<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1xwdym5sne88xldc5809azwrgasp60ze27easgew8e7p3vj7qr7ssjc2lxh.rss" />
  <link href="https://nostr.ae/npub1xwdym5sne88xldc5809azwrgasp60ze27easgew8e7p3vj7qr7ssjc2lxh" />
  <id>https://nostr.ae/npub1xwdym5sne88xldc5809azwrgasp60ze27easgew8e7p3vj7qr7ssjc2lxh</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsyla295gjwetwr8yw2vcsrvmryhgj77t3xszhtnj3ff6jmukpx3lgzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zkav200</id>
    
      <title type="html">📅 Original date posted:2022-02-01 📝 Original message:Hi ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyla295gjwetwr8yw2vcsrvmryhgj77t3xszhtnj3ff6jmukpx3lgzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zkav200" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9g87hys9krm3nmvtww2mjprndcqdkqh83shcm4nu8020gdmcg7gd83g94&#39;&gt;nevent1q…3g94&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2022-02-01&lt;br/&gt;📝 Original message:Hi Bastein,&lt;br/&gt;&lt;br/&gt;&amp;gt; This work will highly improve the security of any multi-party contract trying to build on top of bitcoin&lt;br/&gt;Do you think such multi party contracts are vulnerable by design considering they rely on policy that cannot be enforced?&lt;br/&gt;&lt;br/&gt;&amp;gt; For starters, let me quickly explain why the current rules are hard to work with in the context of lightning&lt;br/&gt;Using the term &amp;#39;rules&amp;#39; can be confusing sometimes because it&amp;#39;s just a policy and different from consensus rules. I wish we could change this in the BIP with something else.&lt;br/&gt;&lt;br/&gt;&amp;gt; I&amp;#39;m actually paying a high fee twice instead of once (and needlessly using on-chain space, our scarcest asset, because we could have avoided that additional transaction&lt;br/&gt;Not sure I understand this part because if a transaction is on-chain it can&amp;#39;t be replaced. &lt;br/&gt;&lt;br/&gt;&amp;gt; The second biggest pain point is rule 3. It prevents me from efficiently using my capital while it&amp;#39;s unconfirmed&lt;br/&gt;&amp;gt; I&amp;#39;m curious to hear other people&amp;#39;s thoughts on that. If it makes sense, I would propose the following very simple rules&lt;br/&gt;Looks interesting however not sure about X and Y.&lt;br/&gt;&lt;br/&gt;-- &lt;br/&gt;Prayank&lt;br/&gt;&lt;br/&gt;A3B1 E430 2298 178F&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220201/48931d6d/attachment-0001.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220201/48931d6d/attachment-0001.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T23:03:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr02l5rftq33egfe4x3dejn9pjd44grxh5yzysezffgua5scj8jcszyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06znmz5jc</id>
    
      <title type="html">📅 Original date posted:2022-01-13 📝 Original message:Hi ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr02l5rftq33egfe4x3dejn9pjd44grxh5yzysezffgua5scj8jcszyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06znmz5jc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszp74x06zawq89pmp6qn3a7fczcrcaxm34tgxe4e22f2jhwhlsgkca0djcu&#39;&gt;nevent1q…djcu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2022-01-13&lt;br/&gt;📝 Original message:Hi Jack,&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; The main purpose of this Fund is to defend developers from lawsuits regarding their activities in the Bitcoin ecosystem, including finding and retaining defense counsel, developing litigation strategy, and paying legal bills. This is a free and voluntary option for developers to take advantage of if they so wish. The Fund will start with a corps of volunteer and part-time lawyers. The board of the Fund will be responsible for determining which lawsuits and defendants it will help defend.&lt;br/&gt;&lt;br/&gt;Thanks for helping the developers in legal issues. Appreciate your efforts and I understand your intentions are to help Bitcoin in every possible way.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Positives that I see in this initiative:&lt;br/&gt;&lt;br/&gt;1.Developers don&amp;#39;t need to worry about rich scammers and can focus on development.&lt;br/&gt;&lt;br/&gt;2.Financial help for developers as legal issues can end up in wasting lot of time and money.&lt;br/&gt;&lt;br/&gt;3.People who have misused courts to affect bitcoin developers will get better response that they deserve.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;I had few suggestions and feel free to ignore them if they do not make sense:&lt;br/&gt;&lt;br/&gt;1.Name of this fund could be anything and &amp;#39;The Bitcoin Legal Defense Fund&amp;#39; can be confusing or misleading for newbies. There is nothing official in Bitcoin however people believe things written in news articles and some of them might consider it as an official bitcoin legal fund.&lt;br/&gt;&lt;br/&gt;2.It would be better if people involved in such important funds do not comment/influence soft fork related discussions. Example: Alex Morcos had some opinions about activation mechanism during Taproot soft fork IIRC.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;-- &lt;br/&gt;Prayank&lt;br/&gt;&lt;br/&gt;A3B1 E430 2298 178F&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220113/17a38cb8/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220113/17a38cb8/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T23:02:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9x58j824sl3k7w75tt8re6hy8k7w4jtwnfd2sh7hyrfnaect3cpszyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zsf2v38</id>
    
      <title type="html">📅 Original date posted:2021-10-11 📝 Original message:Hi ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9x58j824sl3k7w75tt8re6hy8k7w4jtwnfd2sh7hyrfnaect3cpszyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zsf2v38" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyel3l7h747pxy0p3n7hmgkq0g8xd44p0e6p5tn0mmutfaf3v6tvqrhh9sz&#39;&gt;nevent1q…h9sz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2021-10-11&lt;br/&gt;📝 Original message:Hi Michael,&lt;br/&gt;&lt;br/&gt;Agree with almost everything.&lt;br/&gt;&lt;br/&gt;&amp;gt; Miner signaling is a tool for signaling readiness. It is not voting for the soft fork or expressing support for the soft fork. There should not be any attempt to facilitate miner signaling until there is sufficient community consensus (the mining community is a subset of the community) on the soft fork. &lt;br/&gt;&lt;br/&gt;This is really important which gets ignored. I wish there was a way to solve this problem in a way that it is not misinterpreted by users.&lt;br/&gt;&lt;br/&gt;During signalling for taproot, there were lots of users in different communities that believed miners are voting for taproot and we need some percentage of miners to agree before making any changes in Bitcoin. It was not just non-technical users but few mining pools, exchanges etc. also considered miners signaling as some voting process.&lt;br/&gt;&lt;br/&gt;Best I could do at that moment was share this link: &lt;a href=&#34;https://bitcoin.stackexchange.com/questions/97043/is-there-an-active-list-of-bips-currently-open-for-voting/&#34;&gt;https://bitcoin.stackexchange.com/questions/97043/is-there-an-active-list-of-bips-currently-open-for-voting/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;However I am sure there are lot of people who still think miners vote during signaling. Opinions of few developers on MASF vs UASF also adds more confusion to this thing. I could not think of any solution to solve this problem.&lt;br/&gt;-- &lt;br/&gt;Prayank&lt;br/&gt;&lt;br/&gt;A3B1 E430 2298 178F&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20211011/9d118eee/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20211011/9d118eee/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T23:00:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8z8pxtyejy8k2ruz3tt83c8pkj55hljm47tksxuxv42j8llampcgzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zdk52mm</id>
    
      <title type="html">📅 Original date posted:2021-10-01 📝 Original message:Good ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8z8pxtyejy8k2ruz3tt83c8pkj55hljm47tksxuxv42j8llampcgzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zdk52mm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd9gwxvh0sq8t0rqetmuq03cm4hlzg256q295crnlu5v0u5mghcvqfjnacl&#39;&gt;nevent1q…nacl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2021-10-01&lt;br/&gt;📝 Original message:Good morning ZmnSCPxj,&lt;br/&gt;&lt;br/&gt;Although its evening here and time zones feel irrelevant since I got involved in Bitcoin few years back. Initially I tried everything a tech enthusiast does after finding such thing online. Had a startup in 2017 which was a website that can be used to buy flight tickets using bitcoin. It didn&amp;#39;t work. Trading became a part of life, worked for few exchanges, did meetups, spent hours on different platforms discussing issues in which I was called &amp;#34;maximalist&amp;#34; most of the times because focused only on Bitcoin and had so much positive to talk about it whole day. In last 2 years started contributing to development in different projects. But someone told me today all this is nothing and I am negative about Bitcoin development because I don&amp;#39;t agree with all of their opinions.&lt;br/&gt;&lt;br/&gt;Anyway this wasn&amp;#39;t related to thread and your email. Sorry I just had to express myself which some people even call &amp;#34;rage quit&amp;#34; and allow only once.&lt;br/&gt;&lt;br/&gt;I completely agree with all the points you mentioned. Thanks for your understanding of the issue and my approach towards Bitcoin security.&lt;br/&gt;&lt;br/&gt;-- &lt;br/&gt;Prayank&lt;br/&gt;&lt;br/&gt;A3B1 E430 2298 178F&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Oct 1, 2021, 17:57 by ZmnSCPxj at protonmail.com:&lt;br/&gt;&lt;br/&gt;&amp;gt; Good morning Prayank,&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; I think this is still good to do, controversial or no, but then I am permanently under a pseudonym anyway, for what that is worth.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Few questions for everyone reading this email:&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; 1.What is better for Security? Trusting authors and their claims in PRs or a good review process?&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Review, of course.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; 2.Few people use commits from unmerged PRs in production. Is it a good practice?&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Not unless they carefully reviewed it and are familiar enough with the codebase to do so.&lt;br/&gt;&amp;gt; In practice core maintainers of projects will **very** occassionally put unmerged PRs in experimental semi-production servers to get data on it, but they tend to be very familiar with the code, being core maintainers, and presumably have a better-than-average probability of catching security issues beforehand.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; 3.Does this exercise help us in being prepared for worst?&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; I personally believe it does.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Do note that in practice, humans being lazy, will come to trust long-time contributors, and may reduce review for them just to keep their workload down, so that is not tested (since you will be making throwaway accounts).&lt;br/&gt;&amp;gt; However, long-time contributors introducing security vulnerabilities tend to be a good bit rarer anyway (reputations are valuable), so this somewhat matches expected problems (i.e. newer contributors deliberately or accidentally (due to unfamiliarity) introducing vulnerabilities).&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; I think it would be valuable to lay out exactly what you intend to do, e.g.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; * Generate commitments of the pseudonyms you will use.&lt;br/&gt;&amp;gt; * Insert a few random 32-byte numbers among the commitments and shuffle them.&lt;br/&gt;&amp;gt; * Post the list with the commitments &#43; random crap here.&lt;br/&gt;&amp;gt; * Insert avulnerability-adding PRs to targets.&lt;br/&gt;&amp;gt; * If it gets caught during review, publicly announce here with praise that their project caught the PR and reveal the decommitment publicly.&lt;br/&gt;&amp;gt; * If not caught during review, privately reveal both the inserted vulnerability *and* the review failure via the normal private vulnerability-reporting channels.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; The extra random numbers mixed with the commitments produce uncertainty about whether or not you are done, which is important to ensure that private vulnerabilities are harder to sniff out.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; I think public praise of review processes is important, and to privately correct review processes.&lt;br/&gt;&amp;gt; Review processes **are** code, followed by sapient brains, and this kind of testing is still valuable, but just as vulnerabilities in machine-readable code require careful, initially-private handling, vulnerabilities in review processes (being just another kind of code, readable by much more complicated machines) also require careful, initially-private handling.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Basically: treat review process failures the same as code vulnerabilities, pressure the maintainers to fix the review process failure, then only reveal it later when the maintainers have cleaned up the review process.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Regards,&lt;br/&gt;&amp;gt; ZmnSCPxj&lt;br/&gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20211001/25e558c1/attachment-0001.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20211001/25e558c1/attachment-0001.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T22:59:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgzdja5ps69u50nxjfreg86y6grrsewl4neqjjjtswkswvgz4jzfgzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zz9z2cr</id>
    
      <title type="html">📅 Original date posted:2021-10-01 📝 Original message:Hi ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgzdja5ps69u50nxjfreg86y6grrsewl4neqjjjtswkswvgz4jzfgzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06zz9z2cr" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs88xsyp5xjhuxz4u5r7nqmgwerekfdx44kqygz64ndm3l3qa6eh9g5tpmu9&#39;&gt;nevent1q…pmu9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2021-10-01&lt;br/&gt;📝 Original message:Hi Ruben,&lt;br/&gt;&lt;br/&gt;&amp;gt; encouraging an environment of increased mistrust&lt;br/&gt;&lt;br/&gt;I have always tried to review pull requests based on what PR does, code, my tests etc. and it was never based on author of pull request or what author is trying to claim. So there is no trust involved. I am assuming others follow the same thing. Infact there was a PR recently in which I found it doesn&amp;#39;t fix the issues it claims to fix. Its not same as introducing vulnerability but the point is anyone can create PR, write anything, as a reviewer we need to review everything apart from algos already helping us which include Github Dependabot alerts, CI used by respository, other automated tools etc.&lt;br/&gt;&lt;br/&gt;&amp;gt; For this reason, it would be appropriate to check first whether your plan is actually appreciated&lt;br/&gt;&lt;br/&gt;Right. I don&amp;#39;t want to get in some controversy when I am not even doing anything with wrong intentions. If maintainers of important Bitcoin projects think I am not qualified enough to do this, they can plan such exercise internally and do it in a better way. Although I am still interested in the results because they will help us improve review process and security in different Bitcoin projects.&lt;br/&gt;&lt;br/&gt;I would like to repeat what I wrote in another email responding to few other devs for same thread but wasn&amp;#39;t CCed to bitcoin-dev mailing list:&lt;br/&gt;&lt;br/&gt;&amp;#34;I can avoid doing this but it is impossible to stop government agencies and anyone else to do the same thing without informing. All I am doing is creating pull requests and expect them to be reviewed properly before being merged.&amp;#34;&lt;br/&gt;&lt;br/&gt;Few questions for everyone reading this email:&lt;br/&gt;&lt;br/&gt;1.What is better for Security? Trusting authors and their claims in PRs or a good review process?&lt;br/&gt;2.Few people use commits from unmerged PRs in production. Is it a good practice?&lt;br/&gt;3.Does this exercise help us in being prepared for worst?&lt;br/&gt;&lt;br/&gt;-- &lt;br/&gt;Prayank&lt;br/&gt;&lt;br/&gt;A3B1 E430 2298 178F&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Oct 1, 2021, 02:06 by rsomsen at gmail.com:&lt;br/&gt;&lt;br/&gt;&amp;gt; Hi Prayank,&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; While I can see how this can come from a place of good intentions, I’d strongly advise you to tread carefully because what you are suggesting is quite controversial. A related event occurred in the Linux community and it did not go over well. See &amp;gt; &lt;a href=&#34;https://lkml.org/lkml/2021/5/5/1244&amp;gt&#34;&gt;https://lkml.org/lkml/2021/5/5/1244&amp;gt&lt;/a&gt;;  and &amp;gt; &lt;a href=&#34;https://lore.kernel.org/linux-nfs/YH%2FfM%2FTsbmcZzwnX@kroah.com/&amp;gt&#34;&gt;https://lore.kernel.org/linux-nfs/YH%2FfM%2FTsbmcZzwnX@kroah.com/&amp;gt&lt;/a&gt;;  .&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; The main point of contention is that your research comes at the expense of the existing open source contributors – you’d be one-sidedly deceiving them, encouraging an environment of increased mistrust, and causing them a lot of work in order to gather the data you’re interested in. For this reason, it would be appropriate to check first whether your plan is actually appreciated.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Speaking on behalf of the bitcoin-dev moderators, please ensure your plan is welcomed by the contributors, prior to proceeding.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Best regards,&lt;br/&gt;&amp;gt; Ruben Somsen&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; On Tue, Sep 28, 2021 at 10:05 AM Prayank via bitcoin-dev &amp;lt;&amp;gt; bitcoin-dev at lists.linuxfoundation.org&amp;gt; &amp;gt; wrote:&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Hi ZmnSCPxj,&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Thanks for suggestion about sha256sum. I will share 10 in next few weeks. This exercise will be done for below projects:&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; 1.Two Bitcoin full node implementations (one will be Core)&lt;br/&gt;&amp;gt;&amp;gt; 2.One &amp;lt;&lt;a href=&#34;http://2.One&amp;gt;&amp;gt;&amp;gt&#34;&gt;http://2.One&amp;gt;&amp;gt;&amp;gt&lt;/a&gt;;  Lightning implementation&lt;br/&gt;&amp;gt;&amp;gt; 3.Bisq&lt;br/&gt;&amp;gt;&amp;gt; 4.Two Bitcoin libraries&lt;br/&gt;&amp;gt;&amp;gt; 5.Two Bitcoin wallets&lt;br/&gt;&amp;gt;&amp;gt; 6.One &amp;lt;&lt;a href=&#34;http://6.One&amp;gt;&amp;gt;&amp;gt&#34;&gt;http://6.One&amp;gt;&amp;gt;&amp;gt&lt;/a&gt;;  open source block explorer&lt;br/&gt;&amp;gt;&amp;gt; 7.One &amp;lt;&lt;a href=&#34;http://7.One&amp;gt;&amp;gt;&amp;gt&#34;&gt;http://7.One&amp;gt;&amp;gt;&amp;gt&lt;/a&gt;;  coinjoin implementation&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Feel free to suggest more projects. There are no fixed dates for it however it will be done in next 6 months. All PRs will be created within a span of few days. I will ensure nothing is merged that affects the security of any Bitcoin project. Other details and results will be shared once everything is completed.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; x00 will help me in this exercise, he does penetration testing since few years and working for a cryptocurrencies derivatives exchange to manage their security. His twitter account: &amp;gt;&amp;gt; &lt;a href=&#34;https://twitter.com/1337in&#34;&gt;https://twitter.com/1337in&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; -- &lt;br/&gt;&amp;gt;&amp;gt; Prayank&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; A3B1 E430 2298 178F&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Sep 27, 2021, 15:43 by &amp;gt;&amp;gt; ZmnSCPxj at protonmail.com&amp;gt;&amp;gt; :&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; Good morning Prayank,&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Good morning Bitcoin devs,&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; In one of the answers on Bitcoin Stackexchange it was mentioned that some companies may hire you to introduce backdoors in Bitcoin Core: &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://bitcoin.stackexchange.com/a/108016/&#34;&gt;https://bitcoin.stackexchange.com/a/108016/&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; While this looked crazy when I first read it, I think preparing for such things should not be a bad idea. In the comments one link was shared in which vulnerabilities were almost introduced in Linux: &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://news.ycombinator.com/item?id=26887670&#34;&gt;https://news.ycombinator.com/item?id=26887670&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I was thinking about lot of things in last few days after reading the comments in that thread. Also tried researching about secure practices in C&#43;&#43; etc. I was planning something which I can do alone but don&amp;#39;t want to end up being called &amp;#34;bad actor&amp;#34; later so wanted to get some feedback on this idea:&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 1.Create new GitHub accounts for this exercise&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 2.Study issues in different important Bitcoin projects including Bitcoin Core, LND, Libraries, Bisq, Wallets etc.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 3.Prepare pull requests to introduce some vulnerability by fixing one of these issues&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 4.See how maintainers and reviewers respond to this and document it&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 5.Share results here after few days&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Let me know if this looks okay or there are better ways to do this.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; This seems like a good exercise.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; You may want to hash the name of the new Github account, plus some randomized salt, and post it here as well, then reveal it later (i.e. standard precommitment).&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; e.g.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; printf &amp;#39;MyBitcoinHackingName 2c3e911b3ff1f04083c5b95a7d323fd4ed8e06d17802b2aac4da622def29dbb0&amp;#39; | sha256sum&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; f0abb10ae3eca24f093a9d53e21ee384abb4d07b01f6145ba2b447da4ab693ef&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; Obviously do not share the actual name, just the sha256sum output, and store how you got the sha256sum elsewhere in triplicate.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; (to easily get a random 256-bit hex salt like the `2c3e...` above: `head -c32 /dev/random | sha256sum`; you *could* use `xxd` but `sha256sum` produces a single hex string you can easily double-click and copy-paste elsewhere, assuming you are human just like I am (note: I am definitely 100% human and not some kind of AI with plans to take over the world).)&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; Though you may need to be careful of timing (i.e. the creation date of the Github account would be fairly close to, and probably before, when you post the commitment here).&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; You could argue that the commitment is a &amp;#34;show of good faith&amp;#34; that you will reveal later.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; Regards,&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; ZmnSCPxj&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;&amp;gt;  bitcoin-dev mailing list&lt;br/&gt;&amp;gt;&amp;gt;  &amp;gt;&amp;gt; bitcoin-dev at lists.linuxfoundation.org&lt;br/&gt;&amp;gt;&amp;gt;  &amp;gt;&amp;gt; &lt;a href=&#34;https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#34;&gt;https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20211001/0007ec66/attachment-0001.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20211001/0007ec66/attachment-0001.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T22:59:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdg66w3j8zre35yhdfdt2exjpn6htszwxfyhyfm0tmnc9r8ufq0wqzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06znt9s5z</id>
    
      <title type="html">📅 Original date posted:2021-05-08 📝 Original message:My ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdg66w3j8zre35yhdfdt2exjpn6htszwxfyhyfm0tmnc9r8ufq0wqzyqee5nwjz0yuumahzsauh5fcdrkq8fut9tm8kpr9cl8cx9jtcq06znt9s5z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8ngl3g69e6mwkyxzcsnav4tvks5zdlufs0v90ydtmw59t66t0l4c87y56a&#39;&gt;nevent1q…y56a&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2021-05-08&lt;br/&gt;📝 Original message:My opinion:&lt;br/&gt;&lt;br/&gt;1.I don&amp;#39;t consider PoS to be a better consensus mechanism compared to PoW used in Bitcoin. So any proposal related to PoS in Bitcoin is not an improvement for me.&lt;br/&gt; &lt;br/&gt;2.Bitcoin is a protocol for decentralized network that creates consensus without needing a central authority to provide trust. Bitcoin with PoS will be a protocol for a network that creates consensus based on bitcoin holdings.&lt;br/&gt;&lt;br/&gt;3.Experiments with PoS can work in trust minimized applications that use Bitcoin or LN or Bitcoin sidechains. However, PoW works better for base layer or Bitcoin protocol.&lt;br/&gt;&lt;br/&gt;4.Bitcoin protocol should not be changed based on mainstream media articles, new buzzwords or trends, altcoins, governments etc. &lt;br/&gt;&lt;br/&gt;5.Everything involves trade-offs. Not everything needs to be online. Not everything needs to be on a chain of blocks. There are things that you would prefer to save in a spreadsheet offline or write on a paper. Similarly PoS is not the best consensus mechanism for a &amp;#39;decentralized network&amp;#39; but it may work for projects(not decentralized) that want to use Bitcoin for few things.&lt;br/&gt;&lt;br/&gt;6.Most of the Bitcoin users and devs consider PoW used in Bitcoin as the best consensus mechanism. Few people experimenting with PoS will result in another altcoin with nothing much to contribute in improving Bitcoin. I think there are better things to focus on and one of them is privacy.&lt;br/&gt;&lt;br/&gt;Few things related to Bitcoin mining that I consider improvements:&lt;br/&gt;&lt;br/&gt;-Stratum v2&lt;br/&gt;-More countries started mining bitcoin recently&lt;br/&gt;-Recycling ASIC heat: &lt;a href=&#34;https://braiins.com/blog/green-innovation-in-bitcoin-mining-recycling-asic-heat&#34;&gt;https://braiins.com/blog/green-innovation-in-bitcoin-mining-recycling-asic-heat&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;I would love to see people in India researching about creating better ASICs and more involved in Bitcoin mining. &lt;br/&gt;&lt;br/&gt;Related links:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://bitcoin.stackexchange.com/questions/95356/why-doesnt-bitcoin-migrate-to-proof-of-stake&#34;&gt;https://bitcoin.stackexchange.com/questions/95356/why-doesnt-bitcoin-migrate-to-proof-of-stake&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://download.wpsoftware.net/bitcoin/asic-faq.pdf&#34;&gt;https://download.wpsoftware.net/bitcoin/asic-faq.pdf&lt;/a&gt; (Andrew Poelstra)&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://medium.com/@dsl_uiuc/fake-stake-attacks-on-chain-based-proof-of-stake-cryptocurrencies-b8b05723f806&#34;&gt;https://medium.com/@dsl_uiuc/fake-stake-attacks-on-chain-based-proof-of-stake-cryptocurrencies-b8b05723f806&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;-- &lt;br/&gt; Prayank&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20210508/ba41a1a9/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20210508/ba41a1a9/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T22:52:40Z</updated>
  </entry>

</feed>