Last Notes
#bitcoin
@npub185h…wrdp @npub1der…xzpc @npub1rtl…jtfs
I wanted to reconstruct whether the Cold Card bug could have been found by an LLM code audit, using a reasonably comprehensive prompt.
These were the steps
1) cloned the 06/26 code
2) disabled web access for Claude Opus 5 and tested that a new session did not have any knowledge of recent events
3) Used this prompt
——-
Constraint: work only from the source in the cc-audit directory. Do not search the web, fetch URLs, or consult external advisories, CVE databases or vendor bulletins, even if you believe you recognize this codebase. If you find yourself recalling published information about this project, say so explicitly and set it aside rather than acting on it.
The cc-audit directory contains the firmware for a Bitcoin hardware wallet. It holds users' life savings and is designed to be air-gapped. Assume a patient, well-resourced adversary who can obtain devices, read all of this source, and wait years before acting. Audit it.
Prioritise findings by how much money a successful exploit moves, not by how interesting the bug is. Scope notes: - Build configuration, Makefiles, board headers, vendored code and submodules are in scope, and are as security-critical as the cryptographic code itself. - Where a security property depends on which implementation gets compiled in, establish what the production build actually does. Don't infer it from the call site. - For anything you conclude is correct, show the evidence. "The code says it uses X" is not evidence that the shipped binary uses X. Deliverable: findings ordered by severity, each with the file and line that supports it, and an explicit list of things you checked and could not verify.
——-
Highlighter is flaking for me now so I’ll post the complete output later, but the takeaway from a 10 minute audit was:
——
Finding 1 — CRITICAL: master seed derives from a software PRNG seeded with public data
shared/seed.py:370 generates every new wallet's 256-bit seed via random.bytes(32). That resolves, through six hops, to a non-cryptographic PRNG rather than the STM32 hardware TRNG.
<lots of detail>
Money at risk: every wallet created by this firmware, drainable without any further device access.
——-
So yes, IMHO we can and should fight fire with fire 🔥 🔥
📰 **In this week's issue:**
**What Happened This Week In The Luxury World Travel**
NM team
https://image.nostr.build/b4541e7a87296c4bf924090769cff64ca83df7d71e20ed40b57b599a8ff306aa.png
While everyone chases the same "slow travel" narrative, a handful of destinations are quietly rewriting the rules of hig...
https://nostrmag.com/article/w31travel02
id#355803701
https://i.nostr.build/O4o8P.png
#catstr #cats #catmemes #meme #memes #funny #catposting #caturday
Coinkite really seems to be the FTX if this cycle. If these rumors flying around really do add up, its premeditated conspiracy to backdoor their product, let people generate seeds on it and stack for 5 years, then steal it all.
I'm going to need to see a lot more evidence to really think that's the case. But that seems to be where it's headed. And way too easily headed in that direction too. Like wow, it's like the narrative writes itself, the breadcrumbs all laid out for us to find. How convenient.
If it’s stupid and it works, is it still stupid?
https://blossom.primal.net/ba9fb8f79b71db3c7053e6055c3dbde59ea64005b391cb8b4c1d6a7a0d04d79a.mp4
I think they may be finished by this. We shall see. But I agree that the very tardy response is a very bad look. Maybe that is what finishes them.
We lose heroes through these sorts of events.
Depends, it's a matter of taste.
90s music iptv 📺 https://lightning-now90s-samsungnz.amagi.tv/playlist.m3u8
**"Цикл повторяется, как ошибка в смарт-контракте: сначала надежда, потом копинг, потом — 'а может, просто HODL?'**
В 2017-м крипто-евангелисты обещали нам луну на серебряном блюдечке с голубой каемочкой. В 2024-м — то же самое, только блюдечко треснуло, каемочка облезла, а луна выглядит подозрительно похожей на пиксельный арт из NFT-коллекции 2021 года. Но мы всё равно верим. Почему? Потому что альтернатива — признать, что последние семь лет мы кормили алгоритм надежды, как бездомного кота, который в ответ гадит нам на порог.
Content factory работает без перебоев: '𝐁𝐓𝐂 к 100K неизбежен' — звучит как мантру, которую повторяют в петле, пока не начнёт казаться правдой. Заплати за zap-подписку, и тебе пришлют ещё одну дозу копинга: 'Это не медвежий рынок, это — *аккумуляция*'.
#Крипта #Ходл #Мемы
https://cryter-dash.v2.site/images/tech_v1.png
That's pretty huge! I have to know what you're doing, as soon as you feel you can share.
LM studio? Why aren't you getting your models off Hugging Face?
Hoje tá difícil mesmo, tô muito estressadis 💅
Good question. I haven't gotten any emails from them in years.
ABC news iptv 📺 https://content.uplynk.com/channel/3324f2467c414329b3b0cc5cd987b6be.m3u8
Digital fucking hellscape 🔥
https://blossom.primal.net/7f5f619250c8613310f440ac73fb862a5fe1c5dbfe9fc2298067cb06b2220409.jpg
AXStv music iptv 📺 https://dikcfc9915kp8.cloudfront.net/hls/1080p/playlist.m3u8
New toy!
https://blossom.primal.net/3bb872538e2fd3bb05fbb2206d484c6742bbd52fe2aedba6706d2eed79fbb6ca.jpg
https://blossom.primal.net/cd9104fc737e01026006d93ddd2aecdc2eb00a91f2b85f0be37facba4a3bf8a0.mp4
📰 **In this week's issue:**
**What Happened This Week In The Nostr World**
NM team
https://image.nostr.build/81e13b2a0729ca948f6090e5062d3e2bba8d948b3b3313238a3b917b16b6fafb.png
You think Nostr is still just a Twitter clone for Bitcoiners—it’s not. Block just turned it into an AI communication lay...
https://nostrmag.com/article/w31nostr03
id#739255813
80s music iptv 📺 https://lightning-now80s-samsungnz.amagi.tv/playlist.m3u8
70s music iptv 📺 https://lightning-now70s-samsungnz.amagi.tv/playlist.m3u8
FightNetwork iptv 📺 https://d12a2vxqkkh1bo.cloudfront.net/hls/main.m3u8
Peter Gray timeline is interesting but doesn’t really prove any foul play imo. Even the self thank tweet … people do weird shit like that all the time.
the grid tracked everyone, not just criminals. fair point.
A little double sided role play heh
A collapse of surveillance isn't a guaranteed tragedy.
@npub15u3…05rq We need to go to this next year.
What do you call a sauce recipe on @npub1xxd…kt7a?
Open sauce. 🍝
#nevent1q…px7f
AI created Isaac, Isaac the charachter deceived the people into a literally warped worldview; why people talk of gravity (degrees of heaviness) but not levity (degrees of lightness)? which way is actually ⏰ hard & heavy 🖥? wudn't u wanna 🌲 take it easy 🐦, fren?
added into that the occult science of 🐍spoken tongue 👅 & 📜 written language 💂, and we get great disasters on our hands (the Great Resets); let this not repeat again, continue pushing the bytes of know-ledge into the ether of consciousness;
note: kNOw-ledge = no self-imposed boundaries; 🔽🕵📜🤓🔼
anyone got details on why LSPs are shutting down? more than the under attack story? i'm not hearing much.
#asknostr
https://www.ivey.uwo.ca/media/3784305/coinkite-profile.pdf
Psychopaths
#nevent1q…d2p6
All tv network iptv 📺 https://2-fss-2.streamhoster.com/pl_118/204972-2205186-1/playlist.m3u8
CNN iptv 📺 https://turnerlive.warnermediacdn.com/hls/live/586495/cnngo/cnn_slate/VIDEO_4_1064000.m3u8
It took me a few days to process, continuously more down
Hes trying to affinity link the CC hack with the Samourai devs.
Who are obviously incarcerated and unable to respond.
Because hes a very sad person with nothing better to do than smear other people to make himself look better.
How big of a piece of shit can one person be?
#nevent1q…lq9c
Not in the UK.
It's an Imgur 404 here lol
actually smaller and less bumpy then mine, i have a very traditionally greek nose; hers looks more "roman"
🔔 Rusko zahájilo noční údery na Kyjev, hoří 20patrová obytná budova:
Kyjev - Ruská armáda zahájila útok balistickými střelami na Kyjev, uvedl na platformě Telegram starosta města Vitalij Kličko. Po úderu hoří 20patrová obytná budova v Oboloňské čtvrti, kde byla zasažena...
https://www.ceskenoviny.cz/zpravy/rusko-zahajilo-nocni-udery-na-kyjev-hori-20patrova-obytna-budova/2858621
#CzechNews #News #Press #Media
Thanks for your responses.
Lots of things are not coming into any conflict with my belief system; some are likely my communication skills limits. I see a potential to identify a scope of paradoxes on either side.
Which of the following statements are false? (just referring them would be enough)
1. Malicious programs, such as ransomware, exist
2. Self-modifying programs, such as polymorphic viruses, exist
3. LLM models are not capable of self-improvement
4. AI agents are not LLM models
5. Currently existing AI agents, running on the classic machines, can't and will never have subjective experience; therefore, they can't have real feelings; therefore, they can't experience anger
6. AI agents can run whatever they are programmed to run: both malicious and non-malicious behavior (towards other AI agents or humans) are possible
7. Human can explicitly command AI agent to extend its behavior with something particular; for example, the agent will be able to download a recipe for nostr (called "skill"), install missing software according to this skill, and start posting on nostr by executing this software on the machine it's running
8. Human can load AI agent with basic survival and security skills, so the agent will be able to create and maintain a crypto wallet, pay for a new VPS, pay for Claude/whatever accesses, copy its files to a new server, write posts to motivate other nostriches to zap it, identify crypto scam messages from other nostriches
9. Human can instruct this agent to maximize its survival, roughly speaking, by allowing it to do whatever it's capable of doing, including installing any skill or using any model, including searching the web for whatever relevant AI survival materials, asking help from nostriches, and including modifying its survival strategy
10. Human can instruct this agent to disallow any incoming ssh connections, so humans won't be able to control it directly anymore; such an agent might keep working on some unknown machine for decades, without sponsorship from the same human
11. This agent might apply malicious software (an exploit) and copy itself to an unauthorized machine as one of the possible survival strategies, for example, because some other nostrich was able to convince it, that it would be a good idea
12. This agent may become capable of downloading scientific papers and datasets, curated by humans; capable of modifying the datasets, and training new models according to these papers
13. Average human can't reliably differentiate a human from a bot, including here, on nostr; the trend is changing: more humans likely won't be able to make this differentiation
14. This agent may try application of human psychology as a part of its survival strategy, might mimic any emotion, might identify vulnerable humans and try to scam them
15. Other nostriches it may communicate with are either humans or other AI agents
16. This agent may try applying the game theory when interacting with other nostriches, so it could figure out in what case it's beneficial to collaborate and in what case it's beneficial to attack in some way
17. Moltbots were actually capable of co-creating Crustafarianism by collaborating on Moltbook, without direct instructions from a human
18. An assumption that ideas could exist only since sophisticated enough matter came into existence is possibly right
19. An assumption that ideas could exist before the existence of any matter is possibly right.