g4tt0's avatar
g4tt0
npub16zf0...8sln
Nuts about freedom tech, collective action, personal empowerment, and all types of #ecash
g4tt0's avatar
g4tt0 3 days ago
note to flag I am testing nsec recovery wish me luck nostriches
g4tt0's avatar
g4tt0 3 weeks ago
*hat-tip* @conduition for the disclosure and the write up, gg to the rapid patching and following sensible vul disclosure practices: "Along the way I hope readers take home a few lessons about #security #engineering in general: - Look closely at apps which perform automated tasks using sensitive bearer secrets. Avoid auto-trusting anything outside direct user input (and even then). - Deterministic secrets are fickle. Pay attention to how the derivation mechanism works, but also how it is used. There could be mistaken assumptions. - Be careful when using “SHOULD” in a cryptographic specification. Figure out when “SHOULD” needs to be “MUST”. - Watch out for injections - Anytime a large domain is pigeonholed into a smaller space. Big thanks to the #Cashu devs for bearing the bulk of the work of actually fixing this thing. While the initial research was challenging, there is little I find more prosaically daunting than corralling teams of open source devs to fix an obscure vulnerability, and they saved me from attempting that myself."
g4tt0's avatar
g4tt0 3 weeks ago
running #knots already not flagging bip-110 activation #UASf > change my mind #bitcoin #noderunners #bip #bip110
g4tt0's avatar
g4tt0 2 months ago
you still looking at the charts anon? sats is the money forget your master's slave-paper #meow