Last Notes
This is not actually new.
It is, however, extremely cool.
I agree with @nprofile…lvg6 ... it might be worth explaining what you mean 😄 ... also I may need to buy a bigger desk.
This is very interesting.
Why is it so slow? My naive mental model is 'hashing is fast'.
#nevent1q…l4uj
I was actually thinking about this, ehich is closely related but different:
https://arxiv.org/abs/1702.06715
Claude tells me there are a few more similar papers recently, but the 'new' claim here seems to relate to the specific leakage technique like frame rate etc? Very cool stuff.
This is not actually new.
It is, however, extremely cool.
Typo: "I was not the only one to notice several similarities between t."
Yeah worked a few mins later.
I'm getting 504 Gateway timeout for some reason.
Me with said Mk4 yesterday:
https://blossom.primal.net/beebfea1f42a19887cc419c5b088d440fff2aac1647571d42d3f7dd6c0d3e26e.jpg
#nevent1q…d6jv
Well, I partly agree. And every class is different. In many cases your job as a teacher is more to inspire and spark enthusiasm. Really depends on the context though.
Bought a Mk4 about 2-3 years ago.
Just opened it today. Was useful for a class I gave to some students about cryptography and what private keys are.
I agree in abstract. For example they may well try to ban open source in some way or other.
This specific article though, feels more like Schneier being an utter dumbass. Switzerland and Spain are the example to follow!
One very relevant point I forgot to make yesterday.
Between when Taylor Hornby discovered it and when they gated the pool, it's not possible that less than say 3 or 4 engineers (likely more) were also able to steal with no way of anyone else knowing.
It will *always* be this way, albeit as tech improves, the probability of these types of problems will, likely, reduce.
#nevent1q…nr8v
A guy is claiming a 750K bounty for finding the zcash infinite inflation bug and not exploiting it.
A lot of gushing in the comments about how great this guy is.
But he literally, logically, cannot prove he didn't steal any zcash. Maybe if they turnstiled 100% then there would be retroactive proof but that seems practically impossible, for the same reason they couldn't do it for Sprout.[1] There was over $2B at stake, zero chance it'll all be cleaned out.
Sure, the great unwashed are not going to get this. But there are no experts correcting them.
https://forum.zcashcommunity.com/t/retroactive-grant-application-orchard-counterfeiting-vulnerability-bug-bounty/57008
[1] same reason we can't post-quantumize 2009 btc!
I doubt I'd agree with the author on the prognosis, but, good article. Thanks.
Yeah i was wondering about that angle. I doubt it's enough though. There is real additional knowledge developed from practice that's not in hardware manuals.
i wonder if we're heading into a weird limbo: have an obscure technical question about tech? you ask AI, of course. But the AI's knowledge of things like, I don't know, network cards, comes out of a corpus of humans babbling about it on the internet. we used to use tech forums to discuss such things and that's where you used to go; and that's where AIs go (and went, in training) to siphon up tidbits of knowledge. But nobody is going to ask in tech forums if the AIs give better answers. So what happens in 12 months?
I think 'politics' is a good lens for that aspect of human psychology.
libsecp256k1 is a counterexample on C; it's a combination of the right people and the right task, but it's possible, it's just a very narrow field so I'm only like 10% disagreeing there.
On Lightning, yes, there is some kind of generic 'higher complexity' here; e.g. it's obvious you're going to have more attack surface in a coinswap codebase than in a coinjoin codebase.
Yes, it's interesting in many ways, but as per our conversation you maybe could have started finding collisions in 1000 samples. Not sure though.
Murch kinda missed my point; I wasn't saying that 2 groups of anons coordinating might want two fullagg groups; I was saying that the most common case of aggregation is *one* party with a lot of utxos wanting to aggregate. If you had 2 or more such parties each with N utxos they might not want to coordinate into 1 group but still gain the cross-group savings being in one tx. This could happen in a very big coinjoin for example. But, while it's interesting to think about marker bytes, I still ended up agreeing with Fabian that it isn't worth it. In other news, I do absolutely agree that having marker bytes (either in this complicated case or just the half-agg, full-agg mixture) is not great privacy wise.
It feels that way. But I suspect it'll come back to bite people later. Maybe some O(N!) scaling in the worst case.
I don't think it makes a *big* difference.
That's exactly the rationale I'm criticizing.
A lot of people stored their wealth with this thing. Some small proportion were highly technically competent.
The idea that only engineers at competitor companies had sufficient skill to do this is way off base.
Right. And I fully accept that it's surprising no one spotted it. But I don't think it's *crazy* that no one spotted it, it was unobvious.
If 40 bits you probably need 2^20 on average to get a collision. So like 1 million (though I'm not sure 40 is the right number here, maybe it's lower?)
I see people making the argument that the Coldcard bug was a result of the fact that the license prevented others from using their code in products, so there wasn't enough incentive to audit it.
I strongly doubt it. I bet a *lot* of people did examine it, but didn't spot the error. And unlike every other piece of functionality --- apart from entropy generation --- just looking at the output, even looking at hundreds of outputs, wouldn't have revealed the bug.
There is more to it though, specifically if you use your node to send and receive transactions: by having your mempool policies aligned with what is likely mined you get better fee estimation. And second order similar effects from relay.
The whole concept 'my mempool' is incoherent for a non-miner.
And even if they are not purely monetary. Because that is not an objective decision you can make by looking at bytes.
Would be funny if Dario and Sam and their EA friends all end up being right - but that AGI escapes containment and starts destroying humanity via the Chinese open source models.
Another possible break on a (in this case *long established* PQC scheme (McEliece)):
https://eprint.iacr.org/2026/1630
Or heaviest :) though i would not be surprised if it said longest!
What counts as resolution there?
If you are praising libsecp256k1's code quality, then 2 things:
1/ you are very right. It is outrageously well tested and high quality.
2/ it deliberately omits the most dangerous thing: generating entropy, leaving that to the caller (where it's needed, which, thank god, isn't very often).
I don't support either of the former, and have no interest in Saylor's opinion. The reason the fork failed is because it's stupid *and* antithetical to uncensorable money.
Just the typical assertion that miners are attacking bitcoin and that his fork is the real bitcoin etc.
Anyone confused by Luke-Jr's response to today's events hasn't been paying attention for the last 15 years.
https://ocean.xyz/docs/20260807-maintenance
"once the situation is unambiguous (a single sharelog operating)."
?
Oh for sure. Just trying to get into their head: remember they were latching on to the game theory dynamic. I can imagine some of them convincing themselves that bumping from 2% to 4-5% might dramatically raise the probability that other miners perceive some threshold of risk in not signalling and blah blah. I mean it may not be common sensical but you can see how it might happen, despite the cost.
They probably bought up some hash power to maximize it at fork time.
This is better than the world cup.
Do we have a fork?
https://bip110.orange.surf/live.html
I guess not until there's a 110 signalling block mined. This will be a bit of a damp squib unless they get lucky, I guess.
I find it really striking that, take the last 6 months or so, the intelligence of the models has increased a lot, but their writing style is still as hackneyed and stereotyped as before. Something a bit weird about that. I guess it might be different if you actually used it for writing tasks: you might choose to ask it to write in a particular style, but for people like me using it for discussion of technical things, maybe i'm just getting "vanilla writing style" (which by the way is annoying to read, but whatever).
Well ... that's because he is a psychopath.
He probably got it partly from his parents (both of whom should have been imprisoned for their collusion in the theft from customers, btw).
citadelfoss.xyz is interesting.
Decentralize all the things.
https://reyify.com/blog is back up. I forgot to pay the vps bill.
Not exactly the most active blog in the world 😄
in 1838 the Chartists in England proposed the first proper universal ballot. Remarkably, a guy called 'Jolly' designed a voting machine that honestly sounds a ton more trustworthy than most of what is used today (including cryptographic schemes tbh): "Voters using Jolly's voting machine were to vote by dropping a brass ball (the ballot) into one of the holes in the top of the machine. Each hole was to be marked with a candidate's name. The ball, on passing through the machine, would advance a clockwork counter one step before dropping into a tray on the front of the machine, in clear view of the election judges. During the election, the counters would be sealed behind a closed door, so nobody could see the count until the polls closed, and the voter would vote behind a partition, so nobody could see which hole the ball was dropped into. If a voter brought an extra ball into the polling place, the judges would see two balls falling into the tray."
From https://homepage.cs.uiowa.edu/~jones/voting/pictures/#lever
Am I the only one who finds nostr clients fragile? Messages do not arrive reliably. But they're just messages in a social media context, so it's not super important.
I agree that lightning infrastructure is exactly the kind of thing more prone to vulnerabilities and flaws, but why compare with nostr?
#nevent1q…axmh