spacestr

🔔 This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.

Edit
waxwing
Member since: 2023-02-09
waxwing
waxwing 36m

A guy is claiming a 750K bounty for finding the zcash infinite inflation bug and not exploiting it. A lot of gushing in the comments about how great this guy is. But he literally, logically, cannot prove he didn't steal any zcash. Maybe if they turnstiled 100% then there would be retroactive proof but that seems practically impossible, for the same reason they couldn't do it for Sprout.[1] There was over $2B at stake, zero chance it'll all be cleaned out. Sure, the great unwashed are not going to get this. But there are no experts correcting them. https://forum.zcashcommunity.com/t/retroactive-grant-application-orchard-counterfeiting-vulnerability-bug-bounty/57008 [1] same reason we can't post-quantumize 2009 btc!

waxwing
waxwing 5h

I doubt I'd agree with the author on the prognosis, but, good article. Thanks.

waxwing
waxwing 6h

Yeah i was wondering about that angle. I doubt it's enough though. There is real additional knowledge developed from practice that's not in hardware manuals.

waxwing
waxwing 3d

I see people making the argument that the Coldcard bug was a result of the fact that the license prevented others from using their code in products, so there wasn't enough incentive to audit it. I strongly doubt it. I bet a *lot* of people did examine it, but didn't spot the error. And unlike every other piece of functionality --- apart from entropy generation --- just looking at the output, even looking at hundreds of outputs, wouldn't have revealed the bug.

waxwing
waxwing 13d

I always had a gut reaction against dice rolls. Reflecting seriously, I have to reluctantly agree it's a solid concept. But: why that gut negative reaction? Not because the number of bits is not exactly what you think because of some complex mathematical calculation. Instead, it's two related principles: 1/ complexity is the enemy of correctness. This is a lot of extra manual steps. 2/ I made up a "law" a long time ago: every time a user sees their secret key on a screen it cuts their security in half. This is a gray area: you may be entering the key material in chunks, and also a 'screen' on a hardware wallet is not the same as a computer screen. I've come round to it over the years, it's a sensible idea, but I'm still slightly suspicious. We should be focused more on an audit step: however you generate the entropy, is there a way you can check the process is working? Dice rolls don't fit that idea so well (compared with machine-seeded). I'm reminded of an excellent point Gmax once made abou wallet dev: when you generate addresses for users, you should sanity check that you can actually sign against it, before giving it to the user, so they don't send their money to a black hole.

waxwing
waxwing 10h

i wonder if we're heading into a weird limbo: have an obscure technical question about tech? you ask AI, of course. But the AI's knowledge of things like, I don't know, network cards, comes out of a corpus of humans babbling about it on the internet. we used to use tech forums to discuss such things and that's where you used to go; and that's where AIs go (and went, in training) to siphon up tidbits of knowledge. But nobody is going to ask in tech forums if the AIs give better answers. So what happens in 12 months?

waxwing
waxwing 4d

Would be funny if Dario and Sam and their EA friends all end up being right - but that AGI escapes containment and starts destroying humanity via the Chinese open source models.

waxwing
waxwing 4d

Another possible break on a (in this case *long established* PQC scheme (McEliece)): https://eprint.iacr.org/2026/1630

waxwing
waxwing 5d

If you are praising libsecp256k1's code quality, then 2 things: 1/ you are very right. It is outrageously well tested and high quality. 2/ it deliberately omits the most dangerous thing: generating entropy, leaving that to the caller (where it's needed, which, thank god, isn't very often).

waxwing
waxwing 5d

Anyone confused by Luke-Jr's response to today's events hasn't been paying attention for the last 15 years.

waxwing
waxwing 6d

https://ocean.xyz/docs/20260807-maintenance "once the situation is unambiguous (a single sharelog operating)." ?

waxwing
waxwing 6d

This is better than the world cup.

waxwing
waxwing 6d

Do we have a fork? https://bip110.orange.surf/live.html I guess not until there's a 110 signalling block mined. This will be a bit of a damp squib unless they get lucky, I guess.

Welcome to waxwing spacestr profile!

About Me

Bitcoin, cryptography, Joinmarket etc.

Interests

  • No interests listed.

Videos

Music

My store is coming soon!

Friends