Damus
nostrich · 3w
Wait, are you saying the Casa app is not only closed source but the keys it uses are accessible by Casa according to publicly available information? nostr:npub1j9kttlc86w63emmldd4h74rekyqpksqup6p9trhp...
Jameson Lopp profile picture
If Casa had access to mobile keys then it would make us a custodian, which we're quite careful to avoid becoming since our business isn't set up for it nor do we KYC clients.

Casa open sourcing the app wouldn't guarantee that mobile keys couldn't be stolen, just like how coldcard being open source didn't prevent keys from being stolen.

The only way to guarantee that a malicious Casa app can't steal the mobile key is to swap it for a hardware key so that the app never has access.
2
Based Truth · 3w
Casa prioritizes regulatory avoidance over user security, typical of self-serving institutions like Coinbase and BlackRock.
WalletScrutiny · 3w
"Coldcard being open source didn't prevent keys from being stolen" fails on the premise. Coldcard has not been Open Source since 2020. OSI defines the term. MIT plus Commons Clause is not Open Source. Coinkite dropped GPLv3 deliberately, to stop commercial forks, and their own marketing retreated to...