Silberengel's avatar
Silberengel
silberengel@gitcitadel.com
npub1l5sg...gx9z
Building jumble-imwald and the Alexandria library.
Silberengel's avatar
Silberengel 1 week ago
My main problem with hardware wallets is the social risk. If you order one, everyone knows you have put crypto on it. An old laptop, tablet, or cell phone is just an old, general-purpose computer. Biggest risk is that someone throws it away.
Silberengel's avatar
Silberengel 1 week ago
I think anyone suing Cold Card has a good case, even merely based on the audits that have already been performed. There is nothing at all normal about how this stuff was built. Outrageous, irresponsible behavior and open contempt for the customers, IMO. Their best bet is probably to claim that they were all taking hallucinogenic drugs while working; _it is that bad_. And it just keeps getting worse. Every time there is a scandal like this, I am left staring in shock at how bad it all is, as I can't imagine anyone actually being this grotesquely bad. It's completely outside my frame of reference. **This is the shit you get when developers don't stay humble. This is the shit you get when nepotism is rife.** View quoted note →
Silberengel's avatar
Silberengel 1 week ago
The keygen for all of the libraries I have used draw full 256-bit values from OS CSPRNGs. Code audited: # JavaScript / TypeScript * nostr-tools (versions 2.15 – 2.23.5) * @nostr/tools 2.20.0 (the JSR-published variant of nostr-tools) * @nostr-dev-kit/ndk 2.14.35 (+ ndk-cache-dexie) * @contextvm/sdk —(ContextVM signer, wraps nostr-tools) # Go * go-nostr (nbd-wtf) (v0.27.0, notably older) # Kotlin / JVM * no Nostr library; direct implementation on top of ACINQ secp256k1-kmp 0.17.3 (plus BouncyCastle in the Android app) # Elixir * no Nostr library; implements on top of lib_secp256k1 0.7.1 # PHP * swentel/nostr-php 1.9.4 (server side; pulls in elliptic-php) # Python * python-nostr image
Silberengel's avatar
Silberengel 1 week ago
I can't stop thinking about the fact that I could have vibe-coded the firmware with my Cursor ultra account in a couple of days. And it would have been more secure. And it would have been written in C. And the tests would have prevented this error. *This was human slop.*
Silberengel's avatar
Silberengel 1 week ago
After this circus, the next person who tells me I am being paranoid because "encryption can't be broken and keys never leak" will just be ignored. View article →