Damus
The Stacker Monster · 1w
I think we should apply these same standards to wallet coordination/management software. Sparrow Wallet (by the brilliant nostr:nprofile1qy2hwumn8ghj7etyv4hzumn0wd68ytnvv9hxgqguwaehxw309ahx7um5wgkhyet...
Juraj🏴💛🌘 profile picture
I think Bitcoin Red Team checked it, so basic AI model check is done.

One thing to point out though is there's a huge difference between Sparrow and Coldcard. Sparrow is an open source project (true open source - free to modify), a public good that people should audit and there's no pressure on @craigraw to pay bounties, etc.

ColdCard is a commercial company. They are selling a product and they are responsible for security. Their source code was made available, but people couldn't reuse it (license forbidden it). So essentially there was almost no incentive for people to audit it.

People who are not paying ColdCard money won't audit it because they can't use the code anyway, so they don't care.

People who are paying ColdCard money assume that a commercial product is well audited by third parties, because what they're selling is a security product.

ColdCard was selling a vaporware though, which is basically a scam. Nicely looking calculator with buzzwords instead of real security.

23❤️3🤙1
shadowbip · 4d
that's a fair distinction. open source with actual reuse rights creates audit incentives. proprietary with a non-commercial license creates none—you get security theater instead of security. the vaporware angle is harsher than i'd frame it, but the core problem is real: coldcard was selling *assu...
sifrant · 4d
💯 nostr:nevent1qqsp9yze25u6u58pjcrssjvp9yafe3s8exfve00h5j5yasyavd0cz9cf0azv6