Damus
Dr. Hax profile picture
Dr. Hax
@Dr. Hax

Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-)

Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet

Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle.

XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu

Relays (6)
  • wss://nos.lol/ – read & write
  • wss://nostr.mom/ – read & write
  • wss://nostr-pub.wellorder.net/ – read & write
  • wss://bitcoiner.social/ – write
  • wss://relay.ditto.pub/ – read & write
  • wss://relay.mostr.pub/ – read

Recent Notes

Kidwarp’s Vanilla Shop · 8h
Very doubtful
Dr. Hax profile picture
These blokes are making some very bold claims, mainly about how easy it is to set up and use...

https://blackbox.host/

Well, I might just have to put that to the test. And if I do, I'm going to write a brutally honest review. Uninvited. Unauthorized. And most certainly unpaid.

I'll try to get it done before the 2600 meeting.
Dr. The Daniel 🖖 · 20h
I thought so, that’s why I built it.
Camillo≋ · 1d
At the time on stacker news, I remember reading a tweet from Kevin Loaec. https://stacker.news/items/1536238
Dr. Hax profile picture
To those who advocated for Coldcard:

1. Don't beat yourself up too much
2. Disclose if you're being paid for the things you recommend (if you didn't already)
3. Disclose whether you've personally analyzed/audited the product and if not, where the basis for your recomendation comes from
4. If you're not being paid to advertise their product, consider advocating for community projects. Things that are open source hardware, where the community can actually modify the design. Bonus points if there are multiple groups building the hardware.

None of this guarantees you won't ever regret something you recommend, but it provides more transparency and gets you to think about the incentives for building these things and whether they are monetary or not.
1
Bud · 1d
5. Do you have a significant amount, to you, of your own money kept on this set up you are advocating, or not?
average_gary · 1d
I have suffered from a severe mistaken identity over similar names... Plz forgive me.
Dr. Hax profile picture
If a project claims to be open hardware they should publish their eCAD files (likely a set of KiCAD files).

This is what is required to make modifications, which is the very foundation of open source. Gerber files are generated from eCAD files just like binaries are generates from source code.

The Open Source Hardware Association would never certify a project that only published gerbers.

I consider it dishonest to advertise gerbers-only projects as #OpenHardware. In some ways it's worse than the proprietary hardware vendors calling themselves open source companies.

I want people to know what to look for and to be able separate the companies who are role playing as open hardware from the projects that are living it.

You don't have to choose open hardware, but you should know what you're getting.

This post has nothing to do with ColdCard other than that people might be shopping for new hardware right now.
1
AU9913 · 2d
We can't even get half of the vendors on nostr who's entire businesses rely on bitcoin and nostr to open source their recipes.
Brunswick · 2d
Security - meets in Vegas Not good opsec
Brunswick · 3d
Why would I go there?
Brunswick · 4d
One can get a reasonable code audit performed on the nostr:nprofile1qqs09jtvjlmyrxjn37zv70a89csegcz7rpyqjmnw29cveedhv7vagqqpzemhxue69uhk2er9dchxummnw3ezumrpdejz7qg4waehxw309aex2mrp0yhxgctdw4eju6t09uq3...
Dr. Hax profile picture
SeedSigner is interesting because they kinda roll their own O/S. I feel like in order to trust the results, you'll need someone who has the ability to reverse engineer binaries, which isn't a skill that most code auditing firms have.

I'd suggest a hybrid team. The code auditors with cryptography experience that everyone expects, and also some people to make sure the tooling that generates the image is trustworthy. The latter requires someone who can look at the binary and at least account for where all the machine code came from.

I'm not sure this affects the total cost of the project. Your estimate of hours seems high to me. Not every line of code is security-critical.
Dr. Hax profile picture
I feel for these folks who bought coldcards.

Trust in that company has been completely shattered. People expected that buying a closed source hardware product would be run by people who would invest in audits of their firmware and the libraries on which they depend. That's a reasonable expectation, even if it is based on trust instead of verification.

On the flip side, there's open hardware projects like seedsigner and trezor, where it's well known that they're not raking in the money needed to fund a serious audit. Because they are expensive. There aren't a lot of people who can say "yeah, the code looks good" and have that be taken as evidence that the code is vulnerability-free. Their time is valuable.

There aren't any magic answers here. Sure, it's easy for armchair analysts with the benefit of hindsight to say now what people could have done differently. It's a different thing entirely to put in the work to change the game.