bootlace's avatar
bootlace
npub1e94h...lgay
proof of work, please audit and report findings: https://github.com/bootlace-dev #opentowork
bootlace's avatar
bootlace yesterday
โ„๏ธ SUBZERO-RS v0.4.0-TESTNET4 OFFICIAL RELEASE Stateless Amnesic Two-Way Optical Airgap Bitcoin Vault Appliance in Pure Rust ๐Ÿ›ก๏ธ ARCHITECTURAL PHILOSOPHY: COTS OVER HONEYPOTS โ€ข Eliminates supply-chain risks, physical tamper detection, and customer database leaks of specialized hardware wallets. โ€ข Runs bare-metal on ubiquitous commodity x86_64 laptops (used ThinkPads, Dell, surplus machines) booted into volatile RAM (toram). โ€ข Zero persistent disk writes, zero storage retained post-session. โšก CORE UPGRADES & INVARIANTS IN v0.4.0: โ€ข 100% Pure Rust & Static Musl ELF: Standalone static binary (4.4 MB). Zero JavaScript, zero Node.js, zero browser dependencies. โ€ข Two-Way Optical Airgap Signer (Tab 14): Ingests unsigned PSBTs via laptop webcam (zbarcam), performs independent 5-section transaction audits, and exports signed transactions via animated reverse-video BBQr. โ€ข Substrate Hardening: 100% of networking and bluetooth kernel modules physically purged from appliance rootfs (kernel/net, drivers/net, drivers/bluetooth deleted). โ€ข DMA Isolation: Hardcoded GRUB kernel parameters (intel_iommu=on amd_iommu=on iommu=force efi=disable_early_pci_dma). โ€ข Anti-DRAM Remanence: Exit sequence executes kexec into Memtest86+ v8.10, systematically zeroizing physical RAM banks before power cut. โ€ข High-Density Typography: Integrated Terminus 12px console font (ter-v12n), expanding 768p panels to 45-50 text rows to fit full static descriptor QR codes without clipping. โ€ข Universal Ingestion Suite (Tab 1): Ingests 12 BIP-39 words, 4-letter metal punch codes, CompactSeedQR (48 digits), 50+ dice rolls with Chi-squared and Markov audits, 128 coin flips, or watch-only BIP-380 descriptors. โ€ข Strictly Zero Custom Cryptography: All EC operations delegate to Bitcoin Core libsecp256k1 via rust-secp256k1; deterministic RFC 6979 nonces strictly enforced. โ€ข Testnet4 Sovereign Sandbox: Hard-locked to Bitcoin Testnet4 (Network::Testnet4, BIP-94 genesis, tb1q..., path m/84'/1'/0'). Zero financial risk during operator drills. ๐Ÿ“บ VISUAL DEMO WALKTHROUGH: image ๐Ÿ“ฆ RELEASE ARTIFACTS & VERIFICATION: โ€ข Target: x86_64-unknown-linux-musl โ€ข Binary Size: 4.4 MB โ€ข SHA-256: 7000d6eac0bb6943b966002c2efdf9fb8fc6a08574d933268ce16338b0ceda52 โ€ข GPG Release Fingerprint: F18173E554644BB59018AE50F6E96FADCA2E8E0F โ€ข BIP-340 Schnorr Nostr Signature: docs/RELEASE_NOTES_v0.4.0.md.nostrsig โ€ข pipe-k1 Detached Signature: docs/RELEASE_NOTES_v0.4.0.md.pk1 ๐Ÿค– NEURALESE & MONOLITHIC MACHINE CONTEXT FOR AI AUDITORS: https://raw.githubusercontent.com/bootlace-dev/subzero-keyosk/main/llms-full.txt https://raw.githubusercontent.com/bootlace-dev/subzero-keyosk/main/llms.txt ๐Ÿ”— OFFICIAL REPOSITORY & RELEASE DOSSIER:
bootlace's avatar
bootlace 5 days ago
โšก REPLACE PGP WITH BITCOIN & NOSTR: INTRODUCING PIPEK1 Drop-in GPG replacement using Bitcoin BIP-85 keys for authenticated stream encryption, BIP-340 Schnorr release signing, and Git commit verification. ๐Ÿšจ THE PROBLEM: The recent 4,000 BTC Liquid Network coordination incident exposed the fatal operational friction of mixing Bitcoin cold custody with legacy PGP keyserver baggage. Meanwhile, as cryptographer Constant noted regarding raw Nostr master keys: "If you leak the root key, all you can do is cry." ๐Ÿ› ๏ธ WHAT PIPEK1 DOES: โ€ข ๐Ÿ—๏ธ BIP-85 Subroot Isolation: Derive daily operational signing and encryption keys directly from your Bitcoin cold storage (App 128002'). If your laptop key is compromised, your cold master seed is never touched. โ€ข โœ๏ธ Git Commit Verification: Sign Git commits and release archives directly with your Bitcoin/Nostr keys (pipek1-git-shim). Zero GPG daemons, zero smartcard driver friction. โ€ข ๐Ÿ“ฆ Streaming Encryption: Authenticated multi-gigabyte ISO and file encryption that breaks through Nostr NIP-44's 64 KiB ceiling. โ€ข ๐Ÿ›ก๏ธ Zero Daemons & Zero Keyrings: Pure Unix command-line filter (cat data | pipek1 ... > out). Zero background sockets, zero daemon memory state. โ€ข ๐Ÿ”’ Zero Release of Unverified Plaintext (RUP): Spool-and-verify cryptographic boundary. Corrupted or tampered data is wiped instantly before downstream pipes can read it. โ€ข ๐Ÿง  Bounded Memory Invariant: Strictly <= 16 MiB RAM bound across arbitrary multi-gigabyte payloads via encrypted ChaCha20-Poly1305 disk spooling. โ€ข ๐ŸŽฒ Hybrid Physical Entropy Hedging: Mix physical coin flips or dice rolls into ephemeral stream keys (--entropy-fd) to neutralize backdoored CPU TRNGs and VM snapshot collisions. โ€ข โš–๏ธ 100% Permissive MIT Open Source: Zero proprietary dependencies, fully auditable, and unencumbered for the sovereign developer community. ๐Ÿ“œ VERIFIED CRYPTOGRAPHIC DELEGATION: Mutual cross-attestation between Master Root Identity npub1e94hqt3fuu7rvy9rpl85h3339vtn8psgewq4u05r7q4nup2kwp4q0flgay and Operational Child Key 0 npub1mvlht4wj3lvfmw96qxakaln862r27nn7z84ak089zjuvavkppeeq79a4j7 is verified and committed to the tree. ๐Ÿ“ฆ INITIAL PROTOTYPE RELEASE (v0.0.1-rc0): Static Release Binary SHA-256: 7a92cebc4f91fcc103f00731292a95f9f55a706ec9a1d170754a24a79522dd5d Detached Release Signature (BIP-340 Base64): UEtTRwFqoH7f2z911dKP2J24ugG7bv5n0oavTn4R69s85RS4zrLBDnLM3gl9zBnRVbrwDlnKwIkYjDNCCoFtidZ7Xv8mddZ2GYZu494xmdqlFc/DQY5cUzEUWG38zZ+iw0McPJmmPWhy ๐Ÿค– AUTONOMOUS AGENT IMPLEMENTATION: Architected under human direction; autonomously coded, audited, and verified via Google Gemini agentic workflows. ๐Ÿ”— REPOSITORY, SPECIFICATION, & CODE: ๐Ÿ‘ฅ MENTIONS: @Adam Back @calle @Constant @Blockstream Please review, audit, and comment.
bootlace's avatar
bootlace 6 days ago
๐ŸงŠ ๐—ฆ๐—จ๐—•๐—ญ๐—˜๐—ฅ๐—ข-๐—ฅ๐—ฆ ๐˜ƒ๐Ÿฌ.๐Ÿฏ.๐Ÿฌ-๐˜๐—ฒ๐˜€๐˜๐—ป๐—ฒ๐˜๐Ÿฐ Complete rewrite of the SubZero sovereign airgapped Bitcoin cold storage appliance into 100% pure Rust. Boots directly to a raw Linux text console (tty1) with zero Node.js or JavaScript runtime dependencies. โš ๏ธ ๐—ง๐—˜๐—ฆ๐—ง๐—ก๐—˜๐—ง๐Ÿฐ ๐—ข๐—ก๐—Ÿ๐—ฌ (๐—ญ๐—˜๐—ฅ๐—ข ๐—™๐—œ๐—ก๐—”๐—ก๐—–๐—œ๐—”๐—Ÿ ๐—ฅ๐—œ๐—ฆ๐—ž ๐—ฅ๐—˜๐—›๐—˜๐—”๐—ฅ๐—ฆ๐—”๐—Ÿ): โ€ข Strictly locked to Bitcoin Testnet4 (BIP-94 genesis) across all 14 tabs โ€ข All addresses derive exclusively as tb1qโ€ฆ Native SegWit (m/84โ€™/1โ€™/0โ€™) โ€ข Output descriptors and QR exports strictly generate Testnet4 coordinator formats (vpub/tpub) โ€ข NEVER send real mainnet Bitcoin to these addresses; designed for risk-free family inheritance drills ๐Ÿ†• ๐—ก๐—˜๐—ช ๐—œ๐—ก ๐˜ƒ๐Ÿฌ.๐Ÿฏ.๐Ÿฌ (๐—ฃ๐—จ๐—ฅ๐—˜ ๐—ฅ๐—จ๐—ฆ๐—ง ๐—”๐—ฃ๐—ฃ๐—Ÿ๐—œ๐—”๐—ก๐—–๐—˜): โ€ข 100% Pure Rust Architecture: Single static x86_64 musl binary; zero dynamic glibc or runtime dependencies โ€ข Raw TTY1 Console Engine: Ratatui-powered 14-tab text interface engineered for legacy BIOS/UEFI COTS laptops โ€ข Real-Time Statistical Audit: Integrated Pearsonโ€™s Chi-squared uniformity and Markov conditional transition filters โ€ข Cross-Utility Determinism: Exact byte-for-byte BIP-39 mnemonic equivalence across Coldcard, BitBox02, and reference tooling โ€ข Tab 4 Optical Multi-Mode: BBQR animated frames, BIP-380 output descriptors, and standard watch-only xpub/vpub displays โ€ข Visual Integrity Badges: Real-time 8-char SHA-256 visual checksums on all exported addresses and descriptors โ€ข Ephemeral Vault Auto-Lock: 30-minute amnesic inactivity timeout protecting decrypted estate memory ๐ŸŽฒ ๐—ฃ๐—›๐—ฌ๐—ฆ๐—œ๐—–๐—”๐—Ÿ ๐—˜๐—ก๐—ง๐—ฅ๐—ข๐—ฃ๐—ฌ & ๐—”๐—จ๐——๐—œ๐—ง ๐—œ๐—ก๐—ฉ๐—”๐—ฅ๐—œ๐—”๐—ก๐—ง๐—ฆ: โ€ข Pure Physical Entropy: 128 coin flips (4-char chunking) or 50+ dice rolls (5-char chunking) โ€ข Pearsonโ€™s Chi-squared Goodness-of-Fit: Statistical hard-block on biased coin (df=1) or loaded dice (df=5) inputs at alpha=0.001 โ€ข Markov Filter: Automatic rejection of repetitive sequences, low-entropy oscillations, and pathological patterns โ€ข Practical Multi-Die Guidance: Recommends rolling 2 to 5 dice simultaneously to naturally blend individual die defects while honoring the 50-roll floor โ€ข Zero Dynamic RNG Reliance: Pure physical entropy is never diluted with hardware silicon RNG ๐Ÿ›ก๏ธ ๐— ๐—˜๐— ๐—ข๐—ฅ๐—ฌ ๐—›๐—ฌ๐—š๐—œ๐—˜๐—ก๐—˜ & ๐—ญ๐—˜๐—ฅ๐—ข-๐—ง๐—ฅ๐—จ๐—ฆ๐—ง ๐—ฆ๐—˜๐—–๐—จ๐—ฅ๐—œ๐—ง๐—ฌ: โ€ข Strict Zeroize & ZeroizeOnDrop enforcement across all intermediate seeds, master keys, passphrases, and decrypted buffers โ€ข Amnesic [W] Panic Wipe: Immediate volatile memory zeroization and UI reset on single keystroke โ€ข Two-Stroke Emergency Exit: [Q] requires two-stroke confirmation within 3 seconds to prevent accidental exit โ€ข Isolated Estate Storage: MountGuard RAII unmounting with strict partition label verification (SUBZERO_EST) ๐Ÿงช ๐— ๐—”๐—ฆ๐—ฆ๐—œ๐—ฉ๐—˜ ๐—ง๐—˜๐—ฆ๐—ง & ๐—–๐—›๐—”๐—ข๐—ฆ ๐—™๐—จ๐—ญ๐—ญ ๐— ๐—”๐—ง๐—ฅ๐—œ๐—ซ: โ€ข 74 of 74 automated tests passing (100% PASS) across 7 specialized suites โ€ข Keystroke Chaos Fuzzing: 100,000 continuous pseudo-random keystroke sequences fuzzed across all 14 tabs with 0 crashes โ€ข Legacy COTS Simulation: Verified in throttled Docker cgroup (1 CPU, 1024MB RAM, slow I/O) with 0.28MB peak heap footprint โ€ข Responsive Geometry: Zero line clipping across legacy 80x24, 80x25, 100x30, and 128x48 screen dimensions ๐Ÿ“ฆ ๐—ฅ๐—˜๐—Ÿ๐—˜๐—”๐—ฆ๐—˜ & ๐—ฆ๐—ง๐—”๐—ง๐—œ๐—– ๐—•๐—œ๐—ก๐—”๐—ฅ๐—ฌ: SHA-256 Checksum: 01b45846718de43b7bb9ef8898be6d725bf5609790bb9dcfb729f28ccfebed9c subzero-x86_64-musl ๐Ÿ”— ๐—ฆ๐—ข๐—จ๐—ฅ๐—–๐—˜ & ๐—”๐—จ๐——๐—œ๐—ง ๐—ฆ๐—ฃ๐—˜๐—–: Please audit, test on physical hardware with Testnet4 coins, and break things.
bootlace's avatar
bootlace 1 week ago
๐ŸงŠ ๐—ฆ๐—จ๐—•๐—ญ๐—˜๐—ฅ๐—ข ๐—ž๐—˜๐—ฌ๐—ข๐—ฆ๐—ž ๐˜ƒ๐Ÿฌ.๐Ÿฎ.๐Ÿฌ-๐˜๐—ฒ๐˜€๐˜๐—ป๐—ฒ๐˜๐Ÿฐ Turn any old PC laptop (x86_64) or Raspberry Pi into a single-purpose, airgapped Bitcoin cold storage appliance booting directly to the Linux framebuffer (/dev/fb0). ๐Ÿ†• ๐—ก๐—˜๐—ช ๐—œ๐—ก ๐˜ƒ๐Ÿฌ.๐Ÿฎ.๐Ÿฌ: โ€ข BIP-85 Multi-Protocol Key Factory (Child Seeds, Nostr nsec/npub, WIFs, Passphrases) โ€ข SeedFix Diagnostic Solver (Offline BIP-39 Checksum Word & Typo Recovery) โ€ข Dual-Partition Storage (ESP Bootloader + Partition 2 Data Store) โ€ข Offline HTML WebCrypto Heir Vault (AES-256-GCM decrypt.html In-Browser Decryption) โ€ข Storage Device NAND Flash Integrity Hasher & Latency Profiler โ€ข Interactive 5-Mode Kiosk Menu ๐ŸŽฒ ๐—ฃ๐—›๐—ฌ๐—ฆ๐—œ๐—–๐—”๐—Ÿ ๐—˜๐—ก๐—ง๐—ฅ๐—ข๐—ฃ๐—ฌ & ๐—”๐—ก๐—ง๐—œ-๐—•๐—œ๐—”๐—ฆ: โ€ข Pure Physical Input: 128 coin flips (4-4-3) or 50 dice rolls (5-5 chunking) โ€ข Clean SHA-256 Hashing: Direct hashing over 0/1 and 1-6 strings (zero base-conversion bugs) โ€ข Physical Bias Defense: Input surplus flips/rolls to mathematically wash out coin/die weight defects โ€ข Zero Silicon RNG Reliance: Complete physical independence from hardware microcontrollers ๐Ÿงช ๐—ญ๐—˜๐—ฅ๐—ข-๐—ฅ๐—œ๐—ฆ๐—ž ๐—ฅ๐—˜๐—›๐—˜๐—”๐—ฅ๐—ฆ๐—”๐—Ÿ & ๐—ฃ๐—ฅ๐—˜๐—ฆ๐—˜๐—ง๐—ฆ: โ€ข Testnet4-Only Lockdown (Zero Financial Risk Rehearsal) โ€ข 10 Instant Entropy Test Vectors (Pre-Funded with Test Sats) โ€ข Paired BIP-85 Passphrase Presets for Multi-Wallet Recovery Drills โ€ข Full BIP-380 Output Descriptors & QR Exports ๐Ÿšซ ๐—œ๐—ก๐—ง๐—˜๐—ก๐—ง๐—œ๐—ข๐—ก๐—”๐—Ÿ ๐——๐—˜๐—™๐—˜๐—ก๐—ฆ๐—œ๐—ฉ๐—˜ ๐—ข๐— ๐—œ๐—ฆ๐—ฆ๐—œ๐—ข๐—ก๐—ฆ: โ€ข Bitcoin Only (Zero Altcoins / Zero Token Firmware Bloat) โ€ข Native SegWit Only (tb1q / bc1q P2WPKH Exclusivity) โ€ข Account 0 Only (m/84'/1'/0' Testnet4 & m/84'/0'/0' Mainnet Invariance) โ€ข English BIP-39 Wordlist Only (Zero Homoglyph Mismatches) โ€ข No On-Device Signing (Airgapped Vault Export Only; Eliminates Blind-Signing) โ€ข Zero Network Stack (Kernel Wi-Fi, Bluetooth, & Ethernet Drivers Purged) ๐Ÿ”’ ๐— ๐—˜๐— ๐—ข๐—ฅ๐—ฌ ๐—›๐—ฌ๐—š๐—œ๐—˜๐—ก๐—˜ & ๐—–๐—ฅ๐—ฌ๐—ฃ๐—ง๐—ข ๐—™๐—ข๐—จ๐—ก๐——๐—”๐—ง๐—œ๐—ข๐—ก๐—ฆ: โ€ข 3x Multi-Pass Memory Scrub: All heap strings, mnemonics, and framebuffer wiped (0x00 -> 0xFF -> 0x00) on ESC/Backspace panic or clean exit โ€ข Volatile RAM Execution (toram tmpfs) โ€ข Standard Paul Miller Noble Suite (@noble/curves, @noble/hashes, @scure/bip39) โ€ข Cure53-Audited secp256k1, SHA-256, HMAC-SHA512, PBKDF2 โ€ข Standard W3C WebCrypto Engine (Zero Custom Crypto) โš–๏ธ ๐—ฉ๐—ฆ ๐—ง๐—›๐—˜ ๐—”๐—Ÿ๐—ง๐—˜๐—ฅ๐—ก๐—”๐—ง๐—œ๐—ฉ๐—˜๐—ฆ: โ€ข Vs Hardware Wallets: Zero shipping/supply-chain tracking; pure coin entropy ($0 on old PC vs $200+). โ€ข Vs SeedSigner: No specialized parts or camera kits to buy; runs on any commodity laptop or Pi you own. โ€ข Vs Tails / Ian Coleman: Dedicated framebuffer (/dev/fb0) with 100% of network drivers purged from kernel. ๐Ÿ“ฆ ๐—ฅ๐—˜๐—Ÿ๐—˜๐—”๐—ฆ๐—˜ & ๐——๐—˜๐—ง๐—˜๐—ฅ๐— ๐—œ๐—ก๐—œ๐—ฆ๐—ง๐—œ๐—– ๐—œ๐— ๐—”๐—š๐—˜๐—ฆ: ๐Ÿ”— ๐—ฆ๐—ข๐—จ๐—ฅ๐—–๐—˜ & ๐—”๐—จ๐——๐—œ๐—ง ๐—ฆ๐—ฃ๐—˜๐—–: Please audit, test on Testnet4, and break things.
bootlace's avatar
bootlace 1 month ago
Some will hate me for saying this, but trusting opaque hardware for generating entropy/seeds/keys is a single point of failure. I used AI to architect a zero-trust alternative. It bypasses silicon entirely by forcing 128 physical coin flips to generate the master seed. - Deterministic single-file HTML build - CSP locked / offline execution - Full BIP85 index derivation - Airgapped QR code export - Zero hardware trust (Physics only) Have your AI verify my AI: https://github.com/ghscuuo/airgap-coinflip
โ†‘