Author of Defending Bitcoin: Industrial Cybersecurity for the Monetary Grid. Co-founder of BTC HEL Co-author of Bitcoin: The Inverse of Clown World Producer of the Bitcoin Infinity Show
Public Key
npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld Profile Code
nprofile1qqsymrmayr3t54hru0q5w4pfxn6s4pz6j7q60ugsxutajk2ahs0dh8gpp4mhxue69uhkummn9ekx7mqpz4mhxue69uhhqatjwpkx2un9d3shjtnrdakse5zwdu
Show more details
Published at
2026-05-10T17:14:15Z Event JSON
{
"id": "eacc326982592efb0ba732b461528f7fc63736cf79a12efbef44b4c3581fa63c" ,
"pubkey": "4d8f7d20e2ba56e3e3c147542934f50a845a9781a7f1103717d9595dbc1edb9d" ,
"created_at": 1778433255 ,
"kind": 0 ,
"tags": [
[
"client",
"Primal Web"
]
],
"content": "{\"name\":\"lukedewolf\",\"about\":\"Author of Defending Bitcoin: Industrial Cybersecurity for the Monetary Grid. \\n\\nCo-founder of BTC HEL\\nCo-author of Bitcoin: The Inverse of Clown World\\nProducer of the Bitcoin Infinity Show\",\"lud16\":\"[email protected] \",\"nip05\":\"[email protected] \",\"picture\":\"https://blossom.primal.net/741de5ab4158f5ddc79b6082bcb492e605ec0f85f7abe754bcd1e22c9d4922cf.jpg\",\"display_name\":\"Luke de Wolf\",\"website\":\"https://defendingbitcoin.com/\",\"banner\":\"https://blossom.primal.net/0becc47fbea1794fd7781444b70c6037d52a36d91e79c08adc871e621b3a4a37.png\",\"displayName\":\"Luke de Wolf\"}" ,
"sig": "dd8c1e757396cd56d1c57d261d1ed5c161284d42648a4f5cb3f10b753e624ab4de31c1a215aa465049da55f37c3a16a741e2b7b3c4a5fe65fcb566014491fd6d"
}
Last Notes npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Tldr since the Guy interview: I find 110 activating smoothly to be the least risky and least chaotic scenario. I was getting the game theory steps a bit wrong. Something longer coming when I have time to write everything down. Also a few more pods. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Apparently you haven't kept up with my X. I should really make an update on both platforms. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf There is no reason for this. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Knots on StartOS, mining with OCEAN using DATUM. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf This bot account is a deranged moron who apparently thinks I'm pro spam. GTFO. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf The vast majority of Bitcoin users have no idea BIP110 is even happening. Disruptions to the ability to use Bitcoin as money should be avoided. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I content myself knowing that you're completely wrong. Feel free to point out why you think my book is "AI slop". If you don't want to do that, kindly fuck off. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Disagree. If a user's transaction gets mined in a non-compliant block, that transaction will be in conflict. Double spending will be possible on the margins. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks, I appreciate that! I came to my position through writing Defending Bitcoin. I wrote a risk management book. I evaluate the risk of profoundly negative outcomes if BIP-110 causes a chain split to be too high. Frankly, my real position might be that I support it after all (because I still mostly support the changes, I have specific technical objections that aren't direction ally important), but only if those signaling/enforcing drop it immediately if it looks like it's going to end up with a tiny minority of hash rate and just fork off. In other words, try it, see what the outcome is, but don't cling to a dead-on-arrival fork if that's the result. I believe Bitcoin will survive with or without BIP-110. The "with" scenario would be truly positive in my view. A user-activated rebuke of both arbitrary data and the prevailing governance structure. I'm all for that. The "without" scenario is what I'm worried about. I don't want all the monetary maximalists to leave if this soft fork fails to activate and become the longest chain. I don't think making this an all-or-nothing effort is right. And, in the case of failure, there will be much gloating from on high and ridiculing of those who prefer less arbitrary data on Bitcoin and are uncomfortable with Core's governance. In Defending Bitcoin itself, I don't even say "don't support BIP-110." I highlight the potential risks of a chain split, and say DYOR. Know what you're getting into. At this point, I see that the momentum for BIP-110 is absolutely there. Almost half the plebs I met at BTC Prague said they were pro-110 or considering supporting it. The only opposition I heard was from devs. But there are also smart people in the space who support its goals but don't think it will activate. I'm in that camp too. I don't know how to square these positions. My internal schelling point landed on not supporting BIP-110, but I'm not sure that's totally accurate anymore. Perhaps more accurate would be that I support trying, but giving up quickly if it fails. The problem is that we're dealing with individuals. I have a feeling or even know that many people will either continue to support the minority chain or just give up on Bitcoin entirely. This is kind of a chicken and egg problem now. If it's going to happen anyway, does my support or non-support make any real difference? Either way, come August 7th, I'm still going to be here. And dealing with the fallout of BIP-110 being unsuccessful, if that's the case. I don't know if that clarified anything for either of us. But those are my thoughts. Take them as you like. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf See here. #nevent1q…mjyj npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Look at any of my highlighted X posts, listen to any of my recent podcast appearances, or any Bitcoin Infinity Show / Feeedom Footprint Show from about the middle of 2023. But this is good enough to show I've been anti-spam since the beginning: https://x.com/i/status/1766696720572830088 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I don't believe the "good" outcome is likely. That's why I'm not supporting at this point. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Care to tell me why you think that? Did you read it? npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks so much for your support, Jeff! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I'm extremely anti-spam. I don't believe a soft fork that has consensus is the solution. I believe it will do more harm than good. I have receipts. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Haven't been for a while. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Defending Bitcoin is out! It's available now on Amazon in paperback, hardcover, and ebook editions. Pick up your copy today! This is Bitcoin cybersecurity through the industrial lens I've spent the last decade working in. Defense for your Bitcoin and defense for the network. From custodial failures to quantum computing, the full threat landscape is here. Huge thank you to everyone who helped with this massive project. I couldn't have done it without you! https://blossom.primal.net/678ab8b5ca6800770239bcce042d3fcbcd19e431cc144c599f5d379c2c149e4f.png npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Check out my latest podcast appearance on The Bitcoin Way podcast. These guys are on the front line of Bitcoin security, and I thoroughly enjoyed our conversation! #nevent1q…nyc6 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I appreciate you Michael! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I had a great time telling Daniel all about Defending Bitcoin. Give it a listen to find out more about the book! We also cover the BIP-110 situation in quite a bit of deal, with my current reasoning made abundantly clear. #nevent1q…3hac npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf You can download it again yourself. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf https://blossom.primal.net/37d93128dfe4bcc0694e0ea9beb8dfb2d88970e72c307ba61a96955237466d77.jpg This is where the cybersecurity side of the book starts. Chapter 3 walks the core concepts the rest of the book runs on, in plain language. It opens with the CIA triad (just a coincidence, I promise!), the three properties cybersecurity defends in every system. Confidentiality keeps information from anyone who shouldn't have it, integrity keeps it from being altered without authorization, and availability keeps it reachable for the people who need it. Every threat in Part II maps back to one of those three. From there it gets into threat modeling, which is a structured discipline rather than a vibes-check. Before you defend anything, you ask who the adversary is, what the asset is, where the attack surface lies, and what the mitigation looks like. Run that formally and some threats turn out to be less important, while others turn out larger than you'd expect. Then comes defense in depth, which is just the principle that you never lean on a single control. You layer them so each one stands on its own, and a failure in one doesn't cascade through the rest. The chapter walks how to design those layers so the whole system doesn't unwind from a single point. We also formally define the concept of risk, measured as likelihood times impact. A threat that's devastating but unlikely calls for different controls than one that's common but survivable, and that matrix is how Part II keeps everything in proportion. Without it, the threat chapters that follow would read like a long list instead of a prioritized map. By the end, you've got the cybersecurity vocabulary that the rest of the book depends on, and the bridge from "I hold Bitcoin" to "I'm responsible for defending a system I have a stake in." npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Write a review on Amazon if you've read and liked Max's book! It helps the algorithm and gets this book in front of more eyes. Fiat bullshit and all that, but it works. #nevent1q…zj4g npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Max's book is seriously excellent, check it out if you haven't already! #nevent1q…yfw3 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Sounds excellent! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Cheers Roger, it looks great! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Happy to do it, let's talk! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf At least I hope it's interesting! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Looks great! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I want to talk about Defending Bitcoin on as many podcasts as possible and get the word out. Who would you recommend I talk to? Any Bitcoin podcasters here who would like to have me on? #nevent1q…435q npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf The effect is even worse in a permissionless system. Can't stop the things from getting out into the wild. Warning against doing stupid things is one of the only forms of recourse. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I think this falls into the category of just because you CAN do something. doesn't mean you SHOULD. Nobody should use this, IMO. But, like many things, looks like it's getting built. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Look inside my upcoming book, Defending Bitcoin: Industrial-Grade Cybersecurity for the Monetary Grid 👇 https://blossom.primal.net/678ab8b5ca6800770239bcce042d3fcbcd19e431cc144c599f5d379c2c149e4f.png First, the Foreword by Mikko Hyppönen. One of the most widely-respected figures in cybersecurity with his own take on Bitcoin. I'm grateful that he agreed to contribute his view to the Defending Bitcoin! Next the Introduction. My story of how I started in the Industrial Controls sector, then found Bitcoin, and merged the two worlds. Also goes over the format of Defending Bitcoin. Part I is the introduction to Bitcoin and Cybersecurity, forming a basis of vocabulary for readers familiar with either or neither subject. Chapter 1. Bitcoin — The Decentralized Protocol All about Bitcoin the technology, written for technically-minded readers who don't know about how Bitcoin works. Chapter 2. Bitcoin — The Hardest Money Ever Made All about Bitcoin the money. What makes Bitcoin's monetary properties different from every other money in history. Chapter 3. Cybersecurity Fundamentals — The Universal Shield The vocabulary of cybersecurity based on industry best practices. What is risk, what are threats, vulnerabilities, controls. Everything we need for the rest of the book. Chapter 4. Industrial Control Systems and Securing Critical Infrastructure How critical infrastructure is defended differently from traditional cybersecurity. Includes a primer on industrial control systems and critical infrastructure so my the comparison to Bitcoin makes sense. Chapter 5. Bitcoin as Critical Infrastructure — The Monetary Grid The core thesis, that Bitcoin is the first decentralized critical infrastructure for money and should be defended the same way we protect power grids, pipelines, and factories. Part II is the Bitcoin Threat Landscape. 10 chapters of threats on an individual and network level, and what we can do about them. Chapter 6. Exchange and Custodial Failures From Mt. Gox to FTX, why custodial Bitcoin keeps blowing up, and what that means for your stack. Hint: the answer is to get your Bitcoin off the exchanges and into self-custody. Chapter 7. Securing Your Bitcoin: Personal Defense of the Private Key The full personal custody chapter, covering hardware wallets, multisig, seed phrase handling, and inheritance. You have the responsibility to secure your Bitcoin. Learn how here. Chapter 8. Privacy, Physical Security, and Staying Safe Privacy on-chain, OPSEC off-chain, and maintaining your physical security when people know you own Bitcoin. Huge shoutout to the excellent Praxeology of Privacy by @nprofile…8p0e , read that after this chapter. Chapter 9. 51% Attacks and the Decentralization of Mining What a 51% attack would actually look like, why mining concentration is important, and how decentralized the hashrate really is. Includes practical steps to do something about it, as always. Chapter 10. Node-Level Threats and Client-Side Defenses Everything to do with the security of your node, including all the work being done to secure Bitcoin node software, and what they defend against. Run a node, stay secure while you do. Chapter 11. Arbitrary Data and Witness Abuse An overview of ordinals, inscriptions, and arbitrary data. You may not think these are a problem. I lay out why it's a cybersecurity issue and makes Bitcoin worse as money. Chapter 12. Governance Risks. An honest examination of the risks Bitcoin faces from development centralization, and what can be done about it. It's not one-sided, though. I also cover the risk of changing Bitcoin, especially without wide consensus. Chapter 13. Political and Regulatory Threats Bans, surveillance, KYC, and mining restrictions, plus the realistic ways Bitcoin survives state-level pressure. Chapter 14. Grid and Network Failures: Keeping Bitcoin Alive Offline What happens when the grid goes down or the internet gets cut, and how Bitcoin stays alive offline through mesh networks, radio, and satellite. Chapter 15. Emerging Threats: Quantum and AI Full coverage of the latest developments of Bitcoin and Quantum. No FUD, but it's not something we should ignore. Also includes coverage of AI as it affects everyone more and more these days. Conclusion We end summarizing everything together, and it's optimistic! Defending Bitcoin isn't about doom and gloom. It's about knowing what's out there, and finding out what you can do about it. There's always something you can do. Always. Appendices Included in the print book are glossaries of cybersecurity and Bitcoin terms, and a section of recommended reading across all topics. Further resources are available on defendingbitcoin.com, including a threat model worksheet where you can find out how the threats in Defending Bitcoin apply to you. No data collection, I promise! You can see more about the book at the Look Inside page, including the full foreword, introduction, and previews from two chapters. https://defendingbitcoin.com/read Reminder, Defending Bitcoin will be available on Amazon and bitcoininfinitystore.com from June 15th, and the first physical copies will be available at @nprofile…py4c - come see me there and get a signed copy! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf @nprofile…nq3e doesn't bite! Finland’s Bitcoin community is amazing, I'm proud to be a part of it! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks, issue with the epub renderer, I'll fix it. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Max's book is fantastic. A much-needed contribution to the space! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Great to hear! Let's talk. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Very cool! I have my own webshop, bitcoininfinitystore.com, with @nprofile…ddf9, and we accept Bitcoin from there, but maybe we can discuss collaboration! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Always. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Congratulations! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Both! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks! Looking forward to your thoughts. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf It is a Bitcoin maximalist perspective. Although it's really simply a Bitcoin perspective. Other cryptos are essentially not covered at all. Some of the security practices will absolutely apply universally. I appreciate your offer to buy with Monero, but I only accept Bitcoin (and dirty fiat). npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thank you! Looking forward to hearing what you think! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf You can hear me tell @nprofile…3hw8 all about it on the latest @nprofile…k3zk on Fountain: https://fountain.fm/episode/xRzrZHRj9fRDqf3UI3EW npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I've been a bit absent from Nostr for the last little while, but that's about to change. For the past few months, I started focusing on a new project, and I'm finally ready to announce what I've been up to. I've written a book. Defending Bitcoin: Industrial-Grade Cybersecurity for the Monetary Grid. 6 months ago, I realized how I could apply my cybersecurity background to Bitcoin, with a perspective grounded in the world of critical infrastructure and industrial control systems. In Defending Bitcoin, I make the case that Bitcoin is critical infrastructure, and I mean that technically. Critical infrastructure is everything essential for the modern world to run the way it does, and I assert that Bitcoin meets the threshold of that definition. Defending Bitcoin is grounded in the industrial cybersecurity principles that I use on a daily basis. The framework I've built is based on ISA/IEC 62443, the most widespread industry standard for industrial cybersecurity, and applies universal cybersecurity principles such as defense-in-depth, risk management, and threat modeling. And in all cases, there's always something you can do to improve your security or that of the network as a whole. I wrote the book for two audiences at once. The first is bitcoiners who want to improve their security posture. The second is technical professionals who may be skeptical about Bitcoin and want to understand it better. I build a base of vocabulary for both sides to understand each other, then cover the threat landscape over the course of 10 chapters. Launching today is the accompanying website, https://defendingbitcoin.com/ where you can get a preview of the book, read endorsements from Mikko Hyppönen (the foreword writer), @nprofile…w2ua , @nprofile…u7e3 , @nprofile…h4hk , @nprofile…8p0e , and @nprofile…cqdh . I've also built a threat modeling tool where you can check how the book applies to you (fully local, we don't collect any data except your email address, if you want updates). Defending Bitcoin will be available for purchase online on June 15th, right after @nprofile…py4c where I'll be debuting the book physically. Use code DEFENDINGBITCOIN for your ticket, and come see me in Prague to get your signed copy! I'm thrilled to be releasing this book because it's truly the best possible contribution to the space that I can make. I managed to find a way to bridge the two worlds I live in, those of my day job in cybersecurity and Bitcoin. I hope you find the book to be a helpful guide to improving your security, and that it makes a positive impact for Bitcoin as a whole. I'll be posting more often about the Bitcoin cybersecurity topic, and hopefully that's valuable as well. I'm looking forward to hearing what you think! https://blossom.primal.net/678ab8b5ca6800770239bcce042d3fcbcd19e431cc144c599f5d379c2c149e4f.png npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf This looks fantastic Martti, great work! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Merchants need inbound liquidity, this isn't just a typical use case. It's an essential one. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf It's for inbound liquidity, the point isn't to be balanced. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Boltz closes channels with lots of liquidity on their side. I understand, they need to do channel management. But it doesn't work to keep an inbound liquidity channel open to them. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf If you're a merchant and you want one, fat inbound liquidity channel, you want it to be reliable, and you want it to last a long time, who would you either pair with or buy the liquidity from? Bonus points for 2+ options. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks Derek, I'll try it! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf What's the best Nostr key management browser extension these days? I've been using Alby but no longer use their wallet, I'm thinking an alternative would be better. What's out there right now? npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Awesome, Max! I'll give it a read! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf This is incredibly sinister. I had no idea! Thanks for drawing my attention to the issue. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Looking forward to hearing hour the next 22 hours went! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf One of my favorite bands is Moonsorrow. 15, 20, 25 minute songs. Epic, pagan black metal. Lyrics almost exclusively in Finnish. I put on one of their songs and feel instantly relaxed. This is what I'm listening to now: https://open.spotify.com/track/35tbcLF8iniGHOiIy9vPZ6?si=9d1325e9382543f7 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf My day started at 4AM helping my friend @nprofile…x32y buy Beef Bits before departing Finland. My life is blessed. I love you all. #nevent1q…he29 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I really enjoyed this one, and I hope it provides value in this wider conversation. #nevent1q…qf6c npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf You can subscribe to our episodes now if you'd like to support us, with ad-free episodes one day early! We also forward 21% of our value for value to our guest, because we couldn't do it without them. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf The latest @nprofile…k3zk Show is out now, with @nprofile…dgpe . Check it out on @nprofile…cgkr https://fountain.fm/episode/HiBPL8bQhcC4iZ3uEStL With host @nprofile…3hw8 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf My local butcher accepts Bitcoin! I just got back from Kotitila near Kalasatama in Helsinki. I picked up a couple of bags of @nprofile…xmql, some ground beef, and a keto pizza from @nprofile…jhnu. Paid in sats. Check them out if you're in Helsinki, such as for @nprofile…58xa! https://blossom.primal.net/dacfa5e41e2dc4118a35f0b63a225957717715e10d6a86ff2324a20f03fea23b.jpg npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Cloudflare is down, right? npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Good take Matey. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf We had a good run :( npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Look the evil in the eye. If you can. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf This is a great series Jimmy. Thanks for covering this important issue. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf That's not what it means. And I'm not kidding. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I would advocate for consensus changes to fix known exploits. Plus as many known theoretical attack vectors as possible. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Bitcoin is critical infrastructure. What do I mean by that? I have a specific definition, stemming from my experience as an industrial cyber security professional. Critical infrastructure refers to assets, systems, or networks whose disruption would have a profound effect on security, economic stability, public health and safety, or some combination. What this means in practice are those things that we can’t live without in our modern society: electricity generation and grids, oil, gas, and fuel infrastructure, factories, hospitals, transport networks. The list goes on, I hope you get the idea. The Internet itself is critical infrastructure, as the communication network enabling most of our interconnected lives. Additionally, payment networks are considered critical infrastructure. You probably see where I’m going with this. I put forward that Bitcoin is critical infrastructure. No government or agency has officially taken that position. Of course, within the Bitcoin community, this definition shouldn’t be surprising. If Bitcoin is the revolutionized monetary system, the replacement to fiat debasement and the antidote to centralized power structures, the freedom money that enables anyone in the world to save and transact freely, then it had better be considered critical. Now, what is the point in my saying this, especially if it shouldn’t be controversial to anyone in the Bitcoin space? It has to do with how critical infrastructure is defended. As mentioned, I’m an industrial cyber security professional, which means that I focus on defending critical infrastructure and other forms of industrial control systems from cyber threats. Critical infrastructure is treated differently from other types of network systems and assets. Whereas for most systems, confidentiality of data and the integrity of the system are considered most important, for critical infrastructure the focus is on keeping the systems running. Additionally, many of the cyber defenses that work for individuals and normal IT systems simply don’t work in critical environments (for many reasons, not overly relevant here). With that in mind, critical infrastructure is defended based on the types of threats they are expected to face. ISA/IEC 62443 (they couldn’t have picked an easier number to remember /s) is one of the most widely used frameworks for industrial cyber security. It defines 4 threat levels and recommends controls based on those: - Protection against casual or accidental threats - Protection against intentional attacks using simple means - Protection against sophisticated attacks using advanced tools - Protection against nation-states or highly-resourced attacks As you can probably gather, the defenses applied are targeted against more and more intense attacks, with greater motivation and resources each time. One piece of necessary context is that “accidental” threats are still bad - we’re talking about untargeted malware floating around on the internet, for example. The accidental part mostly refers to basic security best practices not being followed (no passwords on a computer - it happens!). Now, at this point, I’ll be clear: I considered non-monetary transactions to be a threat against Bitcoin: specifically against its availability. Non-monetary transactions displace block space and force a higher fee rate. In times of frenzy for some new inscription fad, transactions spiked to the point of pricing out whole categories of users from on-chain transactions, made lightning channel openings much more expensive relative to channel size, and hampered the network overall. Additionally, blocks themselves became much more full and the UTXO set increased rapidly, both putting significant pressure on node hardware requirements, risking decentralization. These points have been discussed ad nauseum and aren’t the point of this post, except for me to be clear that I consider these non-monetary transactions to be a type of threat. I’ve analogized elsewhere that in Bitcoin, policy filters are effectively the defense against casual threats. Mapped to the framework above, the first two categories are essentially tackled by policy filters. Casual, untargeted threats are actually mostly handled by node implementation security features, and those are important in themselves for us to be able to have functioning nodes. Simple targeting Bitcoin itself through abusive transactions are effectively blocked through policy. Default tools and wallets don’t even allow submission of abusive transactions in most cases, because they follow default mempool policy. In the cyber security world, this is enough to deter whole categories of casual attackers, who simply move on to the next potential target. There’s no reason to think that this isn’t the case with Bitcoin also. More sophisticated attackers are a different situation. They use bespoke tools and know what they’re doing. They’re able to bypass policy filters and use specific exploits to get their transactions on chain. The level to be able to tackle these attacks is at consensus level. I’ll save further discussion about that for another time, but I’ll emphasize another point here: this is what is done in the cyber security world all the time. Vulnerabilities are identified, tracked, and remediations are developed. Individuals and organizations either fix the vulnerability, put up some other defense to compensate, or leave themselves free to get exploited. An important distinction is also whether a vulnerability is being actively exploited. If that’s the case, it’s only a matter of time before they find and exploit you. In other words: Bitcoin has a choice - fix identified and actively exploited vulnerabilities, or simply accept that this will continue to happen. Forever. I don’t have any intention to imply that Bitcoin should be managed like a business or any other kind of centralized organization. Bitcoin is unique in that it is the only truly decentralized system in the whole world. All other cryptocurrencies have developers who make changes at their discretion, similarly to companies and individuals who can simply decide to do something and do it. It’s different with Bitcoin. The network has to agree. And that’s good! It also means that if significant portions of the network do not agree that something is a threat or that a vulnerability is worth fixing, it may or even will not happen. At this point, those who think something needs fixing could either throw up their hands and decide to live with it, or decide to try to persuade network participants of their view. I’ll finish with another cyber security principle: an attacker with unlimited resources and motivation will always breach your system. This might sound defeatist, but it’s a reminder that no set of defenses is ever perfect. The higher the value of the potential payoff, the more likely an attacker is willing to throw time and resources into exploiting the system to get what they want. In the Bitcoin context, this means that there will always be attackers looking for vulnerabilities, because what is a more valuable payoff than the best form of money the world has ever seen? Does this mean we should give in to the inevitability that SOMEONE is going to attack Bitcoin SOMEHOW, and just give up? In my view, no. That’s not how things work outside Bitcoin. Critical infrastructure is actively defended. Threats and vulnerabilities are identified and remediated as best they can be. The cat and mouse game goes on, but electricity keeps flowing, gasoline gets to the pumps, factories keep pumping out products, ships bring goods to their destination, trains keep running, and water flows from the taps. We don’t notice when everything is working. We sure do notice when something breaks. Let’s not let Bitcoin break. Bitcoin is critical infrastructure, and we should be treating it like it is, keep it running, and save the world. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Congratulations Matt! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I understand that perspective. Unintended consequences is always a thing. Still, I don't see why we can't fix obvious exploits that are being abused. Otherwise, we just live with things as they are. Maybe it's fine, but maybe it isn't. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Tiresome. Oh well! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Cybersecurity is all about defense. Defending against attackers (threats). There are a few basic types of attackers: - The opportunists who will take advantage of an easy win but will stop when they meet trivial resistance - Sophisticated actors looking for financial gain (think ransomware or extortion for data) - Determined actors with extensive resources who want to do bad things (nation-states, industrial sabotage) (As with all things, I'm simplifying a little) In industrial cybersecurity (my day job, if you didn't know), defenses are all built around the type of threat actor they aim to stop. The opportunists give up after very little resistance. Things like strong passwords or two-factor authentication or a locked door are usually enough to stop them. More sophisticated actors need tailored defenses. You can't cover every attack vector, and it's pretty much a constant cat-and-mouse game. But it's necessary for pretty much all companies to implement some basic protections that stop most cyber threats. Again, you can't stop everything, but you can mitigate most damage. The determined actors like nation-states are difficult. It's taken as a given that an actor with unlimited time and resources will breach your system. The whole idea there is to make it as difficult as possible to get what they want, and perhaps they give up. This maps onto Bitcoin: The opportunists are stopped by filters. If their transaction won't be accepted by most nodes, they just don't do it. More sophisticated spammers try to find new vectors to attack the system. They've found various exploits to abuse. And ultimately, someone who REALLY wants to put their data on Bitcoin will do so. But, we could make it difficult for them. The whole reason I bring all of this up is: outside of Bitcoin, we play the cat-and-mouse game with cyber attackers. We have no other choice! The world enabled by the internet would be worthless if attackers could just do whatever they want. We have the ability to fix some specific bugs which are being actively exploited. Outside of Bitcoin, this is a no-brainer. We can also make it as difficult as possible to put arbitrary data on Bitcoin. This is how we attempt to stop the most determined threats attacking critical infrastructure. Of course, Bitcoin is a distributed system and requires consensus. I don't want to change that. Therefore, I advocate for building consensus towards putting up some basic defenses and fixing exploits that are being abused. That's how we can defend against threats to Bitcoin. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Insults are the thing now (again?) on Twitter. It's exhausting. We can't have conversations with each other if the other side is dismissed with insults. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf If everyone adopts the new consensus rules, it's not control. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf So what is wrong with closing off the currently abused exploits and leaving OP_RETURN only? Regardless, wanting less UTXO bloat is the best argument for this that I've heard. It would be nice if Core focused on that as the messaging. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf 👀In a good way I hope! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf GM Derek! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I'd like to engage with you in good faith here. I hope you don't block me as a filteroor. If the majority of the non-financial data (I like that terminology, by the way) is using some kind of exploit (OP_FALSE OP_IF or baremultisig, for example) then why is it bad to simply fix the exploit? These were not intended features, and in some cases the potential for abuse was raised ages ago. I really don't see what the problem is with making arbitrary data as expensive as possible. Encode what you want in pubkeys, I guess. Pay full price for it. No discount. No multisig optimization. I just don't buy that we have to stick to the existing consensus rules just because they are the existing consensus rules. If something is being abused, why can't we change it? Again, I hope you take this reply in good faith. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I see no reason to make it easier to put arbitrary data on Bitcoin. I'm in this for Bitcoin as money. Not as data storage. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf No thank you. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Very much so. I was in favor of policy-based filters up til the Core change. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf 🤝 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf "They have only been ineffective since Taproot because a certain core devs refused to patch the default policy run by 99% of nodes." - so they've been ineffective. But I'm not disagreeing! "Ineffective" in absolute terms. Effective by another measure, sure. New changes to policy demand that the change be on consensus terms. IMO. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I can't tell if you're agreeing with me or disagreeing with me. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Spot on. With that said: I am against REAL censorship - making addresses unable to transact. That's all. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf I'll take that as a complement! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf What exactly is censorship on Bitcoin? Here's my answer: certain addresses being blocked on consensus level. Changes to policy to limit specific forms of transaction is not censorship, it's discrimination. I'll explain what I mean by that. Bitcoin has always discriminated in terms of what can go into a transaction. It has never been possible to put whatever you want into a transaction, just like it's never been possible to double spend a UTXO. I'm glossing over a ton of minutiae here, for simplicity. The previously agreed amount of data that is allowed in a transaction has been set to a reasonable level, through OP_RETURN. There have been disagreements as to that level, but even the most permissive amount was 80 bytes of data in practice. This has been more than enough, and it has been enforced by policy, not consensus. Since SegWit and Taproot, more ways to put arbitrary data (spam) on chain have been discovered. That is to say, the ability to do these things was right there, as unintended consequences of development changes. Uncaught bugs, or a lack of forethought about human behavior. Filters on the policy level have been ineffective in containing spam. However, they have provided individuals who are against spam with tools to control their own nodes and mined blocks. Individual policy choices are a form of discrimination, not censorship. Discriminating against certain types of consensus-valid transactions is perfectly fine. I even go so far as to say that discriminating against transactions from certain address is also completely fine. These are all individual choices. Every individual on the network is free to make those choices. Anything short of that is coercion. Consensus rules, on the other hand, are where censorship is possible. This is where it would be possible to block certain addresses from moving their UTXOs. As I understand it, this is usually termed confiscation. In practice, this would likely be the result of making some technical type of coin unspendable. In theory, some list of addresses could be drawn up that says they can never move their coins. Good luck getting that adopted. Consensus changes that do not prevent certain addresses from moving their UTXOs are not censorship. Making it so that transactions containing arbitrary data invalid is not censorship. Making those transactions more expensive is not censorship. Private key holders will still be perfectly able to move their UTXOs. They can even add some arbitrary data through OP_RETURN, or jump hoops (and pay fees) to encode their data some other way. This is discrimination against certain types of transactions. Those which have no intention of using Bitcoin as money, or which misuse the network for their own purposes (I use the word misuse here to mean that they are using exploits which were not intentional developments). If the majority of the network decides to eliminate the possibility of those transactions in the future, that is not censorship. And, as previously mentioned, that has not been effective on a policy level. The consensus level is all that is left. I'm not going to discuss the currently proposed soft fork in extensive detail, except to say that I think the proposal is technically extremely reasonable in my understanding. Compromises have been made to allow for other specific potentially useful data types by consensus. The language about legal consequences is completely unnecessary, and I hope it is removed. I hope this proposal or a similar one passes. Bitcoin is money, not data storage. To hammer these points further: I might morally object to some miner rejecting transactions from specific addresses, but I can't do anything to force them to include those transactions in blocks they mine. I can put public pressure on them to change their view, but I can't force them to do so. This would still not be censorship. All individuals on the network are free to do what they want, including rejecting transactions they disagree with. Here's the beautiful thing: we're not all the same! One miner might reject some transactions. Another one almost certainly will include those transactions. This is primarily why filters don't "work" - someone will always mine valid transactions. I still support filters on the node level. Nobody can force me to include transactions I don't want in my mempool. In other words: as long as the consensus is not making it impossible for certain addresses to move their coins, it's not censorship. Discriminating against certain types of transactions or certain arrangements of arbitrary data is not censorship. Everyone on the network is still free to move their UTXOs. Bitcoin is useful as money. The best money. That's the important thing. What do you think? npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Agreed there. I'll try to make my investment count! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks Mr Brisket! I'll do my best to stick around! I've realized I'm not that great at social media. It keeps dropping down the priority list at times. But it's important for staying connected to people and being in the conversation. There's a balance! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf This was a blast! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Is that all there is to it? npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf 🧡 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Thanks Jake, hope all is good with you! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Great work Joe! npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf GM Nostr! I'm back after a bit of a self-enforced social media hiatus. It was Nostr, Twitter, everything. I was more than a little burnt out after BTC HEL. I didn't really get a proper break after the conference, since I went straight back to my fiat job the next day. All I had energy for was keeping the lights on at @nprofile…k3zk . I was also more than a little shaken up by Charlie Kirk's death. I won't say much more about that here, but the TLDR is I did a lot of thinking about the risks of being public and saying controversial things. I was strongly considering taking a big step back from the space. Nope! I'm back, and ready to get started on new things! I got out to a couple of fantastic conferences, first BTC Balkans in Sofia, Bulgaria, then the Plan B Forum in Lugano. My Bitcoin batteries are fully recharged, even if I was pretty exhausted after a week of conferencing. Reconnecting with old friends and making new connections is what this is all about. I especially enjoyed the Rockamoto in Lugano - I can't believe I get to do all this cool stuff! Thanks @nprofile…3hw8 , @nprofile…gud9 , and @nprofile…pykq for just being awesome! Looking forward to next time! https://blossom.primal.net/a25c24b54be67d0034ca72f1fd101cca37eeb0e8c6a7aae79a07b11617c848d7.png As for me, it's full speed ahead with the Bitcoin Infinity Show and the Bitcoin Infinity Academy! You may have noticed that I took a step back from the Bitcoin Infinity Show - it's just Knut now, at least in front of the camera. I'm still behind the scenes doing all the editing, but I couldn't keep my schedule flexible enough to join the recordings. I miss it, and I plan to change that. And of course, I'm involved in the planning for next year's @nprofile…nzfe - stay tuned for all the details about next year's conference, and don't hesitate to reach out if you want to speak! Thanks everyone for making this community amazing. I'm full of gratitude, and I can't wait for what's in store ahead. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf This is an extremely good write-up. I especially like the distinction made about transactions that raise the fee floor - I don't think that point is talked about enough. Read the full thing! What do you think about it? #nevent1q…3h79 npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Fuck, that hit me again man, not gonna lie. I don't even know what to say here. Love to you and your family. Love to everyone fighting the good fight. Love to the Kirk family. I hope they feel all the love and support we can all give them. It won't make up for their loss. But it's something. npub1fk8h6g8zhftw8c7pga2zjd84p2z949up5lc3qdchm9v4m0q7mwws7jcwld lukedewolf Just before I went to sleep last night, I saw that Charlie Kirk had been shot, and that it didn't look good. I hoped for the best, but didn't have a good feeling. I woke up to the terrible news that he had died. This is hitting me harder than I expected. I hadn't followed his work closely. From what I saw, he had reasonable conversations with US college students, he supported his views calmly, and tried to change minds through persuasion and reasoning. It was admirable, even though I doubt I agreed with him on every issue (probably most, though). And someone killed him for that. Whats hitting me hardest is that he was not only younger than me by a few months, but that he had young kids close to the age of my son. Supposedly his wife and kids were in the audience. This is just awful. Then there are people all over social media absolutely celebrating. It's sickening. Cheering for someone's death because you disagree with them. A young father. This feels like an inflection point. I hope the world starts to see the difference between people who admired him and people who are cheering about his death. There is a good side and a bad side here. RIP Charlie Kirk.