Last Notes
Do you want to sell fork coins? (They will likely have no value anyway so not worth bothering)
Yes: you need to care
No: absolutely nothing changes except maybe some BIP110 peers need to have their channels force closed
Risk of fund loss: none
Bye bye Luke's witnesses. Fork off.
Or as my guy put it:
#nevent1q…7pda
and just like that, absolutely no one noticed
https://i.nostr.build/0KjAdVx2oLBxcU3I.jpg
Its not "irrelevant" that CSPRNG security underlies the entire internet. It's something that people need to know as their lives happen more and more online. They are ALREADY trusting device RND in dozens of ways.
So yeah, the discussion was use RNG or roll dice for a seed, there's nothing non-sequitur talking about this when the subject is RNG.
And there's also nothing at all "misleading" about saying that people could ALSO use a devices RNG to generate a private key.
if they're comfortable with it of course.
This gives people the information they need in order to weigh the trade-offs of using different methods.
YOU'RE the only one telling people what they absolutely should or shouldn't do.
So the only one "security theater fear-mongering" is you.
One more reason why it's not a good idea to trust a single manufacturer.
For me it was shocking, that apparently it's possible to extract a seed with a firmware update.
Even tough most manufacturers promise that they are not like Ledger - for most people it's impossible to verify that.
It'll be entertaining and educational to see what comes next for sure.
Secure element RNGs protect billions of credit cards, IDs, passports, computers, and more. Similar RNGs on HSMs protect the entire CA system, DNSSEC, and a lot of cryptocurrency. The Linux, macOS and Windows RNGs protect every website and application on the internet.
With secure elements, the only catastrophe that I can easily recall is RoCA. And that was caused by using a insecure prime generation algorithm instead of an RNG failure.
This is a uniquely Bitcoin problem. All the good infosec people work for general cryptocurrency companies, or at way more reputable companies.
With cutting corners and the incompetence of people at these companies, it is not unexpected that we have scared all the competent people away
Oh, it does do this? I should have checked when you said you thought it might, but I didn't. That is awesome, and reason enough imo to build one. I'm WAY more comfortable doing checksum on something offline than trusting I know enough about computer security to try and do it on a laptop "offline." Thanks!
Funny.
I was originally thinking maybe it's a bitcoin-novice who got lucky with Kimi and hurriedly stole coins (doing multiple addresses would allow thief to deny they were the sole perpetrator, and copycats were doing other coins that weren't tied to them). But now I'm wondering if maybe a State actor isn't a bit more likely, since the benefit to someone like that of doing it this way is that it's harder for people to lie about having funds stolen. Just a random thought I felt like putting out there, so I could claim I KNEW IT if it turns out I'm right, haha.
Thanks to @npub1mpz…0pxm for putting this orange pill in public.
https://i.nostr.build/27xJvHZDnuIdXPYw.jpg
Regardless of your stance on spam, BIP-110 “UA”SF was a horrible idea. It will likely fail anyway.
The only thing it achieved is confuse people and polarize them further. Congratulations.
(My opinion is that we should not encourage it, by blocking it via *relay policy*. People don’t want to build on uncertain ground. But consensus should not be changed.)
You sure it was not the so-so scary john-doe/qwen3.6-27b-ultra-heretic-abliterated-vl-nvfp4-q4-fable-distill-lora-merge-v2-gguf ?
is anyone selling popcorn for sats?
#nevent1q…y0kj
The iRobot integration uses their cloud API, I don’t think it’s local.
I have the iRobot integration set up on Home Assistant, and I’m using ha-mcp with Claude to connect to HA
Mine is sandboxed within a container and wrapped with tmux so I can send it commands you otherwise couldn’t (like /plugin or /clear).
If anybody can help Oshi out he’s an awesome dude!! Let’s share and repost this and get him to the show!!
#grownostr #plebchain
#nevent1q…wkr6
Only 12 blocks to go till mandatory bip110 signaling 🕵
Satoshi’s Coins are like The One Piece.
The era of slaughter of youth and morals. Decadence decade debauchery. It's why it was nice to hear my friend just calmly say "yeah, I don't think I'll sell out on my morals. If I lose from that, I can always build more". We need more of that.
In my case, I’m a power user with nothing else better to do than post on Nostr all day.
I’m sure there’s spam bots that react to what the human network is talking about, in my circle I’ve noticed a lot of former Bitcoiners talk about M*nero more now.
Just seems like a culture shift honestly.
Touch sand > Touching grass
The other trend I find interesting is this approach that, once you parse the wonderful phrasing, roughly translates as "I want to put your skin in my game". Very umm Ukrainian or something
What’s spam vs people using Nostr 🤔?
I’ve noticed an organic move towards a new currency of choice.
Very true! Much more enjoyable.
Ah yes, lucid dreaming! 🤣🤪
I haven't been
but its kinda a nice break from catastrophic self-custody failure 😬
Browsing X after the Coldcard vulnerability has just felt like injecting pure schizophrenia into my veins…
Was just having that conversation with someone. What is the cost to purchase someone's moral fabric? Seems to generally be a low bar
Frankly I’m just not even thinking about it lol.
I see. This is a good fix.
I mean
We were just talking about totp...
That isn't really "less high stakes"
There trillions of dollars and nation state integrity depending on CSPRNG.
But sure, roll your own. Implementation failure is obviously a thing.
Life itself. She’s been good to me. We’ve been through a lot but I take care of her well
I’ll share there too. Thanks F
Nice. Not the only road though, anyone can copy this.
That would be a total game changer.
But it seems like at this point the ux would be atrocious
People keep telling me RNG is broken and its all a larp anyway 😏
It's odd that the CC their moved coins to so few addresses. It seems it would have been better to move them to a slew of different ones, for a number of reasons. The downside of this which I just thought about too, is that it makes the "boating accident" excuse a little more difficult, since you'd have to show funds moving to one of the known theft addresses. Weird...
Sorry i meant "real 2fa" ie totp
They do the text thing.
224k, 2004 Honda. She’s a champ though. Engine is still good!
Lol
Is their a signer for that??
Oh of course!
I didn't know amber would take the hex ...