Trying Ditto for the first time.
Matt - Not Your Entropy, Not Your Coins
matt@gitcitadel.com
npub1l6sc...j5rc
Probably a spook ๐ป
https://zapmeacoffee.com/npub1l6scds4yv7xmcsmhqnhdy9sggm520q09lvts2m5mkvecgr2mmmeqsuj5rc
Another lesson I've learned is to spend the least time preparing for asinine NSA level attacks while the front door is wide open.
Focus the most on the basics first. Move down the line once that is handled.
I made a web tool that lets you enter your seed phrase to see if it can be easily compromised.
https://www.justfuckingwithyou.com
I'm sure this will be out there though ๐
I keep recommending the Entropia product from SeedSigner (or just general concept, however you do it). I guess you could print them but the pills don't stick and work better for me.
For anyone curious:
I verified against the BIP39 list when the 3D printed pill sheets arrived to make sure the words were accurate.
I then mixed them very well in a large mixing bowl.
I move my hand throughout the mixture with no particular pattern for a while and then pinch one of the pills to remove it.
From there, I drop the pill from about one to two feet onto a hard surface and allow it to bounce until it settle. Sometimes they fall onto the floor. No matter what, I go with the word facing up, even if it lands on the floor, cat bowl, whatever.
Then add the word back into the mix and repeat. I've seen people not do this and it's a big mistake. A phrase can and should be able to have the same word more than once. This has happened to me before on a real seed generation mission. Very unlikely, but that's entropy. It happens.
Calculate the 24th word however you decide to for a valid wallet. I used the SeedSigner and drew another word. I think it allows a die roll and maybe a coin?
This is the purest entropy I've found. I'd prefer non-double side but it would be far more cumbersome. I'm comfortable with adding in my drop method.
Anyway, if I'm fucking up, let me know. This is what I'm doing for at least part of my new security model.
Upcoming: Loaded dice attack (lol? ๐ฅฒ)
At this point, I'm going to say you're retarded if you aren't at a minimum running your safety critical software through various AI models before official release. It seems like a duty to know what is popular and likely being used to find exploits, and to use it against yourself first and continuously.
All this bullshit also reminds me of an undergrad class I had on validation and verification of software input and output. Maybe we should be testing assumptions? For example, that generated key output isn't trivial to guess? Surely there's a way to generate and test data prior to release.
Subject to change if someone convinces me otherwise, but that's where my thinking is.
Move fast and break things.
Ship, ship, ship!
Wordle 1,869 5/6*
โฌ๐จโฌ๐ฉโฌ
โฌ๐ฉ๐ฉ๐ฉ๐ฉ
โฌ๐ฉ๐ฉ๐ฉ๐ฉ
โฌ๐ฉ๐ฉ๐ฉ๐ฉ
๐ฉ๐ฉ๐ฉ๐ฉ๐ฉ
Blaming educators, journalists and podcasters for advocating self-custody is misguided. Bitcoin has little point without it. This really has nothing to do with Bitcoin or self-custody. And it isn't fair to blame people who have no duty to be experts in relevant security and engineering principles.
Knowingly promoting dangerous devices is one thing, but I don't think any of them were doing that.
There are things to reflect on and change going forward, but this isn't one of them. I don't see who wins if we have no builders, educators, or self-custody promoters in the space.
Free market certifications, standards, audits, testing, etc... Absolutely.
A Simply Bitcoin title that isn't clickbait. I'm impressed.
At least we know how to increase Nostr activity now. I haven't had this much interaction in a long time.
I'm feeling this too. I'm asking myself whether I really should have given up my 50/50 strategy of gold and Bitcoin.
And the gaslighting is pissing me the fuck off. I get that we each bear the full consequences, but good luck getting new adoption with this garbage ass culture.
I don't think the game is over, but this is a massive fucking failure that has me revisiting everything. And maybe that's a win in this big pile of loss.
View quoted note โ
I'm shifting on AI. I question the ethics and practicality of not using it at least for testing at this point. Particularly in safety critical domains.
Many CC related scams are coming. Buckle up.
For every minute I spend analyzing and criticizing others, I spend probably an hour or more on myself.
There's nothing wrong with pointing out the issues with competitors (I appreciate it when it's done in a healthy way). Just spend more time looking at your own work and not demeaning anyone who points out concerns for what you're doing. It could be the case that you spent so much energy preparing for edge case splinters and preventing competition that you completely missed the plank in your own eye.
External and internal criticism are both important. Ego has no place when lives are at stake. Practice both fairly.