The open source 🄯 server management software for the future.

Joined January 2023
17 Photos and videos
Nirvati retweeted
If you find a security flaw, please follow the following steps in order: 1) Give details to upstream developers to develop or merge a fix 2) Notify downstream developers/distributors of the risk and how to patch it (not the details) so they can ship it ASAP 3) Give people at least a week to upgrade on their own 4) Notify the public that a vulnerability in the old version exists (no details) 5) After you can reasonably hope everyone has updated (months or years later), publish details and/or proof-of-concept There may be circumstances (eg, active exploitation in the wild) that justify deviation from this, but generally, this is a good approach. However, starting with #5 is black-hat behaviour.
3
29
197
7,539
More useless AI slop code that makes misleading claims about security: - Not all dependencies are SHA256-pinned - Dockerfile "removes network-capable Python code" for no reason This just hurts actual security projects. If you don't understand security, stop making slop.
Most Tor Docker images are running outdated Tor, no guard protection, and leave telemetry on by default. HiddenForge v2.0.0 (my creation): Tor 0.4.9.6 Vanguards, every dependency SHA256-pinned, zero telemetry, read-only filesystem, rootless Podman support. Built for a state-level adversary threat model. github.com/DoingFedTime/Hidd… hub.docker.com/r/doingfedtim…
1
78
This is a dangerous idea. Someone else's TEE = Not your keys = Not your coins A TEE makes it harder to access the keys, but a TEE can be compromised. Here are two papers with examples of previous issues: i.blackhat.com/briefings/asi… misc0110.net/files/sgxrop.pd…

Mar 26
This wallet is super interesting. I don't know why they don't mention it but last time I looked it was running a Lightning node for you IN THE CLOUD in a TEE (a server they don't have access to). This is a major technical feat IMO.
1
1
161
You should always self-host your node 😉
1
52
Nirvati retweeted
Mar 21
The Apple App Store rules are borderline illegal. This isn’t about security. It's not about malware. It's not about user experience. It’s about control. - Use Google login? You must add Apple login - Sell digital products? You must use Apple payments - Apple takes 30% of your revenue (this is frankly insane) - You can’t tell users about cheaper prices outside the app - You can’t use a different payment system like Bitcoin - Apple can reject your app with vague reasons (or bend over due to political pressure) - You can’t install apps outside their store (most regions) They own the platform. They compete with you on it. And you still have to pay them. Is this a monopoly or a mafia gang?
80
52
603
120,031
Today, we're releasing Nirvati 0.9.0. We couldn't fit everything we initially planned in this release, but more is coming soon. Thank you for your patience! Here's what's new: - Add a new server overview that shows resource usage and connected servers 🧵 1/3
1
1
1
113
- Redesign the Contribute page to allow you to make financial contributions to Nirvati from the dashboard - Add an emergency repair feature that allows you to repair Nirvati if something goes wrong with an installation or update (Accessible on port 9080) 🧵2/3
1
56
- Allow configuring Tailscale settings - Prevent installing conflicting apps (e.g. Bitcoin Core and Bitcoin Knots) at the same time - Various other bug fixes and improvements 🧵3/3
51
As part of Nirvati 0.9.0, we're also launching a new LND wallet connection flow. This allows to revoke permissions for wallets connected using LNDconnect. Each wallet gets its own connection URL. If your phone ever gets stolen, you can revoke its access to LND with one click.
1
101
As far as I'm aware, we're currently the only project that offers this security feature for LNDconnect wallets (Some projects offer it with Nostr Wallet Connect). Nirvati 0.9.0 will launch very soon.
1
60
Hi! I want to share some short updates regarding Nirvati: 1. Nirvati 0.9.0 will launch during February. This will include Nirvati Connect, our new VPN service as well as advanced storage & server management. 🧵 1/6
1
1
137
You can learn more about Nirvati at nirvati.eu/ and see all ways to interact with us on links.nirvati.eu/. You can also share feedback via the contact methods listed there. 🧵 5/6

1
93
If you want to support Nirvati development, you can also contribute financially at nirvati.eu/contribute, opencollective.com/nirvati-o… or geyser.fund/project/nirvati. 🧵 6/6

70
Nirvati retweeted
Take 1 minute to sign this fam
It would mean a lot if you would sign this petition calling on @realDonaldTrump to pardon me and Bill In 30 days we will report to prison. Unless the President steps in. Developers shouldn't be liable for the actions of bad actors using their software #freesamourai change.org/p/stand-up-for-fr…
4
32
147
14,002
21 Oct 2025
We've just launched Nirvati 0.6.0. This release contains various performance improvements and a new page showing how many resources your apps use. We've also optimized the set up experience to make it faster and easier to get started with Nirvati.
1
1
318
21 Oct 2025
Learn more on our blog: nirvati.org/blog/introducing…

134
Nirvati retweeted
30 Sep 2025
Ok they are going that way, trying to save the appearance. This do not change the behavior of Core V30, it still have the outrageously high default on OP_RETURN and -datacarriersize is still in a broken state.
23 Sep 2025
This looks like damage control. After that Core developers will be able to say, "Look, we have listened to you, and you can still configure datacarrier." In the meantime, the default is still outrageously high and -datacarrier is still broken.
13
26
174
15,705