spacestr

🔔 This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.

Edit
Zsubmariner
Member since: 2025-07-24
Zsubmariner
Zsubmariner 1d

Coldcard: This is indeed a lesson about complexity, dependencies and why you should roll real dice for serious funds. My understanding is that Coldcard used MicroPython and libngu had an ifndef that only checked if the macro was defined, not if it was non-zero, so it didn't go to the chip as it should have. Classic macro footgun. This is a lesson about complexity and dependencies. Security-critical applications like this need to be as simple, direct and explicit as possible. MicroPython is convenient, but you bury the truth in deep call stacks of third-party code. TMK, Trezor and Foundation also use MicroPython, but I don't believe they use libngu. I assume they are checking for similar issues right now, but again, the deep, complicated, third-party call stack makes that hard to do well. I spent the last few days stripping down some call stacks that had gained layers of indirection and conditionals in our codebase for exactly this reason. We have almost zero dependencies and take pains to write simple, explicit code that uses the machine directly. In Zig, which I would and do argue is the best language for this kind of work. (And no, Rust doesn't fix this. Rust is a pile of frameworks and has a JS-like dependency sprawl problem. "Use Rust" is not going to save you.) That said I'm not throwing the engineers under the bus on this. We tend to go for blame on these things, and I definitely get being angry, but focusing on "bad person" tends to distract us from "broken system". This is one of the core tenets of Disaster Recovery as a discipline, for good reason. The fact is, something like this could happen with almost any wallet. Here's the most important lesson: the best way to generate critical entropy is a pack of dice and a shoebox. This has been the received wisdom of serious cryptographers since long before Bitcoin existed. This is how we've been generating our PGP passphrases for decades. It's easy: a five-year-old can do it. You put dice in a shoebox, shake it, read the numbers and look at a list of words. Dice are available at your local toy store. Roll real dice. Not your dice, not your entropy. Trust yourself.

Zsubmariner
Zsubmariner 17d

Or they should. And on honest money they will.

Zsubmariner
Zsubmariner 1d

Rolling dice is not hard. Keeping your entropy is currently hard because the tools still suck but it doesn't have to be that way. The market is still selling us the problem instead of solving it, but that won't last forever.

Zsubmariner
Zsubmariner 17d

😂 Decentralized Dad Jokes

Zsubmariner
Zsubmariner 1d

Use dice.

Zsubmariner
Zsubmariner 17d

Love this. Mercenaries suck. (Site crashed Vanadium on my Graphene phone though.)

Zsubmariner
Zsubmariner 17d

THIS is how Bitcoin on the balance sheet actually works. Not fiat-style zombie companies buying Bitcoin in leverage and playing stupid financial games. THE JUICE IS LOOSE!

Zsubmariner
Zsubmariner 19d

I agree, it's a steep hill. But if we fail, it will be on execution (my fault) and the next team will have to crack it. At the end of the day, either the cypherpunk thesis was wrong, or we still need a general-purpose personal cryptosystem that regular people can actually use. Steep hill or not, it's not optional and it's one I'm willing to die on. That said, I assume I am wrong about plenty of details, so please let me know if you see any problems or better options. I'd genuinely love to hear them. Thanks for digging in and feel free to reach out anytime.

Zsubmariner
Zsubmariner 21d

It expired last night. Fixed. Thanks for the report.

Zsubmariner
Zsubmariner 23d

Thank you, sir!

Zsubmariner
Zsubmariner 23d

Zsub is a general-purpose personal cryptosystem. Here is what that really means. Personal computers were the missing infrastructure that unlocked the value of software. The cypherpunk vision of transforming the world with strong cryptography has not materialized because we've been missing the equivalent infrastructure. All cryptography architecture begins with root of trust. The correct root of trust must be the responsible person. The correct primitive is a seed in self-custody. This just isn't negotiable. This is why I say the seed is the crown jewel of cryptographic primitives. I don't say "Bitcoin seed" because the seed is NOT a feature of Bitcoin. It's the infrastructure that it runs on. Bitcoin runs on the seed. Nostr runs on the seed. SSH runs on the seed. Supply chains run on the seed. Authentication runs on the seed. Encrypted messages run on the seed. Secure networks run on the seed. ... That means what we need is to own a seed, operate it across all the contexts of our lives, and apply it all the things we need to use. A system that does this for everyone has to hold and operate that seed securely, map it invisibly onto normal human actions and trust decisions, and integrate with the things that matter. Some people say it's too hard. And true enough, it's not easy. But if we call ourselves cypherpunks, then this is the job. And it's what we're building. Zsub is a general-purpose personal cryptosystem. It's personal because the root of trust is you. It's general-purpose because the applications are many, but you are one. Strong cryptography is for everyone. https://zsubmesh.net/

Zsubmariner
Zsubmariner 27d

Hey, Luke! Very excited about your book, ordering right now. I wanted to make you aware of what we're building. https://zsubmesh.net I'll try you by DM and perhaps we can chat sometime. I'd love to get your input on our work.

Zsubmariner
Zsubmariner 28d

🎇 New release from Zsub: secure transport layers. This repo contains the transport stack we will use for Zsub integration: - Keel: secure link protocol: fixed cell, mutual auth and double ratchet. - Submerge: reliable transport protocol: chunking, reassembly, and repair. - Surface: the overlay traffic envelope for L2 and L3 traffic. - Mooring: cross platform virtual interface manager. Code, docs, and protocol drafts are up. Comments welcome. This gets us very close to the final integration step and the first release we will properly call Zsub. https://codeberg.org/Zsub/Keel Happy 250 and GN!

Welcome to Zsubmariner spacestr profile!

About Me

Not your keys, not your network.

Interests

  • No interests listed.

Videos

Music

My store is coming soon!

Friends