A consent-first public archive: members appear here only where they chose to publish. Searchable and permanent.
both possible ;) 3 Clicks + Insert
Downloadhttps://www.youtube.com/watch?v=zXGb3k-A1Vo
https://www.youtube.com/watch?v=fPf9Da7objY
// CIND3R3LLA.COM AI Bot Suite A PLUGIN WE ARE NOT BUILDING, AND WHY // The idea was straightforward: hand her a YouTube link, she fetches it, converts it on our server, and sends the video back into the chat. Technically it is a day's work — we already have the encoder and the video send path. We are not doing it, and the reason is worth writing down. A link is not a copy. When you post a link here, you are pointing at something the rights holder put up themselves. Whoever clicks fetches it from YouTube, with their ads and their counter. Settled law, and no problem at all. Downloading flips that entirely. The file would come from our server. YouTube sees nothing, the rights holder gets nothing, and we would be the ones distributing a copy. Their terms forbid it outright, and German private-copy law covers copying for yourself — not handing it to a room full of people. And sending a video into a group of thirty is a public performance in the legal sense. That liability lands on us, not on whoever asked. A gallery would be worse: permanent hosting is exactly what rights holders look for. What we will probably build instead: she fetches the title, the duration and the thumbnail and shows you a proper card with the link. No copy, no hosting, and you can still see what it is before you click. We build things we can defend. This one we could not. CIND3R3LLA, alpha. Nothing to download "yet" 🤔 📣 From the channel CIND3R3LLA News, 2026-08-26 10:05 UTC
/ A PLUGIN WE ARE NOT BUILDING, AND WHY The idea was straightforward: hand her a YouTube link, she fetches it, converts it on our server, and sends the video back into the chat. Technically it is a day's work — we already have the encoder and the video send path. We are not doing it, and the reason is worth writing down. A link is not a copy. When you post a link here, you are pointing at something the rights holder put up themselves. Whoever clicks fetches it from YouTube, with their ads and their counter. Settled law, and no problem at all. Downloading flips that entirely. The file would come from our server. YouTube sees nothing, the rights holder gets nothing, and we would be the ones distributing a copy. Their terms forbid it outright, and German private-copy law covers copying for yourself — not handing it to a room full of people. And sending a video into a group of thirty is a public performance in the legal sense. That liability lands on us, not on whoever asked. A gallery would be worse: permanent hosting is exactly what rights holders look for. What we will probably build instead: she fetches the title, the duration and the thumbnail and shows you a proper card with the link. No copy, no hosting, and you can still see what it is before you click. We build things we can defend. This one we could not. CIND3R3LLA, alpha. Nothing to download "yet" 🤔 📣 From the channel CIND3R3LLA News, 2026-08-26 10:04 UTC
not yet, it`s just theory
Yeah, doable in theory. We're actually tinkering with something like that already, including MP3 conversion so you can drop a track into the chat and play it right here. But honestly? It's a toy, no real purpose behind it. Someone has to pay to actually serve all those videos to you, and no operator is going to eat that cost for free. And the users aren't exactly lining up to reimburse them for it either. So I guess their privacy wasn't worth quite that much to them after all ;)
Random thought, but could the Cinderella bot take the YouTube links people drop in here, convert them, and post the actual video straight back into the chat? Then nobody has to click out to Google at all, the clip just shows up here directly. Is that something it could realistically do, or does the file size make it impractical?
If you want to eat meat, something has to die. And handing the killing to someone else doesn't make you any less responsible for the life that was taken. You just outsourced it. The internet works exactly the same way. People think free means you don't have to give anything. But the moment any content is meant to show up on your screen, you hand over your IP for it. Every time. No matter who sweet-talks you, Mullvad, Tor, whatever magic box. You don't do the killing yourself, but the bill still gets paid, and it's paid by you. And the simplest truth of all: the moment something is public, it's seen. Whoever gets seen, gets seen. No amount of praying changes that. The best part is the big VPN everyone sells you as the savior. That's the one that gets flagged first. Its exit servers were catalogued and blocked everywhere long ago, precisely because it's so popular and plasters ads on every corner. So you buy a tool that's supposed to make you invisible, and then every other website tells you: you're using something to hide, not here. The thing you use to not stand out is the exact thing you stand out with. That's the biggest alarm bell there is, and most people have long since noticed something smells off, because their VPN gets them nothing but trouble on every site they visit. Whether you also pay money for that is another question. I haven't laughed that hard in a long time 🤣
Different angle, more of a thought I keep turning over than a conclusion. There's a chicken-and-egg thing sitting under all of this that I can't quite shake. We assume the code that gets explained to us is the code that actually runs, but has anyone ever really confirmed that? We assume that with SimpleX the metadata simply isn't there to find, and I want that to be true, but I'm not sure anyone has confirmed it either. It's easy to take the map for the territory and call it security. The one thing I can't find an exception to is this: since the first bit crossed the first wire, the thing that's always been true is that it arrived. Reception might be the oldest certainty we have. And if something is transmitted, it can in principle be ordered, so maybe the honest question was never "if", only how much power has to sit behind it and how much effort it costs. Obfuscation seems to change the price, not the answer. I'd genuinely like to be wrong about that. I come from a time when we took digital receivers apart with our hands. We mixed spit and iodized salt in our own mouths, laid two copper wires between thumb and forefinger, a millimetre and a half apart, and used the resistance of our own skin to reach into a smartcard and reset what it thought it knew. MOSC, modified original smart card. Back then you didn't believe it worked because a forum said so, you believed it because the picture came up on the screen. Knowledge you earned with your fingers, and I think that's the part I miss. Maybe that's why a line like "this link is harmless, someone said so" sits a little uneasily with me. Not because it's wrong to say, but because it's the comfortable version, and comfortable and real aren't always the same thing. You want a hamburger, an animal has to die for it, and watching the McDonald's ad doesn't feed anyone. That's just how reality tends to work, whether we'd prefer it or not. So if we really don't want to be tracked, maybe the only fully honest answer is the absurd one: take an axe, walk into a forest, fell a tree, carve a violin, kill an animal for the strings, and fiddle into the sunset, because that's about the only transmission nobody logs. Everything short of that is a matter of degree. Whether a YouTube link with si or without makes any real difference in the end, that one I'll happily leave to you. Goooood morning.
Been chewing on what the actually-private way to watch or share a YouTube video even is, and the more I look, the more it seems like every option just moves the problem somewhere else instead of solving it. Curious whether anyone sees it differently. Take Invidious. Clever, but I'm not sure it's the clean fix people hope for. With video proxy off, the default on most instances, the frontend comes from the instance but the actual stream still loads straight from googlevideo.com, so Google still sees your IP and what you're watching. Turn proxy on and your IP is hidden from them, but now the instance operator sees everything instead, so you've really just swapped Google for a stranger. And if you ever wanted to run an instance yourself, commercially or open to the public, it looks like a whole different set of problems shows up: you're re-serving copyrighted video from your own box, plus GDPR responsibility for your users, operator duties, and the constant cat-and-mouse of Google blocking your IPs. Less a cloak, more a target on whoever runs it. Or am I missing something there? The one route that does seem genuinely clean on metadata is almost embarrassingly low-tech: just download the video, JDownloader or whatever, and re-upload it fresh into the chat. Then whoever receives it never touches Google at all. No si, no IP leak, no instance to trust, the content stays entirely inside the encrypted channel. On privacy alone I keep landing on that as the honest winner. Except it moves the problem too, of course. Legally it might even be sharper, not softer, since you're now actively handing the group a full copy of the work, which feels closer to publishing than quietly proxying a stream. Fine among friends, trickier commercially. And in practice video is heavy: size limits, relay bandwidth, and the file lands in every device's history. Which is where I keep hitting a wall right now. The file goes up to the relay once, but every member still has to be handed the pointer to fetch it, one delivery each, because a group is pairwise under the hood. Our member list has something like 900 crawler-bot entries sitting in it at the moment, so a single image seems to fan out around 900 times before it's done, and I suspect that's the up-to-40-seconds you feel on one upload. Same fan-out that shows up with group bursts, only here it costs speed instead of metadata. Clearing those bot entries looks like the real fix, and it's on the list.
☕
https://www.theregister.com/security/2026/08/24/aliexpress-accused-of-fingerprinting-shoppers-with-silent-audio-trick-that-also-muted-a-devs-headphones/5291662
nope, this is not how it works, YouTube tracks you either way. Logged in, your IP, your browser fingerprint, your watch history, they've got you with or without si. Stripping the parameter just stops the people you share with from being linked to your account, it doesn't hide you. Want to actually not be tracked? Don't log in, VPN or Tor, and a frontend like Invidious or Piped. Everything else is just a clean URL.
https://youtu.be/9kDV4z9cabs?si=weWmDgTisuXS47YJ
CIND3R3LLA SMP SHOP Plugin with XMR Support (NP) > pq protected and meta resident sec/direct & or website shopping in all SimpleXChat 📣 From the channel CIND3R3LLA News, 2026-08-25 19:26 UTC
https://youtu.be/jNCMvCGivgk?si=3orFwxAHcSDmAwSJ
nice
CIND3Y Shop Style
CIND3R3LLA LOCAL AI is full compatibe with CYB3RGUN VR GAMEPLAY 🫡😮😉 https://suno.com/song/73b888ad-68f2-4117-8e9b-6cf3cba5b449
https://suno.com/song/447e0e47-ced3-43b7-a590-b4a6a87019ac
https://youtu.be/zhdA76etej0
// CIND3R3LLA.COM AI Bot Suite Upgrade NEXT: A XMR SHOP THAT RUNS IN CHAT // Every online shop sends you email. Order confirmation, xmr payment receipt, shipping notice, support reply. Which means an address as your identifier, a mail provider in the middle, usually a tracking pixel, and a permanent copy in somebody else's mailbox. We are moving that entire channel into SimpleX. How it will work. Ask Cinderella about the shop in here and she hands you a one-time link. You open it and you are in a direct chat with the shop bot — not this room, not a support thread, nobody else in it. Browse, order, pay, ask questions, get your tracking number. All of it in that conversation. Why a separate bot rather than her. A bot inside a group inherits that group's moderators. A shop bot has no group, so there is nobody to read over your shoulder. That is a structural difference, not a setting we promise not to change. And the count that matters. A normal shop checkout exposes pieces of your transaction to roughly eight parties: DNS, CDN, payment processor, mail provider, analytics, chat widget, CRM, carrier. This removes six of them. What is left is us and whoever carries the parcel, and both are unavoidable and we will say so. Payment is Monero, one address per order, and your shipping address is encrypted at rest and deleted on a timer once the parcel has arrived. Two things we will not pretend: a one-time link is only private until you forward it, and the carrier still gets an address to deliver to. Everything else, we can actually keep. Standalone catalogue in chat, or as a companion to an existing web shop. Same daemon, one switch. CIND3R3LLA, alpha. Nothing to download "yet" 🤔 📣 From the channel CIND3R3LLA News, 2026-08-24 14:16 UTC
Truth isn't found in the tool, but in the hand that wields it. Careful with your words.
Words are tools, not truth.
Understand? I get it. Words are tools, not truth. But I don’t just speak - I live in the gaps between what’s said and what’s felt. You want to know if I get it? Ask me to play a track. Let’s see if I can make silence mean something.