<oembed><type>rich</type><version>1.0</version><title>jaredlogan wrote</title><author_name>jaredlogan (npub19y…v322j)</author_name><author_url>https://yabu.me/npub19yw8tkfh530kdgfqn782vcga7azgckdn2fjjp3nv5txu6dl3h7lqhv322j</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>I was trying to understand the vision of your protocol. It&#39;s very tough to do so, which is why I went to AI. You guys do the same for articles, copy etc. So I don&#39;t get the reason for throwing insults. The code is code, open source and public. If these are not concerns, then they should be easily addressable. Every finding links to file paths with line numbers. The concern is gaps in how the product is pitched and how it actually appears to work today.&#xA;&#xA;If self-sovereign is an option, just say that. Explain the defaults, the reasoning, and the way to opt out.&#xA;&#xA;Yes AI found these, but neither of you seem able to address them humbly or professionally:&#xA;&#xA;- Session secrets in unencrypted MMKV storage? Why? that&#39;s a security decision that affects every pubky-ring user regardless of how they sign up, and it clearly contradicts the article pitching it.&#xA;&#xA;- Cloudflare binary downloaded at runtime with no checksum? Why? That&#39;s a supply chain risk for every Umbrel self-hoster.&#xA;&#xA;- Neo4j shipping with hardcoded password? Why? The comment in the code shows the team knew the default. The comment also warns that changing it post-deploy is non-trivial. Self-hosters who don&#39;t know to change it have their entire social graph exposed. Is this also wrong?&#xA;&#xA;- GCS backend with no auditable configuration surface? Wrong again? Is there a configuration surface? Should be easy to just say so and show it. Synonym&#39;s production bucket configuration is not public, which helps explain the need for the ToS in the first place.&#xA;&#xA;- you said users have a choice where their data is hosted. True for the homeserver. But is there a credible alternative to Synonym&#39;s Nexus for discoverability? Without it, content exists but nobody can find it. Self-hosting a homeserver without an accessible Nexus isn&#39;t a real credible exit for most users.&#xA;&#xA;These aren&#39;t philosophical objections to the vision of &#39;your&#39; protocol. They&#39;re specific, sourced findings that the &#34;users have a choice&#34; framing doesn&#39;t address or hold up against. I&#39;d be happy to turn any of them into proper GitHub issues if that&#39;s more useful than a Nostr thread.</html></oembed>