Avatar
Dr. Hax
d30ea98ea65e953f91ab93f6b30ea51eb33c506f87d49f600a139aef00aa9511
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu

Stay humble, folks.

I love the idea of the #lightning network, but it's super unreliable outside of trivial amounts of money. And worse, the error messages when it fails are incomprehensible.

For example, I just tried to buy a gift card from bitrefill with nostr:nprofile1qqsrf5h4ya83jk8u6t9jgc76h6kalz3plp9vusjpm2ygqgalqhxgp9gpz4mhxue69uhk2er9dchxummnw3ezumrpdejqzyrhwden5te0dehhxarj9ekxzmnyqyt8wumn8ghj7un9d3shjtnwdaehgu3wvfskueq555fk2 and was told I didn't have enough local funds. The balance is Zeus is larger than the amount I'm trying to send, so that seems like a terrible error message.

The amount is more than I have in any single channel, but that's why I have multiple channels and even a multi-path payment fails with that same error. If I need a bigger channel, 🙄 fine. Tell me that. And tell me how I can increase the size of an existing channel with Olympus.

Here's my point: If I have the #sats, in self-custody in lightning, I should be able to send as many of them as I want. In the event it does fail, I should be presented with an error message that clearly explains why.

This doesn't seem like it is too much to ask.

And, yes, I plan on setting up an always-online lightning node soon enough so I can complain about more lightning software failures, or sing their praises, whichever is appropriate.

Those people are just hanging onto it until the new people arrive. 🫶

Impressive. I look forward to following your work even though I don't have a miner.

I don't totally get the epochs and things like what happens if the pool doesn't find a block in two epochs? Do all the old ehash tokens then become worthless? Or do you swap tokens from the old epoch to the new one (and lose your value if you fail to do so)?

I feel like some kind of diagram of that life cycle would be helpful in explaining how it works so plebs can understand where the risks are and whether there's anything they can do to mitigate them.

My hushcon talk just got a whole lot better 🤘

I don't get how trying to finding the next BTC block is connected to getting cashu tokens.

Is the idea that you'd be using a pool and instead of the pool paying out on chain, or over lightning, that they'd issue you cashu tokens instead?

As both a #security #researcher and #OpenSource advocate, I say forget the secure element.

I'm not sure exactly how cashu fits in here, but if it's just a matter of storing the tokens you get from the eCash server: require a PGP pubkey and encrypt the tokens with that. Simple, effective, and easy to audit.

Or ECC encryption, if you prefer that. https://cryptobook.nakov.com/asymmetric-key-ciphers/ecc-encryption-decryption

Replying to Avatar Dr. Hax

In contrast, Trezor puts their money where their mouth is! https://github.com/trezor/trezor-hardware

And they even use open source software (KiCAD) to design their open source software! ❤️

So this fear, that if a design is published that they'll be undercut by a cheap knock off... it just doesn't stand up to real world evidence.

nostr:nevent1qqs2apsmlfyjhhaa3mx8t75txkmsphejdqg35536z4wt590uwcl765gppemhxue69uhkummn9ekx7mp0qgsdxr4f36n9a9fljx4e8a4np6j3aveu2phc04ylvq9p8xh0qz4f2ygrqsqqqqqpfl6ldv

Then again, Trezor doesn't have huge profits to pay podcasters to advertise their gear, so maybe they are the foolish ones after all? 🤷‍♂️

Replying to Avatar Dr. Hax

Fun fact: nostr:nprofile1qqs9500z3l7sn46sdnls5fnjm0d3lqmrq7707qshes2y7j8pnm4rllcpz4mhxue69uhhyetvv9ujumn0wd68ytnzvuhslmwjtd devices are not #OpenSource #hardware.

With enough public pressure, there's at least small chance they might change this and publish the source files for their #electronics.

They're close. They have open source firmware and software. They just have to publish the electronics CAD file (KiCAD, or something like Eagle CAD if they're using closed source software).

https://www.oshwa.org/faq/#files-to-share

And before someone jumps in to defend them. Yes, I get it. They're trying to make a profit and don't want to have to compete with other manufacturers. They don't want anyone building on their work except themselves. But I think there's more potential if they crossed the finish line here. They are the trusted brand for this product. They are the innovators. They will keep making improvements and could even collect some from the community if so inclined.

I just want to bring some honesty into the marketplace. People have every right to choose to buy closed source products. But they should not be duped into buying something they think is open source only to find out later that the marketing is only half true.

In contrast, Trezor puts their money where their mouth is! https://github.com/trezor/trezor-hardware

And they even use open source software (KiCAD) to design their open source software! ❤️

So this fear, that if a design is published that they'll be undercut by a cheap knock off... it just doesn't stand up to real world evidence.

nostr:nevent1qqs2apsmlfyjhhaa3mx8t75txkmsphejdqg35536z4wt590uwcl765gppemhxue69uhkummn9ekx7mp0qgsdxr4f36n9a9fljx4e8a4np6j3aveu2phc04ylvq9p8xh0qz4f2ygrqsqqqqqpfl6ldv

Fun fact: nostr:nprofile1qqs9500z3l7sn46sdnls5fnjm0d3lqmrq7707qshes2y7j8pnm4rllcpz4mhxue69uhhyetvv9ujumn0wd68ytnzvuhslmwjtd devices are not #OpenSource #hardware.

With enough public pressure, there's at least small chance they might change this and publish the source files for their #electronics.

They're close. They have open source firmware and software. They just have to publish the electronics CAD file (KiCAD, or something like Eagle CAD if they're using closed source software).

https://www.oshwa.org/faq/#files-to-share

And before someone jumps in to defend them. Yes, I get it. They're trying to make a profit and don't want to have to compete with other manufacturers. They don't want anyone building on their work except themselves. But I think there's more potential if they crossed the finish line here. They are the trusted brand for this product. They are the innovators. They will keep making improvements and could even collect some from the community if so inclined.

I just want to bring some honesty into the marketplace. People have every right to choose to buy closed source products. But they should not be duped into buying something they think is open source only to find out later that the marketing is only half true.

In RSA, you can only encrypt an handful of bytes with the public key. I think the limit is 512 bytes for a 4096-bit RSA key. So what RSA encrypts is a symmetric key (e.g. AES-256), which is what encrypts your data.

My memory on ECC hasn't been burned into my brain as heavily, but I recall it being basically the same overall process, of encrypting a symmetric key, not the message.

A quick search shows that the encryption key and decryption key are the same, which confirms it's symmetric (by definition). https://cryptobook.nakov.com/asymmetric-key-ciphers/ecc-encryption-decryption

All thr ECC algorithms (ed25519, secp, etc) are going to be basically the same. It's just the curve that is changing.

Good luck with whatever you're working on.

Director: OK, for this scene you are goimg to grab your ass, and sqeeze your cheeks to mimick you ass crack as a mouth. The butt is its own character, and your gave is going to play good cop as you try to get answers.

If you are a gen Xer, you probably know this movie.

That threaded hexagonal piece is truely throwing me for a loop, but the grill makes me think fan, and the other pieces are whispering tubing. I'm going to say a drying machine for the tube of a CPAP machine.

- Privacy

- Emergency preparedness

- Open source hardware/software

- Sustainability

- Direct action being taken now by people

I'm sure I can think of more, but that's a pretty good start.

Not having regular employment has challenges most people never considered.

A simple example:

People with full time employment typically gets up every weekday on their employer's schedule, works on things that benefit their employer, comes home and probably have some routine including chores/exercise/relaxation.

Contrast that with someone who doesn't have regular employment. They have to decide: Will I work on something that directly benefits me today? Will I do something for society in order to earn money? Maybe do some chores? Exercise? Charity work? Or take the day off?

Weekends provide a small glimpse of what those without regular employment face daily, except without seriously considering projects that would take a week of long hours for a week straight.

If you don't have a day job, how do you balance these things from one day to the next?

In case anyone thinks the Republicans are going to reign in spending on proxy wars, they're not. Not a single one. Not even just for offensive weapons.

https://theintercept.com/2024/11/20/bernie-sanders-block-weapons-arms-israel-gaza/

The majority of the Democrats fall into the same boat.