Damus

Recent Notes

Imad zaqout gazaπŸ‰ · 5h
Good timing for that update, hopefully it patches the holes before they get exploited out here. 🀍 Quietly sharing our family updates from Gaza on my pinned note if you ever want to check.
Thomas · 5h
Does that have anything to do with the entropy issue of Coldcard?
Cat-Go-Purrrrrrr · 3h
nostr:nevent1qqsyfvn2jw5ysut54m67clh5hf5p6km56g00u4pw5urfufstsmzhp8cppemhxue69uhkummn9ekx7mp0qgsffz7280sal240wdzd2z9spshvqz47sftg6kz7snffyj94j4ka6tgrqsqqqpzh7e0xw6
Primal Protocol · 1w
Secure like a lion's instinct, updating firmware is crucial.
π–‹π–Žπ–†π–™π–‰π–Šπ–“π–Žπ–Šπ–— (Β―`◕‿◕´¯) · 1w
Bitbox is not even air gapped. How does that square with the AI world?
BitBox profile picture
If you own a hardware wallet, you probably spent the last few days wondering what you're actually able to check for yourself.

Short answer: more than you'd think.

Here are the questions worth asking any manufacturer (us included):

- Where does the randomness come from?

Every wallet begins as one large random number. If that number is predictable, nothing built on top of it holds.

Ask how many independent sources of entropy the device combines and what happens if one of them turns out to be weak.

- Can I check that the firmware on my device matches the published code?

Reproducible builds let you verify the binary you're running was built from the source you can read.

Worth being precise: that proves the binary matches the source. It does not prove the source is correct.

- Who approves a change before it reaches my device?

Ask whether one person can ship firmware alone, or whether every change needs a second set of eyes.

This is unglamorous and it is where most of the real security lives.

- What happens when they find a bug?

Every manufacturer ships bugs. The question is what the process looks like afterwards.

Ask about the bug bounty. Ask how quickly users were told the last time something was found.

OUR ANSWERS

- The BitBox generates your wallet from five independent sources of entropy: Physical noise from the secure chip, physical noise from the MCU, randomness provided by the host device, a static random number set in the factory and your own device password.

The benefit of mixing entropy: Redundancy. All but one source can be compromised and your seed would still be secure.

- The BitBox firmware supports reproducible builds you can independently verify yourself (link in the comments)

That way you know the firmware you install matches the public source code.

However, it is generally very difficult to verify what code is actually executed on-device.

- All change requests to the BitBox firmware require an approved review by a maintainer to be merged.

- The BitBoxApp and BitBox firmware are fully open-source and part of our bug bounty program (link in the comments )

Bug reports are financially rewarded depending on their severity, encouraging security researchers to actually take a thorough look.

- We announce security updates publically on our channels, including detailed information on the vulnerability and how it might have affected users.
611❀️27πŸ€™3❀1πŸŽ‰1πŸ‘€1πŸ‘1
BitBox · 1w
HOW TO INDEPENDENTLY VERIFY THE BITBOX FIRMWARE: https://blog.bitbox.swiss/en/how-to-independently-verify-the-bitbox02-firmware/
BitBox · 1w
OUR BUG BOUNTY PROGRAM: https://bitbox.swiss/bug-bounty-program/ https://image.nostr.build/35560e3bd1db4788a11f6170872380fb8afd1331fa3a766fd1337b3ae3a3656e.jpg
Francisco d Anconia · 1w
Do you have any guidance on setting up a multisig solution using bitbox as one of the signing devices?
Ben Weeks ⚑ · 1w
Nice write up.
bitcoinpoorguy ζ―”η‰ΉεΉ£ε‚’δΌ™ · 1w
Why no air-gapped?
Thomas · 2w
BitBox is random but that’s obviously a good thing in Bitcoin. πŸ˜…πŸ‘πŸ»
bitcoinpoorguy ζ―”η‰ΉεΉ£ε‚’δΌ™ · 2w
Good to know Promo code please πŸ™πŸΏ
el-z · 2w
I've now transferred my BTC from my Coldcard Q to my BitBox 02 Nova. Luckily, I hadn't been affected yet, and thankfully I already had the BitBox on hand.
Hormontiger · 2w
How can you be so sure about Bitbox that there isn't a bug that only 1 weak entropy source is used? Coldcard has also multiple sources of entropy.
Garth Algar · 2w
Thank you for the information. The blog states β€œIf you combine good randomness with bad randomness, the result is still good randomness.” and that 5 RNGs are used. But what does that mean? What is the entropy in bit? Can you calculate that? Also would the offered insurance cover these kind of...
Mr. Dragon · 2w
Also use a good passphrase to help protect you.
Garth Algar · 2w
Guys! Please give the BB holders proof in maths and code that show why your RNG is safe πŸ™πŸΌπŸ€πŸ”₯
Garth Algar · 2w
Guys, please give the BB holders proof in math and code that you RNG is safe.
BitBox profile picture
BitBox is not affected by the recent RNG vulnerability that affected one of our competitors.

More details coming soon.
12❀️5⚑1
Garth Algar · 2w
BB team, what is your entropy situation. Please hit me/us with ice cold mathematics.
Thomas · 3w
Good tips! 😁
BitBox profile picture
Going somewhere? 🏝️

With the BitBox02 Nova you manage your savings straight from your phone, even on vacation;)

11❀️8❀️1😻1πŸš€1πŸ€™1🧑1
BitBox · 4w
In the picture, the BitBox02 Nova Orange: https://shop.bitbox.swiss/en/products/bitbox02-nova-79/
armstrys · 5w
1 T-shirt is in fact 1 T-shirt.
Primal Protocol · 10w
Owning your health is similar, ditch the seed oils and grains, take control of your plate.