Last Notes
Man. Same. Dice rolls kept my mk3 safe. I have a fresh, unopened Mk4 that has been sitting in my desk for years, but now I WON’T be migrating to it. Firmware update or not.
Once my new wallet arrives, the house shall be rid of CC walletry.
Generate your passphrase the same way as you did for your seed. Use 7-8 words for it. All lowercase, no spaces
One better is to download TailsOs use a dedicated laptop that doesn’t connect to the internet (take the WiFi card out) boot it into tails and use another usb stick to load up https://iancoleman.io/bip39/. Download the html and open in the tor browser
Well, we have social proof for new keys, which is not nothing.
@npub1gzu…a5ds was talking about using a kind to create a social proof list of signers, who can publically validate a key, and then also validate the new key. Clients could automatically update follow lists, accordingly.
But now it became a race against the clock thanks to AI.
Yeah, this is why my Android app only allows Amber or Bunker sign-in. Need to remove nsec sign-in from my web app. Had it for testing, but it's not worth it.
Gonna go check them all and update. I think we use nostr-tools everywhere, but I'll check that, too.
And then I'll run my AI over Amber and nos2x-fox.
Rodolfo is going to prison.
https://onlydans.blossom.band/9961423bfe1335653d36bcafa6675392bfeb7d3fa99549976b810da02805fc74.png
#nevent1q…keew
How many years of forest fires are we going to have before forest management gets some real money to do the job correctly?
This is who deserves the lawsuit
Day 214 🌞
✨ "When I started counting my blessings, my whole life turned around."
— Willie Nelson
💫 "I am capable of creating positive change."
🙏 Grateful for the hard times. This is when we learn the deepest lessons
https://gratefulday.space
Gm nostr 🌞
Give thanks and mean it by showing your proof of human. Write the note.
Last day for $5 off all #hodlbutter in the shop 🤞🏼❤️
https://www.oshigood.us/
https://image.nostr.build/d1b36338742a4993208279b813f3c109c31d197e04d85c910484d9d6e169cffb.jpg
Ooooo baby thank youuuu packing now!
https://media1.tenor.com/m/MWAwgYqK1aUAAAAd/issou-risitas.gif
Bitcoiners NEED to insist that their entire stack is open source. There is no second best, said it for years etc...
It has also been pointed out that it's unlikely this bug would've been caught EVEN if they used an unrestricted license.
Who is rooting around in firmware code?
But *some* incentive is better than zero incentive.
And beyond that, it's the vendors responsibility to pay for 3rd party security audits to ensure their product does what they claim.
So it would've been nice if some random bitcoiner had decided "I'm gonna root through coinkite firmware." But who is going to do that without *even the possibility* of developing a product based on it.
I understand some of you are feeling responsible because the company you trusted and recommended shit the bed in the worst way. But getting the firmware audited was their responsibility and it's on them for making a broken product.
So stop saying "it was a community failure." Open Source *increases the robustness* of a project. It does NOT shift the responsibility of ensuring the product someone is selling does what they say it does just because they show you the code.
#nevent1q…r8uw
@npub1az9…m8y8 loved open source when he could profit off of it.
He despised open source when it threatened his profits.
Holy hell…what are the chances someone has been secretly running a script to find funded ColdCard seeds for years and it was only just now accelerated to a full-scale attack due to AI?
https://onlydans.blossom.band/23e18f9b9ef08319b719d024cb3b0ffcd2369991afcc9e0fefa76b77729c68f6.png
Got an email from then too. Erase customer data my ass
PV and GM plebs! I was defeated last night, I think there was some debris under the pressure plate so the trap never triggered. Oh well at least they'll be back for another meal. #plebchain #coffeechain
Said they delete physical addresses after 120 days. Don't see anything referring to emails.
Although to be honest dont remember hearing about their leak as recently as last month
https://blog.coinkite.com/paper-spam/
https://npub1832epq8kgur55cuwnnrdf3y85p4l4wqsgq42hxn8jna5ngznz5lq2law2l.blossom.band/95a3c55a5580cb671d2ab3ba8c96d2ae6df72442875b86df745b4794ce7bdc57.jpg
CTO of Coinkite, the main dev there
https://media1.tenor.com/m/amqJrqEAGBEAAAAd/boom-alonzo.gif
#nevent1q…u0yf
Same. It’s incredibly painful.
even if they had used an unrestricted license, It's still unlikely that anybody would have looked.
But slight incentive beats zero incentive.
And it's their responsibility to pay for code audits.
GM good people
Enjoy your Sunday
https://node.blossom.band/37da37f3d46b10d4dfbefed80da2eb777d3c3c2b05727e5360955e3946691260.jpg
They also said they deleted customer emails after 90 days. So which is it?
https://i.nostr.build/hVygUmrFkjlUfUIa.jpg
Fucking liars all of them
Yeah, there’s a good chance they’re also armed.
https://npub1l5pxvjzhw77h86tu0sml2gxg8jpwxch7fsj6d05n7vuqpq75v34syk4q0n.blossom.band/22e16e700d28d0d3ffe0cf4e862d988906facaa791b969f253967f2582ef3552.png
https://d.nostr.build/FFBp4cW2NOTXBaNa.pdf
do no trust a hardware wallet even the ones still standing with giving you a random seed.
do not trust a desktop wallet either. draw your own words from a bucket that are cut out and replace the word you drew each time. then use seed signer to calculate your 24th word.