Rockin a new NIP-05.
View quoted note โ
BlessedBovine
blessedbovine@mycircl.xyz
npub1c4n2...559a
Husband of npub12wk0tlwr5wa39l6slw8rskwsvkatcll6zjrx8d909ltkvu7lsalsveyvqf
Father
Catholic
Bitcoiner (Class of 2023)
American Dreamer
Bitcoin Full Node Runner on Tor
On Nostr Since 850200; Verified 852712
Let's go!! Nip-05 inbound. ๐ฎ
View quoted note โ
#BIP110 didn't fail because of "corrupt" miners, nor did it fail due to miners "colluding" with one another. Although I do agree that miner centralization could pose a risk, I don't think that the bippers are correct in calling the miners corrupt over the failure of BIP110 to activate. The failure to activate was a due to a lack consesus among the broader node community.
I'm a pleb. I'm not a cryptographer, nor am I a software developer in any way. This post is mostly just testing and articulating my understanding of the Bitcoin network. If I'm correct in my understanding of the #WhitePaper and how the #Bitcoin network operates, then the following is true:
1. Nodes provide the rules for the Bitcoin network through reaching an independent agreement (consensus) of what is and isn't allowed. They communicate these rules to the miners.
2. Miners try to brute force guess the magic number to mine the next block for the timechain. They also create templates for what information they want to put into the block. Generally being monetary transactions based on fees, but also "spam" or other inscriptions (โThe Times 03/Jan/2009 Chancellor on brink of second bailout for banksโ inscribed by Satoshi). Miners can also choose not to include transactions, spam, or inscriptions based on their own criteria. Which is why controlling enough hash to assure your transactions get through is important.
3. If 51% or more of the nodes are in agreement of what the rules of the network are, they have consensus.
4. A miner who tries to submit a block that violates the consensus will have that block rejected by the nodes with consensus, and therefore rejected by the Bitcoin network. If there are nodes that would otherwise accept that block, the minority nodes fork off. Or vice versa, the majority network with consensus accepts a block, while the minority nodes may reject a block, causing the minority to fork off.
BIP110 forked off because they didn't have majority node consensus. They composed a minority consensus with one another rejected a block that was considered acceptable to the majority of nodes, and forked off.
I don't think changing the #PoW (proof of work) of #BTC is the correct solution. For BIP110 (or any other BIP) to succeed, I think they need to:
1. Acquire majority consensus with the nodes all signaling for an upcoming rule change.
2. After acquiring consensus through signaling for the change, they need to put out a specific block height for the change to go effective, and broadcast it to as many node runners signaling for the BIP as possible.
3. After step two they should notify the miners of an upcoming consensus rule change, and warn them (miners) that blocks submissions that are not compliant with the new consensus will be rejected by the network after the specified block height.
Is that all correct? #AskNostr #AskBTC
This is the exact reaction I had when I found out the Bippers want to change the proof of work for Bitcoin.
I was taught that six block confirmations of an on chain transaction solidify it.
Tick tock next block.
This Coinkite failure has seriously left my faith in hardware wallets in a shaken mess. I don't even know where to start over. Back to analysis paralysis.
@SoapMiner is the best. We love the soap, been proud customers of his since November of last year. What has stood out to me the most has been the amazing scents. My wife is very sensitive to odors "good" or "bad" she can find either overwhelming. However, she has given the stamp of approval for every scent I've bought us. The feel of the soap is also great on the skin, so much so that I've also just been using it on my face. Which is nice, because I used to use a separate face wash. I've been keeping track of how long each soapbar lasts us, and have found that each bar last us 30 days of normal use. I look forward to continuing to be a happy customer, and just got some deodorant to give that a try. I'm no soap connoisseur, so I don't have any major critiques. The soap cleans, feels nice, and lasts. The only thing that might be a good addition would be an option to buy one of the soap bar lifting pads as an add on.
Keep up the great work!
#Soap #SatEconomy #CircularEconomy #V4V
I guess #Aqua is down because #Boltz is down. This is the second near miss for me. I had a small amount of Sats on Aqua to use for fun money, however I moved it on chain last week because I wasn't sure what would happen to those Sats in the event of the impending fork.
My heart is heavy for all those who lost any of their precious time and energy to the ColdCard entropy failure. It's devastating to see people talking about losing the entirety of their time and energy from the past X years - long before I found the Bitcoin space. So many pioneers that forged the path ahead and built amazing educational platforms and spaces. They provided me with all the tools necessary to enter into the Bitcoin space with such a strong conviction in the future of what Bitcoin could bring to society.
This is my first Bear Market. The falling USD price hasn't really bothered me. Thanks to the amazing Bitcoin Pioneers' tales of how bad things had been in the past Bear Markets combined with the lack of changes in the fundamentals of Bitcoin. I have stayed grounded in "โ/21M" and, to paraphrase @hodl, leverage won't magically make you an OG." This current ColdCard debacle is the first time I've been extremely uncomfortable to be a part of the Bitcoin community.
To preface the next part: I have zero, zip, zilch, prior experience in cryptography, coding, or other software skills.
I, like many others, spent a significant time trying to educate myself on different hardware wallets before we took our Sats off an exchange. To be honest though, much of the technical jargon was lost on me. One thing did stand out to me though, ColdCard seemed to have the best (anecdotal) hardware wallet. I particularly liked the Q for it's QR scanner and full QWER keyboard. Knowing that most Sats are lost due to user error, I felt the Q provided ample tools to help verify, send, and receive Bitcoin transactions while minimizing user error.
We're all told, "Don't trust. Verify." I did the best I felt I could, short of learning how to code myself to review CoinKite's code. I reviewed as much as I could on the reputation of the devices and feedback from people that had used them. For all intensive purposes, the Q felt like it would provide the best user experience for my wife or heirs if something happened to me, and give them the highest chance of success.
I did not expect that I'd see ColdCard have a failure so catastrophic as to screw up the single most important part of the security, generating a secure 128bit private key. When I saw the warning go out from some of my fellow Nostriches that there was a vulnerability in the MK3 series my heart started racing. Did it go beyond the MK3? Were my wife and I affected? I started reading as much information as I could. Keeping up with every detail as more and more UTXOs were drained and more info was breaking. Then I saw it, MK4, MK5, and Q were all sub 128bits of entropy. I had accidentally exposed my wife and I, and all our future generations, to the vulnerability. To say my heart dropped into my stomach would be an understatement. I didn't know how long it would be before the hostile attackers were finished with all the MK3 wallets and started on the MK4/5/Q. I did know that I needed to update things quickly but smoothly. A problem quickly arose as I realized our security setup was so difficult to access in the event of a true emergency, like this, that I may not be able to move a single sat in time. The amount of time from the initial incident to when I was first able to even look at the public addresses of our sats took far too long. I felt more and more sick the more time passed without knowing if we'd already been rugged. When I was finally able to check our UTXOs, there was not a Sat out of place. Not yet anyways. I knew we weren't out the woods yet. Even though I'd accessed our Xpubs for the Sats, it would still take quite some time before I could gain access to our keys. The only things keeping me calm was that we had used a passphrase (that I later learned was too weak), and my wife. As soon as I had access to our private keys, I wrote out a checklist. The checklist provided myself a step-by-step guide to make sure that I did things as cleanly and orderly as possible, to minimize potential missteps in a complete migration to new keys. I rolled 100 independent dice to generate our new wallet. It took me 32hrs from the time I learned of the vulnerability to the time I was actually capable of accessing my cold storage and generating the new seeds to sweep our sats to. The only reason I managed to do it in 32hrs was that my emergency contact was able to meet me half way. Without the emergency contact, our sats would've been exposed for at least another 12hrs.
I'm incredibly humbled and grateful that our sats are safe. I understand how incredibly fortunate we are to have been able to keep what small amount of Sats we've been able to stack, because it may not be a lot to most people, but it is a lot to us. I feel like I'd prepared for all the attack vectors, but I never expected that the entropy of a non-tampered with hww would be the one that got closest to compromising our sat stack. What a sobering and panick inducing experience.
As a pleb without a background in cryptography or technology, I really took the generation of seed phases for granted. Never again. Rolling my own entropy, and diversifying our hww from now on. Which will be difficult, because the Q was a big purchase, one I thought would be worth the investment. Oh how wrong I was.
Disclosure: I'm a pleb with no technical background (software nor hardware), and I am not a cryptographer.
As far as I can tell, using dice input to generate a seed phrase on a ColdCard Q bypasses the coding failure that causes the low entropy seed phrase generation.
I tested this by rolling dice 100x independently, then inputing the results into the CCQ, the python script provided by CoinKite for the independent verification (I didn't trust this one as much), and https://iancoleman.io/bip39.
The CCQ produced the same HexString as the python script. The CCQ also produced the same seed phrase as iancoleman. I performed this test three times.
Am I correct in my understanding that the provided cross-verification means that if you use the CCQ to process 100 dice rolls then you have a seedphrase generated from the appropriate amount of entropy?
I believe @semisol already confirmed dice generated keys were safe, but I thought it best to verify myself. I also wanted to provide other plebs a way they could check their own devices.
#ColdCard #MK3 #MK4 #MK5 #CCQ
@Dr. The Daniel ๐ @utxo the webmaster ๐งโ๐ป @HODL
Admist all that is going on in the world, a baby was born. My wife is amazing, and recovering wonderfully from giving birth to our son. Hug your loved ones, and remember why we're here. I love you @npub12wk0...yvqf


Here comes the "Bitcoin was hacked" fud.