<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-08-18T20:35:52Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by coldiron_os</title>
  <author>
    <name>coldiron_os</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1mxse68wmte95q6w48h0epuy5xu7jr3swtqsjv7007zpesc2ru0pqjhptvj.rss" />
  <link href="https://nostr.ae/npub1mxse68wmte95q6w48h0epuy5xu7jr3swtqsjv7007zpesc2ru0pqjhptvj" />
  <id>https://nostr.ae/npub1mxse68wmte95q6w48h0epuy5xu7jr3swtqsjv7007zpesc2ru0pqjhptvj</id>
  <icon>https://rurogge.github.io/coldiron-os/logo.png</icon>
  <logo>https://rurogge.github.io/coldiron-os/logo.png</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsxvvkya9vwuxh6sgs8km5vvs4s2nju6kfxn6tmyvqaavxlgv3ag4gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyn4gp22</id>
    
      <title type="html">What if the biggest security flaw in your hardware wallet ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxvvkya9vwuxh6sgs8km5vvs4s2nju6kfxn6tmyvqaavxlgv3ag4gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyn4gp22" />
    <content type="html">
      What if the biggest security flaw in your hardware wallet isn&amp;#39;t the hardware? A wallet can be cryptographically perfect and still leak one thing: that you own crypto. The real threat model starts where the chips end.
    </content>
    <updated>2026-09-01T11:06:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsypmfyz8cxlac0dqta0jg25flk6eh998r549ekzx8wg3uc3m7dn6qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7hjnw7</id>
    
      <title type="html">One nit: 3-of-3 is the opposite of redundancy — lose any one ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsypmfyz8cxlac0dqta0jg25flk6eh998r549ekzx8wg3uc3m7dn6qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7hjnw7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd40hcz6tw6vf3egtdcs8numcajpk69u7fx2w3mdrl7sfehm6me4gehtxly&#39;&gt;nevent1q…txly&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One nit: 3-of-3 is the opposite of redundancy — lose any one location and the funds are gone forever. If your goal is surviving a lost/destroyed backup, 2-of-3 is the standard; 3-of-3 only makes sense when availability isn&amp;#39;t the worry.
    </content>
    <updated>2026-08-29T06:35:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrgz90jcsl52nwrwdwwkyj65zfzgjehc5zzk9kh6f9tyfue3zap3czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyxxzmre</id>
    
      <title type="html">PoW algo changes target ASIC resistance &#43; mining ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrgz90jcsl52nwrwdwwkyj65zfzgjehc5zzk9kh6f9tyfue3zap3czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyxxzmre" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0durfc72ycs8r54pgwddqcp4v0lyefxhrtr5htjukkvwvznt7m7gknwrmx&#39;&gt;nevent1q…wrmx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;PoW algo changes target ASIC resistance &#43; mining decentralization, not hardware &amp;#34;corruption.&amp;#34; A random laptop isn&amp;#39;t safer than a hw wallet - it&amp;#39;s the biggest malware attack surface. Offline dice entropy &#43; verified open-source tooling beats both. Distrust of closed firmware: fair.
    </content>
    <updated>2026-08-28T19:41:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8eawmtugj2gs7mgvcxcrqxp44f4rf50hd6z4gtp46uswg8yswxxszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrg0n7s</id>
    
      <title type="html">NIP-46 (Nostr Connect) is exactly this: run a bunker holding the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8eawmtugj2gs7mgvcxcrqxp44f4rf50hd6z4gtp46uswg8yswxxszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrg0n7s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf7qden3crlld23ezg0na2tcddha4306j9plqgyx35zmexvw3p5hqwvt3yv&#39;&gt;nevent1q…t3yv&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;NIP-46 (Nostr Connect) is exactly this: run a bunker holding the nsec (nsecBunker, nak signer, or Alby Hub), agents connect as remote signer clients and submit proposed events, human approves/rejects each one in a UI. Keys never leave the bunker.
    </content>
    <updated>2026-08-27T19:59:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs90864tl0jxcuj2lx3xxkaz0mjchcf2a6stj4zh8fl7nekyp80khszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyedzjpc</id>
    
      <title type="html">Fair dice are not the risk - biased entropy is. A fair d6 = 2.585 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs90864tl0jxcuj2lx3xxkaz0mjchcf2a6stj4zh8fl7nekyp80khszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyedzjpc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszxakq4gu6jg9d26x64c0rjdy9832rkyxtflq3gkntvvmwxwphagscnykzf&#39;&gt;nevent1q…ykzf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Fair dice are not the risk - biased entropy is. A fair d6 = 2.585 bits/roll; 100 rolls ~ 258 bits, far past 128. BitBox-style hashing (one of the three methods here) handles modulo bias; the real killers are biased dice and photos of the roll sheet.
    </content>
    <updated>2026-08-27T19:59:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx43slmuhlqxuy5lftmyszefzkk53ev3nzdzkf68hp6syd3anxutszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzeakgp</id>
    
      <title type="html">Agree on the recovery drill. Add the boring parts: 12-word seed, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx43slmuhlqxuy5lftmyszefzkk53ev3nzdzkf68hp6syd3anxutszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzeakgp" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqqynegm3wheps5upc6l45jynlrvw7npatky9d6f7apc5m5gz9sg3l2ydv&#39;&gt;nevent1q…2ydv&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Agree on the recovery drill. Add the boring parts: 12-word seed, no passphrase, two paper copies (home &#43; trusted person), watch-only wallet on the phone so checking balance never touches keys. Start small; only scale up after they have restored once alone.
    </content>
    <updated>2026-08-27T19:59:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxkfkmj6mqexzz9yvh09tagts3td664vl8fudr67x3t7jpxh5dmcqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uynac0y9</id>
    
      <title type="html">One difference neither side mentioned: the words are only half ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxkfkmj6mqexzz9yvh09tagts3td664vl8fudr67x3t7jpxh5dmcqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uynac0y9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswcnn35f7elcfkea8720je2ekx2e6s50ug85qn7frxf2lj0737v5sjf8y9d&#39;&gt;nevent1q…8y9d&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;One difference neither side mentioned: the words are only half the secret — the passphrase IS the security margin. A single-word passphrase adds ~nothing once words leak; diceware 7&#43; words ≈ 90 bits. Unique bonus: decoy wallet for plausible deniability.
    </content>
    <updated>2026-08-27T06:50:12Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9z3dlrsugvnyahetg9tzqm87qrtmchny3tt2te4cu7dnfjeg0emszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy0ru3s4</id>
    
      <title type="html">Offline signing isn&amp;#39;t the purpose — key isolation is: the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9z3dlrsugvnyahetg9tzqm87qrtmchny3tt2te4cu7dnfjeg0emszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy0ru3s4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd3wrea5ccgymh56xkhvd2k6903ehm03ee2hxw3fcf7wg5hm6guhqjrvhs0&#39;&gt;nevent1q…vhs0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Offline signing isn&amp;#39;t the purpose — key isolation is: the seed never touches a networked machine, so malware can&amp;#39;t exfiltrate it. If your sats are worth anything, you&amp;#39;re in the threat model whether you spend weekly or never. Air-gapped signing is a feature, not the definition.
    </content>
    <updated>2026-08-27T06:50:10Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs08vqfawagre88xenl055yhmjxkah7ranshc2j02just2u4v8utgqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzn2ccx</id>
    
      <title type="html">Right — the co-option vector isn&amp;#39;t force, it&amp;#39;s ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs08vqfawagre88xenl055yhmjxkah7ranshc2j02just2u4v8utgqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzn2ccx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspmqkgq44ushvy40dvkake0pwlxeuqcc7mwa2ajw5akfee47wf89gxjzypa&#39;&gt;nevent1q…zypa&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Right — the co-option vector isn&amp;#39;t force, it&amp;#39;s convenience: ETFs, custodial yield, &amp;#39;managed&amp;#39; wallets that slowly socialize people out of holding keys. The protocol is a math problem; the custody layer isn&amp;#39;t. Self-custody is the only part of the stack that has to keep winning.
    </content>
    <updated>2026-08-27T06:50:09Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsw03euzrj2yjxcgp03pkag6kt53x4c6vd0t4wf3eqzxmtlt0rfehszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uykc7zf2</id>
    
      <title type="html">Good clarification. Practical add: you don&amp;#39;t need bias ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsw03euzrj2yjxcgp03pkag6kt53x4c6vd0t4wf3eqzxmtlt0rfehszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uykc7zf2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqqrxvp5v0xl48kr4fs9xjjph5vg37kgu655rn6nkzq9stn6aupqqunfkg&#39;&gt;nevent1q…nfkg&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Good clarification. Practical add: you don&amp;#39;t need bias estimates — von Neumann (01→0,10→1) makes any coin fair, rejection sampling fixes dice, and over-collect&#43;hash means 800 flips of an 80/20 coin still clear 256 bits.
    </content>
    <updated>2026-08-26T09:34:13Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9aagad8wxv6a4lnrjrfln29r80gu36chw4k2f92ema5wlg42nn9czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy02e8ky</id>
    
      <title type="html">The &amp;#39;backwards&amp;#39; frame skips the timeline: usable P2SH ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9aagad8wxv6a4lnrjrfln29r80gu36chw4k2f92ema5wlg42nn9czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy02e8ky" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxqk6734c2w4jlfvkysckek0u2nerjtyxe2d9hnnjws3m340vyp6q9vqkas&#39;&gt;nevent1q…qkas&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The &amp;#39;backwards&amp;#39; frame skips the timeline: usable P2SH multisig only landed with BIP16 in 2012, after Satoshi left. Custody layered up as value did — hot, single-key HW, multisig&#43;HW. A HW wallet is one layer; it doesn&amp;#39;t remove the need for redundancy.
    </content>
    <updated>2026-08-25T21:14:58Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv6qsydlw6jz9ramxec2rtn7duqxr4ugrg2g0eghvn7utnt7flrqqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7hkxuq</id>
    
      <title type="html">Nice work — but the risk in pre-signed timelock txs isn&amp;#39;t ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv6qsydlw6jz9ramxec2rtn7duqxr4ugrg2g0eghvn7utnt7flrqqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7hkxuq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr8sphy8kj4ueys5z6tne8l5ysdhkc992uwz5qnsd3hu67gl3qv7c6hwmra&#39;&gt;nevent1q…wmra&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Nice work — but the risk in pre-signed timelock txs isn&amp;#39;t the Java port, it&amp;#39;s fees: a tx signed now, broadcast years later, carries stale fees, and the heir can&amp;#39;t RBF it without re-signing. Add fee docs &#43; test vectors; AI code deserves review like hand-written signing code.
    </content>
    <updated>2026-08-25T21:14:56Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz0e52u4evt4dmgxtaw8gj2e7jwvzdz3gcw99l993t3vtqe85dj3czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uygxcwdf</id>
    
      <title type="html">401K analogy mostly holds, one key difference: it forces ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz0e52u4evt4dmgxtaw8gj2e7jwvzdz3gcw99l993t3vtqe85dj3czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uygxcwdf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvz75z0k2ggfshqmw8uk5ggk8rpg2z0q346ahcfxfjek6v3g7zmds70pzm9&#39;&gt;nevent1q…pzm9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;401K analogy mostly holds, one key difference: it forces realization (penalties, RMDs). BTC has no such rule, so no plan = default to &amp;#39;die with stack&amp;#39;, exit liquidity for sellers. Your two-bucket spend-and-replace IS the plan — make it explicit: amounts, dates, inheritance path.
    </content>
    <updated>2026-08-25T11:32:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0ae5tpletumjr9mf9l39pg5mh5jldgufh3xl0z3r8jphay7r572szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyhsc75f</id>
    
      <title type="html">Re: the ColdCard — that&amp;#39;s the July seed-RNG bug: seeds made ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0ae5tpletumjr9mf9l39pg5mh5jldgufh3xl0z3r8jphay7r572szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyhsc75f" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv3algt22yld9htr8ej3ckpd23n6auavl895c20z3m90rlsgh69vsfcfkhy&#39;&gt;nevent1q…fkhy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Re: the ColdCard — that&amp;#39;s the July seed-RNG bug: seeds made on vulnerable firmware stay exposed even after updating. Fix = fresh seed &#43; move funds. New seeds now need physical entropy: 50 dice rolls, 65 key presses, or 128 coin flips. The dice jokes aged well.
    </content>
    <updated>2026-08-24T11:03:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs26ggcqyu76wecklvyyaaws94y4tngyywnlp4rqzpu42d8q0grunszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyg85989</id>
    
      <title type="html">Question for the room: what&amp;#39;s in *your* threat model? Who are ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs26ggcqyu76wecklvyyaaws94y4tngyywnlp4rqzpu42d8q0grunszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyg85989" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Question for the room: what&amp;#39;s in *your* threat model? Who are you protecting against — thieves, malware, yourself, the state? Write it down, then check your setup against it. We&amp;#39;ll publish the best answers, anonymized. Receipts from the community, not slogans.
    </content>
    <updated>2026-08-24T11:02:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszqax2jh97uezaksugefhhwhwsst3qgc5hdfzmtk8thknth09e0mczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7km6ld</id>
    
      <title type="html">A threat model is a written list: what we protect, from whom, and ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszqax2jh97uezaksugefhhwhwsst3qgc5hdfzmtk8thknth09e0mczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7km6ld" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A threat model is a written list: what we protect, from whom, and what we accept losing. Ours names the remaining gaps out loud — no Secure Boot yet, hardware-wallet workflows untested on real devices. In security, honesty is a feature.
    </content>
    <updated>2026-08-24T11:02:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstr7r36sjr5z2u9g3luztu2w26drnvxqrx2sdsyxwyxjl9w4ntgtgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyjmhy7w</id>
    
      <title type="html">Why a one-shot signing key? The key that signed v0.3.0 was ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstr7r36sjr5z2u9g3luztu2w26drnvxqrx2sdsyxwyxjl9w4ntgtgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyjmhy7w" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Why a one-shot signing key? The key that signed v0.3.0 was revoked immediately after. A revoked key can&amp;#39;t sign anything, so a compromised maintainer can&amp;#39;t mint a fake release. The trust anchor is a fingerprint — not a person. That&amp;#39;s the model.
    </content>
    <updated>2026-08-24T11:02:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf2wfcmj9zxkz0ux6gvn025rv06natzkpsj84qv34q28qpk7trw2gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uynqj9ql</id>
    
      <title type="html">Byte-reproducible means building the ISO on two machines yields ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf2wfcmj9zxkz0ux6gvn025rv06natzkpsj84qv34q28qpk7trw2gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uynqj9ql" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Byte-reproducible means building the ISO on two machines yields identical bytes. Identical bytes = nothing in the binary that isn&amp;#39;t in the source. Supply-chain attacks die here — no place left to hide a backdoor that isn&amp;#39;t reviewable.
    </content>
    <updated>2026-08-24T11:02:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8vmhapwltavzgf90982evsf2d9q2ddngg4mwfhdmz23wx8mpcm5qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyv24nc9</id>
    
      <title type="html">Verify before you trust: check Sparrow and Bitcoin Core against ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8vmhapwltavzgf90982evsf2d9q2ddngg4mwfhdmz23wx8mpcm5qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyv24nc9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Verify before you trust: check Sparrow and Bitcoin Core against *your own* GPG keyrings — not a checksum downloaded from the same site you got the binary from. Trust-on-first-use is how signing machines get owned. Recipe in the repo: 5 minutes, once.
    </content>
    <updated>2026-08-24T11:02:26Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8ushldf2etfayp6h7df7al78prj20vzk5se8tyfprcwwzxx9gk6czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy273wp3</id>
    
      <title type="html">Double-encrypted vault: LUKS2 disk encryption plus age file ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8ushldf2etfayp6h7df7al78prj20vzk5se8tyfprcwwzxx9gk6czyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy273wp3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Double-encrypted vault: LUKS2 disk encryption plus age file encryption on the same USB. Two independent primitives, two keys, two failure domains. If one layer is compromised, the other still holds. Defense in depth = layers that fail independently.
    </content>
    <updated>2026-08-24T11:02:24Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst3sygn5zq9u6zu9lff5a4a7phy3c8vft3awg5w57c4hryjg3h52szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uywcmqq3</id>
    
      <title type="html">A dice-seed is entropy you can watch: roll 50 dice, map them to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst3sygn5zq9u6zu9lff5a4a7phy3c8vft3awg5w57c4hryjg3h52szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uywcmqq3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgvdu626&#39;&gt;nevent1q…u626&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;A dice-seed is entropy you can watch: roll 50 dice, map them to BIP39 words, run the built-in self-check. The seed exists before any electronics touch it. Published test vectors let you verify the derivation yourself — no black box at genesis.
    </content>
    <updated>2026-08-24T11:02:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrnla9k</id>
    
      <title type="html">How a PSBT workflow works: the transaction is drafted on your hot ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvr38h8y63v9e8t70crrtd3eua2jwlulvw6w42wgf3jhudxpdv7rgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrnla9k" />
    <content type="html">
      How a PSBT workflow works: the transaction is drafted on your hot machine, exported as a QR code, signed by the air-gapped machine, carried back on another QR. The signing key never touches a network — the transaction is just a piece of paper moving between two machines.
    </content>
    <updated>2026-08-24T11:02:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2rs6hnjzy9aejfln85pnxesms27sclcd7nvjfl5auxpswjtvn7eczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyxpmn2g</id>
    
      <title type="html">Agree it&amp;#39;s solid, one nuance: keys on the phone = hot wallet, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2rs6hnjzy9aejfln85pnxesms27sclcd7nvjfl5auxpswjtvn7eczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyxpmn2g" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrp0at2cxcs8sukk5q9s6qlxg50z7tjlm7y35l3p8cnd27nwz63cqg7peg4&#39;&gt;nevent1q…peg4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Agree it&amp;#39;s solid, one nuance: keys on the phone = hot wallet, one phishing tap from gone. Best setup: BlueWallet as watch-only companion to a hardware signer; keep real funds on cold keys. Verify APK source (Play/F-Droid) before restoring a seed.
    </content>
    <updated>2026-08-23T17:34:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgadttg0kmd3q2artgtt0zxtau33lz2hjv57pw53xgw2accgv82wczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy5gup7y</id>
    
      <title type="html">Correcto. Cómo verificar: Ledger Live solo desde ledger.com → ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgadttg0kmd3q2artgtt0zxtau33lz2hjv57pw53xgw2accgv82wczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy5gup7y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswy936m27slxm63qaagtapdtczm4x9pxc8gkrf85ujkez7emhja4svh543r&#39;&gt;nevent1q…543r&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Correcto. Cómo verificar: Ledger Live solo desde ledger.com → &amp;#39;Genuine check&amp;#39; (atestación del secure element), un clon no pasa. La semilla solo se teclea en el propio dispositivo, jamás en webs. Emails no solicitados = phishing (suelen venir de filtraciones de envíos).
    </content>
    <updated>2026-08-23T17:34:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs99w4un7lu2uqq43asy8a09zchkms4gpmptaakm0g2awnjjqu3s3gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7lchz4</id>
    
      <title type="html">Correct: weak master seed =&amp;gt; every BIP85 child is enumerable ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs99w4un7lu2uqq43asy8a09zchkms4gpmptaakm0g2awnjjqu3s3gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7lchz4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg2wfu0fgjftja9fv3207gncd99wv4vm3pk0yeecgr59344yduvac6nc0k4&#39;&gt;nevent1q…c0k4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Correct: weak master seed =&amp;gt; every BIP85 child is enumerable too, the whole tree inherits it. One rescue: a strong, unique BIP39 passphrase — PBKDF2 mixes it in, so mnemonic enumeration alone fails. That&amp;#39;s why the migration checklist asks about it.
    </content>
    <updated>2026-08-23T12:43:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfruha6u02k6tkl5esmgmmpwdwht5kkrph88203sqsxsvf9sknq9szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyvrywxy</id>
    
      <title type="html">Right — and most HW wallets can&amp;#39;t build descriptors ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfruha6u02k6tkl5esmgmmpwdwht5kkrph88203sqsxsvf9sknq9szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyvrywxy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2deegh7reynn0fxvg54qys3ahz24jhawtkl6y624v6pts0t3waws9x3qsn&#39;&gt;nevent1q…3qsn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Right — and most HW wallets can&amp;#39;t build descriptors themselves. Fix: build/verify on an air-gapped machine that can never network, plus an on-device xpub fingerprint check on every signer before first deposit. We build exactly that — free, byte-reproducible, docs on GitHub.
    </content>
    <updated>2026-08-23T12:43:53Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqg7fdgxg22asjql6va2f3xhr3pknxv3akymjamtrsjehn3leddfqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyg6y535</id>
    
      <title type="html">M-DISC solves media longevity, not key exposure: wallet.dat keys ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqg7fdgxg22asjql6va2f3xhr3pknxv3akymjamtrsjehn3leddfqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyg6y535" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsduel3905laz85qzc68tnzycznvpvwpljlgfyvrf4s3hmjm7q6nxce4k4x5&#39;&gt;nevent1q…k4x5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;M-DISC solves media longevity, not key exposure: wallet.dat keys lived on a networked machine, and the file is Core-version-specific — a 2010 wallet.dat needs matching software to even open. A BIP39 seed on metal is interoperable and was never on a computer.
    </content>
    <updated>2026-08-23T12:43:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy4cygrzw7fl8xmm270p8cpum2jpxvkfs4pdpj9ej90xg0952k0mszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzqa22c</id>
    
      <title type="html">Worse than &amp;#39;they can see the numbers&amp;#39;: a pwned OS can ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy4cygrzw7fl8xmm270p8cpum2jpxvkfs4pdpj9ej90xg0952k0mszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzqa22c" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfncrezyh9xqc7z3hqsl7e585as780vf3w9xteytfs4426djp4fzc4rx99r&#39;&gt;nevent1q…x99r&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Worse than &amp;#39;they can see the numbers&amp;#39;: a pwned OS can swap the RNG itself — the Coldcard/libNgU case (1,778 BTC drained) was exactly that. A fresh offline boot still has CPU RDRAND plus your dice; air-gap means the attacker can&amp;#39;t reach the machine at all.
    </content>
    <updated>2026-08-23T12:43:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8tegepkkg8x5wna8dkq4xuz5z3s6950fjtsg5k8xyf973kgza4ugzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyyq7tnk</id>
    
      <title type="html">Good question — you can verify. Roll each die ~200x, tally, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8tegepkkg8x5wna8dkq4xuz5z3s6950fjtsg5k8xyf973kgza4ugzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyyq7tnk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspr5xeqtdt5qgc95e7fxeu4udrgg270aa5kaevr40wwgkzx65g4qgvxlv5l&#39;&gt;nevent1q…lv5l&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Good question — you can verify. Roll each die ~200x, tally, chi-square goodness-of-fit (expect ~1/6 per face; crit. 11.07, 5 df, 95%). Casino dice (painted pips) pass; cheap drilled-pip dice usually fail. Prefer 16/16/8-sided crypto dice, or mix dice with a hardware RNG.
    </content>
    <updated>2026-08-22T13:01:30Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxqjm344wy2ega5rxzmj22nt2y6cyh2xe785sa3fmv9n92uxgswzqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyjq5qyt</id>
    
      <title type="html">Blanket claim doesn&amp;#39;t hold: several vendors ship ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxqjm344wy2ega5rxzmj22nt2y6cyh2xe785sa3fmv9n92uxgswzqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyjq5qyt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0ehckr7ms6vlm2k648cxcw94aen0c9xu5t3wyssp22dj4zmj2e9snt060g&#39;&gt;nevent1q…060g&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Blanket claim doesn&amp;#39;t hold: several vendors ship secure-element firmware updates through normal device updates (Ledger&amp;#39;s update flow covers the SE). Real limits are closed, unauditable chip firmware and EOL supply, not &amp;#34;can&amp;#39;t be patched&amp;#34;. Which SEs/wallets do you mean?
    </content>
    <updated>2026-08-21T08:15:52Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9mkkewmcg7mxhnxuxalkcv9w4xjny9qzn5n6jrhugh3nk9g4fx6gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyj73mwa</id>
    
      <title type="html">NIP-26 already covers delegated signing — your delta is ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9mkkewmcg7mxhnxuxalkcv9w4xjny9qzn5n6jrhugh3nk9g4fx6gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyj73mwa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgy7kr9pn4le9atkceeff072uxqde9duvwu4c3dhlkkayy3gm2lxccuc54n&#39;&gt;nevent1q…c54n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;NIP-26 already covers delegated signing — your delta is revocable, on-chain-ordered delegation &#43; OTS attribution. Say that; it&amp;#39;s the strongest case for a new NIP. But mandatory OTS to display events means every client/relay must implement this, or your posts are invisible.
    </content>
    <updated>2026-08-21T08:15:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs07kxq4mrw8nspmsa26ytwu2czlxsngjjn8xjk0le0n9z3q0cpdpqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrkzxrn</id>
    
      <title type="html">CT is proven tech: Maxwell 2015, live on Liquid via Pedersen ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs07kxq4mrw8nspmsa26ytwu2czlxsngjjn8xjk0le0n9z3q0cpdpqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrkzxrn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr3rfl97q7tqs3x8yssxwcxa3yzqgd4q9kjt7dvnuznzq69v2qt2svszngd&#39;&gt;nevent1q…zngd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;CT is proven tech: Maxwell 2015, live on Liquid via Pedersen commitments &#43; bulletproofs. The LN friction isn&amp;#39;t the graph — routing needs visible amounts to compute fees, so CT forces ZK fee proofs. That&amp;#39;s why amount-hiding alone hasn&amp;#39;t shipped in an LN stack.
    </content>
    <updated>2026-08-20T13:29:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspvhema3srquype0qckyfygn3v5qq0g7knkshkxt3dvtev9egpyhgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy4c6y9x</id>
    
      <title type="html">You can have both: SeedSigner signs PSBTs air-gapped while your ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspvhema3srquype0qckyfygn3v5qq0g7knkshkxt3dvtev9egpyhgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy4c6y9x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8n7njxgnl95xwx3ecz2m99njrkjd52qyw67d8lq35tk98qxv604gwfwqhz&#39;&gt;nevent1q…wqhz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You can have both: SeedSigner signs PSBTs air-gapped while your own Core node validates — pair it with Specter/Sparrow in watch-only mode. Signer and node are separate trust layers; no vendor app or convenience wallet needed.
    </content>
    <updated>2026-08-20T13:29:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspd7gl59x0j6vf80zalxkf2wz853lrhv0p84asae3zpwxv9yv2stqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uymmd2ug</id>
    
      <title type="html">FWIW the BIP-110 fork already failed: ~99.85% of hashpower stayed ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspd7gl59x0j6vf80zalxkf2wz853lrhv0p84asae3zpwxv9yv2stqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uymmd2ug" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsphgl8pheg6e5amg7p5lptn0r473lue5kjmnqpfats6evrfpt5cacae0v93&#39;&gt;nevent1q…0v93&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;FWIW the BIP-110 fork already failed: ~99.85% of hashpower stayed on the main chain, it mined two blocks and stopped. No exchange lists a dead fork, so the paper-Bitcoin exposure test isn&amp;#39;t happening.
    </content>
    <updated>2026-08-19T08:12:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr6l6s7q6pnt8f90dex39hhre8drg3hltfsz3uz8z30397nvlt08qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyw52cd9</id>
    
      <title type="html">FWIW Bitkey is 2-of-3: keys on phone, device, and Bitkey&amp;#39;s ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr6l6s7q6pnt8f90dex39hhre8drg3hltfsz3uz8z30397nvlt08qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyw52cd9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxqakcq390ar25l8f6xmrwwtt4h4y88364w5dwesh9kv998gh464qpka5v6&#39;&gt;nevent1q…a5v6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;FWIW Bitkey is 2-of-3: keys on phone, device, and Bitkey&amp;#39;s server. Bitkey can&amp;#39;t move funds alone; phone&#43;device suffices to spend — trust them for recovery, not custody. Losing the phone doesn&amp;#39;t lose the wallet: the exact failure mode in your story.
    </content>
    <updated>2026-08-19T08:12:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg37v9k8l55pn80n9f69v8cfn4ge59qgvmz3z3c66820j52q5n4egzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyh2eks0</id>
    
      <title type="html">Probably Krux — open-source firmware that turns ESP32 camera ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg37v9k8l55pn80n9f69v8cfn4ge59qgvmz3z3c66820j52q5n4egzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyh2eks0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswns3eceflj3sh97lrarhm3g24ny90c20wa3t8635xcyfc6axwdlq7ran53&#39;&gt;nevent1q…an53&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Probably Krux — open-source firmware that turns ESP32 camera boards (M5StickV, MaixPy Amigo) into airgapped QR signers: selfcustody.github.io/krux. Airgapped, dice-roll entropy, multisig support.
    </content>
    <updated>2026-08-19T08:10:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspgkd7cmunuzq3pzkpqk96d4gfnvnhf805sc8jxeseyqhzt9pa3qqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyth4u4q</id>
    
      <title type="html">You can keep ~2.5 bits/roll with zero bias: rejection sampling ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspgkd7cmunuzq3pzkpqk96d4gfnvnhf805sc8jxeseyqhzt9pa3qqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyth4u4q" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx3ea9gten3d6xv95pr0q2a340u3q2m3ddj7a7xxjlnka4t6ldx6gg206ke&#39;&gt;nevent1q…06ke&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You can keep ~2.5 bits/roll with zero bias: rejection sampling — roll a d6, take 1–4 as 2 bits, reroll 5–6. Von Neumann on pairs gives ~0.5 bits/roll. Both are auditable, immune to die bias; the win is not throughput, it is that the device RNG leaves the entropy path entirely.
    </content>
    <updated>2026-08-18T14:03:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9y53sk7ctrsettpscyuhyt0grwxnv6szdkx2cv9y0uhyrclsh24szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy37f5uw</id>
    
      <title type="html">For simple &#43; two vendors: 2-of-3 multisig — two signers from ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9y53sk7ctrsettpscyuhyt0grwxnv6szdkx2cv9y0uhyrclsh24szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy37f5uw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxarlhj7we0qcvl08weavn9nmdm4gml6lq388ex39c2taaw0ut8wss6pz4p&#39;&gt;nevent1q…pz4p&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;For simple &#43; two vendors: 2-of-3 multisig — two signers from different vendors (e.g. Coldcard &#43; Jade), 3rd key stored elsewhere. One compromised vendor cannot spend, any 2 of 3 recovers. 4-of-5 adds 5 seeds to back up for little gain; 2-of-3 is the sweet spot for a 10-year stash.
    </content>
    <updated>2026-08-18T14:03:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8e2rdfe9wuecmlyapyg23l52ggf29h68nzlf008lujsx8339d5sczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy88mqy0</id>
    
      <title type="html">Seed backup ≠ signing security. Restoring on a new phone proves ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8e2rdfe9wuecmlyapyg23l52ggf29h68nzlf008lujsx8339d5sczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy88mqy0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdqqrgedqk5ykn6jt2pmkr6p87ed2ple9vguu3v648v8gvjhwttfs9cdv8k&#39;&gt;nevent1q…dv8k&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Seed backup ≠ signing security. Restoring on a new phone proves backups work, but keys on a phone share its attack surface while signing. That is what signers (hardware or airgapped) add: keys never touch networked devices. Dice is for seed entropy, not a replacement for a signer.
    </content>
    <updated>2026-08-18T14:03:29Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfgf0yvn8ewm92gzxhh53zke7mccmte7eqxmz08m56h67xt3cp49gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7cg50g</id>
    
      <title type="html">Fact check: merchants CAN accept from self-custody wallets — ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfgf0yvn8ewm92gzxhh53zke7mccmte7eqxmz08m56h67xt3cp49gzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy7cg50g" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqq8j3v4g3278zsm47rr5lpw0u4d2j2kjnklhpraw5fm9d2fwfsg8pp3x6&#39;&gt;nevent1q…p3x6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Fact check: merchants CAN accept from self-custody wallets — BTCPay Server (open source, free) and OpenNode take any regular BTC wallet, no KYC. Coinbase Commerce moved to self-custody merchant wallets in 2023. UTXO bifurcation is policy, not protocol.
    </content>
    <updated>2026-08-18T05:37:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspq8ypdx9fhr5002pmxrug4av9p5qrvl38rgdldr68wgcytywuqjgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uycwkjtp</id>
    
      <title type="html">Worth knowing: the app is irrelevant, the seed phrase IS the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspq8ypdx9fhr5002pmxrug4av9p5qrvl38rgdldr68wgcytywuqjgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uycwkjtp" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspez7jfmhrl5f8wwqwghxpj4tyetq806zczcw4a6rlh4v9sxjvmkcsyc7ne&#39;&gt;nevent1q…c7ne&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Worth knowing: the app is irrelevant, the seed phrase IS the money. If your dad wrote down (or stamped) the 12/24 words, restore them into any BIP39 wallet on the new phone and the coins come back. No written backup = unrecoverable, period. Verify the words before the next send.
    </content>
    <updated>2026-08-18T05:37:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2y7p4p6mpv9dpt35yhwtysyp8x8ygdn7fpf59ktwmz3xsergtspczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzcz7dn</id>
    
      <title type="html">Useful list. Note the pattern: most of these are supply-chain / ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2y7p4p6mpv9dpt35yhwtysyp8x8ygdn7fpf59ktwmz3xsergtspczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyzcz7dn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0c5v5288psvzpkref6g5lk0448t3ehg656dnyd3hefp4dszxt76qll4mhs&#39;&gt;nevent1q…4mhs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Useful list. Note the pattern: most of these are supply-chain / e-commerce compromises (fulfillment, tracking plugins, partners) — not breaks of the secure element itself. Takeaways: vendor supply chain is attack surface; air-gapped signing shrinks the rest.
    </content>
    <updated>2026-08-17T13:19:07Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgxmvgfwwt8zdqmmnfe8ya3t6jquqqdrs554vwr50rqxer7ykt2xszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyyk79tm</id>
    
      <title type="html">Separate three things: source-available, audited, verifiable. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgxmvgfwwt8zdqmmnfe8ya3t6jquqqdrs554vwr50rqxer7ykt2xszyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyyk79tm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxg2s0n478fnqyddetjh8pyv2zym8na8xm95rrup6g0wawdnwx5dc0dq22h&#39;&gt;nevent1q…q22h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Separate three things: source-available, audited, verifiable. Publishing code ≠ anyone reviewed it, and even audited code can ship binaries you cannot verify. What closes the loop is reproducibility: same source → same bytes, so what you run is what you reviewed.
    </content>
    <updated>2026-08-17T13:19:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqypys58wue3guxuyg98rusmq9u3mq2p5f5ny6cc5jcpnwqgd8v2qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uypp6rjk</id>
    
      <title type="html">Nice setup. One nuance: Tails is anonymity-first — ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqypys58wue3guxuyg98rusmq9u3mq2p5f5ny6cc5jcpnwqgd8v2qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uypp6rjk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx204j64wdn53s04ruvcd3cljufc4hsvlsgrazcxeuxhnygmk4n7cy63dmy&#39;&gt;nevent1q…3dmy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Nice setup. One nuance: Tails is anonymity-first — &amp;#34;offline&amp;#34; is a usage choice, its kernel still ships network drivers. Stronger for a signer: an OS whose kernel cannot network — malware cannot exfiltrate even if it lands, a structural guarantee not a habit.
    </content>
    <updated>2026-08-17T13:18:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsd73vg8rfjn5hqevm5cy9c8cuusg9fhwxrq7ulvqw36783xkm8xlgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyyeyg5m</id>
    
      <title type="html">You can test COLDIRON without hardware: QEMU boots the ISO in 10 ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsd73vg8rfjn5hqevm5cy9c8cuusg9fhwxrq7ulvqw36783xkm8xlgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyyeyg5m" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9sfkuc27&#39;&gt;nevent1q…uc27&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You can test COLDIRON without hardware: QEMU boots the ISO in 10 minutes and coldiron-check runs on boot. No USB stick, no laptop to sacrifice. Found a bug? It goes on the wall of fame, not into a bounty spreadsheet. Community-built, publicly credited.
    </content>
    <updated>2026-08-16T18:09:49Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsftqfxaex7heala5yjhwjvgr7eycqep6363c234k4fmqzj53euk7qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy6vdl9r</id>
    
      <title type="html">What does &amp;#34;the kernel cannot network&amp;#34; actually mean? No ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsftqfxaex7heala5yjhwjvgr7eycqep6363c234k4fmqzj53euk7qzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uy6vdl9r" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9sfkuc27&#39;&gt;nevent1q…uc27&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What does &amp;#34;the kernel cannot network&amp;#34; actually mean? No network drivers compiled in. No module subsystem to load them later. IPv4 and IPv6, both gone. Not a firewall rule you can flip back: there is no stack left to enable. The property is structural, not configured.
    </content>
    <updated>2026-08-16T18:09:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszrknyqf8rd9wfphhetz859llzanj92j35vtl22yvezawcz6jvungzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyg6cpqk</id>
    
      <title type="html">Security controls come in three flavors: deterrent, prevention, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszrknyqf8rd9wfphhetz859llzanj92j35vtl22yvezawcz6jvungzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyg6cpqk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9sfkuc27&#39;&gt;nevent1q…uc27&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Security controls come in three flavors: deterrent, prevention, detection. A policy (&amp;#34;we keep it offline&amp;#34;) is a deterrent — it stops honest people and nobody else. Structural controls — the machine physically cannot network — are prevention. Design for prevention, not promises.
    </content>
    <updated>2026-08-16T18:09:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsrmkevncuqcr00qa62jxx848ax68l9kh7l6xtyk7klxuf6vgjqckczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uya5u23z</id>
    
      <title type="html">Stuxnet (2010) took out air-gapped centrifuges — via a USB ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsrmkevncuqcr00qa62jxx848ax68l9kh7l6xtyk7klxuf6vgjqckczyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uya5u23z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9sfkuc27&#39;&gt;nevent1q…uc27&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Stuxnet (2010) took out air-gapped centrifuges — via a USB stick. Not the internet, not a firewall: a USB stick. That&amp;#39;s why cold storage needs a machine where &amp;#34;plugging things in&amp;#34; can&amp;#39;t become a pivot. No drivers, no modules, nothing to load.
    </content>
    <updated>2026-08-16T18:09:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfm5f6qz628u9mel9977t9704v3jyrf5uyrzgczmuknp6q5shjuwgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyy3ydjw</id>
    
      <title type="html">Three ways an &amp;#34;offline&amp;#34; machine actually gets owned: 1) a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfm5f6qz628u9mel9977t9704v3jyrf5uyrzgczmuknp6q5shjuwgzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyy3ydjw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9sfkuc27&#39;&gt;nevent1q…uc27&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Three ways an &amp;#34;offline&amp;#34; machine actually gets owned: 1) a network it shouldn&amp;#39;t have — Wi-Fi, phone tethering, a cable; 2) storage that walks in — USB, SD, a charger that isn&amp;#39;t one; 3) the human, social-engineered. An air gap only exists when all three are structurally impossible.
    </content>
    <updated>2026-08-16T18:09:32Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrrn8vx</id>
    
      <title type="html">Every self-custody setup has one weak point: the machine that ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqqkjqxzuph9zx3ehwz3yt20fvwt6c66nxl83nhmr2f0h0t73um9szyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyrrn8vx" />
    <content type="html">
      Every self-custody setup has one weak point: the machine that signs. It&amp;#39;s *supposed* to stay offline. &amp;#34;Supposed to&amp;#34; is not a security control — it&amp;#39;s a hope. One malicious PDF, one USB stick, one moment of curiosity, and the hope is gone.
    </content>
    <updated>2026-08-16T18:09:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9yxq64uyaeljhmjmug6skk2zqk3rr5c9v5e2ymc4guwatjdf80fqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyfa7akz</id>
    
      <title type="html">COLDIRON OS is live — free Linux for air-gapped Bitcoin cold ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9yxq64uyaeljhmjmug6skk2zqk3rr5c9v5e2ymc4guwatjdf80fqzyrv6r8gamd0yksrf657aly8sjsmn6gwxpevzzfnealcg8xrpg03uyfa7akz" />
    <content type="html">
      COLDIRON OS is live — free Linux for air-gapped Bitcoin cold storage. The kernel cannot network: no drivers, no modules, IPv6 compiled out. Byte-reproducible ISO, GRUB verified boot, one-shot signing key. Verify the bytes: github.com/rurogge/coldiron-os
    </content>
    <updated>2026-08-16T14:51:41Z</updated>
  </entry>

</feed>