Any company guarding access to any large sums of money (or even small sums) should consider how people will get social engineered their way out of those funds. Encryption alone probably won’t save them.

Reply to this note

Please Login to reply.

Discussion

Yes, was saying as well about the coinos thing is how easy it would be to steal many people’s nsecs and gain access to these accounts, I could do it if I was that kind of person.

Yeah and with vibe coding anyone can do it

Exactly! I could do this so fast and most people have a primal or coinos.

Do you mean social engineering or actual security holes? Or do you mean Coinos could steal nsecs?

Yes, however you can only go so far before it becomes a nuisance.

Wouldn't be the first time I get my bank account blocked for transfering fiat to some random bank account while trying to stack some sats using robosats. I used to get super angry at them and i still wish they had an opt-out for it, but i have come to understand that most people are easily fooled. Heck even i get emails that give me a jump scare at first and then when i read properly i find out that it's phishing.

You definitely need to inform the user that:

- We will never ask you about your

- We store this information about you

- Our communication always comes from

Maybe something about general best practices about not reusing passwords etc.

100%

As Eric Hughes said back in 1996, code alone doesn’t cut it.

“Perhaps the single most important lesson I've learned from cypherpunks

1s that code alone doesn't cut it.

Not code alone, not code widely

distributed.notevencodewidelyused

Somemeasureoftoleratton1n society for activities conducted in private is _necessary for long

term success.

Not convenient, not easier,

but necessary.”