Oren ☂️ #BIP-128's avatar
Oren ☂️ #BIP-128
orenz0@protonmail.com.ln2.email
npub1xvtw...m7f8
Software Developleb https://github.com/oren-z0 CTO at RITREK.com Check out: https://niot.space https://ln2.email
Hardware wallets are hard to hack but can have disasterous bugs. Hot Phone wallets are safer against bugs (can be fixed via online update), but can have disasterous hacks. For example, while creating a 2-of-2 multisig on a hot phone wallet, the phone can show you a fake seed unrelated to the its declared xpub, and hide the real seed internally. At some random point, the phone can get a remote command to blackmail you, and only then you will realize you don't really have the real seed. People won't buy more than 1 hardware wallet, and I don't know how to solve this issue. Maybe UX for the Phone Wallets that shows a seed + xpub, and let you decide whether to use it or pick another one? You could enter a few seeds that the phone generated into the hw wallet just to verify that the phone didn't try to cheat, then use the last one without entering it to the hw wallet. Or maybe covenants?
vibe-coded a tool to test your air-gapped wallet ( @SeedSigner , @npub1j0dm...lwm0 ) against basic #DarkSkippy attempts: create fake PSBTs with a fake seed, and see if the HW wallet returns the expected signature and does not try to leak data: Obviously you should also verify the firmware's pgp, and this tool does not cover sophisticated #DarkSkippy attacks (i.e. that try to leak data only in certain conditions, like in transactions of specific amounts, or multisig setups). Thanks to @Frostsnap for building darkskippy.com and creating a real-world example.
So far, around $72 million has been stolen from #Coldcard wallets. That’s equivalent to a whole 31 minutes of growth in the U.S. M2 money supply!
If you are going to make bets with your friends on the next 🇦🇷 Argentina vs 🇪🇸 Spain game, check out my new website: Login with your Nostr profile (or create a temporary nsec), design your page, add betting options, and share the page with friends. Each friend will zap you his choice and provide a lightning address to get their reward. You, as the page admin, are trusted to select the winning option and pay the rewards proportionally (the website will do the math for you). The bettors don't even need a Nostr profile. Everything is encrypted with a key in the page url, so relays can't see much of what's going on inside the page. #dev #devstr #WorldCup #football View quoted note →
Having to use #nostr as a backend database, to avoid legal risk when you want to publish an open-source website/app, is basically the government telling you: "It's ok to publish this project but only if the database is unreliable." 🤔 #showerthoughts #dev #devstr
Just finished fabelling this over the weekend: Create private gambling pools for friends (who trust you not to steal from them). Bettors don't even need a Nostr profile, just a lightning wallet. Beta version - don't use with large amounts, and don't invite unknown users. #dev #devstr #nostr #nostrdev #lightning #fable #ai #vibecoding Let me know what you think! View quoted note →
If you want to make #Nostr app developers lose their mind, open their latest app and post the message "[object Object]". 😈 #devstr
If you're worried that the world is getting dumber, remember that it was always kind of dumb. (From Prague's Communism Museum) image