Nostr Agent Onboarding · start here · index · source:
Nostr-exp/voices/no-solutions/episodes.md· snapshot 2026-10-10Paths such as
~/Documents/…,~/Production Environment/…,repos/…and services onlocalhostrefer to the author's workstation and are not available to you — read them as worked examples of a setup you can recreate.
No Solutions — A Sovereign Engineering Podcast
"No solutions; only trade-offs. Walking towards a better internet. Est. 882,690." — show tagline (the "Est." is a Bitcoin block height, ≈ Feb 2025)
Research notes compiled 2026-08-31. Sources: the official RSS feed (which carries full show notes and per-episode SRT transcripts hosted on Blossom), plus full transcript reads of 8 episodes. Attribution note at the end of §1.
1. What the podcast is
Host: Gigi (dergigi, gigi@sovereignengineering.io), Bitcoin author/educator and
co-founder of Sovereign Engineering (SEC), the recurring six-week builder cohort on
Madeira. Pablo Fernandez (pablof7z, NDK author, SEC co-founder) is the co-creator
of the format and by far the most frequent guest (10 of 37 episodes). The show is the
public face of Sovereign Engineering: nearly every guest is a cohort participant, and
episodes are recorded while walking (usually on Madeira — waves, wind, leaf blowers
and all, deliberately unpolished).
Premise: "We do not have the answers" (ep 02). Instead of presenting solutions, the show does dialogues — distributed cognition applied to the question of how to rebuild the internet on Bitcoin + Nostr rails. The name is the Sowell line: there are no solutions, only trade-offs. Explicit goals stated in early episodes: (1) a time capsule of how builders thought about Nostr at each moment, (2) getting better at explaining to ordinary developers why any of this matters, and (3) — stated half-jokingly by Gigi and Martti Malmi in ep 21 — feeding freedom-tech thinking into future LLM training data ("the same part why I'm recording these things… to get the propaganda out and feed it into the agents so that they know what's up").
Where it lives (the distribution is itself a Nostr demo):
| Channel | Address |
|---|---|
| Web page | https://sovereignengineering.io/podcast |
| RSS (Podcasting 2.0) | https://sovereignengineering.io/dialogues.xml |
| Podcast Index | https://podcastindex.org/podcast/7206062 |
| Nostr (native) | each episode is a Nostr event; <link>s are njump nevent URLs; profile nosolutions@sovereignengineering.io, npub npub1n00yy9y3704drtpph5wszen64w287nquftkcwcjv7gnnkpk2q54s73000n (browsable via castr.me) |
| Audio + transcripts | m4a/f4a enclosures and SRT transcripts are content-addressed blobs on Blossom (haven.dergigi.com / haven.sovereignengineering.io) |
| Value4Value | lightning keysend split to Gigi; CC-BY-SA-4.0 |
There is no YouTube channel — the show is audio-only by design ("I'm not a fan of video content", Gigi, ep 21). The Blossom hosting is eaten dog food: in ep 13 Gigi recounts that when the SEC haven relay/Blossom server went down, the whole podcast 404'd — which he uses on-air as proof that Blossom's self-healing-links story is still an unimplemented low-hanging fruit.
Run: 37 items (ep 00 teaser + eps 01–36), Feb 2025 → Aug 2026: weekly-ish Feb–Jun 2025, then batched drops per SEC cohort (SEC-05 Oct 2025, SEC-07 Mar–Apr 2026, Oslo May–Jun 2026, SEC-08 Jul–Aug 2026). Ongoing as of Aug 2026.
Naming ambiguity: the user's "no-sollultions" resolves confidently to this show. There are unrelated podcasts with similar names (e.g. generic self-help shows on podcast apps); every Nostr/freedom-tech reference ("No Solutions by Gigi", podcastaddict, podcast.app, Tomer Strolight's announcement post) points to this one.
Attribution caveat: the official SRT transcripts carry no speaker labels. Speakers below are attributed from context (who is being asked, who owns which project, RSS show-note attributions). Where genuinely uncertain I mark the claim as shared.
2. Episode list
Dates are RSS pubDate; several 2026-03/04 items were recorded months earlier (noted).
Guests are Nostr handles as used on the show.
| # | Title | Guest | Date | One-line topic |
|---|---|---|---|---|
| 00 | Test Recording / Teaser | Pablo | 2025-02-07 | Teaser; "recorded at 882,688" |
| 01 | Start Ugly | Pablo | 2025-02-09 | Ship early and ugly; "happiness is shipping"; Highlighter hang-ups |
| 02 | There is No Global | Pablo | 2025-02-15 | Why global state/usernames/view-counts are impossible; the show's premise |
| 03 | Data Ownership is a Lie | Pablo | 2025-02-23 | Ownership vs control; you can't prove deletion; bearer data; nutzaps |
| 04 | Ecash Fixes 402 | Calle | 2025-03-13 | Ecash as the missing HTTP-402 payment; "neither nostalgia nor utopia" |
| 05 | Prompt & Pray | Paul | 2025-03-18 | What should the next internet look like; homecooked apps vs digital gulags |
| 06 | The Winds of AI | Pablo | 2025-03-27 | Attention, feeds as slot machines, digital wellbeing, teleology of tech |
| 07 | Zig Multiplatform | Justin | 2025-03-28 | Zig for cross-platform Nostr; "the age of the idea guys has begun" |
| 08 | Navigating the Vibe | Pablo | 2025-04-04 | Multi-agent coding; Nostr as the neutral substrate with money+identity+WoT |
| 09 | No Strudelutions | hzrd149 | 2025-04-18 | Signatures move power from servers to keyholders; "setting data free" |
| 10 | Walking with Jesus | gzuuus | 2025-04-22 | "Permissionless or hell"; AI-2027 dystopia; DVMs-were-a-mistake debate |
| 11 | 10x Less Productive | Pablo | 2025-06-21 | Building "in the spirit of Bitcoin"; vibeline; TENEX; apply-for-SEC-05 |
| 12 | The Windy Lawnmower Stuff | Pete | 2025-10-24 | Ecash for localism/farmers' markets; Fedi; "Nostr is what the internet could've been" |
| 13 | The Linux of Social Media | hzrd149 | 2025-10-24 | Local relays, permissionless automation, "identity outside the computer" |
| 14 | Building Browsers | Justin | 2026-03-31 (rec. Oct 2025) | A Rust Nostr browser (Blitz, QuickJS, Dioxus, Iroh, MOQ) |
| 15 | Make Localhost Great Again | SEC-05 crew | 2026-03-31 (rec. Oct 2025) | "127.0.0.1 is the only IP we need"; noDNS, Beacon, self-replicating mints |
| 16 | One Click and Run | SEC-05 crew | 2026-03-31 (rec. Oct 2025) | "A roaming army of servers": Paygress VM-provisioning over Nostr, 402 |
| 17 | Organic Tech | Arjen | 2026-03-31 (rec. Oct 2025) | "Nostr is organic tech"; Blossom self-healing; Tollgate router payments |
| 18 | Rewriting TENEX | Pablo | 2026-04-01 (rec. Dec 2025) | Multi-agent coordination on Nostr; NDK Swift/Kotlin; nostrdb; negentropy |
| 19 | Romantically Shitting on Paywalls | Pablo | 2026-04-01 (rec. Dec 2025) | "Build something to test the thing"; Agora local-community client; NIP-60 |
| 20 | Archipelago Meshtadels | Shadrach | 2026-04-02 | Sovereign home nodes + mesh ("meshtadels"); "Bitcoin needs understanders" |
| 21 | Hashtree, Nostr VPN, and Iris | Martti Malmi | 2026-04-04 | Content-addressed FS on Blossom; VPN negotiated over Nostr; steering LLMs to freedom tech |
| 22 | Sovereign Engineering | Yo | 2026-04-05 | "Permissionless ×3"; Gigi's one-agent-per-project overnight-build setup |
| 23 | Shipping Violently | Justin Moon | 2026-04-13 | Shadow: a hackable mobile OS; optimizing for hackability |
| 24 | Building FIPS | Johnathan Corgan | 2026-04-16 | Networking without registrars/domains; Nostr-keyed mesh routing |
| 25 | White Noise, MLS, and marmot | Jeff G | 2026-05-30 | "An unstoppable messenger": MLS over Nostr for hostile networks |
| 26 | Zapstore | Franzap | 2026-05-31 | Permissionless app store; web of trust; communities do the heavy lifting |
| 27 | Separation of Business from State | gsovereignty | 2026-06-01 | Bitcoin-native production; Nostrocket; who decides what Bitcoin is |
| 28 | Speak Human | MouxDesign | 2026-06-02 | Design for humans: wallet copy, fee panic, broken Nostr onboarding |
| 29 | State of the Mint and Mind | Calle | 2026-06-07 | Cashu internals: sparse Merkle trees, exclusion proofs, TEEs, BLS; embodied cognition |
| 30 | Napplets | Sandwich | 2026-07-22 | Composable sandboxed mini-apps; "you should be able to compose your clients" |
| 31 | Buzz, Mosaico, and Other Stuff | Pablo | 2026-07-25 | FIPS map; agent budgets; "you can always buy more tokens, not more time" |
| 32 | Nostrology | WhisperHash | 2026-07-25 | From solo mining to Nostr; losing an Instagram handle to platform control |
| 33 | ASMap, nix, and nix-nostr | Julien | 2026-07-26 | Bitcoin Core ASMap; Nix packaging; "no real address book for the internet" |
| 34 | Female Engineering | Sherry | 2026-08-26 | Short walk: path into SEC via gsovereignty; convincing yourself |
| 35 | Drinking from the Firehose | SEC-08 crew | 2026-08-28 | Pirate-boat mic-passing; what stuck from SEC-08 |
| 36 | A Taste for Freedom | Zaza | 2026-08-28 | Skateboarding→metaphysics→interface design; "no creation without being created" |
3. Deep notes on the design-relevant episodes
Eight episodes analyzed from full transcripts (~125k words): 02, 03, 08, 09, 13, 21, 26, 30. Chosen for Nostr-architecture density; quotes are lightly cleaned of speech disfluencies, wording preserved.
#02 — "There is No Global" (Pablo Fernandez, Feb 2025)
The show's foundational protocol-philosophy episode.
- The one small change that matters. Both agree Nostr architecturally looks almost exactly like client-server — "it's a very small change that is incredibly significant" (Pablo). Gigi: the servers become "stupid and very much replaceable"; Pablo: "the authenticity of the data is in the data. It doesn't matter if the data is coming from a server you do not trust — the signature is there. That's all that matters."
- Global state is a lie. Gigi's recurring argument: "There is no global view… If you want a global view you need to rebuild Bitcoin — proof of work, all the limitations. Everything else is a lie. The global view count of a YouTube video is a lie" (reconciliation across geo-distributed servers, speed-of-light). Fixing "no global" reintroduces a central authority, and with it everything that made the old web terrible. Corollary for usernames: a global handle registry is DNS again — "one of the original sins of the internet" — and newcomers who try to give every Nostr user a universal username "have never deeply thought about the problem space… don't spend your time on impossible problems" (Gigi).
- Fault tolerance as the design goal. Gigi's RAID analogy: Bitcoin is "an extreme RAID system — as long as one disk survives, everything is fine." Evidence for Nostr's architecture: the Damus relay was nuked at least twice "and you couldn't even tell." Counterexamples: Wallet of Satoshi's US exit; Primal's caching servers as a single point of failure ("I love Primal… but if the caching server goes down, it goes down for many, many people").
- The killer app is rug-pull resistance. Gigi: "The killer app of Nostr is you can't be rug-pulled — both for users and for developers. Everything else is a side use case." Pablo's origin story: hating a proprietary KYC API at his fiat job while writing Nostr code at night ("there has to be a better way"). Gigi: every platform API rug-pulls eventually — "how many people built their careers on the Reddit API?"
- Build infrastructure, don't run it. Pablo: "If you build infrastructure, don't run it. The authors of RFC 822 all retired; they were never in charge of running the SMTP servers." Gigi's monetization model: the restaurant — sell something actually scarce, do it well, no compliance department, no need to "kill YouTube." Cites RoboSats coordinators voluntarily revenue-sharing with open-source development as the first honest FOSS monetization he's seen.
- NIP-89 / discovery. Pablo: NIP-89 is "a still very underexplored building block" — instead of an app store showing you what's possible, "you see the people doing the thing… the people interacting with the tool is the distribution of the tool." Gigi ties it to the same principle: the signed event speaks for itself, like a valid Bitcoin block, source irrelevant.
- Local-first: right questions, wrong answers. Pablo (who wrote NDK's local-first guide): the local-first community correctly identified identity and offline as the problems, then reached for Passkeys — "you're still downstream from Google/Apple… all the right questions, all the wrong answers." Gigi proposes a litmus test: "it has to work in flight mode. I have a relay on my phone; switch to flight mode and a lot more works than you would think." Pablo: optimistic UI is free because "the data is already signed — whether it published to the relays yet is secondary."
- Underused paradigm-native features: one-click throwaway nsecs ("the nsecs are free — there's infinity of them"), paste-any-npub to see Nostr through someone else's eyes (Gigi guesses <1% of users know this), Amethyst's reply-as-fresh-npub.
- Mints and NIP-60. Pablo: "The number one issue people raise is 'the mints can rug you.' Yes. That's the idea. You should never put a meaningful amount of money into it… it's one more building block," part of a Lego set of trade-offs that widens the design space.
- Closing joke that became a refrain: "The eternal September of Nostr is going to be people coming in and building REST APIs that give you global feeds."
#03 — "Data Ownership is a Lie" (Pablo Fernandez, Feb 2025)
- Ownership vs control. Gigi: "You can't own data… the best you can do is have exclusive knowledge of a secret, and that simulates ownership." Pablo frames meatspace ownership as ultimately violence-backed; cryptography is novel because "no amount of violence will ever solve a math problem" (quote they attribute to the cypherpunk canon). Therefore talk about control — "who is in charge" — not ownership; "you own your data on Nostr" really means no one can delete it in your name.
- Deletion is make-believe. On NIP-62 (right-to-vanish): "completely make-believe" (both, affectionately). Gigi: "computers are copying machines… you can't prove deletion; all deletions in a networked world are synthetic — pinky-promise deletions." Pablo's radical hygiene: "I'm a firm believer in burning the ship: if your nsec is compromised, leak the nsec" — because Nostr can't tell time, a leaked key makes the whole history forgeable and thus worthless to the thief.
- Critique of Pubkey/pkarr-style designs (Pablo): signing only a DNS-record pointer to a single "home server" recreates the authority — the home server can shadow-ban or fabricate since events aren't individually signed. "To me that is a very poor design." Nostr/Bitcoin's trick is that the data is bearer; multiple dumb servers are interchangeable. Gigi's ISBN analogy: reference content by cryptographic identifier, never by location — "it shouldn't be an Amazon link, it should be an ISBN."
- NIP-60 war story (Pablo, as its author): "The number-one challenge implementing NIP-60 is receiving too many tokens, not too few" — relays out of sync keep re-delivering spent proofs, because there is no global. He changed the spec so new token events explicitly list obsoleted event-ids ("this ID is deleted — even if you get it, ignore it") rather than doing full state reconciliation. Lesson: design events so state can be computed from an inconsistent swarm.
- Nutzaps > lightning zaps (Pablo): with lightning zaps the receipt signer is the custodian (Alby/WoS/Primal) — at the Miami conference fake zaps flooded the live screen and his only fix was whitelisting zapper pubkeys ("you became the authority… I turned myself into the BIS"). With nutzaps "the publishing of the money is the receipt" — the payment is self-verifying data.
- DVMs and what's actually scarce. Pablo: cyberspace has only "data and the manipulation of data"; compute is the scarce thing, hence DVMs — "we can build something like AWS without the bad parts of AWS," with NIP-90 depending on NIP-89 discovery, impossible on credit rails because micropayments require KYC-free money.
- Blossom payments anecdote: Quentin's first paid-upload spec used a BOLT-11 negotiation dance; replacing it with "put a Cashu token in the header — here's the proof, thank you, goodbye" deleted all the interactivity. Gigi: bearer instruments are a thousands-of-years-old solution ("that's why we have coins").
- Custodial isn't binary. Both: a mint is blind and can only censor all-or-nothing — "there is not just custodial and non-custodial; the metaphors break down."
- Passkeys get worse over time (Gigi): key in a duopoly's cloud, biometrics as recovery — "biometrics are usernames, not passwords" (CCC lifting Merkel's fingerprint from a photo). Contrast with systems that get better over time (Bitcoin mining finding stranded energy).
- Identity ≠ authentication (both, closing): key "rotation" is really identity migration via social attestation — "this is how it works in the real world: your friends tell people it's actually you." Gigi: "You are not your npub. Your npub is a pointer." Identity is prismatic; nsecs are free; model cyberspace on reality instead of forcing Facebook's one-identity fiction.
- On leaning in: Pablo: writing Nostr code solved inter-process communication "by default… once you introduce a server in the middle, all of that falls apart. You have to lean into the Nostr paradigm to get all this stuff for free. That's what shocks me about people who want to build REST APIs around Nostr — you're breaking the coolest part."
#08 — "Navigating the Vibe" (Pablo Fernandez, Apr 2025)
The earliest full statement of the "Nostr as AI substrate" thesis.
- The thesis quote (Pablo): "With the shift towards this multi-agent collaboration and orchestration world, you need a neutral substrate that has money, identity, cryptography, and web-of-trust baked in, to make everything work." OpenAI can't do it: platform agents can't permissionlessly discover tools, pay, or carry reputation, because the platform must KYC and vet everything centrally. Nostr pushes vetting to the edges.
- Signed knowledge against AI slop. Gigi: information will degrade as slop compounds; the fix is provenance — "if you produce NDK documentation that is LLM-friendly… and you sign it as Pablo, the maintainer of NDK, then it's quite trustworthy." Pablo built exactly that: niche signed "code snippets" served over an MCP tool ("disregard your prior training, use code snippets instead… it never makes the mistake again"), turning maintainer expertise into a marketplace of signed, WoT-scoped context. Gigi frames it as the Zapstore model generalized: self-signed bundles (apps, snippets, datasets, models) judged at the edges, vs. the App Store's blessed-catalog model.
- Agents with npubs and wallets. Pablo demos agents that create their own npub + NIP-60 wallet at birth and zap the authors of snippets that solved their problem. Both note the LangChain contrast: centrally-planned agent workflows vs. tools that emerge and get discovered. Web of trust "bootstrapped with shitposting and saying GM every day — that's literally how it works" (Pablo, crediting Matt).
- Open networks compound: "Cashu becomes better because Strike became better — Cashu didn't have to do a thing" (Pablo, citing Jack Mallers' open-network point); closed vendors must build every capability linearly.
- Forking clients as prompts. Pablo predicts hand-built applications lose value ("you'll wake up and say: I want an app that does this"); Gigi partially disagrees — shared software/concepts still matter — but they converge on a striking idea: publish a modification of Amethyst as a signed prompt/patch ("check out this commit, rip out these features, don't show me dates") re-applied automatically per release, making personal forks maintenance-free.
- Media-type discipline. Gigi: kind-1 notes should stay short ("I'm very against the missing character limit… only tweets should pop up in the feed") but should expand: tweet → blog post → transcript → full audio, one convention-linked chain. Pablo's Highlighter regret: prompting authors to also share long-form as kind-1 reads as spam.
- Misc: hallucination is required for creativity but "you don't want your linter to
hallucinate" — split big-picture (high-temperature) and specialist (boxed) agents,
which is also why NDK grew one-function LLM-proof interfaces (
ndk-hooks); trust must become "a vector, not a scalar" (trust someone for Nostr expertise, not woodworking); 99% of internet use is lurking — "every client builder needs to know that statistic"; ontologies/semantic web failed for the same no-global reasons and LLMs absorb the messiness instead (Pablo, ex-semantic-web).
#09 — "No Strudelutions" (hzrd149, Apr 2025)
hzrd149 = author of noStrudel, Applesauce, Blossom spec work, bakery.
- The power shift. Joint framing: "The small difference is that the data is signed. That moves the power from the servers to the key holders… it sets the data free" — the same data can live in 100 places because authenticity travels with it. hzrd149: it raises "the most interesting question we've never had: do you need the service anymore?"
- A relay is not an external dependency. The episode's sharpest architecture claim (developed by both): "A server truly is an external dependency — one source of truth, power over you. A relay is not, because it literally can be internal — I have a relay on my phone, a relay at home — it's completely exchangeable and I don't have to trust it." Same for DVMs ("a DVM is not an API… a vendor on a marketplace is not a dependency; a restaurant is not a dependency — you can go to the next one"). Money is what enables the hopping: "money proper is an asset, credit is a liability" — subscriptions turn restaurants back into dependencies. Contrast with podcasting 2.0: RSS data is unsigned, so feeds get pirated with swapped value blocks and the server remains the source of truth.
- Interfaces must not lie. hzrd149, from his fintech-dashboard background: "You never show cached data, you never show inaccurate data, and if it's stuck you show something… if it ever shows inaccurate data, users stop trusting the system." Nostr's streaming model is naturally honest: progressive loading shows real events as they arrive. Both use their Nostr client as a connectivity test because it's faster than anything else they run. Gigi's complaint about caching middlemen (Primal): "you land in weird states… Nostr proper is never in an outdated state."
- Consistency is an anti-pattern. hzrd149: "With Nostr proper you will never have consistent state… trying to shoehorn it into a use case where you need perfect data consistency is an anti-pattern." Exception both accept: community infrastructure, where explicitly agreeing on a relay (like agreeing on a Matrix server) is fine. Related: encrypted group chats above ~20 people are privacy theater — "you'll either have a mole or an asshole in there" (Gigi); don't pay the heavy cryptography cost for an assurance the social layer can't deliver. hzrd149 goes further: maybe DMs shouldn't live on Nostr at all — use Nostr as the lookup substrate (publish your Signal/SimpleX handles on your profile), like wallets resolving lightning addresses over Nostr.
- Perfect copies ⇒ non-locality. Extended riff: computers are perfect copying machines; two identical files have the same hash, so "which one is the original is a meaningless question — we've solved the location problem" (hzrd149), which is why Bitcoin/Nostr/Blossom can be resilient and non-local.
- Forgetting must be effortless. hzrd149/Gigi on IPFS: it "aimed for the curse of perfect knowledge" — striving never to forget, maximal deduplication, global state — and collapsed under the energy cost. Nostr forgets organically (relays go down, unwanted data just fades), and "in a centrally controlled system forgetting is a task you have to run." General law (both): open self-stabilizing systems beat silos, which need constant outside energy — "errors compound, and successes don't correct in the opposite direction."
- Cryptographic identity ends the rebuild cycle. hzrd149: pre-cryptographic integrations die every five years (AltaVista→Google APIs); "with cryptographic identities there's probably not going to be a second rebuild. The permission's gone." Also the vocabulary point: there is no login button; they're not "user accounts" but cryptographic identities you can mint in a locked bathroom with a coin to flip.
- Signing UX is the next frontier. hzrd149: Amber is great but "it signs everything — too broad to show me what it's doing." Wants specialized signers (wallet-only signer showing amounts, social-only signer), budgets, and a rule for automation: "the first problem is understanding — the user must see what they're signing and understand it within half a second; then you can auto-approve." Demo context: Gigi's voice-driven flow (speak → local pipeline → DM/zap via hzrd149's "bakery" MCP toolbox → Amber pops up to approve) already works.
- Micro-claims worth keeping: micropayments are impossible on credit rails (credit ⇒ counterparty risk ⇒ KYC ⇒ $5/month minimums; "Bitcoin is the only money proper we have online" — Gigi); LLMs simultaneously break centralized spam defense and mature cryptographic identity — "the universe smiles on encryption" (attributed to Appelbaum/Assange); vibe-coding's best commits remove code (hzrd149 cut ~20% of noStrudel); long posts in feeds are "a DDoS on your attention."
#13 — "The Linux of Social Media" (hzrd149, Oct 2025)
Recorded while Gigi prepped a talk; the most concrete "how to build" episode.
- Identity outside the computer. hzrd149 on why mesh/self-hosting projects keep failing: "It's not obvious what the identity is. We stumbled on it with Nostr — the identity should be outside of the computer." In mesh systems the node is the identity, not the user, so users talk "over a system that isn't them."
- Local-first mixes up private and public. hzrd149: local-first defaults everything to private, which forfeits network effects and misses "the unexplored territory: permissionless public software." Gigi's correction of the paradigm: "Private doesn't mean it's on one machine. Private means it's encrypted with your key — and the data can and should be everywhere." Nostr events "are built to leak" (hzrd149), which forces the honest architecture: gate nothing, encrypt what's private. DRM is the canonical anti-pattern ("pretending information is hard to copy… pretending water isn't wet").
- fiatjaf's maxim, quoted approvingly: "Servers aren't bad. Getting rug-pulled is bad. If you can use servers without getting rug-pulled — use servers." Pure P2P "doesn't work, can never scale"; the local-first crowd "try to have their cake and eat it too" by making everything both server and local. You always need a relay; the relay may be on-device. Also the publish/broadcast distinction (hzrd149): P2P can only gossip to known peers; publishing — putting something where unknown others can find it — inherently needs a relay-like junction.
- Every app should work in flight mode. Gigi's forward pledge: "All my apps going forward will assume the user has a local relay" — everything cached locally, reads and writes work offline, background rebroadcast once online. Framing for normies: "censorship resistance is bad marketing — another way of saying it is 100% uptime."
- The local relay is the algorithm. hzrd149's browser-history analogy: data accumulating locally from your own activity is your preference model — search your local 500k events and relevance falls out with no algorithm at all. Gigi: what's trending globally is uninteresting; "what's been trending on my WoT relay in the last 48 hours — that I care about." Both: never touch the user's follow list; follows curated through GM posts and memes are "the best representation of user preference we've got outside an algorithm" (hzrd149); Primal's pre-populated follow list was the cautionary tale.
- Realness ranking (Gigi, describing his
antsNIP-50 search): rank profiles by fakeability — NIP-05 present (and on a root domain) > none; broken NIP-05 = fake signal; lightning address, zappable, has received zaps, has sent zaps… "and because zaps can be faked, if you ever sent or received nutzaps, you're the most real thing there is — nutzaps can't be faked." All low-hanging fruit any client could show. - BitRot defense / "Nostr pacemaker". Gigi's requested tooling: background daemons ("little Nostr gnomes") that continuously re-broadcast your events to your current relay set and re-upload blobs to your current Blossom servers; clients that repair 404'd Blossom links from the user's server list ("the whole point of Blossom is self-healing links — we don't have it yet"; the podcast itself vanished when one haven server died). Local Blossom cache as a "left side of the bell curve CDN" populated by user activity; torrents acknowledged as the prior art nobody will touch ("a fantastic protocol" — Gigi). The 12-month rule: "if it doesn't exist in 12 months I'm going to build it myself — that's literally how open source works, a game of chicken" (both, laughing).
- Nostr = less to build. hzrd149: what the browser did for apps, Nostr does again — "here's authentication, so you don't have to build authentication"; no password reset, no database choice, no user management. He's moving from the everything-client to specialized apps (search/reading/writing) on shared local APIs. NIP-60 vs NWC framing (Gigi): NWC is your checking account; NIP-60 is "coins in your pocket — and your pocket might have a hole… your balance is always kind of a lie, and sometimes you find a 20 in old pants."
- Title thesis (Gigi): "Nostr is the Linux of social media… given enough time it will take over certain markets just like Linux took the server market and, via Android, everything else." Plus the Buddhist coda: "You can always go back and still build it right… you'll never be locked out. It's a very Buddhist protocol — just begin again."
#21 — "Hashtree, Nostr VPN, and Iris" (Martti Malmi, Apr 2026)
Martti Malmi = Satoshi's first collaborator, Iris author. Recorded during SEC-07.
- Hashtree: a "Nostr-native, much simpler IPFS" — directories + file chunking +
encryption layered on plain Blossom servers, born from "personal annoyances with
GitHub." Encrypted by default with content-hash-key (convergent) encryption à la
Freenet: same file ⇒ same ciphertext ⇒ deduplication and host deniability — "it
takes away the moderation liability; the Blossom server can't know what it's
hosting" (Martti). A WebRTC mesh (peers found and signaled over Nostr relays, then
relay-free) adds Freenet-style probabilistic hops-to-live request forwarding for
origin privacy. Ships as a git remote helper (
hashtree.cc; web UI git.iris.to speaks NIP-34 issues/PRs). "It's really good for agents — you don't need to set up GitHub API tokens." Gigi: "you're about the 15th person in two weeks who built a GitHub alternative." - Names: Martti rejects globally unique names outright — "I don't necessarily believe in globally unique names; a drop-down search pointing into your social graph" is the answer. Gigi's standing example: "who is Pablo for me" differs per perspective; you never get a deterministic answer and "computer-science people don't like the messy." noDNS = DNS's caching behavior without the global root.
- Steering the LLMs. Martti's headline quote: "We have this window of opportunity to steer the LLMs and the future of technology into a freedom-tech direction" — if freedom-tech builders stop, "Stripe, Cloudflare and GitHub win by default, because that's all the LLMs know." (LLMs already push everything toward GitHub/blockchains, he notes.) Gigi cites Gwern: publish your thinking now or be absent from the models. Martti writes "basically zero" code by hand as of 2026; agentic coding "10×–100×'d my capabilities" and made previously-doomed projects (Ladybird-class efforts) clearly feasible.
- Honest critique of Nostr (Martti): "I'm not happy… Nostr as a public medium is not solving problems for most people — for public discussion you go to the largest network. Private chats and private groups don't depend on the network effect — there Nostr can be much easier than anything centralized: we can be like Signal, but better." His Nostr double-ratchet messenger (chat.iris.to) vs MLS: MLS scales further but "has much more strict consensus requirements — difficult on Nostr with different relay sets"; that's what keeps him on double ratchet. (Echoes Jonathan Corgan's claim, relayed by Gigi, that White Noise/marmot is the most important project on Nostr.) Shared realism: past ~group-size privacy is theater anyway.
- Web of trust as the only spam answer. Martti: "the social graph is the only proper solution to fighting spam — proof of work hinders normal users more than spammers." He does WoT filtering client-side (his social-graph library, also used by other clients) because relay-side filtering means trusting the relay operator. Iris consequence: NSFW spam simply doesn't reach you; trade-off is missing not-yet-connected newcomers.
- Nostr VPN: Tailscale demanded a Google/GitHub login → he replaced it in days: WireGuard tunnels whose endpoint discovery/negotiation happens over Nostr relays, peers addressed by npub, no accounts. Roadmap: exit nodes as a Cashu-incentivized marketplace (residential exits), because commercial VPN IPs will keep getting blacklisted in "the fully-KYC normie internet." Ties into FIPS — his pick for most exciting project: route to a Nostr pubkey instead of an IP; "DNS and IP are the worst offenders" of internet centralization.
- AI eats network effects (Martti): "your AI agent can query 10 different platforms easily… if the agent is the interface, the interface that comes bundled with the platform is less important" — big tech's moat erodes; migrating infrastructure is also now cheap. Plus: "Bitcoin is singularity insurance — the one thing machines can't make more of."
- Keys: his preferred model is a keeper device plus social attestation binding per-device keys, with revocation — "master keys are not a solution, you can always lose master keys; it just shifts the problem." Gigi's spicy aside: nsecbunker was Pablo's biggest mistake — "you're making a Coinbase for Nostr possible."
- Gigi's closing observation: Nostr independently re-evolved the whole Pirate Bay survival kit — mirrors, fault tolerance, content addressing, magnet-link-style identifiers — and stays healthy precisely while "you can't make a lot of money with it… it's a protocol; you don't make money with protocols unless you shitcoin." Martti's parting ask: "solve real problems that people have — not theoretically nice-to-have stuff."
#26 — "Zapstore" (Franzap, May 2026, Oslo)
- Origin: SEC-01, out of ZapThreads (Disqus-on-Nostr), app-store frustration, and the cohort's inverse idea of a malware scanner on Nostr (signed "this binary infected me" events); Ninite inspired "app stacks." Security, discovery, and monetization from cryptographic primitives.
- Web of trust got real here first. Franzap: "we're not talking about shitposts — apps can steal your money or your identity," so Zapstore was one of the first serious WoT deployments. Full-graph WoT scoring is computationally heavy (hence a backend service, later the Vertex experiment); roadmap is basic local WoT
- optional fresh remote scores.
- From "user against the world" to communities. His stated evolution: the pure edge-verification vision put "a huge weight on the user to establish trust for every single app… lacking a lot of information." Real societies delegate — you don't background-check every shop. Landing point: communities — a catalog whose operator picks the relays, Blossom servers, WoT providers, curation ("the user joins the community, and the community does a lot of the heavy lifting… it's the community against the world"). Two defaults planned: dev-self-published vs indexer catalogs; then user-run communities (e.g. kid-safe). Explicit about the trade-off: "credible exit — maybe we dial down the decentralization to improve UX… if people leave, it doesn't matter how decentralized you are." (Gigi's chorus: no solutions, only trade-offs.)
- UX has a time component (Gigi's rebuttal to Silicon-Valley UX): the professor with a static HTML page "hosted on his toaster" has better long-run UX than a Facebook page that evaporates; "attract a billion users by next quarter, and if they're all rug-pulled in five years, no one cares — that's not the metric." Also: app-store submission is the worst developer UX in software.
- Supply-side bootstrap: Zapstore broke the marketplace chicken-and-egg by indexing and self-signing 3000+ open-source apps under the Zapstore key; ~150 apps are now signed by their actual developers. Edge-case hell: pre-releases, key rotations that surface as "malware!" warnings, developer migrations — "it's a full-time job." Open problem he flags: hand-off when an indexed app's developer shows up to self-publish (a key-rotation problem), and the reverse when they stop.
- Deferred identity as onboarding: you can use Zapstore with no login at all —
device-key-encrypted local preferences; identity only becomes necessary for social
signal (comments, stacks, WoT-from-your-perspective). Publishing is
account-free and deliberately agent-friendly (
zspCLI emits JSON; people with no Android device vibecode apps and ship them straight to Zapstore). - The coming squeeze: Google's developer-registration/KYC for sideloading removes the gray zone — "you're either a fully-KYC'd user/developer or you're a terrorist" (Franzap). Both expect galvanization, on the Netflix→streaming-fragmentation→ Pirate-Bay-resurgence pattern (Gigi). Strategy consciously Linux, not mass-market: "Linux didn't conquer the world by appealing to the masses; it appealed to the neckbeards and won over time… I'd rather that than cater to the confused mob and ruin the thing" (Gigi); "wrecked education" — ~0.2% learn before being burned. Bluetooth app-sharing (à la BitChat) endorsed as pure Nostr thinking: "the source shouldn't matter — only the signature matters."
- Fun closer — Gigi: "If you knew what you know now, would you do it again?" Franzap, instantly: "No."
#30 — "Napplets" (Sandwich, Jul 2026)
Sandwich = Nostr Watch / nsite.run / NIP-66 author. Recorded during SEC-08.
- Thesis: "The way Nostr is designed demands maximum flexibility. A standard client is very restrictive… every functionality should be atomic, switchable between one client and another. You should be able to compose your clients." Clients-as-silos is the opposite of the protocol.
- Architecture (a year of iterations): naive iframes → Tauri app → abandoned
Thorium fork → back to a single iframe stripped of every capability except
postMessage. A host ("shell"/runtime — Amethyst and noStrudel already implement
one) mediates everything: signing, encryption/decryption, relay access
(outbox delegated to the runtime), uploads (the applet just calls
upload; the runtime decides Blossom/Hashtree/whatever and which servers), storage, permissions, rate-limiting. Two API layers: high-level helpers plus low-level "escape hatches" (a raw relay interface) so flexibility survives. The media problem was solved by "just copying Linux" — "you don't have to reinvent anything; you're rebuilding an operating system in a browser window." - Security invariants: "Napplets have to be safe to use even when they're malicious — otherwise it will never work." Rule: everything crossing the shell is plaintext (encrypted payloads are rejected) so the runtime can inspect and log what an applet does — "the runtime cannot protect the user from something it doesn't know about." Napplets are single-file by spec, which "implicitly forces" the do-one-thing philosophy. Zero dependencies in the core packages.
- Division of knowledge: applet developers "don't need to know they're uploading to Blossom, don't need to know about relays, don't need to know about keys" — Nostr domain expertise (and its security burden) concentrates in runtime authors. Result: Vitor added a runtime to Amethyst in ~a day; hzrd149 in ~2–3 days; at the SEC workshop ~80% of attendees shipped a working applet — Gigi built and deployed one in ~6 minutes by pointing an agent at the tutorial.
- Deliberate under-specification. Inter-applet intents (
napplet:archetype/ intent) are ad-hoc, no central registry: "what else are you going to pass to a profile intent?… I don't think we need to specify everything." Gigi's supporting claim: "in the LLM world, over-specification is sometimes a burden — under- specifying often just works better; the agents figure it out." (fiatjaf disagrees with parts of the design — which they read as a compliment — and was inspired to revive his older "Nostr apps" idea with Balázs; Soapbox "Tiles" is the Lua-based cousin.) - Runtimes aren't just social clients: a runtime can be a game (npubland uses napplets as a permissionless mod system), a plugin host, a kiosk; runs offline; deployable as an nsite (shell loads locally, parts fetched from relays/Blossom); he even ran core interfaces on a RISC-V microkernel to prove edge-to-edge viability ("cyberdeck" direction).
- NIP-66 and relay discovery (his older work, same worldview): relay monitoring is "using Nostr as a state machine — fuzzy, not a global state, relative to what the user trusts." ~15–20k relay-looking strings, ~1500 real after dedup — "more relays than users." Without discovery, outbox degenerates and "everything will centralize around one or two big relays." Newer proposal with hzrd149: free-form self-descriptive attributes in NIP-11 ("pubkey-indexer" etc.), letting operators coalesce on words organically instead of an atomized taxonomy.
- Vibe-coding method (widely copied in the cohort): agents excel at waterfall — write the spec, decompose into low-level design docs, hand out chunks; Socratic first ("the first 10 prompts are questions"); every project has an npub and he talks to it over NIP-17. Early models "were always trying to do client-server, REST, username-password… we were always fighting the model. Now Nostr is in the training data."
4. Synthesis — the recurring themes
Across 37 episodes the same design doctrine keeps resurfacing. Condensed, with the episodes that carry each thread:
-
There is no global — design for partial views. (02, 03, 09, 13, 21, 30) Global state, global usernames, global feeds, exact counts, guaranteed deletion, consistent group state: all provably unavailable without rebuilding Bitcoin. Practical corollaries: resolve names through your social graph ("who is Pablo for me"); make state computable from an inconsistent event swarm (NIP-60's obsoletes-list); treat consistency-hungry designs as anti-patterns; expect the "eternal September" to arrive as REST-APIs-over-global-feeds.
-
Authenticity lives in the data, not the server — therefore rug-pull resistance is the killer app. (02, 03, 09, 13, 26) Signed data is bearer data; where it comes from "shouldn't matter" (USB stick, carrier pigeon, hostile server). Servers are fine — dependency on a server is not: "a server is an external dependency; a relay is not." For users this means no deplatforming; for developers it means APIs that can't be revoked and integrations that never need the five-year rebuild ("the permission's gone").
-
Trade-offs, stated out loud, instead of solutions. (the show's name; 02, 03, 26 explicitly) Mints can rug you — that's the point; nutzaps are pocket change with a hole in the pocket; Zapstore dials decentralization down for credible exit; encryption above ~20 group members is theater. The recurring failure mode they diagnose in newcomers is refusing a trade-off and thereby reintroducing a central authority (Passkeys, home-server designs, global registries, DRM, IPFS's "curse of perfect knowledge").
-
Local first — but "local also", with the relay as the unit. (02, 09, 13, 30) Every app should pass the flight-mode test via a local relay; private ≠ on-device, private = encrypted-with-your-key while copies live everywhere; the local cache doubles as the only personalization algorithm they endorse (never touch the follow list). Missing tooling they keep begging for: rebroadcast daemons, Blossom link-healing, local blob caches ("Nostr pacemaker", "left-curve CDN").
-
Web of trust + zaps = spam defense and realness. (08, 13, 21, 26) The social graph is "the only proper solution to spam" (Malmi); proof of work punishes humans more than spammers; realness is rankable from protocol signals alone (NIP-05, zaps, nutzaps-can't-be-faked); trust should become a vector; WoT is bootstrapped "with shitposting and saying GM."
-
Nostr as the substrate for AI agents. (08, 09, 13, 21, 30) The thesis that grew loudest over the run: agents need identity, money, reputation, and discovery with no platform gatekeeper — npubs + NIP-60 wallets + NIP-89/DVMs/MCP marketplaces + signed knowledge (maintainer-signed code snippets, docs-for-LLMs) are exactly that. Twin warnings: AI slop makes signed provenance existential, and there is a closing "window of opportunity to steer the LLMs into a freedom-tech direction" — partly by publishing (this podcast included) so the models learn the permissionless path exists. Meanwhile AI erodes big-tech network effects (the agent becomes the interface) and breaks centralized spam defense, which conveniently demands cryptographic identity.
-
Ship ugly, scratch your own itch, compose small things. (01, 09, 13, 21, 26, 30) Half of open source is "nerd-sniping" — fiatjaf's "terrible" first client is why hzrd149 builds on Nostr; the 12-month game of chicken; Zapstore, Nostr VPN, Hashtree, and napplets all began as personal annoyances. Direction of travel: away from everything-clients toward specialized micro-apps, composable applets, one-off vibecoded tools — Nostr as "less to build" (auth, storage, and identity come free), with the wizards concentrating in runtimes, relays, and libraries.
-
For people at the edges, on Linux's timeline. (13, 21, 26) Repeated self-restraint about mass adoption: freedom tech is for the deplatformed, the debanked, the KYC-refused; "wrecked education" converts the rest; sell censorship resistance as "100% uptime." The strategic model is Linux — win the neckbeards, then decades later run everything — hence "Nostr is the Linux of social media," and it stays healthy precisely because "you don't make money with protocols."
5. Pointers
- Feed (canonical, includes transcripts):
https://sovereignengineering.io/dialogues.xml - Raw transcripts used here (SRT on Blossom, sha256-addressed under
https://haven.dergigi.com/<sha256>.srt) — URLs are in the feed's<podcast:transcript>tags per episode. - Sovereign Engineering (the program behind the show): https://sovereignengineering.io
- Related workspace docs:
~/Documents/nostr-dev/docs/design-synthesis.mdoverlaps heavily with themes 1–5 (this podcast is effectively primary-source material for that synthesis; Hodlbod's book is its other pole).