Replying to Avatar Braydon Fuller

I remember working on bitcoin libraries for multisig hardware wallets and thinking to myself, all that security is kinda moot when all it takes is *one* dependency from NPM to be compromised and every one of the signers, using identical software, signs the wrong thing. We ended up with zero third-party libraries and we checked the signatures of every package, with Git, when updating. Stay frosty.

Avatar
Abstract Equilibrium 10mo ago

Having a multisig quorum with 1 vendor of signers, is like choosing a password, choosing your mothers maiden name...and calling it MFA.

nostr:nevent1qqswma8a4ah605k9e53evjv6p53j3950wlwh8tfahn0dwgrhng43xlcpzemhxue69uhhyetvv9ujumt0wd68ytnsw43z7q3qr0ulywwu593kzjdu9uluxdq80t54n65kql9vl9z7lrutkgnachssxpqqqqqqzyd2avz

Reply to this note

Please Login to reply.

Discussion

No replies yet.