Bring your own entry.
๐ This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.
Edit
Bring your own entry.
Can we stop using AI slop? The what happens section is just completely wrong in that image.
Not sure if it applies to you honestly, but with all of these statistical things, it always feels like the best things feel the least intuitive. We just cannot trust our guts ๐.
If you plug that shit into a 9-volt battery, then you were either playing make pretend or you really didn't trust that piece of shit hardware. If you didn't trust that piece of shit hardware, you shouldn't have been using the built in RNG.
One thing that alludes me is that if it really is just a low entropy random number generator, then why has it taken so long for these funds to be discovered and swept? Why now suddenly?
On that repo is also a video and a link to slides. Useful for context.
Multisig is not the answer. It's not _not_ the answer, but people will spend hundreds of dollars to avoid doing the work themselves simply due to ego. You are not too good to get pen and paper and dice.
Yeah, I made something that we can use bit it can be refined for sure and it's original intent was to help people experiment with seedxor but I have used it just to create one key from dice rolls. Honestly I've started to make a guide/walk-through a couple of times, but the main issue is the complexity of that last word is hard to explain. Anyway: https://github.com/dipunm/seedxor/blob/main/assets/dice-xor-instructions.md Skip the following headings: - Repeat for B - XOR time - The final set of seed words And yeah, I doxxed myself. Fuck it.
The fecal matter: John Doe is a scientist who studies feces for a living. When he runs out of containers, he must take matters into his own hands.
Its the industry. Hardware wallets are here to do a job, that job is not creating seeds and it is not guaranteeing that you can't lose your keys. People got the second rule, now they need to get the first. The industry wanted to make themselves more saleable so they included and promoted their convenience based bad practices. Now we pivot. Devices need to advise people to do it the right way just like they convinced people to write down and look after their seed words on top of having a device. These devices still serve a purpose, but the two selling points were never their primary purpose. is probably the only one that got it right to be honest. I think I'd like to see them downplay the camera based seed word generator too, because no company is ever going to guarantee their own seed generators, so we need to promote DIY guides more aggressively now.
The market doesn't care. Maybe this is a sign that the cold card community was not as big or as much of the market at least needed to move the market. If this will ledger or one of the shit coin devices, the market would probably have moved.
This reads/sounds like theater. Like he's just trying to pretend he's Julian or something. But he doesn't look or sound prepared enough to face the consequences, as if he knows there will not be any... Probably because it's all just a story.
Abc. Airgapped bitcoin computer. Oh I remember those discussions fondly. It's not like no one was raising the red flags, they just got drowned out.
So that means there's a chance that we can track down the original thief?
Even if you use multiple entropy sources. If I can't observe the source and verify the result myself, it's no good.
Invite code for the welcome group?
A rare post that actually says what I've been saying. I still think the need to sell hardware wallets has caused of what a hardware wallet is supposed to be and how useful it is and is not supposed to be all in the name of sales. In hindsight, we should push for it to be common practice for devices to warn users that generating keys on device is not guaranteed to be 100% secure and to propose rolling your own entropy. By the way, even supplying dice rolls to a device is not good enough. If you can take that entropy and turn it into 11 words yourself then when the device gives you your 12 seed words, at least you can compare notes and know that the computer is using the entropy you provided.
Create your own entropy. Everything else is just extra. Create your own entropy. Create your own entropy.
Yes yes, but now we must learn from this mess. Unless you are ready to insure all of your customer's bitcoin, disincentivize using the RNG and promote physics based and self verifiable entropy the same way we all promote writing down your seed words because people kept assuming their devices were their be all end all as you all initially marketed. What do I mean by verifiable? Even if you allow users to enter dice rolls, they should be able to follow a worksheet with pen and paper and no computer and see at least the same first 11 or 23 words derived from their source numbers. Without this, we are still trusting your device.
When the boss says, "you said 1-2 weeks, so I booked us in to show it off on Friday. I know you won't let me down."
I 100% agree, but don't forget that the mocking happened in both directions. And humans are humans. When you tell someone to put in the work they are going to resist and they are often going to be very mean about it, and they are often going to rub it in your face for as long as all the things that you tell them could go wrong, never goes wrong. Finally, we have a real world story that we can use to get people to take us seriously. This one hit hard. We will get better. Sometimes things need to happen before things can get better.
Don't like dates, also they are high in sugar.
It did not affect self custody, it affected halfway-house self custody. This is the only way we can learn unfortunately. It's super sad, super unfortunate, very stressful and pretty disastrous. But those who told you how to avoid this type of situation we're being ignored and maybe even laughed at Probably more laughed at by the people who just kept their shit on exchanges but, still.
Nah, I think it is the opposite to all of our shortcuts and attempts to put security second to convenience. Cryptography is sound and the source entropy was always its achilles heel. Cyprography always advertised that it is only ever as good as the entropy you give it.
Dates... Why not sausage???
Just do not open.
Do right for everyone by promoting this: - roll your own entropy - secure your seed words yourself - use low bandwidth communication channels when interacting with a signed (air gap). Let's build and PROMOTE the tools that guide people to do it in front of their own eyes, not the tools that _promise_ to do right by you _this_ time. Let's push back harder on the people that say it's too hard or not worth the effort. Even entering dice rolls into a computer is not secure enough... How do you know that the seed words it generated was directly derived from the numbers you gave? There are worksheets that can guide you through deriving your seed words from dice rolls or other natural entropy and although it is frustratingly annoying that you can't get the last word without the computer, if you do it and the computer gives you the same 11 or 23 words, you know you've left very little room for the device to bamboozle you. Most of the entropy is honestly yours. Funnily enough one of such worksheets was based on a worksheet created by NVK: https://github.com/dipunm/seedxor/blob/main/assets/dice-xor-instructions.md Based on https://seedxor.com/files/worksheet.pdf Note that the purpose of this particular guide was to use seedxor to provide secure seed splitting and multi-sig-like capabilities for people who aren't sharing their wallets with a co-hort, but the gold is in the beginning where you create your own seed words using physics. The closest thing we have to real entropy (if you believe we live in a simulation).
Calculators calculate. Users provide the numbers.
Big Barry Bitcoin - Bitcoiner, pleb, developer, enthusiast, ๐๐ฉcoins Check out my nostr blog! https://big-barry-bitcoin.npub.pro/