light 📜

49.3K posts

light 📜 banner
light 📜

light 📜

@lightcoin

p2p electronic cash enthusiast || 🏴🦔 @light__nh || ☿ he/they

Katılım Şubat 2013
320 Takip Edilen14.2K Takipçiler
light 📜
light 📜@lightcoin·
@AriDavidPaul > transparency for consumers to compare with. ... in an easy to consume way, anyways. you/your clanker have to dig through docs and repos to find most of this info, if it is even publicly available. that doesn't suggest impossibility, but i will concede there is difficulty.
English
0
0
0
19
light 📜
light 📜@lightcoin·
@AriDavidPaul knowing which dependencies are not only tolerable to be shared but actually encouraged to be shared is probably as important as knowing what should be diversified. what's true is that there is no widely agreed upon standard for this, or transparency for consumers to compare with.
English
1
0
1
21
Ari Paul
Ari Paul@AriDavidPaul·
The coldcard compromise is being somewhat shrugged off, correctly, since it revealed nothing new. But what it reminded us of is that there is simply no way to secure crypto. If you custody it with Coinbase or another custodian, they’re frequently hacked and you get no compensation. Custody it yourself, perfectly, and you may lose it to coldcard-like compromises. Same vulnerabilities apply to every hardware wallet and custody company (who all have to make use of possibly compromised hardware and software.) The sad reality is that the legal system remains a far more reliable safeguard of financial assets than cryptography today in most of the developed world. I wish that wasn’t true, but it is. For someone in 70% of the world with a less trustworthy rule of law, crypto may be more secure.
Jonathan Goodman 🇨🇦@itscoachgoodman

$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack. My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet. This part's nerdy, but here's what happened: Hackers discovered a vulnerability in the part of the hardware wallet code used to create seed phrases. This allowed them to use AI to brute force guessing seed phrases. I was at our cottage and heard about the hack today. "No way this affects me." I thought. I logged into Wasabi––software that lets me view my bitcoin wallets online. Right away I saw lines of red transaction–withdrawals–and I knew. From 9:36pm - 9:43pm on July 29th, every wallet I had had been emptied. 18.25245043 btc gone. That's just over $1.6 million dollars CAD. Perhaps the hardest part about this is that I did everything right. I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability. I'm filing a police report and a report with the Ontario Securities Commission. But I don't expect to recoup anything. A part of me is trying to make sense of what just happened. Or try to figure out a lesson in it. I'm struggling. $1.6 million is a staggering amount of money to have stolen. I guess all that I can think about right now is that I'm so damn happy that I'm an entrepreneur and that my earning potential is under my control. Mark my damn words. I'll recover.

English
99
29
365
211.3K
light 📜
light 📜@lightcoin·
@nosecondbestbtc @_julian256_ the point of multisig is to eliminate single points of failure. if you're relying on having n of n seeds then you've missed the point.
English
0
0
1
15
NoSecondBest
NoSecondBest@nosecondbestbtc·
@_julian256_ If you have the seed you have the xpubs. It's not a separate item. Full wallet descriptor is important. A password protected Sparrow wallet file is one way to take care of that, and Sparrow lets you export the descriptor as a pdf too.
English
1
0
0
84
Julian 📜
Julian 📜@_julian256_·
if you are setting up a new wallet with a multi sig please understand this you need to back up not only the seed phrases but also the full wallet descriptor especially make sure you have all your xpubs (one per seed)
English
20
29
142
13.5K
Justin
Justin@m1sterc001guy·
Is there an onchain watchtower project? I know everyone wants covenants but we can get pretty close to having vault-like functionality by just having one technical local community member run a watch tower.
English
2
1
4
288
light 📜
light 📜@lightcoin·
@AriDavidPaul what specific common points of failure ("same root dependencies") you are referring to, and what hw signers do they apply to? github doesn't count (if you're treating github as a ttp, you're doing it wrong).
English
1
0
0
48
Ari Paul
Ari Paul@AriDavidPaul·
“Heterogenous hw/sw” isn’t a real thing. We keep learning about how so many companies have the same root dependencies on hw/sw that even their senior engineers didn’t know about. On the software side, it’s GitHub and library dependencies. On the HW side - most chips go through one of 2 doors in the world at many separate stages. We’ve found hardware backdoors in everything from bitmain mining chips to DoD servers.
English
1
0
1
67
light 📜
light 📜@lightcoin·
@AriDavidPaul > A 100 IQ rando I presume OP is not a 100 IQ rando > still susceptible to RNG unlikely for a quorum of devices if heterogeneous hw/sw is used as I described > you’re trusting a third party collaborative custodians are trust-minimized - they cannot steal or freeze your funds
English
1
0
0
82
Ari Paul
Ari Paul@AriDavidPaul·
I think for the average person in the world, I’d advise against that. A 100 IQ rando trying to do geographically distributed multisig is likely to either get scammed, mess something up, or even so, they’re still susceptible to RNG and some hardware and software vulnerabilities. Maybe a service like Casa to do this for you, but then you’re trusting a third party on top of the underlying risks.
English
1
0
2
210
light 📜
light 📜@lightcoin·
@oldmanmawn @KLoaec it is still usable, make sure to update to latest firmware and add a strong passphrase and/or use 100 dice rolls to generate your own entropy for extra security.
English
2
0
4
331
Old Man Mawn
Old Man Mawn@oldmanmawn·
@KLoaec I literally just opened this POS. I even had to pay another $60 for customs. I hadn't even set it up yet.
Old Man Mawn tweet media
English
12
0
28
10.9K
Tay 💖
Tay 💖@tayvano_·
@lightcoin @diopter_ring Yes, this is correct. Most of the entropy issues do occur at the seed level these days too. Bc the seed is what’s being generated. There are rare exceptions, like when some retard manages to fuck up signing to reveal the underlying, individual private keys.
English
1
0
0
122
light 📜
light 📜@lightcoin·
@brian_trollz should this list in your post be updated? > Coldcard MK3, MK4, MK5 and Q are being drained.
English
1
0
2
183
Bitcoin Isn't About You
Bitcoin Isn't About You@brian_trollz·
@lightcoin Yes they are. Any device used to generate a seed without dice rolls after March 2021 is vulnerable.
English
2
0
2
376
light 📜
light 📜@lightcoin·
@diopter_ring the lost and found is premised on the attacker not knowing the seed phrase if the attacker knows the seed phrase, then they could just take the funds from the lost and found before the rightful owner
English
1
0
2
46
DxM
DxM@diopter_ring·
@lightcoin thats not quite right lost and found still works if the seed is intact the coldcard issue is about extraction during use, not the seed itself
English
1
0
0
54
light 📜
light 📜@lightcoin·
@ProofOfMoney > look into multi-sig specifically, multisig with a quorum of hardware signers from different vendors (multisig with a quorum of vulnerable coldkites is still cooked)
English
0
0
1
426
Terence Michael
Terence Michael@ProofOfMoney·
Check out these two Bitcoin seed phrases: (a general lesson in entropy) SEED A: ocean tiger silver dance pigeon melody crystal rocket amber jungle violin sunset. Now check out this one: SEED B: garden mirror silent canyon river melody crystal rocket amber jungle violin sunset They both look random to me. But this is the issue that has unfortunately happened with the Coldcard wallet bug. It's random generator didn't give sufficient randomness. You can't tell the two phrases apart if you use the device to give you your words. You get them. You write them down. Stamp them in steel. Done. All proper 12-word BIP-39 seed phrases starts with 128 bits of high-quality randomness (entropy). And most devices have a TRNG (True Random Number Generator). If that TRNG is flawed or has a bug, the device doesn't produce the full 128 bits of real entropy (or 256 bits for a 24-word seed phrase). SEED A above was generated with 128 bits of entropy. SEED B, however, was generated with only 40 bits of entropy. Again, so what? Doesn't someone still have to guess those 12 words? With only 40 bits of entropy, a skilled attacker could download the entire possibilities of those seed words, which is about 1.1 trillion. Although large, that's small enough to run a program, extract every possibility, and begin taking funds from wallets with balances. This is the bug/attack that struck Coinkite with their Coldcark MK3 generated seeds (using firmware 4.0.1 and later). You cannot spot the problem just by looking at the words👀 SEED A above has the full 128 bit entropy, and thus gives 340 undecillion combinations. This number can't be brute forced with any computing power currently available to man. The fix? Roll your own words for true, full randomness you can see and verify. Add a passphrase (a 13th "word") to increase that randomness. And don't let those words touch the internet. But still... look into multi-sig. It really solves so many problems that we've had and continue to have.
Terence Michael tweet media
English
76
272
1.4K
120K