spacestr

🔔 This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.

Edit
Lightning_buck
Member since: 2023-02-23
Lightning_buck
Lightning_buck 1d

This is so fucked up.

Lightning_buck
Lightning_buck 6d

Driver took the worst way possible up that incline

Lightning_buck
Lightning_buck 14h

Why do you keep spamming this?

Lightning_buck
Lightning_buck 20h

Now that the weakness is leaked more hackers will come to exploit. In a few weeks every sat on a vurnerable coldcard seed will either be migrated by the owner or swept by a hacker.

Lightning_buck
Lightning_buck 10d

Form what I've seen all hosted mining is bordering on fraud.

Lightning_buck
Lightning_buck 19d

Ich denke das würde ihm sogar gefallen

Lightning_buck
Lightning_buck 25d

Tut mir leid, das war extrem unglücklich und dumm formuliert von mir. Ich wollte nur ausdrücken, dass ich es für extrem unwahrscheinlich halte, dass sich jemand aufgrund des posts von Markus in eine problematische Lage begibt. Dich hätte ich also nicht zu dem Kreis der "Kernbehinderten" gezählt, da du ja offensichtlich keine Steuern hinterziehen möchtest. Aber rückblickend sehe ich, wie man meinen Post wohl eher anders interpretiert. Entschuldigung dafür.

Lightning_buck
Lightning_buck 11h

I'm with you on not trusting that device or anything ever touched by coinkite. But by now we have a pretty good understanding of what the actual bug was. This blog post for example goes though the code line by line: https://wizardsardine.com/blog/coldcard-rng-vulnerability/ My earlier comment was not about how to use a cold card in a safe way, but on how the industry needs to evolve so that normies can figure out how to securely set up their storage. Again I don't thing throwing some dice is the difficultty, it is the confusion surrounding that process and actually finding the safest option.

Lightning_buck
Lightning_buck 12h

Where are you getting the information that you can't trust the dice that you fed into the cc? From what I have read from independent researchers 50+ rolls are still safe and moving funds would only be a precaution.

Lightning_buck
Lightning_buck 12h

I agree with everything being said in this letter, but I am not willing to sign yet. Priority in near term for NVK, Coinkite and the entire BTC space should be to minimize the damage. Everyone who owns a coldcard needs to be informed, that the device didn't do what he expected it to do. The next few days are a race between hodlers and hackers. Every vulnerable seed will be drained. Every second NVK has should be spent on finding new ways to inform his costumers of their situation. Yes, there need to be Consequences for his negligence and questionable business practices. But that should not come at the cost of hodlers. There will be enough time to have this discussion after the dust settles.

Lightning_buck
Lightning_buck 17h

Unlikely, someone would have noticed when they imported their seed + passphrase into a hardware wallet from another manufacturer, right? If a different private key was calculated on for example a trezor no UTXOs would show up.

Lightning_buck
Lightning_buck 17h

Rolling dice is easier than filing your taxes. The problem is not the difficulty of secure seed generation itslef. It is the lack of knowledge paired with no obvious path to obtain that knowledge. Most people who decided to use dice were either lucky, because they found good advice when they first set up their wallet (it's luck because they had no ability to actually verify the quality of the advice they were given at that point). Or they got educated enough by passively consuming content. If you listen to your 40 hours per week of podcasts you might stumble upon enough self custody discussion to make an informed choice. But I assume the number of people who actually took the time to do a proper deep dive before choosing their first setup is almost zero. My hope for the future is that we will get options to purchase insurance against u key generation. The insurance providers will have a financial incentive to quantify the security of each method of key generation to accurately price their contracts. Based upon their research they can design guides that their customers have to follow during setup. These of course would be as easy to follow as possible because the providers are interested in making their product usable for as many people as possible. And again, rolling dice or other methods of real world entropy generation is not that difficult. Once these well documented, easy to follow best practices exist everybody can use and benefit from them, even if they are not buying insurance.

Lightning_buck
Lightning_buck 18h

Except coldcard was known not to pay bug bounties. There were multiple instances where vulnerabilities were disclosed and no bounty was paid. A team of researchers received cold cards and coffee mugs for their disclosure 😂

Lightning_buck
Lightning_buck 5d

I was about to say that 😅

Welcome to Lightning_buck spacestr profile!

About Me

Test

Interests

  • No interests listed.

Videos

Music

My store is coming soon!

Friends