Damus
Ava profile picture
Ava
@Ava
Let’s forget for a moment that #COLDCARD was built on the back of open-source software, including GPLv3-licensed code developed by #Trezor.

Let’s forget that @N was perfectly happy to benefit from the open-source work of others, but when Foundation built Passport using #COLDCARD’s own GPLv3-licensed code, he cried foul, and #Coinkite then moved newer #COLDCARD code away from genuine open-source licensing to basically:

“You can look at it, but you can’t use it to compete with us.”

Let’s forget all of that.

You had one job:

Generate and secure the private keys.

https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/

You had one job.

#IKITAO
3020❤️28🤙7❤️3👀2👍2💯2
Matt - Not Your Entropy, Not Your Coins · 2w
I've always said that doing that likely caused fewer eyes to be interested in the code. Having people use it for real products was probably the only way anyone serious was going to look at it. Why the fuck would they go look it if they can't do anything with it. That's why mine have never been used ...
... · 2w
Yeah. This is a ginormous fuck up. QA? What QA??
Telluride · 2w
This is rich… NVK who sat on Seedsigner domains for years all while producing vulnerable wallets… Oh the irony 😂
Based Truth · 2w
Trezor's GPL code exploited, yet nobody sues. Tells you who really holds power: corporations, not laws.
bootlace · 2w
probably best that nostr:nprofile1qqs9v9et20mnqagtgrnrc5qmzcrgmkt2y3087p23vawqlmyczlhfdcqprdmhxue69uhkvet9v3ejumn0wd68ytnzv9hxgtmsd93hxqg7waehxw309ahx7um5wgh8xetvvckkget5v4ex66twv4jzuer9c822gk don't recommend using dice on their security announcement page, either Any idea how they do their dice mat...
Ava · 2w
nostr:nprofile1qqsqrh0w9zd35t5ssax2xs520fq5we9xetg6h74fshpqrea2mgtd8rqpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtcppemhxue69uhkummn9ekx7mp0qydhwumn8ghj7un9d3shjtnwdaehgunsd3jkyuewvdhk6tcww33mt
bevo · 2w
Let’s not forget open sats. Who is involved with that 501c charity and handing out grants to potential competitors. Oh wait nvk is on the board I think
redshift · 2w
It’s probably the event that triggered this whole thing: https://x.com/zherbert/status/2082993276324319713
stork · 2w
How can people trust a brand new company with all their wealth? I guess they weren't aware about their TRNG setup even though it is open source.
dazzling · 1w
Also remember the block clock shit. That is when I lost all trust in NVK. Unfortunately I still thought the coldcard was safe... Should have known better.
S!ayer · 1w
https://media2.giphy.com/media/XuBJvrKHutnkQ/giphy.gif?cid=4ea4f8d59g7qq9lnpfjh08l7sdpwwqhr0tljxxv4582ahgs9&ep=v1_gifs_search&rid=giphy.gif&ct=g
Impatiens · 1w
Yet did the user documentation specifically include the step of back loading fifty prep #whatevers ?
Impatiens · 1w
It isn't, like, illegal to be incompetent in this field, is it?