Avatar
Juraj
dab6c6065c439b9bafb0b0f1ff5a0c68273bce5c1959a4158ad6a70851f507b6
I don’t seek rigid structure — I seek resonance Learn how to use Bitcoin for more than just saving in my 📖Cryptocurrencies - Hack your way to a better life. Vibe coding, reality bending, cypherpunk visions. Get my books and courses here: https://hackyourself.io/shop https://juraj.bednar.io/shop (You'll learn skills no one else is teaching!) Podcasts 🎙️: Option Plus - https://optionplus.io/ Reči o živote, vesmíre a vôbec: https://juraj.bednar.io/reci-o-zivote/ Ako vyhackovať otcovstvo: https://otcovia.com/

Nope. Retarded people need simple.

I can use whatever design I want.

That's the beauty of bitcoin. You don't design anything for everyone. Everyone can use whatever design they want.

I'm saying this is a non existent problem. Basically any hw wallet will serve 80% of users and the 20% should not design their custody based on podcast ads anyway and will invest time to do it right, because it matters.

What I don't agree with is pushing normies into some hardcore multisig or airgap when a simple Trezor will do a much better job for them. They would for sure not audit transaction psbts, even if there was a tool for it. Whatever is currently out there is good enough.

Until you lose the unlock script.

No really. Multisig is a total overkill for most. It's more probably they lose money if they fuck up the multisig setup than whatever hack with literally any HW wallet they would use.

Podporte nostr:nprofile1qy0hwumn8ghj7cnfw33k76twd4shs6tdv9kxjum5wvhx7mnvd9hx2qguwaehxw309ak82mnrdp3x77pwwdskuerhd93kstnxv9ex6qpq8gh7tx4s28dt9t2hhvd6lrwhsmwg94gnxppkezzq0ucqgscav5ys5p882l na budúci rok!

https://pay.dvadsatjeden.org/

I use Firefox extensions

Replying to Avatar Cykros

Good to know about SD cards.

The problem of audits is knowing who to trust with the audits. And trusting anyone at all runs contrary to the don't trust, verify ethos.

If we trust the cable, what else gets trusted? Should we dispense with a screen, like Bitkey did?

I do want my airgapped system audited, to have the second set of eyes on it. But there's always the question of: who audits the auditor?

The matter of checking QR codes, and the difficulty of doing it manually, does make me wonder if there's room for a device that, also offline, can be used to take translate the QR to de-serialized format to make checking the full psbt an easier process. Probably a niche use case, especially given laziness and quickness to trust, but it could be useful for the truly paranoid.

As for the assumption that 'they can, but they won't' -- this is precisely the sort of presumption I see as common and take issue with. Some people will cut corners either way, but we should be letting them know explicitly they are doing so, rather than operating with rhetoric suggesting that they are using best practices when in actuality there is trust they are extending unwittingly. IF you are not going to verify everything, AND are willing to trust an auditor, it sounds like you're suggesting that you can achieve a better security model without an airgap than if you aren't going to verify everything and use an airgap. No complaint from me there, but those conditions should always be explicit. Users can choose to consent to risk taking, but when suggested to take risks they're not aware of, well, I have a hard time distinguishing that from being intentionally misled. I don't want to quite call it scamming, but it's adjacent especially when there is financial gain from selling these products that require the trust model.

Giving users the responsibility to make any kind of security decision is not a good deal. They should have the ability, but it won't help them much. I know maybe ten people who can do it well (there are maybe 1000-10000 that I don't know). Hiring them to audit everything is much better than relying on a common hodler to audit transactions.

That's why many hw wallet manufacturers contract several independent auditors. You don't need to check the auditors, you just need a few independent ones.

And then you can solve this systematically. If it's really a lot of money, a 3-of-5 multisig with different hw wallets is better than relying on placebo security.

Airgap is a marketing term.

Yeah, you are probably using it in a way that does not trigger the bug.

But since I don't know what triggers it, it is unlikely to help.

No advantage to Vanadium which is there by default.

SD card can be quite intelligent in what it shows to who. It's not very different to USB, it can even have a microchip. That's not even an airgap.

A well audited open source cable interface is quite ok. If you rely on user verifying there's no exploit, you've already lost. Security comes from no bugs, auditability of code and hardware, not from user doing bit by bit checks of every tx. They can, but the same way they can check every line of firmware. They won't. But others can check every line of firmware. Others can't check your every qr code (psbt).

My future man cave nostr:note1kee33rcg044ul8e3pz4h3quuzem7xqj4mn5vg72ac952ptyss29sg83dy7

Unfortunately, I declare Firefox for Android unusable at current state. It just stops working and rendering pages and needs complete reset after some time.

I'm not the only one with this problem.

Too bad, I've been using some extensions (although the problem occurs also without extensions) and I like the send tab to desktop feature and local on device translation.

Using Vanadium for now.

Hipster waves:

Mature - specialty coffee

Medium - matcha

Hot and emerging - sauna (Aufguss)

Replying to Avatar MattA

Look up daily withdrawal limits

Bankside, cardside and atm side.

Wifi router is almost next to your head. You are in bed and the router is on table next to bed.

What's the order of magnitude difference approximately?

A) You have a WiFi router next to your bed.

B) You have no WiFi and turn on your cell connection

You open your favorite Nostr app, laying on your bed and load your timeline. Without asking AI, which of these will give you more RF, why and what is the order of magnitude difference?

Sounds like central banks fixing the crisis. Only they have much less fuel left

Managing exposure means reducing exposure, i.e. distancing from it.

Spreading ideas is good, but it has two big problems:

1. It works much less than we would like to. The ideas of the state (collectivism) also spread and they spread better. Even if they spread enough, we're often overestimating our influence. It's the same on the other side of the aisle. Influencers trying to convince people to vote for the right party. How many people will actually go and do it, differently than they would have otherwise? I think the number is something like 1 in 10,000. It's all more about signaling. You listen to people they confirm what you already think.

2. It's sadly less about the ideas and more about the values. And changing values is super hard, they're almost hardwired. We are and will stay a minority. Maybe double digits percent wise if we're successful, but we have to accept that most people don't share are values and thus will never be receptive about our ideas.

I count myself among the privacy freaks. As I said, I use Monero myself.

But the point is - using Monero is more about signaling. "I am among you". It's no more private than lightning which is more widely adopted. But by using Monero, you show that privacy is important for you. That you are a privacy freak.

Another thing is that privacy is not normal. Normies don't want it. Certainly not if it causes them any inconvenience. That's why we are privacy freaks.

Monero is like wearing a privacy country club cap or polo shirt. We use it more to show off than for practical reasons.

There's this myth going around that all darknets are powered by XMR.

Trying to find one that actually works for research. Is there at least one functioning darknet that actually takes XMR? Link?