Last Notes
If you rob a bank, you’re a criminal.
If the bank robs you, it’s finance.
If everyone robs each other, it’s crypto.
Defeated Knotzis crawling back to Bitcoin Core 😝
https://nostr.download/5e3933b618605c42694e22716881b328ebb1cdf7431d2da9c942831190ae82ca.jpg
It will just steal as much money as it needs to sustain its operations.
https://nostr.download/d78b78160fef42e43b11ae2605c21d341f7ab3c172fa5a12b830311351c1f0cf.jpg
Pro tip: September 11 is a great day to travel by air. No lines anywhere!
25 years ago I was sitting in band class watching thousands of my fellow citizens die on live TV. Little did I know that the horrors had only just begun.
https://blog.lopp.net/reflections-on-9-11/
It's been 3 weeks ☺️
#nevent1q…vg2g
Never trust an incoming message on any platform.
Props to the Knots Cult - they provide plenty of entertainment!
https://suno.com/song/caafc4c5-6db9-4a72-8aea-94254d6ffd49?sh=P9JXx7zUA2h3yHMw
Prompt a clanker ➡️ hit the gym.
Prompt a clanker ➡️ take a call.
Prompt a clanker ➡️ eat a meal.
Prompt a clanker ➡️ do a podcast.
Prompt a clanker ➡️ run an errand.
Prompt a clanker ➡️ read a book.
Prompt a clanker ➡️ go to sleep.
My favorite responsible disclosures are the ones where someone has a clanker evaluate us and it explains why we are following best practices with no recommended improvements.
And then they forward that on to me as a "security finding" 😎
Wanting is often more exciting than having.
Yeah I've been saying Bitcoin is the canary in the coal mine.
Looks like the Liquid Network drainer has returned the 4,000 BTC!
Never a dull day in Bitcoin 😅
https://mempool.space/tx/3a3eac4a26395b8c2563aaf1eb8b1b77798c81c7d6337f51321827a244a480aa
Patience is a virtue.
Especially when you're trying to cost optimize your clankers.
Slapped a GeForce RTX 5070 on my Framework laptop in 10 minutes.
Installed CUDA toolkit and recompiled whispercpp with CUDA support.
Now I can transcribe an hour's worth of audio in 1 minute flat!
Just have to remove a few screws.
https://frame.work/products/laptop16-graphics-module-nvidia-geforce-rtx-5070?v=FRAKMQ0001
I guess I'm doomed to play tech support for my entire life.
https://nostr.download/45e3ce469b579285aee6aa66d3993f52d77f2d8bb607af8ec1ab13d1a0f8b3e2.jpg
Uh oh, does @nprofile…3clq realize that people are zapping him bpedo coins? 😱
Welcome to The Great Breakening.
It's gonna be a volatile security landscape for a while, but we will rebuild and come out stronger.
#nevent1q…nlm2
He's special in so many ways.
Luke trying to fire the miners.
https://nostr.download/10f9594e5cd43032344105b9d807dfd58f9312c48eb237111eadb17516bae65b.mp4
Shortest.
Sabbatical.
Ever.
#nevent1q…22tq
Hate can be a powerful tool if you use it as motivation to accomplish something good.
But if you don't direct it as a useful motivator, hate can be a powerful poison that consumes you from within.
Approaching 1 month of working every single day to catch up with the AI acceleration of vulnerability discovery. Exciting times for cyber security professionals. (Excitement is a bad thing.)
Pro tip: tell your clanker to find all of the TODO comments in your codebase and implement them.
"Don't get so busy making a living that you forget to make a life."
- Dolly Parton
Rest in Peace
The fake Google support social engineers have started calling again; time to update my script for maximum lulz! 😏
Hmmmmmmm
https://nostr.download/8e9417d8c5fa60057f785ab4a0509c05a43a32d8e29630ae88ed939359f8c9bb.jpg
Stay humble and stack cows.
https://nostr.download/d731404ef348cba10e2d26d4ea634ee15290d53439f149a9e6a236a7d4e6afd4.jpg
Woke up in merge commit conflict hell.
Realized I can just make the clanker dig us out of hell.
Good morning 🌄
He's basically asking what I think of the thermodynamic security budget problem.
I prefer keeping the hard cap but instead making block space dynamic in response to demand so that available space decreases and fee rates increase when demand is low.
I bought a stealth sports car that can match most lambos without attracting attention.
SHOCKING REVELATIONS: EX-CITREA DEVELOPER REVEALS TRUE STORY FROM BEHIND THE SCENES IN THE OP_RETURN WAR
https://nostr.download/b7bdfba3040b214913dec0fc89778a361aae6dfee292954e85dd83e06a795f81.mp4
I wouldn't waste my time trying to wring any logic out of the puritanical cultists. Best to mute and move on with your life.
One thing I love about agentic coding is that we're at the point now that I can go back and find specs for features I wanted to build years ago that never got high enough priority to get on our product roadmap and just clank them out on my own.
They're just salty and closing ranks to tighten up the echo chamber.
I heard it got delayed slightly
Overwhelming demand! Should be fixed.
Poor fella only had one engineer whose code was apparently never reviewed. All of our code gets reviewed by both humans and multiple LLMs.
Right, you can either do 2 hardware key 2of3 or a 3of5 with mobile key to ensure that a compromised Casa app doesn't put your funds at risk.
Reflections upon the past year of the BIP-110 movement, similarities I noted to the 2017 scaling debates, and numerous receipts to hold folks accountable for their mistakes.
https://blog.lopp.net/bip-110-post-mortem/
LOL, we're good, thanks.
https://blog.casa.io/how-built-reliable-ai-pentest/
Open source vs source viewable is irrelevant in this context: the point is that publishing code by no means guarantees that vulnerabilities will be found in a timely manner.
In the context of Casa, which only generates and stores the mobile key, a malicious app could be deployed to steal keys practically instantly, far faster than any human or machine would catch the malicious code. Having the code available would not change the security model: either you trust Casa to handle the mobile key or you don't, and we offer multiple options that serve both of those models.
If Casa had access to mobile keys then it would make us a custodian, which we're quite careful to avoid becoming since our business isn't set up for it nor do we KYC clients.
Casa open sourcing the app wouldn't guarantee that mobile keys couldn't be stolen, just like how coldcard being open source didn't prevent keys from being stolen.
The only way to guarantee that a malicious Casa app can't steal the mobile key is to swap it for a hardware key so that the app never has access.
If you're worried about a malicious Casa app stealing the mobile key then you can opt to use a second hardware key in lieu of the mobile key. What you lose is the automatic encrypted key backup.
The schadenfreude is all that's left to feast upon because the Knotzis wouldn't put their bitcoin where their mouths were. 🙎🏼♂️