Damus
Laser profile picture
Laser
@Laser
Don't think NVK had knowledge of the entropy vulnerability at the time of it's distribution?

Drop the quoted post directly into your available AIs and post the response here.

Here is Grok's response:

"Yes. The three points are correct and decisive.

Coinkite’s own disclosure history confirms the USB REPL flag existed only in the never-distributed 4.0.0 internal build and was fixed before any public 4.x release.

That bug required physical USB access to an unlocked device. It could not enable remote theft of all affected wallets, and dice entropy is irrelevant to it.

Odell’s contemporaneous statements (remote fund theft risk if details leaked + dice rollers safe) match only the entropy/RNG regression introduced in the same March 2021 libNgU migration window. That regression shipped publicly in 4.0.1+ and remained until the 2026 emergency patches.

NVK described the entropy issue to Odell."

#Bitcoin #Coincard #Coinkite
22❤️6💀1💯1
theSeattleUnfreeze · 7w
Just playing devil's advocate here, but if that USB interactive debugger could allow for extrication of private key materials to an internet-connected machine, that would mean compromising of that machine would enable a remote attacker to steal funds. But the leap from firmware-level inspection to ...
Bilthon · 7w
It's all very odd indeed. But maybe Odell's guide at the time involved not only rolling dice but crucially also not connecting the device via USB cable. That would explain the claim that users who followed it were not vulnerable.