Damus

Recent Notes

gladstein · 2d
Initial reflections on the Coldcard catastrophe, the bitcoin-only approach, and financial freedom: 1) Many people, me included, trusted and recommended Coldcard more than we should have. Especially a...
AENEAS profile picture
There were known cognitive biases at play here, all throughout the Bitcoin space. Everyone in their inner heart (yes Shogun reference) wants to paint themselves as the intelligent know-it-all, but it's necessary—and actually perfectly okay—to recognize that you, me, the other normies in these comments and across Nostr, are all inclined to be retarded.

1. Red flags have to be 'flagged' 🚩when they happen in advance, not remembered after the fact like "Ah I felt there was something off about that."

2. We can't afford a cool kids table that's above criticism. Fiat sponsorships can distort incentives.

3. We need to troll each other more and give each other a little more shit—not because we're assholes, but because we're probing for weakness and we care.

4. Influencers need qualifications. I don't necessarily mean academic, but mother fucker, if you're talking authoritatively about seed generation I want to know what you know about cryptography, right?

5. It's useless for someone to beat themselves up (too much) because "I recommended a Coldcard 😔." It did good things (integrating physical entropy into its seed generation is legitimately good) that can be used again in the future. Nobody knew about the PRNG bug.

6. This 👆is what needs to be focused on more. The PRNG bug is not some hyper obscure bug only Skynet could have found, and people have been complaining online about Coldcard sweeps for years without garnering attention because it was assumed they were just stupid. It only got attention because someone Pearl Harbored everyone with a Coldcard at once.

7. Sure as sally, all of these problems are still affecting the network. We have to take stock and think about what we're doing, right now, that we don't recognize that we're doing, that can lead to yet another avoidable disaster. It sure as shit is not arguing on Twitter about muh quantum.
112❤️18❤️2💯2👍1👏1🚀1
Gigi · 2d
Well said.
Justin (shocknet) ⚡ · 2d
Yea it's being abused by a scammer that doesn't want people to know the truth, k00b is fixing it: https://stacker.news/items/1539032/r/justin_shocknet?commentId=1539392
Car · 2d
ya not surprisingly it was hated on by NVK last year, so even more reason to use it, compliments nostr very well and is a filter for X
Vitor Pamplona · 2d
We spent the last year panicking about quantum computers with 100,000 qubits breaking SHA-256 in 2035… only to get wiped out in 2026 by a C macro that forgot to roll the fucking dice.
AENEAS profile picture
Most of your worries are total bullshit, and you're blind to the real threats. Everyone needs to learn this.

Zoom out and think about the biggest things you spent worrying about in any given year. Usually they were news stories put in your face by some algorithm and amplified by the usual retards.

Compare that list with the things that ACTUALLY hurt you. I will bet anything that the things you worried about were mostly phantoms, whereas the things that truly fucked you, you never saw coming at all.

LiveJazz · 3d
I’m not familiar with the technicalities of paraphrases, but it seems like 2 words wouldn’t do much if the seed is already cracked, right? It might be a tailgate in case of duress, but not an extr...
AENEAS profile picture
Yea, once the seed is exposed, the passphrase is the last line. It has to, all by itself, furnish the entropy to keep the baddies out, so it has to be a strong password/phrase in and of itself.

Most people don't think it'll ever come to that, so their passphrases are normie stuff like "My dog Smith" or whatever.
❤️1
scl · 3d
How much risk is a tezor, or any wallet, without a passphrase? It seems like that risk has gone up quite dramatically
AENEAS profile picture
It may "seem" the risk has gone up dramatically, but mathematically, it hasn't. A seed phrase properly generated is as secure as it's always been.

Coldcard's seeds were NOT properly generated since at least 2021, but people thought they were. That illusion exploded dramatically, so that's why it seems like the risk has gone up.

What we should really explore is how that illusion was created and cultivated for so long. SJWs can afford to have illusions and "identify as a cat," but we can't afford to only identify as cryptographically secure!
Softer Skin | Tallow Based Skincare · 4d
Has this been 10000% confirmed? Is Dice input into coldcard + 2/3 multisig (Coldcard only) safe? 😟😟
AENEAS profile picture
Yes because that's how the math works. For the victims, who relied only on the hardware itself—which was coded idiotically and had an obvious bug in it—Coldcard never generated generated a truly random seed phrase at all. What they got was marginally better than inventing your own seed phrase in your head, and with the same predictable end result of someone recreating their easily guessable key.

But the people you're talking about DIYed their own randomization using dice and the BIP word list. This is not the same thing at all; they didn't rely on Coldkite's shitty code.
The Bird · 4d
So my 185 dice rolls will cover it lol?
Jay · 4d
Zero. Always has been
Clayton · 4d
The best of the best didn’t know this vulnerability existed yet every bitcoiner should have known better
AENEAS profile picture
Well, there *is* a significant subset of bitcoiners who've long complained about the overemphasis on HWWs, who view them as security theater, but:

* They don't really do podcasts
* They're not exactly on YouTube
* They tend to be seen as assholes. Which isn't unfounded, some of them really are assholes.

I like HWWs and think they're good for adoption, but it is true they're treated like a sacred, unimpeachable vault in this space; many incorrectly think you 'need' them to secure your Bitcoin.