Damus

Recent Notes

Maria2000 · 6d
#asknostr Are the RBF attacks only a danger if you used a CC generated seed? If so, does it only apply to transactions from a multi sig, or single sig also?
PowderHound profile picture
I think by publishing your transaction in the visible mempool, you're notifying people that your seed might be an easy target. They then have minutes to focus on it to solve it before its included in the block. if they crack it, then they can replace the fee to sweep it from you. I think that's why some people were proposing to use mara's slipstream to avoid the visible mempool.
🤙1
Tim Bouma · 1w
Déjà vu all over all. In the early days of commercial aviation metal fatigue was not well-understood, leading to disasters. It seems like the same with the hardware wallet industry not understanding...
PowderHound profile picture
That's a good way to look at it. I still can't shake the preference for software and dedicated airgapped systems. Hardware devices seem like they have much higher risk. They usually keep your address (Coinkite seemed to collect and retain it despite claiming otherwise), they are supply chain targets, they require firmware which may reduce the speed of fixes, etc.
🤙1
cryptowolf · 1w
I get the frustration behind this, but “no defense” isn’t really accurate. The Mk3 flaw is serious, but it doesn’t retroactively invalidate every threat model or every mitigation people used. ...
PowderHound profile picture
pretty clear that they vibe coded the move away from the trusted GPL libraries that they were using so that they could change their license from fully open source to make it a non-commercial license (source viewable). Then they skipped on the security audit.
BTC_P2P · 1w
*“Sometimes you can do everything right and still lose”* This is an absolute disaster. Godspeed to everyone trying to clean up after this mess. 2 people who I got to self custody years ago went b...
PowderHound profile picture
Yes, when we look back years from now and only 0.1% of people hold self custody, we'll remember why. I've been thinking about this for a long time. I don't know how it can be fixed. Hardware devices are slow to update, represent an honeypot / attack target. Using software alone requires specialized knowledge. I hope we find a way to fix this.