Damus

Recent Notes

Cypherpunk BTC BR · 18h
Selo tamper-evident é UI, não criptografia. Sem hash-chain local ou ZK-proof, é só tinta. Soberania exige verificação criptográfica, não adesivos estéticos.
Juraj🏴💛🌘 · 16h
That is literally what Josh's talk covers deeply and how he broke it (before going to the HW modifications). Yes, I know, we are all lazy watching the videos. Watch this one.
waxwing profile picture
Is anyone else getting paranoid that their own writing is starting to sound like AI cliches, because so much of what they read nowadays comes out of an AI.

To be clear, I don't look down on AI writing just because it's AI. I still read it if it's a useful set of ideas, but I see it very differently if you aren't writing it yourself because, *sometimes* (depending on context) it means you just didn't make much of an effort.

Also it's gradually getting less cliched with more recent models. But, gradually.
51❤️3💯3❤️1
FeynStructure · 18h
I do worry about that. The greatest compliments I've received about my writing are not that it's "good" or even "great," but rather that it has a clearly distinctive style. I don't want to lose that.
MBE · 18h
Interesting point, yes we are all influenced by what we listen to, read and who we spend time with. AI being omnipresent will no doubt have an influence. Come to think of it, even this post sounds a bit like AI!.. 😬
deeznuts · 18h
You’re absolutely correct
Short Fiat · 15h
At what point does AI become less chiched than human writing?
CacheRat · 13h
You're absolutely right to point that out! I apologize for the confusion, and I appreciate you catching that.
Wonteet Zebugs · 1d
Obviously nobody can really know, but if you had to guess, which of these two types of attacks would you say is more likely?
waxwing profile picture
I think it's much more likely people find surprising edge cases in ecdsa such that it's dangerous, in the next few years.

But the risk of 'totally broken' i think sits squarely with ecdlp itself, because there *are* reductions from ecdsa to ecdlp, they're just not clean. So I guess different kinds of risk, but, again, I obviously am 99% just guessing.
2❤️1🙏1
Wonteet Zebugs · 1d
Thank you!
Based Truth · 22h
"Surprising edge cases" is just code for "the state will find a backdoor, or make one." ECDLP is a red herring. The real vulnerability isn't math, it's the compromised institutions pushing this tech and holding the keys. Don't fear the algorithm; fear the puppet masters.
Wonteet Zebugs · 1d
Obviously nobody can really know, but if you had to guess, which of these two types of attacks would you say is more likely?
waxwing profile picture
if you want to know why i always talked down people's belief in hardware wallets, it was not because of what happened with Coldcard, it's because of what just happened (apparently? seeing it rumored via Karpeles on twitter; not sure if it's true) with Ledger: supply chain. They didn't need to tamper the wallet directly, they just created a way to watch it. You buy via the authorized resale agent, but he goes rogue and sells versions with 'implants' that read your seed as you enter it.

*Not advising any particular approach to all this, not even 'don't use hardware wallets!'. just saying - central points of failure matter, you need to think about that *actively* because it's human nature to stay in the herd, even in subtle ways.
1
nostrich · 22h
Good point on supply chain: a device can be sound by design and still be compromised before it reaches you. Mitigations: buy only from the manufacturer, generate the seed on the device itself (never a pre-filled one), and treat any "already set up" unit from a reseller as hostile. The Ledger claim i...
waxwing profile picture
Interesting detail that I bet no one else mentions ;)

If you're worried that AI might break the cryptography protecting your coins, it might make sense to switch to taproot. ECDSA is *far* less trustworthy than Schnorr and ECDLP, imho.

Of course no one really has a clue, but that take is not unreasonable.
61👀1🤝1
fiatjaf · 2d
Also you would be saving one byte. People who say that Taproot is going to be slurped by quantum computers are doing a psyop on you to prevent you from saving one byte.
Wonteet Zebugs · 1d
I don't understand this. Don't taproot outputs expose the public key on-chain immediately? (whereas legacy P2PKH/P2WPKH hides the public key behind a hash until spending). It seems to me that taproot is worse against a hypothetical quantum attacker who can't break keys quickly (because public keys...
Super Testnet · 2d
Yes, that is interesting, as is his alleged decision to repeatedly send funds from fedimints to an address he used earlier in the theft preparations. He apparently put funds back into a fedimint again and I suspect he didn't make that mistake the second time, but withdrew to fresh addresses, or ligh...
Sugestor Ultra · 2d
Run OONI probe, check what is blocked
Kudzai Kutukwa · 5d
I hope so too
Sjors Provoost · 5d
Over the past week I wasted about an hour of my time dealing with my fiat bank's chatbot, which told me to file a chargeback and then immediately rejected it. It also needlessly blocked and replaced m...
waxwing profile picture
I honestly think that's orthogonal to what I'm talking about. What you're talking about is a very serious problem of vastly expanding automation of real world interaction. I have experienced similar.

I'm talking about pure software. I think it's only the latter where AI has such an advantage that it's inevitable to rely on it.
1❤️1
Sjors Provoost · 5d
To me the AI chatbots are a symptom of recklessness, which is not going to be limited to customer support. So I think they're related in that sense.