Damus
mobiusmoe profile picture
mobiusmoe
@mobiusmoe

w/e
sue me
(but only if it's payable in BTC)

Relays (12)
  • wss://feeds.nostr.band/ – read & write
  • wss://librerelay.aaroniumii.com/ – read & write
  • wss://nostr.gleeze.com/ – read & write
  • wss://relay.damus.io/ – read & write
  • wss://relay.notoshi.win/ – read & write
  • wss://relay.primal.net/ – read & write
  • wss://puravida.nostr.land – read & write
  • wss://eden.nostr.land – read & write
  • wss://nos.lol – read & write
  • wss://nostr.wine – read & write
  • wss://offchain.pub – read & write
  • wss://relay.snort.social – read & write

Recent Notes

3mily · 4w
Courtesy note - you are engaging with yourself only 🧡
syntaxerrs · 4w
What I thought too.
CptKook · 4w
There was no weak entropy fallback. Stop giving air time to air head feds. The weak PRNG (Yasmarang) wasn’t Coinkite’s fallback. It’s MicroPython’s built-in general-purpose RNG — introduced ...
mobiusmoe profile picture
If this is true, it does open the door to gross negligence being the cause again for me. Before reading this it had started to look more & more like a potential long-range exit scam that got uncovered by kimi3 ahead of time.

I think it would be interesting to find out if relatively small amounts of bitcoin had been regularly swept through this mechanism over the 5 years the bug existed.
❤️2
protozoan numbness · 4w
So it's their job to take care of you?
mobiusmoe profile picture
It is their job to make maximum effort to ensure as many of the tens of thousands of people they recommended Coldcard to were aware of the urgent, time critical catastrophic bug.

All I am saying is not broadcasting an emergency message on ALL the mass audience channels on which they promoted, what turned out to be, an exit scam, is a serious gap.

If there is a family out there who, like me, heard about Coldcard on RHR, still listen to those podcasts but do not monitor x or nostr constantly, and are now wrecked FOREVER, are you going to throw that barb at them?

It's reductive reasoning. Their job was to get the message out on all of their mass audience channels urgently & not to risk leaving a whole group of their audience exposed for 5 days.

I am sympathetic to their situation & human experience, which is horrible, but I think they might easily have saved more people with minimal effort & they should be called out on this so they can reflect & learn.

My anger at being left exposed by them has faded, but if I had been wrecked while I was exposed, I do not think I would be okay with it. Would you be?

We are just talking about posting a 5 minute video / pod over a 5 day period. @Rob Hamilton was helping people too after being warned by @HODL , but he still went out like a warrior & appeared on as many podcasts as he could in a time critical way to warn as many people as possible.

This is how I found out & I am forever grateful for that.

Fark, as soon as I found out I stopped & thought, who have I mentioned Coldcard to and how can I ensure they are warned. I phoned that one person in the first five minutes & didn't wait five days.

Not good enough, and I stand by it. I am just saying this needs to be reflected on & learned from.

This is what best practice looks like:

mobiusmoe profile picture
When I think of the longer-term implications of the Coldcard entropy bug, I find myself coming back & thinking about the basic fundamental security stack protecting my bitcoin.

1 - can I generate a true 256 bit seedphrase?

2 - if I have a true 256 bit seedphrase which has never been exposed, is it impossible for that seedphrase to be found?

3 - does the open source technology stack I use for signing transactions, generating addresses, etc ensure my seedphrase is never leaked so I can rely on 2 above?

4 - does the open source security model provide sufficient security so I can rely on 3 above?

5 - can I personally & continuously verify 3 & 4 above?

This is a cascading security framework & the failure of any item can lead to the total loss of funds.

The only item I can currently be certain of is item 1. We know that item 2 will eventually flip to a "no", unless a new signature scheme is implemented.

While I understand the Coldcard entropy bug related to item 1, given the catastrophic bug was hiding in plain sight & lot of people who have the skills to identify it had a large financial incentive to find it but didn't, I find myself spending a lot of time thinking about items 3 & 4.

Can I ever rely on these? Currently the answer is use "multi-vendor signing devices to diversify the risk", but it seems to me that many of these projects rely on common libraries, shared code, etc. True diversification does not seem possible & this approach does not meet the requirement for items 4 & 5.

In the immediate term, if I am signing transactions with an air-gaped device via qr code, is it possible to have an independent software stack that can scan the qr code and ensure my signing software has not emended my private key into the qr code. I do not know if this is technically possible, but I would very much like that missing piece of independent software in my stack as a backstop to items 4 & 5 not being able to ensure item 3.

Following this, I would very much like item 2 to be addressed as soon as there is a good chance it will fail at some point.

When I think about the victims of this disaster, I also find myself thinking about my exposure to item 3 and the failure of item 4 to enable reliance on it ... not sure where that leaves me & all of us?
4
Aldocstr · 4w
Looking into this as well, been an eye opener to see how everything can fall apart in an instant. Solid custody and security to simplify yet protect holdings
Chris · 4w
Strive for Clarity. Not Certainty. Certainty is an illusion. A trick of the intellectual (left brained) mind to keep chasing its own tail until it literally drives itself mad. 🫶😌🙏🏻
Chris · 4w
Paradoxically, all those questions are indeed the right questions. In my opinion…..