Tim Bouma's avatar
Tim Bouma
trbouma@safebox.dev
npub1q6mc...x7d5
| Independent Self | Pug Lover | Published Author | #SovEng Alum | #Cashu OG | #OpenSats Grantee x 2| #Nosfabrica Prize Winner
Tim Bouma's avatar
Tim Bouma 1 week ago
hashing and trusting are one-way functions.
Tim Bouma's avatar
Tim Bouma 1 week ago
abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon abandon
Tim Bouma's avatar
Tim Bouma 1 week ago
128 bits of entropy versus 72 bits (more likely, 35) image
Tim Bouma's avatar
Tim Bouma 1 week ago
My bet this attack was weeks in the making. Once the attackers assembled enough private keys for high value utxos they executed. My biggest disappointment is relying on a hardware vendor that has 'Don't Trust. Verify.' plastered all over their product marketing and the primary motivation that led to the bug was a 'get out of open source' licensing issue. Let this be a lesson for all in the industry. 'Not your keys, not your coins' rings a bit hollow now. It's more like: 'God plays dice for those who self-custody.'
Tim Bouma's avatar
Tim Bouma 1 week ago
I took all of the necessary migration steps with my #ColdCard but I might be ok. After doing a recovery for one that I gifted, I noted that the firmware was 3.1.9(2020) versus an affected version 4.1.9(2023). I realized that my seed was generated on the unaffected version, and I should be ok. I upgraded the firmware after the fact, so I should be safe? Is that a correct assumption #asknostr ? Nonetheless, I plan to continue all migrations.
Tim Bouma's avatar
Tim Bouma 1 week ago
QOTD: Will God blame you for not rolling dice?