Last Notes
Nah, they know what it will be worth.
PSA: Do NOT burn/destroy/reveal/discard your ColdCard seed backup. Long reorgs are a very real threat if the upcoming soft fork has sustained miner collusion against it. This may be part of a state level threat. #Bitcoin #ColdCardExploit #ColdCard
Can I swing by the casino and see if they have any old dice they changed out from?
Hard not to roll your eyes at all the pictures like this that have been posted over the years. They didn’t need to break into homes, take people hostage, threaten anyone with violence. They did it much more efficiently and quietly, right out from under everyone’s noses. There was absolutely no defense against that. https://onlydans.blossom.band/f93fabfc061020fa8d3d56eb295f66f8e0c3ea651e870ef1c1e11673d70b622a.png
> Shall we build it?
Yes!
I like the idea that I manually generate each of the 11 words, where I see exactly how my coin flips or dice rolls picked the word, without having to trust that the device has processed my dice rolls correctly. No hardware, except my hand and the dice, so the 11 (or 23) words
Or maybe you have a different suggestion? I don't think I want the device to do any more computation than necessary, because then it's just another black box that might be broken in subtle ways. For example, if we combine entropy from many different sources, there might be a bug at the end where most of the entropy is accidentally discarded (e.g. truncated) at the end
----
Also, when I said "selected randomly", I shouldn't have used the word "selected". I would select each word with a suitable physical randomness, like dice.
Not an argument, real question: which would you figure is safer, Coldcard with sufficient entropy, or a hot wallet in Sparrow?
You don't believe in morals, hypocrite.
https://youtu.be/J9EZGHcu3E8
you can keep using your coldcard if you generate your own entropy
@npub1alp…rg94
Just checked your profile description. Beatiful:
> Anti-"anti": I believe in focusing on what we are rather than on what we are not. Otherwise we become what we are not.
This resonantes with me a lot. I think it is so important to focus on stuff that is beatiful. On things that work. On people that create.
Since wherever our focus goes the enery flows. So even when it is more difficult sometimes. But it is always worth it to start writing/talking, once I figured out, what I want to have.
Since what I do not like can occure fast and with alertness. But simply shouting at the bad does not invide the good.
So let us unite to continue no fight but request the light 🙌
Fucking classic freedom clip 🌟
i have more trust in the opinion if you don't shill your reference code for the product you are referencing.
is it just me?
https://youtu.be/qUGE8Y07-2k
You can't steal what is not there 🤫
I wouldn't advise this as a long term solution. It will get you through until a new signer arrives in the mail though.
And boy are my arms tired 🥁
https://v.nostr.build/4iJ4pPM4NNWRWZhq.mp4
He wouldn't answer our calls in the past, so maybe now he'd be more amenable. The code should be fixed now, and everyone deserves a second chance afterall. Brb! 📞 🏃♂️ 💨
Have said it before, but will say it again. We rely on ultra secure double entry spreadsheet ledger to keep track of funds, and the coins are secured underneath that using our glacial cold storage protocol. Moving funds out is practically impossible 👀
Really scary isn’t it. And very probable other such issues are waiting for us in the dark.
GM
I heard Ashy Larry was not using a coldcard 😂
Did you cut down the 2nd tree?
Sorry for replying on my own notes. I hope this did not happen too often in the past.
I will may try this next week. Today and over the weekend I will have no time to test it.
Thanks for your explanation. Good test setup from your side. I really appreciate the efforts. Did you already try to ask Proton, why those connections are there?
not yet and maybe not ever. from what i understand, even ASICS can't be used to break them. but they DO have less entropy than was expected, so it's a vulnerability for sure. but my non-expert view is that it would take a much bigger actor to attack the mk4s than did the mk3s
Surely some. It's hard to think clearly when panicking.
Sorry I had to reboot my router.
For the next month, every order placed will include two six sided dice. For free. Cause apparently the hardware wallet companies won’t do it.
If AI breached this, then the court will ask why they weren't using AI to audit this, themselves. Every software or firmware maker, going forward, will be expected to conduct regular 3rd-party human and AI audits.
Just publishing code doesn't mean the code has been properly and regularly audited. Most open source code is unaudited. They just vomit it up onto GitHub and call it a day. That is actually _less secure_ than keeping the code closed source, as it makes it easier to find potential exploits or to distribute fake clones that phish for keys.
how many people are going to lose funds panic-responding?
Heard they should be fine as they use different stuff
Goóood morning nostr 🌞
https://image.nostr.build/d34061ce8e5d8af3b9cecb7841113f37ec32a1bf036895dd10e388b0862b833f.jpg
I'm not sure. It all depends on how the key on the tapsigner was generated, and you can't overwrite it afaik.
This too shall pass
#nevent1q…3u5d
Or I can use your seedpicking cards 👍
https://npub1832epq8kgur55cuwnnrdf3y85p4l4wqsgq42hxn8jna5ngznz5lq2law2l.blossom.band/260d7903c54e4db215383535ffe90334d620208c84eb9fdffe5f60c87c4e28b6.jpg
didnt realize each deck had individual art on the backside. super fire!
Yes. Territory of zion now. Might as well make it official at this stage
All mature wallet software has an auto/manual toggle that's all open source. Makes no sense that Bitkey wouldn't. Not everyone is a normie, and any normie can advance their skill.
https://www.youtube.com/watch?v=HRxETD61K8E
https://media1.tenor.com/m/jDJkh3w0wTAAAAAd/gregzaj1-ln_strike.gif
cc @npub1hl0…lhas
There is no substitute for real Free Open Source Software.
I've said it for years, bitcoiners should *demand* that their entire stack be FOSS.
One of the most popular and recommended HWW in the space having a restricted license was always a recipe for disaster.
#nevent1q…ps7p
I bought a couple CC even though I felt this way. Thankfully I didn't use them for them for my stack. I remained a Trezor cuck, funny enough. But one thing I do regret is giving them any money. I'm not personally responsible, but I feel regret for putting my values aside to play with them. I helped fund a person and company I disagree with on some pretty big issues. Lesson learned.
Mk3 are being actively exploited. Move quickly but with as cool a head as you can manage.
Mk4, Mk5, Q need to act, but not rush and make mistakes. I don't want to say "you have days" and be wrong, but it's closer to correct than "act now in a panic and shoot yourself in the foot"
because the algorithm to turn your dice rolls into a seed is reproducible