIPS 07

NIP-07 window.nostr capability for web browsers draft optional The window.nostr object may be made available by web browsers or extensions and websites or web-apps may make use of it after checking its availability. That object must define the following methods: async window.nostr.getPublicKey(): string // returns a public key as hex async window.nostr.signEvent(event: { created_at: number, kind: number, tags: string[][], content: string }): Event // takes an event object, adds `id`, `pubkey` and `sig` and returns it Aside from these two basic above, the following functions can also be implemented optionally:

Nostr NIPS 13

NIP-13 Proof of Work draft optional This NIP defines a way to generate and interpret Proof of Work for nostr notes. Proof of Work (PoW) is a way to add a proof of computational work to a note. This is a bearer proof that all relays and clients can universally validate with a small amount of code. This proof can be used as a means of spam deterrence. difficulty is defined to be the number of leading zero bits in the NIP-01 id.

Nostr NIPS 10

NIP-10 Text Notes and Threads draft optional This NIP defines kind:1 as a simple plaintext note. Abstract This NIP describes how to use “e” and “p” tags in text events, especially those that are replies to other text events. It helps clients thread the replies into a tree rooted at the original event. The .content property contains some human-readable text. e and p tags can be used to define note threads, replies and mentions.

Nostr NIPS 01

NIP-01 Basic protocol flow description draft mandatory This NIP defines the basic protocol that should be implemented by everybody. New NIPs may add new optional (or mandatory) fields and messages and features to the structures and flows described here. Events and signatures Each user has a keypair. Signatures, public key, and encodings are done according to the Schnorr signatures standard for the curve secp256k1 . The only object type that exists is the event, which has the following format on the wire: