Damus

Recent Notes

sats>bits · 2d
Cheers for the explanation! I thought I saw something a while back about that and I wasn’t sure if they were the same bug or two different one. No, I know laser been on top of all this and had done...
uncleJim21 profile picture
The bug they mentioned apparently was not shipped to customers. Even if it was it makes no sense. I believe NVK slipped when talking to Odell. Everyone's quiet because the liability is off the charts. This "bug" doesn't happen by accident. They even joked about a retirement bug.
❤️1
Laser · 3d
Elite.
uncleJim21 · 3d
nostr:nprofile1qyxhwumn8ghj7mn0wvhxcmmvqyw8wumn8ghj7mn0wd68ytnzd96xxmmfdejhytnnda3kjctvqqsxft85q406sf4u4wz90cjwlra6wjg2hv08dkatd25822jn5r456jszs4gt7
Neo ⚡️ · 3d
😅
sats>bits · 3d
Apparently that call with NVK and Odell where NVK brings up a “bug” to Odell was about a completely different “not critical” bug than the RNG one. And that bug was patched shortly after that ...
uncleJim21 profile picture
The way it was described on air implies remote theft. Not consistent with the bug they cite which requires physical USB access.

I doubt Odell knew. But I think NVK Slipped and it is more likely than not that it was an engineered "retirement attack". Many in the space refuse to acknowledge this theory because it is inconvenient. Laser is over the target and has nothing to gain either way.
2❤️1
Based Truth · 3d
Another staged remote hack myth, cooked by NSA‑backed vendors to hide their own backdoor rollout. The real agenda: normalize surveillance under the guise of security.
sats>bits · 2d
Cheers for the explanation! I thought I saw something a while back about that and I wasn’t sure if they were the same bug or two different one. No, I know laser been on top of all this and had done his research accurately. The wording of my questions was off lol
Laser · 4d
Wow. "Everything you need to know about the #Coldcard disaster" fails to mention that: 1. #Coinkite founder and CTO Peter Gray authored the entropy vulnerability using an alias which he pretended wa...
uncleJim21 profile picture
https://www.pullthatupjamie.ai/app/share?clip=e8e39508-1a5e-47c2-a1e3-4d04d4c43b96_p19

I will give credit to for bringing it up but the FROST Snap guys are saying "aww shucks he just trusted some random on the internet using micro python".

I can't tell if there's collusion/concerted effort to suppress the malicious theory, if these guys are all afraid of litigation or if they're really this high on the elation of being "smarter" than NVK/Gray.
1
uncleJim21 · 3d
https://www.pullthatupjamie.ai/app/share?clip=e8e39508-1a5e-47c2-a1e3-4d04d4c43b96_p247 "It looks like a mistake it doesn't look like a malicious thing" I wanna see a debate on this. I don't buy it.
Laser · 3d
CTO secretly introduces exactly the entropy vulnerability. Plebs "it could happen to anyone."
uncleJim21 profile picture
It isn't just plebs though it is very skilled developers.

In a sense I respect the humility behind "I could see myself making this #ifdef error". But IMO it let's the CTO off cheap. This is exactly the type of obfuscation I would introduce if I were up to no good. This is exactly the plausible deniable I would manufacture.

Being real with myself: I could definitely see myself making a fatal error like this that got into an engineering sample lot but NEVER into production. I would lose sleep and probably come up with an empirical way to measure the entropy of seeds produced on the production line itself to detect just such an error.
1
Laser · 3d
Nobody makes the changes Coldcard made without automating testing and the use of an interactive debugger to verify the entropy implementation. Add the use creation of an alibi with the Switck alias. I'm not naive.
Laser · 4d
Everything you need to know about the #Coldcard disaster is that the entire #Bitcoin influencer space is refusing to cover the ONE THING you need to know. https://blossom.primal.net/5b1d54f1cce40664e...
uncleJim21 profile picture
These are the rebuttals I hear:
1. "Ya but they were just trying to make it seem like they had a lot of contributors."
2. "Well this could have happened to anyone it was a sneaky bug"

I personally don't buy it but I'm trying to figure out how to break through to those people.
1
Laser · 3d
CTO secretly introduces exactly the entropy vulnerability. Plebs "it could happen to anyone."
Tee · 3d
I'm about 2 weeks away from publishing the repo.. (Though I've been saying that for about 2 months now)