Avatar
Foxfire Mushrooms
7bc70ce80a898cc4b3e17d0992fa17264df188e1c806b60ed54424e8b41f5686
Gourmet mushroom and cultivation supply company.

I’m no expert but I’m going to get a VPN running on my computer, download Sparrow wallet which allows you to do coin joins, and do a coin join transaction from there to the Cold Card. I’ll let you know what I learn.

No, multisig can be done on Ledger as well. But it sketched me out when Ledger put out their firmware upgrade allowing you to opt in to a custodial seed phrase recovery service, meaning technically they could theoretically extract your seed phrase from the device. Then I listened to a podcast with NVK, one of the founders of Coinkite (you can follow him on here), learned more about the trust associated with hardware wallets, and decided I wanted the most hardcore thing possible to protect my keys. I’ll still be using the Ledger as an intermediary wallet, just don’t want to keep all my savings on there. The podcast I listened to was on Natalie Brunell’s Coin Stories podcast btw.

Yep. Really don’t understand what’s up with all these Trumpy bitcoiners.

Donald Trump on Squawk Box: “There has been a lot of use of that, and I’m not sure that I’d want to take it away at this point.”

Glad he’s “not sure” he wants to “take it away” from us. Hopefully he doesn’t change his mind on a whim.

#GrapheneOS: We're continuing work on integrating ARMv9 security features. MTE is the highest impact and most interesting of these features, but there's less important work to do expanding usage of PAC and BTI. Android uses Clang's type-based CFI but not everywhere so BTI is still useful.

Pixel 8 was the first device with a usable MTE implementation despite it launching as part of ARMv8.5. Android world stayed on ARMv8.2 until ARMv9 and Apple hasn't shipped MTE. Apple was a much earlier adopter of the much less useful PAC. From our perspective, PAC was a misstep.

PAC is a weak probabilistic mitigation requiring lots of case-by-case integration. MTE can provide many deterministic guarantees and does a much better job as a probabilistic mitigation by catching memory corruption rather than only protecting specific memory corruption targets.

PAC requires bits which would have been better served by 16-bit MTE support and using a 48-bit address space. Hardware shadow stack is a better backwards edge CFI approach. MTE could be used to mimic hardware shadow stack support via a reserved tag for ShadowCallStack.

We're currently the first platform using userspace heap MTE for hardening in production. We plan to do the same with userspace stack MTE along with doing both in the kernel. Turning ShadowCallStack in the kernel into a hardware protected shadow stack would also be nice to ship.

In the kernel, Pixel OS uses PAC for backwards edge CFI and Clang type-based CFI for forward-edge. We use ShadowCallStack + PAC together and enable BTI in addition to type-based CFI due to lots of functions being excluded from type-based CFI. We plan to do the same in userspace.

I’d really like to get into using GrapheneOS instead of Apple but it seems like a big leap for me as someone who knows nothing about it

Advice on getting started with multisig? Coldcard + Tapsigner + Nunchuk?

#bitcoin #multisig #hardwarewallets #coldstorage