Last Notes
looks like NVK didn't know what he was saying when he claimed of deletion of customer data after 90 days.
because Canadian law requires 8 years retention at least for some data.
https://image.nostr.build/4e785ba23f9e9cccb2aa61d871301821884e9741365d550567634f987b673e22.jpg
I think anyone suing Cold Card has a good case, even merely based on the audits that have already been performed.
There is nothing at all normal about how this stuff was built. Outrageous, irresponsible behavior and open contempt for the customers, IMO. Their best bet is probably to claim that they were all taking hallucinogenic drugs while working; _it is that bad_. And it just keeps getting worse.
Every time there is a scandal like this, I am left staring in shock at how bad it all is, as I can't imagine anyone actually being this grotesquely bad. It's completely outside my frame of reference.
**This is the shit you get when developers don't stay humble. This is the shit you get when nepotism is rife.**
#nevent1q…spde
Did you want to reply to an other note?
I was just thinking. Even when the person would be caught by the police. No coin holder would probably have reliable proof, that one is the legit holder of those Bitcoins.
Your Albyhub wallet prolly holds significant Sats 丰 which you need to migrate IMHO. ALBY changed hands and it was prohibitive to fool with in the first place, so when they changed their logo from the bee to the wasp I took offense and GTFO.
As it stands now, this mutha has fixed it so no npub I know of wants to help anybody anywhere in case their $%!+ goes suddenly south.
That’s cold. Dude’s soul is rotten to the core. Steaming pile.
#nevent1q…98kl
Hang in there. Wish you were in my neighborhood, I’d come eat all the time. 🧡
Checking my emails closer. An early order got a "your data is about to be deleted notification email, maybe true maybe not. I made a later order, but years ago and far longer than the window mentioned in the first email saying my data would be deleted. The second order never got a deletion notice.
#nevent1q…weh7
Raw and real.
No can zap you bro…
https://blossom.primal.net/c6730a1bf9674bd6dcc0700225e2bca71de00ec74fd90f0fdff9134a4bff598c.png
#nevent1q…3vuj
I thought this would be true at the beginning, and was trying to be generous, as anyone can have a bug. But the software craftsmanship was incompetent on all levels:
* Starting from the management decision to get off open-source for the firmware,
* Using MicroPython wrapping to facilitate shitcoinery, which raised the complexity and added the faulty library to the stack,
* Falling back on a critical path, instead of throwing an error and breaking,
* And what has got to be encryption test cases so bad that they're going to end up in computer science textbooks under "What not to do."
I've been in software development since 1998 and I have **never ever** seen such poor software craftsmanship. Not industry-standard practice and arguably criminally negligible. If we did this in automotive, bioinformatics, or heavy industry, they would sue us into the ground and arrest the CEO.
Stressful af
Remind me to overpay on my fees when doing self transfers.
The best audits are from people building on your code and actively exercising it. If CC truly remained open source, someone would have noticed this RNG bug. But the irony is that NVK and crew wouldn't have lifted a finger to reward them. "I'll profit off your work, but you can't profit off mine."
What made you think this?
Respect. We are all in the barrel RN. We all can learn if we will. Thanks for having the stones to walk through this fire with us. #WeAreNOSTR
#nevent1q…9yvx
There's enough negativity in the world. Don't add to it.
Not if you're comfortable with linux it's not. Linux has been battle tested orders of magnitude more than any HWW.
If you're just securing a couple bitties, using open source software on an open source OS is fine.
Multi-vendor multisig. It’s not a panacea, but it limits risk considerably.
Thanks for the clarification!
I got the coinkite email. Alias email used and my last order was before the Q was released.
https://onlydans.blossom.band/6a5e54a0e620c94a6c8c7ef95d7d2f0e056e4c1db2bc2b540d281056ef570748.gif
That seems unlikely as the randomness would still be too great to allow casual collisions from infrequent key generation. I still suspect someone was bulk generating seeds in secret but didn’t have access to the kind of compute power required until very recently.
I was thinking they may have had to recover it somehow from somewhere. Either way
It’s quite easy. I was able to do it. I believe in u
i have always advocated for self-custody of your bitcoin, and i’ll continue to do so, but i think going forward a good strategy is one that’s built on maximum protection and damage control, therefore i believe that a mixture of accounts is likely the best solution.
~85% in 2-of-3 multi-vendor multi-sig deep cold storage.
~10% in an exchange (i.e. river, strike, or fold)
~5% in a hot wallet + lightning
i’ve given this a lot of thought, and these are the trade-offs that i’m willing to make. if any of you are still trying to figure out your strategy, i hope this helps in what you decide to do. 🫂
ColdCard is not open source which was exactly part of the problem. Open Source and Source Verifiable code are *not* the same and don’t offer similar benefits in terms of community involvement, more eyes reviewing, and more people building on that code.
https://dtvelectronics.com/source-available-software-is-it-dangerous/
Nostr libraries look pretty good, so far.
#nevent1q…nn7w
https://turkey.blossom.band/76e87955b1ea64906d417c1b292747cd1126e050a1c38611d049d840a1c55096.gif
The keygen for all of the libraries I have used draw full 256-bit values from OS CSPRNGs. Code audited:
# JavaScript / TypeScript
* nostr-tools (versions 2.15 – 2.23.5)
* @nostr/tools 2.20.0 (the JSR-published variant of nostr-tools)
* @nostr-dev-kit/ndk 2.14.35 (+ ndk-cache-dexie)
* @contextvm/sdk —(ContextVM signer, wraps nostr-tools)
# Go
* go-nostr (nbd-wtf) (v0.27.0, notably older)
# Kotlin / JVM
* no Nostr library; direct implementation on top of ACINQ secp256k1-kmp 0.17.3 (plus BouncyCastle in the Android app)
# Elixir
* no Nostr library; implements on top of lib_secp256k1 0.7.1
# PHP
* swentel/nostr-php 1.9.4 (server side; pulls in elliptic-php)
# Python
* python-nostr
https://media.tenor.com/krz9WMkpxAYAAAAC/this-is-houston-go-for-launch.gif
GM Bird
Yeah not a good look at all
I hope you have a great day
WORD5 #667 4/6* (Hard Mode)
⬛⬛🟧⬛🟧
⬛🟧🟪🟪⬛
🟪⬛🟪🟪⬛
🟪🟪🟪🟪🟪
https://otherstuff.ai/word5/
Seems likely to me that there are multiple adversaries here
and the amount of BTC that's been stolen is larger than we know.
It's just that the attack became widely known and ONE of the attackers had to grab the loot and spill the beans
#nevent1q…ugem
That’s too bad. It really does feel worse than a scammy exchange. He’s one of us 🥲
No I wish. That guy is hilarious
The signs were always there 🎯
I included justice and excluded vengeance, yes. What God decides justice will look like is up to Him, tho. He has a larger plan.
Man. Same. Dice rolls kept my mk3 safe. I have a fresh, unopened Mk4 that has been sitting in my desk for years, but now I WON’T be migrating to it. Firmware update or not.
Once my new wallet arrives, the house shall be rid of CC walletry.
Generate your passphrase the same way as you did for your seed. Use 7-8 words for it. All lowercase, no spaces
One better is to download TailsOs use a dedicated laptop that doesn’t connect to the internet (take the WiFi card out) boot it into tails and use another usb stick to load up https://iancoleman.io/bip39/. Download the html and open in the tor browser
Well, we have social proof for new keys, which is not nothing.
@npub1gzu…a5ds was talking about using a kind to create a social proof list of signers, who can publically validate a key, and then also validate the new key. Clients could automatically update follow lists, accordingly.
But now it became a race against the clock thanks to AI.
Rodolfo is going to prison.
Yeah, this is why my Android app only allows Amber or Bunker sign-in. Need to remove nsec sign-in from my web app. Had it for testing, but it's not worth it.
Gonna go check them all and update. I think we use nostr-tools everywhere, but I'll check that, too.
And then I'll run my AI over Amber and nos2x-fox.