su-do's avatar
su-do
npub1j444...he65
su-do's avatar
_kami_gawa 7 hours ago
You have no idea how secure a 256-bit private key is. You do NOT need multisig. Influencers told you to use Coldcard. Now they’re telling you to use multisig. Meanwhile, Satoshi’s coins are still secure in the most insecure address type (P2PK) and were probably generated on a
su-do's avatar
_kami_gawa 8 hours ago
The idea that schools should teach kids how to do taxes or how to make money is the dumbest shit ever. Schools should teach kids how to think, how to abstract, how to reason through logic problems, how to imagine and dream. Schools should give kids the instruments to wander.
su-do's avatar
_kami_gawa 1 week ago
The fact that we do _not_ need an hardware wallet, was the lesson learned from the @COLDCARD shitshow. Today is @Trezor , tomorrow it will be someone else. You do not need an hardware wallet if you are just hodling.
su-do's avatar
_kami_gawa 1 week ago
I'm sure many of you have seen these two posts side by side in your timelines. Well, look at them again and cry while you reflect on the thousands of man hours wasted by these larping drama queen #bip110 assholes. This attack on bitcoin has been no joke. Learn from it. I have.
su-do's avatar
_kami_gawa 1 week ago
Those ~70 bits make a real difference. They push bruteforcing from “trivial” (MK3) into “painful but still theoretically possible.” The entropy remains weak, just not catastrophic. Has anyone actually cracked an MK4 using a seed that was generated on the device itself (not imported)?
su-do's avatar
_kami_gawa 1 week ago
After a full dive into Mk4 today: Mk4 keys are not enumerable like Mk3 keys at all. Thanks to the reseed, it’s basically impossible to bruteforce them even, if they have weak entropy. When correctly set up, the private keys are so secure that they remain effectively uncrackable,
su-do's avatar
_kami_gawa 1 week ago
About the Mk3 draining, attackers can choose different "cones" to look into for wallets to hack. The weak Yasmarang RNG value is determined by a small state (pad + chip/mixer skip history). A "cone" is just a hypothesis about that history, e.g: first boot vs later login vs weird PIN session. Each cone is a slice of skip/space. Wrong cone → almost no hits. Right cone → mnemonics become enumerable. That’s why wallets can still sit unexplored in other cones. The attack can go on for years and still find utxos
su-do's avatar
_kami_gawa 1 week ago
I remember Jimmy Song writing, on the first day of Ordinals: “The first one that forks loses, and they (the spammers) will surely fork.” What I’m witnessing three years later feels like a lysergic experience. People I once thought were smart now look like completely unhinged madmen.
su-do's avatar
_kami_gawa 1 week ago
After carefully analysing and testing the @COLDCARD rng bug, I am quite sure the attacker(s) knew about the bug already and spent weeks if not months to enumerate some vulnerable wallets. The whole enumeration did not take 3 days (the delta between Kimi K3 release and the attack)
su-do's avatar
_kami_gawa 2 weeks ago
Instead of buying dice on Amazon, go to your local boardgames store. These guys will have amazing choice, dice that FEEL (and look) great, and they don't need to know where you live. Support your local game store.
su-do's avatar
_kami_gawa 2 weeks ago
Taproot Wizards - gone BIP110ers - gone Everything is going according to plan.
su-do's avatar
_kami_gawa 2 weeks ago
mistakes by 110ers: arguing nodes control protocol changes and miners will capitulate. subtly wrong. the economic users control the protocol, via the market. they transmit their views by transacting with their economic nodes. 1000s of nodes with no economic use have no influence.
su-do's avatar
_kami_gawa 2 weeks ago
If you belived that BIP110 was suddenly going to activate, you are retarded 😉 cheers
su-do's avatar
_kami_gawa 2 weeks ago
Today was an excellent day for Bitcoin. It demonstrated perfectly that it worked as it supposed to work.
su-do's avatar
_kami_gawa 2 weeks ago
The more you learn about Bitcoin security, the more you become a SeedSigner (or more broadly a general-purpose air-gapped computer) maximalist: generate the seed entirely offline with dice or other analog entropy, and ideally never load it onto a device that remembers or stores it. Even when you spend, use a stateless device so the seed only exists temporarily in RAM and is wiped on power-off. Add a strong dice-generated passphrase and/or a geographically distributed multi-sig quorum, and you have ironclad security for your stack.
su-do's avatar
_kami_gawa 2 weeks ago
Single sig. did not fail at all. What failed were pk generated by the wrong function. The era or device-generated seeds is done. Long life to human generated entropy.
su-do's avatar
_kami_gawa 2 weeks ago
Watching the BIP110 crowd complain about their fork is getting embarrassing. Lads, nobody cares. Go activate your fork today, switch the PoW as soon as you can, and move on. Nobody is going to follow you. The rest of us have more important things to do.
su-do's avatar
_kami_gawa 3 weeks ago
I wasn’t around for the Mt. Gox disaster, but what’s happening with @COLDCARDwallet today is a catastrophe. Self custody just took a serious hit. Wen CTV?
su-do's avatar
_kami_gawa 3 weeks ago
I am wondering how a company that makes money securing bitcoins, did not run a stupid LLM against their hardware wallet firmware to look for bugs. Also, why the hell do ColdCards have a fallback insicure element that generates entropy wtf.
su-do's avatar
_kami_gawa 3 weeks ago
#BIP110 people when the image is split into two pieces