Damus
Satoshi Coffee Co. · 4w
Wow. Runs
ben · 4w
wow. i dont write code that sloppily for my side projects, let alone at work, let alone on software this critical. “runs” unbelievable.
thepurpose · 4w
Not to justify things, but this was in front of everyone's eyes for 5 years. Therefore I assume: a) nobody looked at it, b) some looked at it and didn't bother to further investigate, c) some looked at it, investigated, and the findings were quietly buried. I.e., it was known but inconvenient to ac...
9x9 Bertha Returns · 4w
https://primal.net/e/nevent1qqsdvndzsa9tgr7vur4uweqahs8l5xvfd49s80a20l0p7rjs8qeg29csyw07x
Vincent Anton · 4w
This is troubling: From here, I assume in a bout of frustration, he set `MICROPY_HW_ENABLE_RNG` to 0, which would have resolved the compiler error.
AncapAnon - Activate OP_GFY now! · 4w
We were all trusting that someone had verified. Meanwhile, the whole thing was a clown car built by the intern who knew how to write Python but not C.
OzzyHB · 4w
Brutal.
roundtheworldman · 4w
I read the entire article. My first pass opinion: Hardware Wallet Co's should not even be using hardware that offers a low / fake entropy option to a C Programmer. Use the correct entropy source or your compile fails. There should be no "fallback" option, e.g. yasmarang or whatever.
zaytun · 4w
What I dont understand is, in an industry so focused on security, how did this go unnoticed? I mean, it looks to me like basic software engineering principles were neglected, so why was that not noticed? It might very well be that its a "hindsight is 20/20" kind of thing, but it just doesnt seem li...