When I first took the orange pill after learning about the difficulty adjustment and having the “aha” moment, I was all set to self-custody my stack. Then I realized I had to use someone’s software to broadcast transactions and set up my self-custody hardware the standard way (granted, I could roll dice to generate it offline, but even then I’d need to connect to software to move coins), and it struck me as the most vulnerable part of Bitcoin hodling. Using FOSS mitigates the risks tremendously over closed source, but I still stand by that part of the tech stack being the most worthy of caution. Self-custody remains infinitely superior to trusting a third party to hold your keys if you know what you are doing, but it requires eternal vigilance.
The duality of the coldcard fiasco is that it is both worse than Mt Gox in that it happened to Bitcoiners who adhered to “not your keys, not your coins,” and at the same time it is far less bad than Mt Gox in that 1K BTC was taken vs 850K, so it’s barely registering in the market cap or as a mainstream news story.
Open source > closed source Multiple vendors > one vendor Multi-signature > single-signature Multiple baskets > all in one basket Offline entropy > random # generator
Possible.
To be clear, the coldcard bug could have been exploited even without the use of AI, so AI is no excuse for the coinkite team’s oversight. Still, the impetus to assess other hardware wallet vulnerabilities using AI in light of this event has been a welcome trend.
To be clear, the coldcard bug could have been exploited even without the use of AI, so AI is no excuse for the coinkite team’s oversight. Still, the impetus to assess other hardware wallet vulnerabilities using AI in light of this event has been a welcome trend.
Just as it takes a good guy with a gun to stop a bad guy with a gun, it takes a good guy hardening systems with AI to stop a bad guy finding exploits in those systems with AI. One of the silver linings of this recent coldcard exploit is it has spurred white-hat hackers into action. And thankfully, cryptography itself favors defenders.
This Aussie interviewer didn’t get enough credit at the time for asking real questions.
The Saylor simp era is ending. The Bitcoin era has just begun.
PSA: Bitcoin nodes are not some magical public utility that exist only in the cloud. In my case, it is literally a hard drive and Start9 OS in my living room. My full node is not your Dropbox.
Bitcoin is a monetary network.
There is more to life than magic internet money.
♥️
Tools change. Principles endure.
Welcome to alanbwt spacestr profile!
About Me
"This is it." Author @npub109gj5765thuet2hj2nk2j9r89a03xm2cpd0jp8rel2mqd68cn04s5wvahd | Dev @npub1fjh05rc223et4emdwex3ec34qya339szfe2w6yf8vcguuqrclh6s8us2yr
Interests
- No interests listed.