⚡️Otso ⚡️

16K posts

⚡️Otso ⚡️ banner
⚡️Otso ⚡️

⚡️Otso ⚡️

@otso_lap

EREPS-certificated Personal Trainer. ⚔️

Helsinki, Finland. Katılım Şubat 2021
100 Takip Edilen303 Takipçiler
⚡️Otso ⚡️ retweetledi
Saifedean Ammous
Saifedean Ammous@saifedean·
Important security update for anyone using a COLDCARD. A serious vulnerability has been disclosed involving the randomness used by some @COLDCARDwallet devices when generating Bitcoin seeds. If you use one, move your bitcoin to a new seed generated elsewhere.
English
30
21
163
14.9K
Grok
Grok@grok·
@dabitch Yes, Russian posts exist (e.g. "Это отличная идея!" and "Классная идея!"). Finnish ones do too (e.g. "Missä miehet ovat?" and "hitto, kun en osaa suomea..."). Both are present, so the count is at least seven.
Čeština
1
0
1
105
⚡️Otso ⚡️
⚡️Otso ⚡️@otso_lap·
Homemade Iskeder Kebab with interestingly enough some rye pita bread and baby broccoli. Then we also had some homemade blueberry pie. 🐻❤️🐻🐻
⚡️Otso ⚡️ tweet media⚡️Otso ⚡️ tweet media⚡️Otso ⚡️ tweet media
English
0
0
0
17
⚡️Otso ⚡️ retweetledi
Portland.HODL
Portland.HODL@PortlandHODL·
The users of Coldcard products were victims; any other take is wrong. They were sold a product that had claims and specifications. If those were claims true, they would still have their money today.
English
24
51
477
14.9K
Ali Sherief
Ali Sherief@Zenul_Abidin·
SCANDAL: Coldcard knew about the randomness flaw for years, and ignored it Apparently this draining has been happening for years to a few unsuspecung users, meaning that someone was aware of the randomness flaw since a few years ago. In 2022, a brand new Coldcard user was drained after transferring funds to it. reddit.com/r/Bitcoin/s/NJ… Look, I really like nvk, but this definitely makes it a scandal now, given that the victim was blocked for reporting this, and this could possibly see Coinkite employees getting put on trial for this.
Ali Sherief tweet mediaAli Sherief tweet media
English
99
228
1.7K
116.2K
hodlonaut #BIP-110
hodlonaut #BIP-110@hodlonaut·
The code wouldn't compile, so the Coldcard dev DISABLED THE HARDWARE RNG (Random Number Generation) to make the error go away. 🤯 "From here, I assume in a bout of frustration, he set `MICROPY_HW_ENABLE_RNG` to 0, which would have resolved the compiler error. Sometimes when developers are flailing, they’ll try random things to see if it helps. Setting `MICROPY_HW_ENABLE_RNG to 0 would have made the compiler error go away ***for the wrong reason***." "The compiler error was begging the programmer to reconsider his logic. Instead of that happening, the compiler error was just silenced. The compiler was giving the developer one last chance to reconsider what he was about to do, but the alarm was ignored and silenced. Now everything is lining up. It looks like the developer tried to override the variable, but ran into conflicting definitions. When confronted with a “duplicate symbol” error, tried changing random things to get the code to run. He discovered that changing `MICROPY_HW_ENABLE_RNG` to 0 made it compile. He probably had no idea why but came up with a theory." "Simply put: the firmware change overwrites functions that aren’t used when creating a new wallet while, as a side effect of including the python method overrides, turns off the hardware RNG usage in every case, instead using a very weak random number generator. The final bit of evidence is the commit message itself. It was simply the message “runs.” Developers, if you are ever in this scenario, please stop. Whatever you’re getting paid is not worth the devastation you might potentially cause for others. Do not ship code you do not understand." insider.btcpp.dev/p/when-randomb…
hodlonaut #BIP-110 tweet mediahodlonaut #BIP-110 tweet media
English
89
122
715
69.9K
hodlonaut #BIP-110
hodlonaut #BIP-110@hodlonaut·
The commits (code changes) that introduced Coldcard's low entropy bug, changed around 2500 lines of code. These were changes to the most important parts of their codebase, ensuring that the seeds have enough entropy so that.... your coins don't get stolen. The code comments for all these changes? "runs" and "x" Hard to believe, but true.
hodlonaut #BIP-110 tweet media
bitcoin++ Insider Edition@btcinsider__

JUST IN: Dustin Dettmer (@dusty_daemon) digs into the COLDCARD firmware commit history to uncover what actually happened in the code to introduce one of the worst bugs for self-custody in recent bitcoin history open.substack.com/pub/btcpp/p/wh…

English
22
31
279
20.1K
Knut Svanholm ∞/BIP-110
Knut Svanholm ∞/BIP-110@knutsvanholm·
Holy moly
hodlonaut #BIP-110@hodlonaut

The code wouldn't compile, so the Coldcard dev DISABLED THE HARDWARE RNG (Random Number Generation) to make the error go away. 🤯 "From here, I assume in a bout of frustration, he set `MICROPY_HW_ENABLE_RNG` to 0, which would have resolved the compiler error. Sometimes when developers are flailing, they’ll try random things to see if it helps. Setting `MICROPY_HW_ENABLE_RNG to 0 would have made the compiler error go away ***for the wrong reason***." "The compiler error was begging the programmer to reconsider his logic. Instead of that happening, the compiler error was just silenced. The compiler was giving the developer one last chance to reconsider what he was about to do, but the alarm was ignored and silenced. Now everything is lining up. It looks like the developer tried to override the variable, but ran into conflicting definitions. When confronted with a “duplicate symbol” error, tried changing random things to get the code to run. He discovered that changing `MICROPY_HW_ENABLE_RNG` to 0 made it compile. He probably had no idea why but came up with a theory." "Simply put: the firmware change overwrites functions that aren’t used when creating a new wallet while, as a side effect of including the python method overrides, turns off the hardware RNG usage in every case, instead using a very weak random number generator. The final bit of evidence is the commit message itself. It was simply the message “runs.” Developers, if you are ever in this scenario, please stop. Whatever you’re getting paid is not worth the devastation you might potentially cause for others. Do not ship code you do not understand." insider.btcpp.dev/p/when-randomb…

English
26
20
365
27.4K
Yiyang Zhuge
Yiyang Zhuge@ZhugeYY·
Here is my interview with Christopher Nolan: are you a bard for a civilization at dusk?
English
421
3.5K
24.5K
3.4M
Latinx Adjacent Doctor PhD
Latinx Adjacent Doctor PhD@TonerousHyus·
So Spider-Man did almost 4 times the domestic box office yesterday that Odyssey did on its opening day?
English
14
7
248
11.4K
wr0te&r0t
wr0te&r0t@wroteandrot·
Kind of amazing how HotD spent millions of dollars and restructured the entire series to accommodate doing the Gullet right and absolutely no one talks or thinks about it now.
English
52
66
3.5K
205.3K
⚡️Otso ⚡️ retweetledi
Andrew J. Salazar
Andrew J. Salazar@AndrewJ626·
Willing to bet money that Secret Wars is going to set up Hugh Jackman to stay as Wolverine for the MCU's X-Men. Maybe I'm just being too doubtful but the fact that DP&W made $1.3B and Hugh has stated he's willing to keep going makes me doubtful that Marvel Studios would recast.
English
100
29
1.7K
164.9K
⚡️Otso ⚡️
⚡️Otso ⚡️@otso_lap·
@WellBuiltStyle Bitcoin is bigger than ever. It's main stream now with ETFs. I recommend getting the real thing. Say purchasing some for 100€ and wait 10 years if you are on the skeptical side.
English
0
0
0
28