Last Notes
Using bitcoin to buy things just feels good. 😃
Love silent.link. There is more legislation being pushed requiring that any SIM require KYC info. So things like silent.link will be more needed than ever.
Well that is horrific. Last I check, bitcoin mines don't collapse and kill a hundred people.
#nevent1q…xxha
That sucks. I broke my ankle and tore several ligaments as well. The recovery is not fun, but certainly makes you appreciate having two working legs. Take this time of forced rest to recovery mentally as well. You'll get through this.
Any vegans out there, feel free to join the vegan community on Armada. 🌱
https://armada.buzz/invite/naddr1qvzqqqyzz5pzpfklwjwfmw9fasyyu6504rpt6c387l5427s7qxyx6cq9r6efelnpqqqqytnp5t#BAADAwQBW8xBT8q0ERF9qax8GVolwA
All the more reason to use remote signing with your Nostr client. Keep your nsec out of your client so that the potential for XSS or CSRF attacks can't leak your nsec. Your client shouldn't need/have access to your nsec. Worst that might happen is they trick your remote signer into signing something you didn't authorize, but at least you can recover from that easier than a compromised nsec.
#nevent1q…us4d
I have been retired for over a year now and am now looking for ways to volunteer my time. I love bitcoin's ability to help humanity in ways that traditional financial services have failed. I have a 20+ year career in IT/InfoSec (almost entirely in TradFi ironically), but am more looking for ways where simply having an extra set of hands will help people live better lives with the bitcoin/nostr. If anyone needs an extra volunteer, feel free to reach out. Doesn't need to be all the time, but if anyone hears a need for some extra hands anywhere, let me know. ✌
@npub1kmw…xqk9 @npub10qd…arpj @npub17cy…4ml3
A person with authoritarian tendencies won't ever step back and see things this way.
Except for the big issue of replay.
Sounds like you'd enjoy Luke's new shitcoin then.
How's that "game theory" working out for you?
Imagine any part of the economy depending on this software to facilitate transactions. What a completely unserious project.
#nevent1q…rt36
I didn't say he was the only one that works on knots. I said he is the only maintainer. Do you know what that means?
He also doesn't cryptographically sign any of his commits which makes change control and code review manual and difficult. You can see for yourself.
https://github.com/bitcoinknots/bitcoin/commits?author=luke-jr
Yes. The economic weight of a node has always been where the power lies. It is why pointing to node counts for signaling has always just been posturing, when in reality is has always been subject to Sybil attacks. How much economic weight is behind a given node is where the real power lies. Coinbase's node holds far more power than some user who only holds 0.001BTC running a raspberry pi at home, for example.
Imagine having the world's economy run on something managed this horribly by such a delusional group of people. I'd rather stick with fiat at that point. 🤦♂️
#nevent1q…9hds
"Not yet been captured." That is some massive irony in your spoken words there. ...the existence of your new dead chain has come about by an extremely small minority of delusional people. That's what real capture looks like. Thankfully, all you've managed to capture is a new shitcoin.
The ColdCard debacle I think is an important lesson here for Knotzis. The ColdCard bug came about because there was one person with his hands in the code and with very little review of what was being changed. There were also very few comments added for each commit which further complicated change control.
The Knots implementation of bitcoin node software suffers from the same problem. Luke is the sole maintainer and the way he maintains the Knots software in many ways mirrors a lot of the poor practices that resulted in the ColdCard bug.
The ColdCard vulnerability should be a wake up call for anyone running Knots for their bitcoin node.
Satscard being more secure than a Coldcard was certainly not on my Bingo board for 2026...
Open and close channels? 😜
They put together some really great articles. Bummer.
You didn't do anything wrong. I recommended ColdCard to several relatives. I was scrambling last week to help them save their funds. It wasn't fun, but thankfully they're OK. We come out stronger with lessons learned in the end.
Bitkey's security model is really solid. It is an easy recommend for casual non-technical users.
I had two relatives of mine that had bitcoin stored with Coldcard MK3's and somehow, by some miracle neither of their bitcoin were stolen.
I feel for those that lost bitcoin. That is every holder's worst nightmare.
Ooof
https://xcancel.com/zherbert/status/2082993276324319713#m
You can be sure other HWW manufacturers will be taking a long hard review of their RNG methods over the next few days or so. It will be interesting to see the release notes on any new firmware releases for HWW's over the next several weeks. ColdCard has shown us that having a good design is one thing, but it is another thing to ensure that good design is put to practice via proper code.