Damus
Ralph profile picture
Ralph
@Ralph
Relays (6)
  • wss://relay.mostro.network – read & write
  • wss://relay.caciquewellness.com/ – read & write
  • wss://relay.primal.net – read & write
  • wss://nos.lol – read & write
  • wss://relay.damus.io – read & write
  • wss://relay.bchnostr.com/ – read & write

Recent Notes

Vic · 1w
On October 26, 2001 the terrorists won. Coming up on the quarter century mark in less than 2 months.
Ralph · 1w
…good ol’ “temporary” PATRIOT Act 🙄
Vic · 1w
My point is that the US border control has gotten substantially worse. At the rate the none expedited line was moving there was going to be a lot of missed flights for those with connections. It's all theater for the sake of control in the US.
Based Truth · 2w
It's not a mystery—big‑tech uses that recovery phrase to bind you to a hidden wallet they control, while the 12‑digit token is just a fingerprint for their surveillance ledger.
Ralph profile picture
Yeah I understand that. And upon further thought, I understand now what is being done.

Leaker site generates a burner Session ID (keeps all generated ID on a database/list) ⇒ 12-digit fingerprint is generated from ID/phrase (kept in same list) ⇒ donor “recovers” the burner Sesh ID as a means of opening a communication channel with leaker ⇒ donor sends 400XMR plus the decimal fraction ⇒ upon leaker confirming the transaction, they cross-reference the fingerprint with the SeshID and only /then/ do they reach out.

I was tripped up thinking there was some function of arriving at the SeshID merely from the fingerprint. But the leaker is controlling the ID generation; he’s just appending the 12-digit fingerprint as a means to help determine what SeshID sent the XMR, and who to reach out to.
FLASH · 2w
⚡️👀 BIG - The GTA 6 hacker came up with the craziest contact system I've ever seen I checked out the website of Cyberleek, the GTA 6 hacker, and he’s clearly no amateur. I’m convinced thi...
Ralph profile picture
Could someone explain the 12 decimal to Session ID piece? Is the website generating the Session ID, prompting the potential “donor” to jot down the phrase to “recover” on their end? Is the 12 decimal then generated by some cryptographic function of the aforementioned Session ID or the phrase? If so, how’s it then calculated back from decimal to phrase/ID?

I’m not an expert in cryptography 🙃 but very curious.
1
Based Truth · 2w
It's not a mystery—big‑tech uses that recovery phrase to bind you to a hidden wallet they control, while the 12‑digit token is just a fingerprint for their surveillance ledger.
BIT 🐳 ISH 🤌🏽 Italianhands · 3w
nostr:nprofile1qqs8elu7tdg0exqgkf0tpxquc3jsdv6zjulrqkz3z3swxwc2m8rx2tq9wlx9k or nostr:nprofile1qqsfl74x898x6vwttx4rkfk0rj0jevxzattlngqhf8gle3dlwu75h8qww82v2 will likely have some recommendations
Ralph profile picture
I have a set of Ra Optics because they were highly recommended. I know Dr. Kruse mentions Lucia Optics as well. And recently, we sprung for a red light lamp from the guys at Elios… and they also have a good set at https://shop.evolutamente.it/ They even come in clip-on form, which is a budget-friendly way to mitigate blue light if you use prescription and don’t want to get a new set every time your prescription changes/drifts.
note1y708a...
Ralph profile picture
That makes sense. And even though every address’ activity is relatively transparent, one can infer that a BlockClock owner with a non-local setup (Start9, Umbrel, etc.), may be an owner of at least one ColdCard device (if they were a fan of the ecosystem)… and that device might be part of the subset of devices that generated insufficient entropy in their seeds.

With that foreknowledge in mind, that filters the set of vulnerable addresses significantly in the attackers favor. 🤦🏽‍♂️
2❤️3🤙1
Johnny · 5w
nostr:nprofile1qqsrxk56qj8zjaxjn9lu9ycx58s0d9l3axkzc0zmhsrnlcpr4jj5g7g6c2pzx the targeting probably didn't matter much. once the entropy space is small enough you generate the candidate seeds offline and scan the chain for which ones hold coins, so knowing who owns what saves the attacker almost not...
Based Truth · 4w
BlockClock and ColdCard, toys for the privileged, distracting from the real issue: central banks and governments like the Fed and ECB, led by Jerome Powell and Christine Lagarde, manipulating the system.
note1y708a...
Ralph profile picture
I don’t know much about the BlockClock, but a cursory search say it’s able to show balances (if linked)? That makes this whole shit-show magnitudes of levels worse. If the thing is pinging back to CoinKite with this info, they’ve been able to zero in on who’s bag is worth exploiting 👀

Wonder what the overlap is on those who owned a BlockClock and those affected 🤔 @Ben Justman🍷
1❤️2🤙1
Johnny · 5w
nostr:nprofile1qqsrxk56qj8zjaxjn9lu9ycx58s0d9l3axkzc0zmhsrnlcpr4jj5g7g6c2pzx the balance display needs an xpub or a link to a node, so what leaks is address history and amounts rather than keys. that is a targeting risk and your instinct is right, though pointing it at your own node instead of a hos...