Aha no this is bullshit and everybody knows that except for a few people in the tech industry, apparently. That’s exactly why I made it optional in the Cesium2 settings, based on general feedback.
Then please open issues, the open issues are already known and will be addressed in the next release.
Okay, so let me be more specific about this:
Gecko was created following the technical abandonment of the main G1 wallet, which was detrimental to the entire ecosystem.
It was therefore agreed that we would learn from past mistakes and avoid repeating the same patterns.
One of these, in particular, is to avoid building a monolith where the core functionality related to Duniter isn’t shared with the rest of the ecosystem.
That is why I took the time to build the durt2 library, which integrates 100% of the business logic related to the Duniter ecosystem and is completely agnostic to the state manager, so that any Flutter tool can use it and, most importantly, contribute to the library for its own needs, thereby helping everyone grow.
So “contributing to the rest of the ecosystem” refers to this mindset.
On the other hand, I’m starting to get really sick of repeating myself over and over again on this topic. It seems completely out of touch to me, as if you’d just landed from who knows where. Focus on your own topics, and allow yourself to shed light on issues that have been open for years and have been debated at length, it’s starting to get tiresome.
The issue is still on the table; nothing has changed since then, so I don’t understand why I’d be asked to change anything.
Yes, of course, and Ginkgo doesn’t address this at all, and I’m puzzled by the fact that no one is pointing out anymore that this app allows users to create members accounts without even making sure they’ve written down their recovery phrase.
To me, this is obviously the most critical security issue, we’ve been talking about it on this forum for literally 10 years, and you keep saying that everything is fine with this app? But what exactly is your problem? Did you even test this app just once before passing judgment?
However, it’s not for lack of having:
- Contributed to G1nkgo in its early days to open a dialogue and show my willingness to work as part of a team.
- Contacted the app’s developer to explain the security risk of having member accounts without ensuring that users have written down their recovery phrases
- Sent a private message to the app’s developer as soon as development on durt2 began, asking for their requirements so they could integrate it into g1kngo and contribute to it
- Created a durt library when I decided to transition Gecko to the v2 migration in order to support the development of that migration, rather than rushing out an app without investing in the future. This is precisely what g1nkgo did by using durt1 directly and only taking an interest in v2 a few months before the migration.
So now, once and for all, no, g1kngo does not meet the security standards we collectively set for ourselves many years ago, and I am stunned to see that you are acting as if nothing has happened.
Finally, I’d like to clarify this:
The Gecko website and its communications follow their own editorial line. That’s precisely why it isn’t hosted on the duniter.org domain, which was managed collectively.
I therefore reserve the right to post whatever I see fit there, without being pressured by anyone if I feel certain things are counterproductive.
Please keep this in mind going forward.