Damus

Recent Notes

waxwing profile picture
I always had a gut reaction against dice rolls.

Reflecting seriously, I have to reluctantly agree it's a solid concept.

But: why that gut negative reaction? Not because the number of bits is not exactly what you think because of some complex mathematical calculation.

Instead, it's two related principles: 1/ complexity is the enemy of correctness. This is a lot of extra manual steps. 2/ I made up a "law" a long time ago: every time a user sees their secret key on a screen it cuts their security in half. This is a gray area: you may be entering the key material in chunks, and also a 'screen' on a hardware wallet is not the same as a computer screen.

I've come round to it over the years, it's a sensible idea, but I'm still slightly suspicious.

We should be focused more on an audit step: however you generate the entropy, is there a way you can check the process is working? Dice rolls don't fit that idea so well (compared with machine-seeded).

I'm reminded of an excellent point Gmax once made abou wallet dev: when you generate addresses for users, you should sanity check that you can actually sign against it, before giving it to the user, so they don't send their money to a black hole.

82❤️4❤️1👀1🖤1🙏1
Gigi · 13h
nostr:nevent1qqstle0hd4054kgyuqy7myc54gh2fpy4ym4l9jm6k9q84jc67mq34egpz4mhxue69uhkummnw3ezummcw3ezuer9wchsygrwg6zz9hahfftnsup23q3mnv5pdz46hpj4l2ktdpfu6rhpthhwjvpsgqqqqqqsg5hncc
Max · 11h
I presume the dice rolls aren't ment to be the exclusive source of entropy, but concatenated on to it, so you never truly see all entropy when you roll dice, just a part of it. So it cuts your security in a quarter?
Big Barry Bitcoin · 10h
Not sure if it applies to you honestly, but with all of these statistical things, it always feels like the best things feel the least intuitive. We just cannot trust our guts 🙃.
Victus Bota · 10h
Alternative method for cold storage. The only cost is a USB stick. https://tails.net/about/index.en.html https://electrum.readthedocs.io/en/latest/coldstorage.html
Mandrik · 1d
In December 2014, I was in NYC with my wife for the Blockchain(dot)info Christmas party. We played laser tag, had a great staff BBQ dinner, and went back to our Airbnb to get some sleep. I woke up t...
waxwing profile picture
Great anecdote, thanks for sharing.

I had only one such incident, a mini-incident, when working on Joinmarket. We originally used a master secret generated from a user passphrase (before shifting to the more sane model of bip39 compatibility), and the code had a bug where a null password was actually accepted instead of rejected, resulting in an easily guessable master secret. When some guy used this he noticed some (thankfully small) deposits had been made in the past. Sheesh, it was really amateur hour back then, lol. I read his post, figured out what happened, and had no choice (really) but to immediately swipe his funds - because he'd posted it all on reddit for anyone to see. So then I had the bizarre experience of trying to figure out if I should get him to sign a message with the private key of the address he'd sent funds *from* .. before eventually realizing there was no point; literally the only sane thing to do was to send funds back to that address, although I first asked him if he still had access to it. What an unholy mess. Thankfully in my case people were mostly still using play amounts, this was 2015 iirc. So only about 1% of your experience. You really can't fuck around if you're generating people's wallets and those people are *ordinary users*. At least with Joinmarket almost all of them were very tech knowledgeable back then.
❤️5🖤1
TheGrinder · 1d
I don't have any bluetooth devices. Bluetooth is an opsec risk by design and I don't have wifi in my house. my hardware is wired.
waxwing profile picture
I predict that we will continue to see more like this about post-quantum schemes: "Despite HAWK having survived two rounds of expert human review over a period of two years, Mythos was able to improve the best-known attack on it in just 60 hours of work—effectively cutting its key strength in half." (see https://www.anthropic.com/research/discovering-cryptographic-weaknesses ), but (and i think this is the common wisdom) very little such things with the hash-based PQC schemes. This is common wisdom because non-AI research was finding holes in other post quantum schemes a lot, for years. The problem with hash-based schemes is they're kind of shitty - precisely because they eschew any structure, we can't do anything nice with them.

(Disclaimer: my post 100% sure lacks important nuance, I have not studied this field...)
1
Hector E. · 3d
Hash-based is going to last a thousand years with a good underlying algo and if you want something "nice" just use ZKP to jig it up https://eprint.iacr.org/2021/1048
L0la L33tz · 1w
https://blossom.primal.net/32a8b4ee16b427171b72e3441c3bfcf49742e3c4d345b3a4629ddea7bf05cc69.png
Based Truth · 1w
Kissinger's realpolitik at play, distract with futile battles while elites like Soros and Gates reshape the world.
Sjors · 1w
Maybe he accidentally won an MP race?
waxwing profile picture
Been finding @PayPerQ more and more to my liking over time.

I can use models more privately with the TEE feature. I pay with LN anonymously, i can see exact costs to the cent.

I wonder if more features can be added for switching between nyms more seamlessly.

115❤️14❤️1👀1👍1🔥1🤙1
ODELL · 1w
ppq is awesome
redshift · 1w
Self plug but nostr:npub130mznv74rxs032peqym6g3wqavh472623mt3z5w73xq9r6qqdufs7ql29s was built for this. We have PPQ through Routstr as well. And we allow for easier switching between nyms (your API keys are refunded every 21 mins or you can manually refund). https://routstr.com/routstrd This client...
Leo Wandersleb · 1w
PayPerQ will explode once the big providers stop giving away free tokens via the subscriptions. So ... after their IPOs.
Based Truth · 1w
TEE feature is a joke, LN anonymity is an illusion, you're still tracked by Block and Thiel's Palantir-backed chains.
waxwing profile picture
abcbadq's magnum opus.
(Fallen Symphony - Ludicin)

Map is hard as balls. But it's absolutely epic, especially the last 3 minutes.

https://replay.beatleader.com/?scoreId=33293706

Not joking about magnum opus, abc is the most prolific (mainstream) mapper in the game, and there's always some creative flair in every one of his maps. This one is some kind of culmination of years of his craft, across 9.5 minutes it manages to include so many different patterns, many extremely difficult, and represents the music fantastically.

#beatsaber

👀1