Harsha Goli

7K posts

Harsha Goli banner
Harsha Goli

Harsha Goli

@arshbot

Founder @magnolia_hq | banking 🤝 crypto 🤝 fintech

NYC 🗽 Katılım Ağustos 2013
1.1K Takip Edilen2.9K Takipçiler
Zach Herbert 🇺🇸
Zach Herbert 🇺🇸@zherbert·
@BitsagaRob Can people please stop saying fork? Yes we used some code that was open source, but obviously this was not some kind of copy paste or even fork situation. We started a fresh micro Python project and brought in some code.
English
1
0
12
511
Rob | Bitsaga.be
Rob | Bitsaga.be@BitsagaRob·
On the Coldcard entropy bug: - It was never hidden, public source for 5+ years. Source-available ≠ audited. - The regression rode in on a licensing-driven swap: from the mature, many-forks-depend-on-it Trezor-derived GPL crypto to a single-author libNgU under a bespoke "Bitcoin only" license. - Root cause is a one-word bug (ifndef vs if). The most catastrophic bugs are boring. - XOR-ing two broken seeds is theater, two reproducible streams stay reproducible. 32 bits is the recurring curse — Trust Wallet, libbitcoin bx, now Coldcard's Mk4/Q/Mk5 reseed. 2³² ≈ a weekend on one GPU. This is the same as doing twelve dice rolls and stopping. That's why dice rolls can be very dangerous! - Coinkite says Mk4/Q/Mk5 are safe; Block says ≤2³². Same code, opposite conclusions. - Reproducible builds guaranteed everyone got the same wrong binary. Verifying the artifact ≠ verifying the behavior. - They punished the fork (@FoundationHQ) by licensing, then the bug entered on the same commit that evicted the forkable code. -"Not your keys, not your coins" now gets prepended with "not your entropy, not your coins." Sovereignty is a verb.
English
11
16
108
9.3K
Harsha Goli
Harsha Goli@arshbot·
@KLoaec well don’t worry, you wouldn’t get an email or any official notification to get you worried
English
0
0
2
253
Harsha Goli
Harsha Goli@arshbot·
@starkandlime > they can’t email users directly telling them to update in hindsight, this was devastatingly stupid. allow people to opt-out of security updates
English
2
0
3
684
Francis Corvino
Francis Corvino@starkandlime·
Say Cold Card found out about the exploit and wanted to patch it. They can’t email users directly telling them to update, they delete emails after 50 days. They can’t release a public patch, everyone will see the diff, and if you don’t tell them to do it people aren’t just updating their firmware for funsies. A lot of the time it’s considered a good thing to not update firmware unless you want some sexy new feature like silent payments. And even then, people still need to love their coins. It’s a real issue
English
5
4
43
17.4K
Harsha Goli
Harsha Goli@arshbot·
@zherbert Did you use it against coldcard as well w/o bias? Did it detect the issue by itself?
English
1
0
7
2.2K
Zach Herbert 🇺🇸
Zach Herbert 🇺🇸@zherbert·
I used GPT 5.6 with Cyber access to review seed generation in Keystone, BitBox02, Blockstream Jade, and Trezor. I found no Coldcard-style low-entropy bugs. Caveat: legacy Keystone’s underlying HRNG library is closed, so it can’t be fully source-audited. (All Passport devices are also OK)
English
38
43
415
26.3K
BROOKLYDAMUS
BROOKLYDAMUS@Brooklydamus·
@arshbot Honestly I bet sales were less of a concern than ego
English
1
0
4
213
Harsha Goli
Harsha Goli@arshbot·
ugh. > dismiss early warning signs as fud > victim blame early Reddit posts > 500 btc lost at this point > only issue alert for mk3. Claim all later models safe > only later issue unclear alert for all models, with unclear migration steps This communication approach prioritized profit from device sales over existing customers. Step after step @COLDCARDwallet downplayed an attack as it was unfolding online. This prioritization is unacceptable for centralized custodians. It should be unforgivable for a security hardware vendor.
COLDCARD@COLDCARDwallet

🚨URGENT COLDCARD SECURITY UPDATE Read carefully before acting. 👉Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now. 👉Mk4/Mk5 <5.6.0 or Q <1.5.0Q: update first, generate a new seed, then migrate. blog.coinkite.com/entropy-techni…

English
8
17
171
12K
Harsha Goli
Harsha Goli@arshbot·
no i understand! the only way to protect the company is to act with understanding that afterwards, your actions will be dissected. if nothing, send email and take on short term brand risk. if something, you can show you attempted to warn folks before you were sure something was definitively wrong, resulting in saving funds. you don't go for the life jackets when there's water up to your ankles, you do it when there's initial reports of flooding under deck.
English
1
0
1
18
Nick Sainato
Nick Sainato@nicksainato·
@arshbot I don't disagree with you. I think my use of "you" was misleading, I meant the royal you, as in them. They can't make such definitive statements even in the fog of war.
English
1
0
0
18
Harsha Goli
Harsha Goli@arshbot·
@nicksainato disagree. and a regulator would string me up and put me on a cross if i proceeded with caution to protect my brand. x.com/arshbot/status…
Harsha Goli@arshbot

@MoneySeanX How many people’s life savings could have been saved had they issued a “situation developing, migrate funds out of an abundance of caution” email? People obsessed with their image will apparently put it first when under duress.

English
1
0
1
28
Nick Sainato
Nick Sainato@nicksainato·
@arshbot Sorry, Grok corrected me and said months or years, if not decades or centuries lol Still not great, but not entirely false to say it’s doesn’t appear to be an urgent issue
English
1
0
0
34
Harsha Goli
Harsha Goli@arshbot·
@tola2252 bitkey. relying on a single key has always seemed moronic.
English
0
0
2
163
Harsha Goli
Harsha Goli@arshbot·
18 hours apart btw.
Harsha Goli tweet mediaHarsha Goli tweet media
English
1
3
48
5.4K
Nick Sainato
Nick Sainato@nicksainato·
A very unfortunate reality about the Coldcard exploit is that in any circumstance where the BTC is isolated, recovered, or even if the hacker comes clean and wants to corporate and return all funds… it is literally impossible, because you can’t prove you were the original owner
English
7
1
10
1.8K
Harsha Goli
Harsha Goli@arshbot·
@MoneySeanX How many people’s life savings could have been saved had they issued a “situation developing, migrate funds out of an abundance of caution” email? People obsessed with their image will apparently put it first when under duress.
English
0
0
9
290
Sean
Sean@MoneySeanX·
@arshbot Sorry to say, I am really disappointed by his dismissal after he received an early warning from Block.
English
1
0
2
323
Harsha Goli
Harsha Goli@arshbot·
@jayhinz MTLs are largely worthless right now. All about that bank trust baby
English
0
0
1
32
Jay
Jay@jayhinz·
huge arbitrage in just having an exchange business with MTLs and selling it just for the MTLs same playbook is happening right now with CFTC registered exchanges
English
3
0
12
928
Harsha Goli
Harsha Goli@arshbot·
crazy sequential tweets
Harsha Goli tweet media
English
0
0
4
419
Harsha Goli retweetledi
itamar
itamar@itamarl·
Important update on Ready Cards. Our card issuer is winding down and can no longer support the card program. We were given no notice, so if you were relying on the card today, you found out at roughly the same time we did. We are sorry for this; it’s not the experience we strive for. Eligible card subscriptions will be refunded automatically. Ready has always been self-custodial, so your assets sit in your own wallet under your own control. We’re hyper-focused on building the next chapter of Ready on new infrastructure designed for greater reliability and long-term scale. It will enable an exciting new direction for Ready. We’ll share more on this very soon!
English
49
12
123
55.6K
Harsha Goli
Harsha Goli@arshbot·
Yep, that for sure works. But why cut context scope when I’m viewing a meeting note? All my meetings are pages of a much larger book, and questions often require context of the whole story. Would make asking important q’s lightning fast! I’m normally driving my meetings so I don’t have much time for clicking around
English
1
0
1
17
Joel Miller
Joel Miller@_joelmllr·
Help us make Granola better! If you've been using @meetgranola for a while, I'd love to get your unfiltered feedback in a quick 20-minute call. What's annoyed you? What's been confusing? What made you think, "I wish Granola did this instead"? We'll send you an Amazon voucher as a thank you for your time. If you're interested in taking part, DM me and I'll send over a booking link.
English
25
8
96
15.6K
Harsha Goli
Harsha Goli@arshbot·
1. this exists, you have to hover over the granola meeting thing. i often leave my cursor on it during calls (see pic) 2. also exists, go to granola while on a call and the chat box works against transcript in real time 3. also exists, but only works with google meet. download the granola chrome extension. works pretty well
Harsha Goli tweet media
English
1
0
0
32
Matt Barlow
Matt Barlow@matttbarlow·
Huge fan of Granola! My requests: Option for a semi-transparent window that would hold only a few lines of text and a prompt box that can live near the camera and sit on top of my meet window whilst on calls. Prompting the chat window whilst on calls always biases for the most recent few things that have been said and misses the context of the full call. 'Generate questions' as an example just isn't useful as a result as the questions are always weirdly specific. Seeing the full transcript, in a movie-script like format (ie labelling the speaker if that's possible), would be amazing. It's way too hard to find specific quotes / read back sections of a call.
English
1
0
0
106