Avatar
₿logging₿itcoin
75bf23531ae9f98c62995ba07191e488ead475975371d63d7dfd46bde1bfa895
₿itcoin geek who writes a ₿log about bitcoin and other freedom tech on the nostr. My mission is to promote bitcoin as a store of value, medium of exchange, and unit of account. https://nostree.me/bloggingbitcoin@iris.to Get notified of new blogs on [Keet](nosl.ink/TgS14vtN)

Running a node is easy these days and fiat can be instantly converted to SATs. There are no excuses anymore.

Congratulations an being awsome everyone. 🫶

Replying to Avatar hodlbod

**Security Update**

I've got some bad news for you guys. This morning, as I was adding error handling to flotilla, I discovered that Coracle has been sending user session objects to bugsnag when reporting errors.

Who is affected: Users who triggered an error in Coracle while signed in with their private key, since December 5th 2023.

What I've done:

- I immediately released a new version of Coracle, both to web and to zap.store

- I have deleted the affected apks from my releases

- I have deleted all my error data from bugsnag

- I have deleted my bugsnag project and rotated my api key, so lingering error reports will be dropped

- I have audited my code for use of the session object to ensure nothing else like this is happening

What you should do:

- If you're logged in with your private key, log out

- Hard refresh the page to ensure you have the latest version of Coracle

The bottom line is that if you signed in to Coracle with your private key, it has been shared with me and with bugsnag. In practical terms, your keys should still be secure, since they were sent over TLS, and have been deleted. But there is no guarantee I can offer that they are in fact gone.

I take my users' privacy seriously. My error reporting implementation doesn't record user IPs, it redacts identifying data, and it allows users to opt-out. I also warn the user when they attempt to enter an nsec into a text field. In this case, I simply screwed up, and I sincerely apologize. Reply to this note if you have any questions.

I used alby, but Is there a way to check if my key was compromised with my npub?

I accidently forgot I had $3,000 cuck

bucks in a bank account since July. I"m so pissed off at myself. 😡😡😡

Not so long ago, I thought $600 was a lot of money.

It is, but SpotTube shows how much artists would get paid.

Fedimints and Cashu are more akin to free banking.

Bailed out banks can GFY.

I've officially stopped using the Spotify app.

Can Keet run on meshtastic? #asknostr

If your block clock could only display one number, what would it be if it could not be the price?

I don't need or want to know what Satoshi's mom called him.

This was a great episode. I really enjoyed the stuff about misinformation as being a cyber atrack against "democratic institutions."

Yuval Noah Harari made this exact argument on The Waking Up Podcast. He thinks we need to fight misinformation and disinformation with FICTION to protect our institutions.

I used to think monero was better than bitcoin for privacy, but now I know monero is not necessary.

We can achieve privacy using chaumian e-cash instead of a blockchain. What's more, these e-cash solutions are interoperable with the lightning network.

The steel-man argument against this is that chaumian mints require some trust.

This is true, but Bitcoin is a peer to peer electronic cash system that requires no trust. We can trutnthst there will never be more than 21 million #bitcoin. Every other blockchain is an attempted breach of that trust, an attempt at debasing bitcoin the same way governments have debased gold by adding other metal to it.

That's my two sats.

I would rather trust a few thousand sats with an e cash provider than try to debase the p2p electronic cash system that bitcoin is.

I think it's the incintives. The people who pay the politicians get paid to sell bombs psychopaths sign, but the ROI of saving people in a disaster = 0%.

It's sad, but destroyers make money. Heros lose money.

By the way, what's the d word?