Last Notes
I didn't think about it much for a long time, then pretty late after I couldn't deny. I take issue with people who think they have it all figured out, or strictly believe the official narrative even when presented with mountains of odd loose ends
Imagine if the guy who lost 200 BTC… https://onlydans.blossom.band/63e149b4e4f480295c69ba245c473589ebee63795114715dfd563f72f74eff5f.png
Why would you manifest this 🥲
This sounds really good in terms of privacy. Would be great if @nprofile…0n4w and other collaborative multisig providers like casa etc. could adapt this too.
https://blockdyor.com/bitkey-chain-code-delegation/
Yeah funding is always and forever an issue it seems
Um sweetie. Less Santino, more Vito.
It’s pretty new, and currently out of stock. I’m encouraging them to make a purple Nostr version.
https://blossom.primal.net/a3e0dba220c5bcd24e79b67881cddf4112a353868c9eb950c36460c6be561f67.jpg
Thank you, @npub1xnf…lpr5 and @npub1psm…8970 for being on the ball and keeping us informed on Nostr. 🫂
I'm not going all or nothing. I am asking myself why? for what benefit? is there another way? And other questions first now instead of just a blind cool new tech I'll find a use for it mentality.
You are at risk as much as singlesig users.
Yeah I don't see any meaningful and significant difference between any of them for any of the things we care about as freedom lovers.
this guy wrote all the shitty coldcard code https://x.com/DocHex
Me too. This is modern language honestly.
https://youtube.com/watch?v=-4eQZdxlPCU
this it wrote libngu. https://x.com/switck
Your Uncle sounds like he would be fun at parties.
How does spark rely on boltz?
this is the coinkite post office box
3219 Yonge Street, Unit 376, Toronto, Canada
send them a letter
https://i.nostr.build/v66qhGyInwsdQaaZ.jpg
I am a bit annoyed personally with Infineon, especially since they like to cheap out on their crypto it seems. See EUCLEAK (32-bit masking instead of full masking) and RoCA (weird “cheaper” prime generation algorithm)
Most commercial SEs also feed TRNG bytes through whitening and processing
I would say the random numbers generated by it, when mixed with the OS pool, are sufficiently good
“I’m broadcasting.” #overheardincornychat
I did not. I had a multisig set up with three different MK4s, where the seed was autogenerated.
TL;DR if you did not SeedXOR seeds yourself, and instead used Coldcard to *split it* with TRNG:
- All except 1 part is predictable
- The last part is enough by itself to get your original seed
This is because the Coldcard generates n-1 dummy seeds, and XORs them with your seed to get the last share. However all the dummy seeds are weak
So someone could just bruteforce all possible ones.
Your funds are not at risk of being stolen remotely by an attacker.
It just is that, if you did this way of share splitting, you should assume 1 share is enough to crack it.
I guess not if you're just learning about it
Did you add your own entropy?
Yes. These are rules to maintain at least some beauty of the village. But you seem to see problems in everything and not even trying to find solutions.
Stop whining. The world is not as dark as you want it to see.
End-to-end quality assurance testing using the Kolmogorov–Smirnov method, and not just for the TRNG chips, would enhance product reliability.
don't hate on @npub1qny…95gx he is legit
#nevent1q…0ll9
Both awesome products, great for someone who wants to do a deep dive into the technology. I would run a workshop on those, but I wouldn’t recommend them as a first cold storage option my neighbor down the street who just wants to get off Coinbase.
When you want to actually fact check it, might look into other reports about it. Unless there is proof of manipulation, rare outcomes are no evidence against it being real.
Today I'm wondering if the outcome is that AI destroys the tech industry and forces us to abandon connected devices altogether.
Why would I want my new thing to be connected or even electric at all if avoidable?
Around 10-15 years ago I was obsessed with the idea of connecting all the things. Now I don't want it anymore when that future finally arrived. Will it take another 10-15 years for wider society to catch up to my thinking again or will I diverge forever and just become more weird?
No. That was the video presenter's opinion at the time, but the latest ColdCard vulnerability has proven him wrong.
The issue we know now is that the onboard RNG was also not sufficient. People just believed it was at the time, including this video presenter, and advised users against complicating their setup by adding their own dice rolls or adding a passphrase they might lose.
The speed with which you responded makes me think you're a bot, but replying was still necessary to keep others from being confused.
Not through Boltz. You’d need to do it another way.
I'm all aboard the supercycle train. Let's go!
Okay I just wanted to make sure I wasn't remembering things wrong. I haven't seen or heard anything about it for a couple of years now.
Definitely will moving forward.
As a non technical person, I simply trusted what others would say about ColdCard. It also seems NVK did a very good job of killing any narrative that went against his products, which didn't help in making a good consumer choice.
I'm lucky I got out on time, and happy I can learn from the ordeal. Now I know about entropy and dice rolling, which I had no idea about previously.
Makes me wonder what else I'm not accounting for.
Seedsigner plus sparrow has an extremely user friendly workflow once you get past the hurdle of building and flashing the thing. Far better UX on a built seedsigner than a coldcard by comparison.
Not sure if this is it.
I watched the video and the danger he points out is not the ColdCard's onboard entropy generation, but the ability to create a wallet using dice rolls alone and people creating wallets with too low an amout of dice rolls (less than 50). His problem is that the UI doesn't prevent people from creating wallets with that few dice rolls, and that it can appear that the dice rolls are being added to onboard RNG, when that is not the case when the user selects dice only.
In fact, his advice is the same as what got us into this mess: "Just trust the onboard RNG if you don't know what you're doing. Maybe add a passphrase, but even that can be dangerous because the more you complicate your setup, the more likely you will forget how to access your funds and lose all your money."
From what I could tell, he had no warning in the video about the onboard RNG for creating adequate entropy whatsoever.
https://youtube.com/watch?v=Arlnc6P4qpY
The government does not serve justice. It obstructs it. #Ancap is the only way to go.
Coins are been sent to exchanges in recent days because there's a ColdCard exploit, were coins are been drained from wallets
The on-device random number generator isn't used in MK3 or *or later*, and therefore those devices generated seed phrases that are easy to guess
Did you know this?
If you have a cold card, you must act immediately
Does anyone remember that one clock that used old Soviet vacuum tubes to show the price?
another scammer
https://i.nostr.build/13qqgLT6ho8sM4XM.jpg
Just curious what someone who wasn't that old during the time it was more hotly debated might think. Agree with you, and don't claim to know exactly what went down, just that official story has a ton of holes
It’s a crappy product. I’m glad to have my Blocktron instead.