Ungovernable's avatar
Ungovernable
ungovernablemisfits@nostrplebs.com
npub1jcym...2890
An Ungovernable Bitcoin & Privacy Movement
Ungovernable's avatar
Ungovernable 20 hours ago
Your weekly reminder to get your funds off an exchange has got a lot harder to give. Get them on chain. Don't use Lightning, you might get hacked. I would not use Liquid, it is probably not safe. Don't use a sidechain. Don't use a second layer. Bring them into self custody, but make sure your entropy is good, and think very carefully about who you trust as your hardware provider. Have self custody. Don't have all your eggs in one basket. Ask the questions. And don't trust any cunt.
Orange Surf pointed at something uncomfortable in his analysis. The fix for the bug that drained Liquid had a commit dated the 3rd of August. The pull request carrying it was still open on the 1st of September. Which means the patch was public while the hole it closed was still live on the network. Anyone reading that repo could see exactly what to look for. If you are sitting on 4,000 Bitcoin of other people's money, an open pull request is a map for anyone who bothers to read it. @OrangeSurf
"He went ahead and just deleted everything and then fucked off of the comms channels, taking a load of code with him, which pissed me off no end." So Dojo Bay has a button on it that downloads the whole source. Anyone can take it, run the installer on any Ubuntu box that already has a Dojo, and have their own directory up in a couple of minutes.
Ungovernable's avatar
Ungovernable 2 days ago
"Why do you need a VPN? My traffic is all encrypted with TLS." Carl Dong: that is half right, which is the most frustrating type of right. TLS does encrypt your traffic. But when the connection starts, the client hello carries a field called SNI, and SNI shows the hostname you are visiting in plain text, to everybody on the path. WikiLeaks, your bank, whatever it is. Encrypted contents, fully legible destination. @npub1dd9z...xe7p
Ungovernable's avatar
Ungovernable 2 days ago
Pocket Bitcoin leaked compliance records for 291 customers, tying identity information and documents to Bitcoin addresses. Another 5,120 had names, IBANs and payment amounts exposed. No private keys were touched, and it barely matters. An address on its own doesn't identify anybody. A leaked compliance file does exactly that, permanently, against a public ledger. Max put it better than I could. The safest way to use Bitcoin is the way that causes you the most trouble. Buy peer to peer, hold your own funds, jump through hoops to keep it away from your identity, manage your UTXOs, and then you cannot spend it in normie world because you cannot prove where it came from. That is the cost of KYC. This information gets leaked because it had to be collected in the first place, by people making decisions for your safety who do not understand what they are regulating.
Ungovernable's avatar
Ungovernable 2 days ago
On the surface, an 11 of 15 multisig to peg out Bitcoin sounds unbreakable. How are you going to compromise 11 geographically distributed companies? You don't have to. The federation keys were never touched. The withdrawal had valid authorisation because it went through the normal service. The failure happened earlier, when the network accepted liquid Bitcoin that should never have existed. Every signer was reading the same faulty software, so every signer agreed. The number of keys does not fix a shared code failure.
Ungovernable's avatar
Ungovernable 2 days ago
Roughly 4,000 Bitcoin was withdrawn from Liquid after a software bug allowed LBTC that should never have existed to be accepted as valid. Initial reporting put it at around 320 million dollars. To be clear about the scale, there was something like 150 or 200 Bitcoin left on the network afterwards. Essentially every coin on Liquid went out the door in one go. Blocks stopped. If you had funds on Liquid, you could not move them.
Ungovernable's avatar
Ungovernable 3 days ago
A single hop VPN is the only middleman, so it sees everything. Your home IP, which is basically your identity, and every host you visit through TLS SNI and DNS. Two hops splits that in half. First hop sees who you are and never where you are going. Second hop sees where you are going and only ever sees packets arriving from the first hop. No single party can bind your identity to your browsing history. Carl Dong on why that is the whole game.
Ungovernable's avatar
Ungovernable 3 days ago
The negotiation over 4,000 Bitcoin is happening in transaction metadata, in public, where anyone can read it. The attacker put an OP_RETURN in the peg out saying they were white hats and to contact them on chain. Blockstream answered an hour later with an OP_RETURN pointing at a support email address. Six hours after that they sent an encrypted message to the hacker's PGP key. The hacker came back with: bug first. The chain is under risk at latest commit right now. Make sure every node is patched, then we will transfer the money back safely after confirming the fix. Three minutes later, Blockstream said thank you. @Blockstream
Ungovernable's avatar
Ungovernable 3 days ago
On the surface, an 11 of 15 multisig to peg out Bitcoin sounds unbreakable. How are you going to compromise 11 geographically distributed companies? You don't have to. The federation keys were never touched. The withdrawal had valid authorisation because it went through the normal service. The failure happened earlier, when the network accepted liquid Bitcoin that should never have existed. Every signer was reading the same faulty software, so every signer agreed. The number of keys does not fix a shared code failure.
Ungovernable's avatar
Ungovernable 3 days ago
Max Tannahill, on Freedom Tech Friday, with a story I had not heard before. When Keonne Rodriguez had to make the Bitcoin payment for his fine, he had no node of his own to connect to. He used Max's Dojo, found through Dojo Bay. "When you've actually got the developer of Samurai wallet comfortable in a set of trade offs using someone else's node, I think it kinda tells you that some people are a bit too prescriptive on you must always use your own node." Preferable and mandatory are not the same word.
Ungovernable's avatar
Ungovernable 4 days ago
The VPN industry is built on horrible YouTube sponsorships, scare tactics, fake top 10 lists and ownership structures you would need a private investigator to untangle. And underneath all of it sits one fact the influencers skip over. Your provider can see who you are and everything you do. Every single one of them. "No logs" is a pinky promise that nobody can truly verify, because you have no way to check it. @npub1dd9z...xe7p
Ungovernable's avatar
Ungovernable 4 days ago
The thing that changed with Dojo Bay is not the technology, it is who there is to serve paper on. Samourai was a known legal entity running the back end. A directory has none of that. It does not hold your transactions, it is not running the Dojo you connected to, and the page gives no indication which of the twenty listed you picked. Operators are in Spain, Singapore, the UK, the US and Canada. Max Tannahill's point: if you are in the US, why would you put your XPub on a box in the US.
Ungovernable's avatar
Ungovernable 5 days ago
Best explanation of the two hop model I have heard. Think of the packets you hand Obscura as a box locked with a key only Mullvad has. Carl's words: "we have no idea what the fuck is in it. All we can do is hand it over." Mullvad opens the box and talks to Google for you. It sees thousands of users' packets arriving from Obscura and cannot tell which one is you. Obscura knows who. Mullvad knows what. Neither knows both.
Ungovernable's avatar
Ungovernable 6 days ago
GG wanted miniscript on @npub17tyk...3mgl. Rob Hamilton opened an issue about it three years ago and it sat there. So GG put the clankers to work and built the fork himself, plus a standalone bridge so it talks to the live Liana desktop without patching Liana at all. Twelve months ago that was an insurmountable challenge for most junior developers, let alone someone who is not a developer. Nobody is claiming these forks are safe to hold funds on. But getting 95% of the way there, so an actual engineer can pick it up and review it properly, is completely fucking wild. This is the other side of the AI story, and it does not get the headlines the hacks do.
Ungovernable's avatar
Ungovernable 1 week ago
Carl Dong's origin story is about as clean as they come. His dad ordered a National Geographic subscription over the first dial up connection in the house, just so the family could see the outside world. Then the Great Firewall went up. He remembers the exact month. The day before he was sharing clips with his friends, the next day there was no YouTube, no Facebook, nothing. Technology should further the sovereignty and freedom of individuals. He has been building on that ever since. @npub1dd9z...xe7p
Ungovernable's avatar
Ungovernable 1 week ago
SIX DOLLARS VERSUS THREE GRAND @Seth For Privacy has the Grafana dashboard on screen and gives the actual week-one numbers, so the payback maths is checkable rather than hand-waved.
Ungovernable's avatar
Ungovernable 1 week ago
Between the 17th and the 24th of August, wallets tied to sanctioned exchange HTX sent roughly 12,000 dust transfers into Kraken user addresses. The deposits tripped Kraken's AML controls and froze the accounts. Access has been restored, but Kraken still holds 4.2 million it considers tainted, and restored access is not the same as getting your money back. HTX denies all involvement. Look at the asymmetry. Sending dust from an address you know is sanctioned costs an attacker close to nothing, even at current mempool rates. It can cost the victim their entire account. This is what coin control is for, and it is what leaving coins on an exchange can cost you.
Ungovernable's avatar
Ungovernable 1 week ago
Core Lightning told every node operator to shut down or restart with an offline flag, and left it there. Two days later a fix arrived as signed binaries only. No source. That comes in a fortnight. The reasoning is that publishing the diff hands attackers a map to unpatched nodes. Fair enough. But you can reverse engineer a closed binary too, so you slow the clock down without stopping anyone. What you do get is an open source project asking you to trust a binary. That precedent outlasts this bug.