Cyph3rp9nk's avatar
Cyph3rp9nk
cyph3rp9nk@getalby.com
npub1lnms...rrnt
Non nobis, Domine, non nobis, sed nomini tuo da gloriam.
Cyph3rp9nk's avatar
Cyph3rp9nk 1 week ago
Problem that I myself have refused to see. Although most hardware wallets are open source, there is no incentive for them to be reviewed by a third party. There is a huge industry of podcasters who promote hardware wallets. Bitcoin Core is the most reviewed software in the space.
Cyph3rp9nk's avatar
Cyph3rp9nk 1 week ago
@JWWeatherman_ is absolutely right when he says that HWWs are garbage. Blockstream has proven this to me—they closed my GitHub issue, claiming that part of it was written by AI, which is true in the sense that I used AI to make it sound more professional, but I personally analyzed the bug, and they simply told me to submit it through another channel. They’ve shown me that they themselves didn’t know how Espressif’s ESP32 works because they literally failed to meet its specifications and literally sent me to a manufacturer’s thread discussing another model—the one used in the Jade Plus, which is the ESP32-S3. Either they haven’t even read my ticket, or they’re literally mentally challenged. If I were you and you had a Jade Classic with a seed generated in non-radio firmware version 1.0.40 or lower, I would regenerate a seed because there’s no guarantee that seed has sufficient entropy.
Cyph3rp9nk's avatar
Cyph3rp9nk 1 week ago
Given Blockstream’s response, I don’t think they deserve any further benefit of the doubt on this issue. Classic Jade devices running non-radio firmware version 1.0.40 or earlier have a legitimate trust issue regarding the entropy produced by the hardware RNG, because the way it was being sampled appears to fall outside the conditions recommended by the manufacturer, Espressif, for obtaining maximum entropy from the SAR ADC source. It is true that Jade later mixes multiple entropy sources into its internal state, but without a published lower bound or measurement of the min-entropy contributed by those sources, there is no public evidence demonstrating that the resulting BIP39 entropy necessarily reaches 128 bits. What has surprised me most is Blockstream’s apparent lack of awareness of these ESP32-specific RNG constraints, despite relying on that hardware as a core part of the device’s entropy-generation process.
Cyph3rp9nk's avatar
Cyph3rp9nk 1 week ago
I would appreciate the dissemination of this message because it is something important for Blockstream to clarify. I have my doubts about the entropy of the seeds generated by jade classic in firmware versions 1.0.40 no radio and earlier and I think they have not been sufficiently clear about the reason for the 1.0.41 update or whether they are aware of this problem that I mention in the no radio version. View quoted note →
Cyph3rp9nk's avatar
Cyph3rp9nk 1 week ago
@Blockstream Technical question for the Blockstream/Jade team regarding Jade Classic (original ESP32) + No-Radio firmware, especially around v1.0.40. In v1.0.40, Jade initialized its 256-bit entropy state with: bootloader_random_enable(); esp_fill_random(entropy_state, 32); bootloader_random_disable(); On the original ESP32, bootloader_random_enable() enables the SAR ADC entropy source when RF/Wi-Fi/Bluetooth are disabled. The point I am trying to understand is the entropy extraction rate. For ESP32 Classic, esp_random() uses: APB_CYCLE_WAIT_NUM = 16 With an 80 MHz APB clock, this corresponds to a minimum enforced interval of ~0.2 us between RNG reads (~5 MHz theoretical maximum, excluding execution overhead). However, the ESP32 Technical Reference Manual recommends reading RNG_DATA_REG at no more than ~500 kHz when using the SAR ADC in order to obtain maximum entropy, which corresponds to ~2 us per 32-bit read. So there appears to be a difference between: SAR ADC recommendation: <= 500 kHz > = ~2 us/read esp_random() on ESP32 Classic: > = ~0.2 us/read minimum enforced delay > ~5 MHz theoretical maximum Espressif also uses a much more conservative extraction rate in its bootloader RNG code when the SAR ADC is the entropy source. At the same time, Espressif explicitly documents bootloader_random_enable() + esp_random()/esp_fill_random() as a valid way of obtaining true random numbers when RF is disabled. Jade later changed this logic and now performs individual esp_random() calls separated by ~1 ms, explicitly mentioning additional time for HWRNG entropy refeeding and scheduler jitter. My questions are: 1. Did Blockstream measure or estimate the min-entropy of esp_fill_random(32) on ESP32 Classic with bootloader_random_enable() active and RF disabled? 2. Was the ESP32 TRM recommendation of <=500 kHz for maximum SAR entropy considered? 3. Is there a known lower bound for the min-entropy of the 256-bit entropy_state generated by Jade v1.0.40 in this configuration? 4. Was the later 1 ms delay purely defense-in-depth, or was it also intended to remove uncertainty about the SAR entropy refresh rate on the original ESP32? 5. Does Blockstream consider a 12-word BIP39 mnemonic generated on Jade Classic + No-Radio + v1.0.40 to retain the full expected 128 bits of entropy? I am not claiming a demonstrated vulnerability. I am trying to understand how the entropy guarantees of Espressif's SAR ADC/HWRNG path were evaluated in Jade.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
The state and all its workers are nothing more than a gang of organized thieves and murderers. The murderers part is often forgotten, the state not only steals, it also kills day after day in different ways. Police abuse, people who commit suicide over debts to the state, people who commit suicide because of stupid laws or the judicial system, medical negligence and finally wars. View quoted note →
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
You don't hate the state enough. You don't hate the government enough. You don't hate politicians enough. You don't hate public workers enough. They all deserve to die, they only bring suffering to the world.
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
“It would be strange if someone who lets his herd of cows dwindle and fall into disrepair did not admit to being a bad cowboy. But it is even more astonishing that someone who leads a people while letting them dwindle and fall into disrepair is not ashamed of it, nor does he admit to being a bad leader of that people.” (Xenophon. Memoirs of Socrates)
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
People who praise the state security forces = mentally deficient
Cyph3rp9nk's avatar
Cyph3rp9nk 2 weeks ago
Omarchy is a psyop 😂 No security, no party 🎉
Cyph3rp9nk's avatar
Cyph3rp9nk 3 weeks ago
Omarchy vs Fedora Silverblue Security Rating Omarchy — Security Rating: 6.7/10 — Moderate / Good with additional hardening Fedora Silverblue — Security Rating: 9.3/10 — Very Strong / Recommended for security-focused corporate endpoints image
Cyph3rp9nk's avatar
Cyph3rp9nk 3 weeks ago
The book *One Hundred Years of Solitude* provides a perfect analysis of the state. Macondo was born without a state. No one needed a government to found it, build it, trade, or live together. Political power came later… and with it came impositions, war, repression, and massacre. From an anarcho-capitalist perspective, *One Hundred Years of Solitude* offers a provocative idea: Society created Macondo. The state arrived when Macondo had already been created. And it was almost never for the better. It’s curious that Gabriel García Márquez was very close to the Cuban regime.
Cyph3rp9nk's avatar
Cyph3rp9nk 3 weeks ago
I wonder what the starting price will be for Luke's shitcoin.