-
plowsof
I got an email saying RINO.io is live and on mainnet escapethe3ra
-
nioc
when matrix irc bridge for the main monero channel?
-
selsta
in 2 years™
-
Rucknium[m]
We got three new Monero wallet announcements just this week. Not bad!
-
Rucknium[m]
Rino, Stack Wallet, and MyNero.
-
Rucknium[m]
Will replace the wallets that died due to hardfork ;)
-
sech1
supply and demand, I guess
-
selenze[m]
I think someone may need to create a Matrix account such as "Monero-help Desk" at
getmonero.org/community/hangouts where people could be channel their questions and may get answers....I think this may smooth things. What do you think?
-
selsta
we have a matrix support channel
-
selenze[m]
selsta: could you plz share the link
-
SerHack
I wonder if anyone with frontend skills wants to build a frontend for monero-lws
-
selsta
selenze[m]: I don't use Matrix myself, but search for Monero Support or something
-
endogenic
you already know i built one
-
endogenic
i am struggling to release it as i have no help
-
endogenic
and other things you dont need to know
-
endogenic
i wish the monero community supported people like me and the noethers
-
endogenic
speechless
-
SerHack
endogenic: I've written you a couple of private messages but you never answered :(
-
endogenic
that's false
-
endogenic
and hey so that means you can pretend like i dont exist
-
endogenic
how lovely.
-
endogenic
when are you all going to wake up
-
endogenic
youre like children
-
selenze[m]
selstawho is in charge of adding the matrix channel for the one I mentioned. I would be glad to help with the little know I have.
-
ofrnxmr[m]
#monero-support:monero.social
-
selenze[m]
ofrnxmr[m]: and where is the web link for this....
-
selenze[m]
It would be better to find it in the monero website somewhere in
getmonero.org/community/hangouts or
getmonero.org/community/workgroups
-
selenze[m]
-
plowsof
alot of skilled contributors "fall through the cracks" and dissapear, due to lack of support (be it funding , or just 'help') . we're all in our own caves , dealing with our own issues and sometimes we miss when devs create things. I discover ~2 year old monero projects every other week it seems , it's not that i was actively ignoring that developers work for 2 years , i just 'didnt know'
-
selenze[m]
plowsof: yeah....things seem broken while at the same time the house has a lot of expertise....kind of house management for what I can see
-
plowsof
if you have an idea that you believe is going to help the monero community, no one is going to hand you support, you must push it in peoples faces and ask. for example, someone wanted to do 3 months of greek translations , put a donation address up, and actively advertised / sought support on Reddit / other avenues , and boom , 40 xmr - if they had no asked for help they would have got nothing, and disapeared
-
plowsof
everyone gets ignored, no one cares, unless you ask / seek help
-
selenze[m]
plowsof: if we are talking on the same issue....I think the primary reference should be better house manged
-
Rucknium[m]
selenze: Could you define "primary reference" and "house managed"?
-
selenze[m]
<Rucknium[m]> "selenze: Could you define "..." <- the primary reference point means for getmonero.org and what I mean on house management is I thin the getmonero.org needs a revamp...a kind of house management form a management perspective.
-
Rucknium[m]
selenze: Ok. You can make a Pull Request for website content here if you want something improved:
-
Rucknium[m]
-
selenze[m]
Just have a look at this
getmonero.org/resources/roadmap and no 2022
-
Rucknium[m]
plowsof updated the roadmap in a PR. It has not yet been merged and uploaded
-
selenze[m]
I guess we should task someone for such tasks ....If I am not mistaken someone did the CC thing I gues
-
Rucknium[m]
-
selenze[m]
I kind of feel someone need to better be tasked with the overall project. may be this should be forward/Advertised by the core team as a CC by them selves so that skilled people can overtake it.
-
Rucknium[m]
It's hard to find good, trustworthy people. Though I do think that the people who have the power to update the website have been slow to review potential improvements. I think they may just be concerned about screwing things up in an update.
-
Rucknium[m]
-
selenze[m]
Rucknium[m]: Well, I think the core team need to advertise for such main task having put forward a certain incentive in the CC and then select candidates, which the core can select from a pool of experts...you know the process.
-
MajesticBank
why fix if it's not broken?
-
selenze[m]
Rucknium: The sarcastic think about git is....If I want to do some git contributions..I am asked for email. Why can't the people put an option to have some other login mechanism.......just think monero (privacy by design....we proclaim!) on a non privacy platform ...I think we still are cought in the old tradition and the community seem not to divorce itself to create the other side of the story
-
Rucknium[m]
selenze: Monero accepts patches submitted through IRC and Matrix. Makes things a bit harder, but it can be done.
-
NorrinRadd
or just use a new account with a throw-away email....
-
selenze[m]
I prefer to eliminate the hassles in the middle. But could you please take my point...I am talking about the principles of monero and the things/platforms we should make ready for it to flourish in such context, not a temporary solutions.
-
selenze[m]
<Rucknium[m]> "selenze: Monero accepts patches..." <- that means I have to visit all the matrix channels which I think are in a kind of disconnected fashion leaving the few.
-
Rucknium[m]
There is already a website manager CCS, by the way:
ccs.getmonero.org/proposals/erciccione-website7.html
-
selenze[m]
<Rucknium[m]> "There is already a website..." <- I see ErCiccione is handling the issues...even the recent git issues that he is trying to address. I better write to him at the Monero website matrix then....because there seems some issues are still pending and his contract is near to expire.
-
selenze[m]
Rucknium: Will submiting a request via the matrix channel suffice as same to that of the gits....how are they going to synchronize...I am thinking of writing some issues via the "Monero website" matrix channel
-
Rucknium[m]
I assume so. Just explain in your message that you don't want to use GitHub directly for privacy reasons.
-
selenze[m]
Sure. will do that.
-
selenze[m]
[But sarca](
repo.getmonero.org/users/sign_up) just look at this...no option for alternative signin. And this is hosted I presumed within the getmonero.org thing!
-
selsta
selenze[m]: what kind of alternative signin are you expecting?
-
selenze[m]
selsta: Thanks for your attention. If I could do via non privacy concerning issue.
-
selenze[m]
something that I can sign in with my monero account for example ..and you add a password for that
-
Rucknium[m]
spirobel was developing something like that. Stopped I think.
-
selenze[m]
the whole I idea is in all the platforms that relate to Monero, those platforms should uphold the principle of monero too....privacy by design. If not lets get them revamped
-
NorrinRadd
i'm late and just now getting up to date on this:
y.com.sb/watch?v=vM9voeuUWVo
-
NorrinRadd
damn wrong window, sorry
-
Rucknium[m]
selenze: Having an email address is a basic part of using the internet. And not requiring an email address makes it easier for the system to get spammed. And the gitlab has been spammed before.
-
selsta
also this would requires us to have our own gitlab fork, something we definitely don't have the resources for
-
RavFX[m]
I'm fine with emails as long as they don't have that issue with non-mainstream email provider
-
RavFX[m]
signing with you're monero "account" would be less private for you're money than signing with you're throw away email account created in tor
-
selenze[m]
selsta: where is
repo.getmonero.org/users/sign_up hosted? And how much can the monero gitlab can cost ...just a roug estimate
-
selsta
it is self hosted on some server that the core team has
-
selenze[m]
RavFX[m]: You could create monero ID that doesn't have to deal with your funds. Infact the way I see it, we can escrow people to do tasks, activities having some funds of their wallet ID for all their activites...we can use it as a collateral to do many things by escrowing the funds to be locked ...many poping ideas on that.
-
selenze[m]
selsta: so why can't the fork thing with the monero git repository...
-
monerobull[m]
Because we have barely enough devs to work on monero
-
monerobull[m]
No bandwidth for novel gitlab forks
-
selenze[m]
monerobull[m]: then we advertise in the CC and am sure people will come for that. And I can see the community would be happy to fund it.
-
selenze[m]
even the bandwidth thing...just lets put the estimates
-
monerobull[m]
I don't mean literal bandwidth
-
RavFX[m]
Brain bandwidth 🙂
-
RavFX[m]
* Brain collective bandwidth 🙂
-
selenze[m]
<selsta> "it is self hosted on some server..." <- ...what I mean is how is it provisioned...even the official monero website....I guess this should be primarily documented and that it be rooted in the privacy that monero upholds.
-
Rucknium[m]
-
selsta
-
selsta
here is some info on the setup
-
selenze[m]
Rucknium[m]: I will look into and ...and hopefully it won't ask me for email sign in. But I guess this should be addressed or advertised by the core team
-
selenze[m]
selsta: Thanks. will get into that.
-
NorrinRadd
so.... a unique identifier is a unique identifier, even a pub key. so anyone find out what the actual difference would be?
-
selenze[m]
<RavFX[m]> "Brain bandwidth 🙂" <- ???
-
selenze[m]
<Rucknium[m]> "spirobel was developing somethin..." <- could you point me the link to this plz
-
Rucknium[m]
-
selenze[m]
lol. plz send me the privacy upholding link
-
Rucknium[m]
Reddit does not block TOR. So use TOR.
-
selsta
yes, why not use Tor and disable Javacsript?
-
selsta
otherwise it's a bit weird to ask someone a link and then complain
-
NorrinRadd
when you could teddit edit the link anyway....
-
NorrinRadd
this complaints i don't think are valid
-
NorrinRadd
s/this/these
-
RavFX[m]
<selenze[m]> "???" <- Dev time is not free & unlimited ressource
-
RavFX[m]
That been said, for private auth, one could simple make it so you can use a Fido key for login.
-
RavFX[m]
send the same challenge to everyone and the key calculate the answer according to it's private key
-
RavFX[m]
So send the same challenge to everyone and store answer for each user.
-
RavFX[m]
As a bonus, one can use a Ledger instead of a Fido key
-
selenze[m]
> <@al800:0wnz.at> That been said, for private auth, one could simple make it so you can use a Fido key for login.... (full message at <
libera.ems.host/_matrix/media/r0/do…ea19cb2e408f2ddf03c732240d6fbdb9c02>)
-
RavFX[m]
Yeah, it's just a Fido key.
-
RavFX[m]
Lot of service use that for 2FA
-
RavFX[m]
So make it so the key response is the login
-
RavFX[m]
And make it so the password is the 2FA (doing it backward compared to normal systems)
-
RavFX[m]
And because it's widely used and well documented, that kind of auth setup could be replicated easily for other systems
-
selenze[m]
RavFX[m]: link plz
-
selenze[m]
<RavFX[m]> "Dev time is not free & unlimited..." <- On this issue....I think like wikipedia puts for its yearly or something budget....can't we the community finance it.
-
-
RavFX[m]
use look hot it work, and make if for main login instead of 2FA
-
RavFX[m]
s/use/just/, s/hot/how/
-
RavFX[m]
s/use/just/, s/hot/how/, s/if/it/
-
RavFX[m]
And on successful "login" with the Fido thing, prompt for a password
-
RavFX[m]
If you have a ledger, it's even better (as you can recover you're "key" using your ledger seed phrase)
-
RavFX[m]
Or you cane make a slight variation.
-
RavFX[m]
Get the client side compute the answer from the challenge the server send
-
RavFX[m]
Then make the client encrypt the password using the answer from the key and send that to the server
-
RavFX[m]
server hash what he received from client and look for it in the DB, the matching entry it find is the user
-
RavFX[m]
* Or you cane make a slight variation.
-
RavFX[m]
Get the client side compute the answer from the challenge the server send
-
RavFX[m]
Then make the client hash the password using the answer from the key as salt then send that to the server
-
RavFX[m]
server hash what he received from client and look for it in the DB, the matching entry it find is the user
-
RavFX[m]
OR lets make another one.
-
RavFX[m]
The server could prompt for only a username and a password and ask no information (like email).. What about that? No key needed and no need to involve Monero in authentification
-
selenze[m]
> <@al800:0wnz.at> OR lets make another one.
-
selenze[m]
>
-
selenze[m]
> The server could prompt for only a username and a password and ask no information (like email).. What about that? No key needed and no need to involve Monero in authentification
-
selenze[m]
that would be wonderful. plz send the link then
-
RavFX[m]
Just use you're ledger or Fido for 2FA as it was designed for.
-
RavFX[m]
The last one is just user+pass auth... without asking for extra information. If you know how to program you can implement that easily
-
RavFX[m]
Just fork gitlab and replace the email db field by username and rename the "email" text for Username and remove the check that verify that it contain a @ symbol and a .something. And strip all code that rely on email or add email as an extra optional field.
-
RavFX[m]
Banhammer: BanhammerMonero
-
escapethe3ra[m]
plowsof thanks for the ping, done
-
Rucknium[m]
-
jeffro256[m]
Awesome stuff! So is there some version of the document available right now before the shortened public one comes out?
-
Rucknium[m]
jeffro256: Not sure your question exactly. There exists a full version, but it is not publicly available yet. Decision on publication of the full version is pending an analysis of competing risks.
-
jeffro256[m]
Sorry, yeah there's a new version, I was just wondering if there was a revision publicly yet. Thanks!
-
Rucknium[m]
Not yet. I plan to release the shorter public version simultaneously with the launch of mj-xmr's MAGIC fundraising campaign, which is going to complete some C++ tasks related to OSPEAD.
-
Rucknium[m]
Since I can't really read or write C++
-
jeffro256[m]
C++ is an abomination and an offense to everything that is good and holy. I don't blame you lol
-
jeffro256[m]
But I'm eager to see the results!