Last Notes
I thought this would be true at the beginning, and was trying to be generous, as anyone can have a bug. But the software craftsmanship was incompetent on all levels:
* Starting from the management decision to get off open-source for the firmware,
* Using MicroPython wrapping to facilitate shitcoinery, which raised the complexity and added the faulty library to the stack,
* Falling back on a critical path, instead of throwing an error and breaking,
* And what has got to be encryption test cases so bad that they're going to end up in computer science textbooks under "What not to do."
I've been in software development since 1998 and I have **never ever** seen such poor software craftsmanship. Not industry-standard practice and arguably criminally negligible. If we did this in automotive, bioinformatics, or heavy industry, they would sue us into the ground and arrest the CEO.
Nostr libraries look pretty good, so far.
#nevent1q…nn7w
The keygen for all of the libraries I have used draw full 256-bit values from OS CSPRNGs. Code audited:
# JavaScript / TypeScript
* nostr-tools (versions 2.15 – 2.23.5)
* @nostr/tools 2.20.0 (the JSR-published variant of nostr-tools)
* @nostr-dev-kit/ndk 2.14.35 (+ ndk-cache-dexie)
* @contextvm/sdk —(ContextVM signer, wraps nostr-tools)
# Go
* go-nostr (nbd-wtf) (v0.27.0, notably older)
# Kotlin / JVM
* no Nostr library; direct implementation on top of ACINQ secp256k1-kmp 0.17.3 (plus BouncyCastle in the Android app)
# Elixir
* no Nostr library; implements on top of lib_secp256k1 0.7.1
# PHP
* swentel/nostr-php 1.9.4 (server side; pulls in elliptic-php)
# Python
* python-nostr
https://media.tenor.com/krz9WMkpxAYAAAAC/this-is-houston-go-for-launch.gif
I included justice and excluded vengeance, yes. What God decides justice will look like is up to Him, tho. He has a larger plan.
Well, we have social proof for new keys, which is not nothing.
@npub1gzu…a5ds was talking about using a kind to create a social proof list of signers, who can publically validate a key, and then also validate the new key. Clients could automatically update follow lists, accordingly.
Yeah, this is why my Android app only allows Amber or Bunker sign-in. Need to remove nsec sign-in from my web app. Had it for testing, but it's not worth it.
Gonna go check them all and update. I think we use nostr-tools everywhere, but I'll check that, too.
And then I'll run my AI over Amber and nos2x-fox.
MatLab and Simulink generate the C code, now.
We used to sit around, looking at diagrams on the beamer. Called it function review.
Fucking hell, our software was so fucking good. I never appreciated how good our software was.
Yeah, cosigned as Laeserin.
I can't stop thinking about the fact that I could have vibe-coded the firmware with my Cursor ultra account in a couple of days.
And it would have been more secure.
And it would have been written in C.
And the tests would have prevented this error.
*This was human slop.*
Even if this were true (Cold Card code was not really open-source, it was only published), doesn't that just mean we devs should also be using the open-source models for auditing?
Well, when any appears and we become aware of it, he can add an addendum.
Where they or their funds (Ten31 and OpenSats) using Cold Card? Were any coins compromised?
It has a lot of libraries, so it can be fun to play with. I am a bit perplexed that they used Python and Javascript for most of their system.
https://github.com/Coldcard
This is what they wrote about it:
> We’re hopeful that altcoin proponents will be able to take our system and extend it to support their speciality crypto coins. It should help that all of the firmware is written in MicroPython.
https://blog.coinkite.com/coldcard-annoucement/
Yeah. Weird architechtural decision.
I have explained to everyone that the easiest way to "break" encryption is faulty or malicious code, firmware, hardware, or to perform phishing attempts (such as fake copies of well-known software, websites, or customer service contacts). Or just user error, like your AI checking your keys into a git commit or accidentally including your hex nsec in a post, when you meant to include your hex npub.
That means the robustness of the encryption _in theory_ can be much less secure _in practice_. Which is why even quantum encryption can and will be circumvented all the time. Which is why you have to structurally mitigate risk and plan sensible systems _in advance_ that automatically and immediately kick in when a key is compromised.
Don't only plan for the happy path.
Yeah. I don't feel like I'm that far ahead, but I regularly meet IT professionals that still can't explain keypairs or what an LLM is.
But a bank... You would think people at a bank should be thinking about security, right? People keep their money there.
After this circus, the next person who tells me I am being paranoid because "encryption can't be broken and keys never leak" will just be ignored.
#naddr1qq…08fp
That's why I removed direct wallet access from Imwald Android and am also taking it out of Imwald Web. Alexandria never had it. Payment targets that open a wallet are enough.
Removing non-essential features that are attractive to an attacker is half of security.
Bitcoin and Nostr, yeah. We're supposed to be so cutting edge, but okay. Also, government agencies holding critical data and a surprising number of large corporations.
It's crazy how little AI is used in QC and QA, everywhere. Terrifying. Haven't been able to find a single potential employer utilizing AI for inhouse testing and it's like
https://image.nostr.build/1c854596eb5a6b949c86e4210f369f7332a390237b21fc2899346db4e161762a.gif
I brought up AI and cryptography at an interview for a bank IT department and they were like, "Oh, we don't worry about that." Okay.
Interview was going well, until that moment.
Thanks.
https://wizardsardine.com/blog/coldcard-rng-vulnerability/
Bitcoin is only trustless when auditing the chain. The chain itself is verifiable.
Most of us haven't personally audited the entire ecosystem and it's unreasonable to expect us to.
I use Python for parsers. 😐
This is why people use exchanges: insurance.
There is currently no evidence of malice.
I'm sorry for your losses, @npub1cmm…lr6f . Thank you, for informing us. 🫂
Yes, material losses don't equate to the loss of human life, regardless of how high those losses are.
But we should also not be oblivious to the fact that material losses can indirectly lead to loss of life. Unfortunately.
We should pray for everyone who has suffered devastating financial losses or severe emotional stress caused by this crises. Our hearts are truly filled with sympathy with and concern for them.
We should pray for each other, as hodlers, who are watching the purchasing power of our savings be negatively impacted by the chaos and bad press.
We should pray for the wider Bitcoin wallet industry, as they are going to be collectively tainted by these errors they hold no responsibility for, and will be left to repair the industry's reputation.
We should pray for @npub1az9…m8y8 and the employees of Cold Card. That they and their families remain physically safe, that they resolve the crisis in a judicious and swift manner, and that they make a sincere attempt at restitution for the widespread suffering their negligence and competence created.
Amen. 🙏
I am so sorry that y'all are going through this. I can't even imagine the emotional strain of the chaos this has caused.
Praying for all of you. 🙏
He's had a very hard time in his personal life, but he shouldn't be bowling alone. Everyone tries to save on staff and ignore the downsides to being chronically understaffed.
Because people prefer to donate to a fund than to individual projects, as a general rule.
That is not true. Even a broken clock can tick correctly, twice per day.
First thing I checked this morning. No changes to the page.
https://opensats.org/about
I think the time for excuses is past. It's over. He's had three days to rise from the ded and he spent them digging a deeper ditch.
Shame about him. Moving on. I have software bugs to fix.
Well, I guess that's a wrap.
He can try to delete his stuff on here, but I know about some archive relays.
Some of us are trying to extend grace, as that is how we would wish to be treated, but there's been little effort to meet us halfway. That is on him, then.
My primary concern is with those who lost savings. That is a bit similar to your house burning down. Shocking and traumatic.
Bad taste to kick someone when they're down.
But typical. Get obsessed with some hot feature and neglect the dull basics you can't impress anyone with.
I see the same thing going on with the private messaging discussion on Nostr. I try to educate people about the topic, but they just want to tell me I'm being paranoid or overly-cautious. But if there is a leak (there will be one), they'll rip the developers to shreds and say, _But you were supposed to know better!_
Because we are. We're supposed to know better. We're supposed to be the adults in the room.
Developer myopia is common. That's why checklists were invented.
Yes, certainly.
And the Cold Card people weren't the only ones full of themselves. We have all been flying so high, for so long, that we have forgotten to stay humble and remember that, in the end, it's just money.
It's not your body. It's a different person. Don't murder people. That is wrong.
Okay, but the diversification is less through sheer number than by diversity of providers and/or multisig (diversity of holders), or both.
The person who pays the piper determines the music he plays.
We are supposed to be staying humble, is the thing. We stay humble for our own sakes.
He could still redeem himself by showing heroic humility. Lots of his users are Christians and love a good redemption arc.
Everyone can be wrong. Everyone can make mistakes or have lapses of judgment or character.
I am not going to measure him with a longer stick than I use to measure myself. Computers are hard.
Good point. There might be other wallets with the same or similar problems.
Every wallet will have some problem. Including problems we don't yet know to be problems.