pull down to refresh

Show me the code.

reply

Each person has their counterpart to prevent these things from happening

reply
115 sats \ 12 replies \ @optimism 12h

Let me ask the same question so that you don't have to bullshit me:

How do you know that the offer you're taking was not from the same person as the person doing the dispute resolution. Don't say different nostr key because I can generate one in about 18ms.

How do you know? Simple question. Don't tell me vague shit about rules or prevention. Show me the code or the protocol documentation where it is explained which mechanism prevents this.

reply

https://github.com/MostroP2P

Opti.....can you work your magic there?

reply
23 sats \ 8 replies \ @optimism 10h

work what magic? I am aware of the code. I am just not aware of anything that would protect me from a self-dealing coordinator. So if people are saying that no there are protections, then I'd like to know where, because I in fact didn't find them.

reply

Ahh....I just understood your point now.

reply
263 sats \ 4 replies \ @optimism 9h

Thanks. I'm not trying to be coy or anything.

Just we see some naive tooling popping up that measures mostro activity per coordinator, but just like in the early days when coinmarketcap was launched and some exchanges were inflating their trade volume, you can do that on nostr too. Everyone will be more likely to believe you because "it's decentralized", and "the proof is in the signatures" and therefore it is true. But you don't need a super intelligent LLM to see how this can be gamed (after all, these didn't exist back in the day either) and there's a risk here.

So, "reputation" can be faked - it can even be automated. And I frankly have no idea how to fix this due to the sybil nature of nostr. Every trade is a risk, because reputation is a risk, so you want as little as possible data trail to your trades from a privacy perspective, but at the same time a maximum data trail to your trades from a reputation perspective. This goes for coordinators as for makers as for takers. It's a mess because the incentives are poorly aligned. Even if the mostro network were big enough to do pgp-style WoT, where I would add trust to your key and follow your key's reviews and pray that your key didn't get exposed, it still means that you should reuse an identity key for me to be able to follow it, even while your identity should not be mixed with your transactions (that goes against the pseudonymity principle, no matter what some prominent nostr devs got told by Claude to be totes ok)

Bottom line, FATF was smart: control the on- and offramps, control much of Bitcoin. The only thing that could have solved it was localbitcoins, before they went into compliance mode and iirc eventually gave up because it became impossible for them to operate compliantly. The only real defense we have today is to not use fiat at all.

reply

Yes, I understood your point before... I can just take my two cell phones and my wife's cell phone here and start making quick small transactions between them and quickly inflate my reputation.

This approach is interesting; if the numbers can be manipulated, I hope they aren't doing so.

13 sats \ 1 reply \ @mkmloom OP 1h

When creating the project, the developers consider all those potential scenarios, and there are certainly safeguards in place to prevent such issues; there is likely a supervisor overseeing a coordinator, and that supervisor has someone above them ensuring the project isn't defrauded. The reality is that it is filling the void left by @inp2p in the community and is easier to use than the bot. Your question is valid, and other Stackers surely share that same doubt.

reply
13 sats \ 0 replies \ @optimism 1h

reply
13 sats \ 1 reply \ @mkmloom OP 10h

Firstly, the number of SATs traded here is small; everything has a counterpart. The keys are generated by a node and reviewed by an administrator in case of a dispute. In the scenario you propose, it's very difficult because an administrator shouldn't risk their work and reputation in the community for so few SATs. I obviously don't have the codes; the developers or a senior administrator must have them. I'm only promoting the project because of its importance.

reply
46 sats \ 0 replies \ @optimism 10h

I understand that you're promoting, that is clear. However, be careful to answer questions with things you don't know. I don't raise this issue for you to defend it, I ask because that's how people get rugged.

Note that nostr identities are disposable, and that there is no sybil resistance. A reputation can be faked. So be careful.

reply