Avatar
bitcoinranger
3d19329302e9ee2a2f68b71ba6a2ff9c64552bec9be923256be175417a77ff68
#bitcoin 🧡 #nostr 💜

Most people aren’t too lazy to use Lightning - they’re just fed a false narrative.

The idea that self-custodial Lightning wallets are ‘too hard’ is outdated at best, FUD at worst pushed by custodial wallets and their promoters who benefit from user lock-in.

You can set up nostr:npub1xnf02f60r9v0e5kty33a404dm79zr7z2eepyrk5gsq3m7pwvsz2sazlpr5 or Phoenix wallets in a few easy steps! Do your own homework and don’t fall for custodial traps!

Replying to Avatar Blockstream

The latest release of the cln-application is live!

This update introduces the Bookkeeper UI, making it easier to understand, track, and audit node activity in real-time.

https://blossom.primal.net/cc256110efdc5c6110217ba51f277629cb8bac54c14cbbce8e56f2eb624a7e76.mp4

---

The new visual dashboard lets you explore:

🗓️ Account Events

🏞️ Sats Flow

📈 Channel Volume

It's a big step toward simplifying Lightning node management for both devs and operators.

---

Also in this release:

🧑‍💻 A SQL Terminal to query your node directly

💻 UI support for `clnrest` and `cln-grpc`

Special thanks to Michael Evans for the Bookkeeper UI.

---

Try out the latest CLN App with Bookkeeper dashboards, SQL terminal, and more.

Download and run it here. ⬇️

https://github.com/ElementsProject/cln-application/pkgs/container/cln-application/426141765?tag=0.0.7

Noice

#nostr won’t go mainstream until it stops feeling like a tool for devs and starts working like a tool for humans. Simplicity is the 🔑

Noobs won’t touch it.

Key management is already hard, throwing FROST into the mix without clean abstraction is UX suicide.

Thresholds? Coordination? Lost shares?

Without solid recovery, you’re one mistake away from a brick 🚩

With today’s tools, there’s no reason not to take control of your funds with a self-custodial Lightning wallets! Zero excuses!

Yolod fat channel on Phoenix and never had any closures. It’s been for a long time. The routing fees are what we pay for the self custody which is fair !

When key management? It’s sad that the biggest security issue on this platform continues to be ignored. Odds are many accounts are already compromised, and users just don’t know it yet. The longer developers dismiss this, the more damage it will cause and eventually, it’s going to drive people away. Tick tock 🍿

When #nostr key management?!

We're still investigating what happened here. It seems a handful of accounts may have been compromised and had their autowithdrawal settings tampered with, including our own "coinos@coinos.io" account.

We ran a script to search for accounts that had the attacker's "speed.app" withdrawal address in place and found about 9 that seem to have been affected. There could be more though, we will update as we have more information.

I worry that this may be the same attacker who exploited a password reset vulnerability back in January which allowed them to gain access to a number of accounts. It's possible that since that time they have been sitting on the account data and working to brute force the encrypted nostr private keys that we had on file for some accounts that had imported their nostr key into Coinos. Those keys were encrypted at rest in our database but it's possible they may have been cracked.

We no longer store nostr private keys for accounts and have since added support for external signing apps and browser extension login, but there was a time when we were storing encrypted nsec private keys.

Having a users nsec would allow an attacker to authenticate into Coinos by signing a nostr event and change the user settings. It also means your entire nostr profile and identity may be compromised.

This is only a hypothesis at this point and we need to investigate further but we may end up recommending that affected users rotate their nostr keys.

nostr:nevent1qvzqqqqqqypzpggzvz325tcf9kz79s9c9627430ccc82r8rgujycwxd43n92y037qy88wumn8ghj7mn0wvhxcmmv9uq32amnwvaz7tmjv4kxz7fwv3sk6atn9e5k7tcqyrdx8njpnvvulfcsqqd7ud47uw6dnzl4a3fmsrafsp0rte9f29h5uxpgg73

Ooof!

Trying to hook up Phoenix wallet on #nostr can someone try to #zap me one sat ? Thanks

Imagine how retard this guy!

Running #Yakihonne