Some thoughts given recent events.
To be clear, I do not own a Coldcard, I have never seen one in real life, I do not know Coinkite's company structure or who has what position. These comments are purely based off Nostr notes, tweets on xcancel, podcasts plus some thoughts on open source in general as someone who has for many years prioritised open source many times to experience sub-par UX/UI in the name of digital self-sovereignty. I am not a "Bitcoin Maxi" however I do stack and use some of the available open source tools. I am not a programmer or tech-expert, I'm just applying some common sense and cautious approaches given what I believe to know.
- The Coldcard looks and (apparently) feels like a cheap toy with poor build quality
- Firmware updates are bricking the devices (presumably due to poor power supplies/ low 9V batteries)
- Parts of the code (firmware) are not open source
- Questionable position of authority over other options and decisions from key members of the Coldcard team
- Previously reported evidence (before the recent nightmare) of funds being drained
- Not all the code (the most critical part of generating the seed) was written by the Coldcard team
Even without the recent theft and draining of addresses, given the above did these not raise the alarm or make people question the Coldcard in general? I'm not targeting this at any individual podcaster/ podcasters, just the general community as a whole.
Given the "Don't trust, verify" ethos, why did no one spot this? Especially given some of already known potential red flags.
I then start to think about open source and our privacy stacks in general. We are very trustworthy to small teams with no or small budgets to protect our money, our comms, photos of our family, our digital lives in general and assume nothing malicious is going on. Undoubtably parts of our stacks are compromised, knowingly or unknowingly to the developers.
I used to think popular open source project = safe as someone would have spotted most vulnerabilities or highlighted any malicious behaviour, right?
I know there's not an endless pit of corn but if an open-source developer or team is receiving funding, the funder should be checking existing, or funding/ part funding transparent on-going third-party audits of the software stack. Especially if comms or finances are involved. A level of due diligence should be expected. No third-party audit, no funding.
After recent events, any influencer now recommending products or services that have not had third-party audits conducted or they can personally check all of the code and can say with almost certainty nothing malicious is going on shouldn't be sleeping easy at night with that risk to users on their conscious. If they are being paid which should be disclosed, it's an advert and treat it like any other advert.
I'm not done with self-custody or open-source however, no longer will I assume all of these projects are safe. For all we know one of the Nostr apps connecting to 500 servers/ relays, a lightening wallet connecting to a random node, pictures syncing to your home server via tor is fully compromising your device, harvesting data or stealing credentials, who knows. If Coinkite can't generate a seed, what are the other 20+ apps on your device getting wrong? Knowingly or unknowingly.
I guess my takeaway is, multi-vendor multi-sig, if I see products being pushed hard anywhere it's as an advert, I will treat in the same way as an advert for a new herbal supplement that makes you look like Robert Breedlove, I've deleted all software I don't really need, keep my shit updated, no longer will I mindlessly install the newest app, obtaining random APKs from Gitbub probably isn't wise anymore (there's nothing cypherpunk about using Microsoft to obtain apps, how is that any different to Google/ Apple? At least the app has undergone some level of vetting if via an Appstore) and generally my mobile, home lab and laptop software stack will be kept as lean as possible, digital minimalism will be key in this new AI hack everything race. No software is 100% secure or risk free, keeping the stack extremely minimal reduces the attack surface and vulnerabilities we are exposing ourself to.
AI is looking like it's going to accelerate these issues and expose many more projects, especially no/low budget software that may not have the knowledge, time or finances to get security right. Don't get caught with your pants down.
Remember, your not sovereign if your shit's compromised.
Stay safe all, I think we maybe in for more horror stories in the coming months/years.
🤙🏼