For anyone worried by the Coldcard vulnerability today and wondering how Trezor generates a seed, hereās there explanation: https://trezor.io/guides/trezor-devices/trezor-fundamentals/what-is-entropy-and-how-does-trezor-generate-your-wallet
Any miner thatās unwilling to take a 0.01% hit in revenue to protect the long term success of Bitcoin as money is a bad actor. They would rather kill the goose that lays the golden eggs than protect it.
Over the past 950 blocks (approx. 1 week) that earned around $193M in block rewards, according to the Bitcoin portal BIP-110 simulator, BIP-110 would have blocked spam that paid $18k in fees and consumed 5.7% of block space. Thatās less than 0.01% of mining revenue to protect 5.7% of block space. https://thebitcoinportal.com/live/nodes/bip110-simulator
Glad you have read the BIP. What part of it did you disagree with?
Also - donāt take advice from random people online - there will be scammers trying to take advantage of the panic.
Here are the brands he recommends: https://www.willapproved.com/
Coinkite currently claims open dime is not affected, but they also previously claimed MK4/5/Q were not affected but now say they are. If you have known secure non-Coinkite hardware wallets available, that is what I would be moving to. Be careful - donāt lose funds by rushing too much and making mistakes. Their advisory is here: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
I watched the first couple of seasons, then stopped. Is season 3 any good?
Will Prowse hates them: https://youtu.be/1xlvM2fpFGM
It looks like they didnāt test a code change to ensure it still had sufficient entropy (randomness), and since generating a wallet based on randomness is one of the most important things a hardware wallet does, thatās a pretty bad bug to introduce. Their design also seems less secure than for example Trezor that combines multiple sources of randomness from hardware and software in a way that if one source failed to be as random as it should be, the overall result would still have enough randomness.
Yeah - the idea that Bitcoin needs STRC to be money is nuts and shows you how Saylor has taken things too far with his financial engineering. Bitcoin already is money - people buy your wine with sats.
Some stores like Best Buy sell Trezors and you can pay with cash to not dox yourself.
The white paper called it a āpeer-to-peer electronic cash systemā. Thatās never been what Saylor was about. He saw it as a āstore of valueā hedge against fiat money printing, which it is. Then, because he is incredibly smart and one of the first to realize the opportunity, he wrapped it in a Wall Street friendly way and pumped MSTR sky-high. Now heās gone way out in front of his skis with STRC, and heās feeling the pain. If he ever buys your wine himself (not an assistant) and pays with sats, then you will know heās truly using it as āmoneyā which is a medium of exchange AND a store of value.
Mechanic said he knows someone who had an MK4 drained today. I would assume itās possible they might have moved a seed that was generated on MK3 to MK4, but itās also possible that MK4ās low entropy is within reach of the amount of compute thatās being thrown at this attack. Safest bet is to carefully move funds from any Coldcard to a new known high entropy wallet (and Coldcards new firmware claims to fix the entropy bug on MK4/5/Q, so it might be possible to reuse some devices if you still want to trust Coinkite).
Yes - and the appropriate response is to not run that shit. We need more options Knots vs Core is too easy for people to argue about - needs to be more like cars or Linux distros. Some people still argue, but at least thereās a lot of options.
There are people who claim to have reproduced the vulnerability, and Coldcard updated their announcement to acknowledge MK4/5/Q are also much lower entropy than they should be but not as bad as the MK3 with the affected firmware.
Ben - you should stop listening to the influencers who need to go to the Bitcoin conference every year to grow their number of followers. Itās run by David Bailey who invested in a LOT of spamming companies. That means influencers need to sit this one out or attack BIP-110. If they support BIP-110 they might not get on stage in Nashville next year. Arbitrary data is harmful for node operators. It doesnāt matter if it is because they worry about legal, ethical, moral, or resource concerns - thatās their personal decision. As node operators decide not to run nodes anymore, nodes gradually get centralized like mining pools and miners already have and Bitcoin will be easier to capture. When you send an on-chain payment transaction that typically uses less than 300 bytes (you can verify this by opening your Bitcoin wallet and clicking the link to see one of your transactions in the mempool). Even opening or closing a lightning channel that uses multisig and time locks is typically less than 600 bytes. On chain payments and lightning channels account for almost all financial use cases in Bitcoin. So⦠that begs the obvious question of who needs 100,000 bytes of OP_RETURN data for a monetary use case? Enshrining the 83 bytes OP_RETURN limits from before Core v30 in consensus rules so even if node filters get bypassed by miners, those transactions are still invalid is the main thing BIP-110 achieves. It also causes minor disruption to ordinals and limits how much data can be embedded in some scripts. Perhaps most importantly, it signals to VCs that spam is not welcome so they should reconsider before investing in spammers. Take 10 minutes to read the BIP. Thereās going to be nothing there that you disagree with. That will get you to start questioning what your heros have told you about the BIP. https://bip110.org/
The spec and rationale take about 10 minutes to read. Itās quite clearly explained and easy to understand: https://bip110.org/
Itās been a catastrophic day for many Bitcoiners who lost a lot of money - lawsuits seem likely.
Please take 10 minutes to read the BIP. Itās explained fairly clearly and includes answers to most questions youāre likely to have. Thereās a big difference to a VC between virtue signaling and actual protocol changes that periodically disrupt a business that is maliciously abusing the protocol, because future protocol changes might one day wipe that business out. Hereās a couple of relevant parts of the BIP for this particular thread: āRequiring users to divide their files into chunks of at most 256 bytes, raising the cost both in fees and in effort, sends a clear message that data storage abuses in general are unwelcome rather than sanctioned or supported.ā āActivation of these new rules thus sends a clear message that arbitrary data storage will continue to be actively resisted, and that such unsupported usage should not be permitted to derail network priorities.ā I replied in good faith, but unfortunately I think youāre just a troll. Maybe this will help someone else. https://bip110.org/
Itās not virtue signaling. Through consensus tightening, BIP-110 closes the OP_RETURN spam vector that already existed and then Core v30 made convenient and anonymous. It also causes minor inconvenience to some other spam vectors, and shows that action will be taken against non-financial use of the protocol. Virtue signaling like going on podcasts does almost nothing to deter VCs who fund spam companies. Occasional disruptions that force spammers to modify how they inject spam makes VCs wonder if a future change might destroy that spam business. So at least some VCs will decide not to fund spammers that are abusing the network. Even anti-BIP-110 Odell says Ten31 wonāt invest in companies that need a protocol change. Thatās essentially the same as only investing in companies that play by the FUTURE EXPECTED protocol rules. If a spammer is outside the accepted protocol use and the protocol is periodically pruning out those malicious uses, thatās not a safe investment because you should expect that the protocol may block it in a future release.
Welcome to Anonymous spacestr profile!
About Me
Interests
- No interests listed.